HHS Workplace for Civil Rights Creates FAQ Webpage in Response to the Change Healthcare Cyberattack

on

|

views

and

comments


Right now, the U.S. Division of Well being and Human Companies (HHS) Workplace for Civil Rights (OCR) posted a brand new webpage to share solutions to regularly requested questions (FAQs) regarding the Well being Insurance coverage Portability and Accountability Act of 1996 (HIPAA) Guidelines and the cybersecurity incident impacting Change Healthcare, a unit of UnitedHealth Group (UHG), and plenty of different well being care entities. The cyberattack is disrupting well being care and billing data operations nationwide and poses a direct risk to critically wanted affected person care and important operations of the well being care business.

OCR enforces the HIPAA Privateness, Safety, and Breach Notification Guidelines, which units forth the necessities that HIPAA lined entities (most well being care suppliers, well being plans, and well being care clearinghouses) and their enterprise associates should comply with to guard the privateness and safety of protected well being data and the required notifications to HHS and affected people following a breach.

The webpage solutions questions and supplies useful data on many matters, together with:

  • Why did OCR concern the March 13, 2024, “Pricey Colleague Letter”?
  • Why is OCR initiating an investigation and what does it cowl?
  • Has OCR obtained breach experiences from Change Healthcare, UHG, or any affected well being care suppliers?
  • Are giant breaches (these affecting 500 or extra people) posted on the HHS Breach Portal on the identical day that OCR receives a regulated entity’s breach report?
  • Is OCR’s 2016 ransomware steering relevant to the Change Healthcare cyberattack?
  • Are lined entities which are affected by the cyberattack involving Change Healthcare and UHG required to file breach notifications?
  • What HIPAA breach notification duties do lined entities have with respect to the Change Healthcare cyberattack?
  • What HIPAA breach notification duties do enterprise associates have with respect to the Change Healthcare cyberattack?

The brand new FAQs on the Change Healthcare Cybersecurity Incident could also be considered at: https://www.hhs.gov/hipaa/for-professionals/special-topics/change-healthcare-cybersecurity-incident-frequently-asked-questions/index.html

The HHS Breach Portal: Discover to the Secretary of HHS Breach of Unsecured Protected Well being Info could also be discovered at: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf

OCR is dedicated to implementing the HIPAA Guidelines that shield the privateness and safety of peoples’ well being data. Steerage concerning the Privateness RuleSafety Rule, and Breach Notification Guidelines will also be discovered on OCR’s web site.

If you happen to consider that your or one other particular person’s well being data privateness or civil rights have been violated, you’ll be able to file a grievance with OCR at https://www.hhs.gov/ocr/complaints/index.html.

Share this
Tags

Must-read

Books I Learn & Beloved in 2024

Inside: In case you’re in search of a brand new learn (or an excellent reward for somebody), listed below are the books I...

Ep257: 6 Easy Mineral Hacks for Perimenopause: Add These to Your Weight-reduction plan and Really feel Higher Quick

In this episode, Tina dives into the necessary position minerals play throughout perimenopause, specializing in how they help vitality, metabolism, and total well-being....

Revamped Cervélo P-Sequence UCI TT & Tri Bike Will get French Painter-Impressed Restricted Version

Help us! Bikerumor might earn a small fee from affiliate hyperlinks on this article. Be taught Extra Cervélo simply rolled out a flashy restricted version...

Recent articles

More like this

LEAVE A REPLY

Please enter your comment!
Please enter your name here