Right now, the U.S. Division of Well being and Human Providers (HHS) Workplace for Civil Rights (OCR) posted a brand new webpage to share solutions to ceaselessly requested questions (FAQs) in regards to the Well being Insurance coverage Portability and Accountability Act of 1996 (HIPAA) Guidelines and the cybersecurity incident impacting Change Healthcare, a unit of UnitedHealth Group (UHG), and plenty of different well being care entities. The cyberattack is disrupting well being care and billing info operations nationwide and poses a direct menace to critically wanted affected person care and important operations of the well being care business.
OCR enforces the HIPAA Privateness, Safety, and Breach Notification Guidelines, which units forth the necessities that HIPAA coated entities (most well being care suppliers, well being plans, and well being care clearinghouses) and their enterprise associates should comply with to guard the privateness and safety of protected well being info and the required notifications to HHS and affected people following a breach.
The webpage solutions questions and offers useful info on many subjects, together with:
- Why did OCR difficulty the March 13, 2024, “Expensive Colleague Letter”?
- Why is OCR initiating an investigation and what does it cowl?
- Has OCR acquired breach experiences from Change Healthcare, UHG, or any affected well being care suppliers?
- Are giant breaches (these affecting 500 or extra people) posted on the HHS Breach Portal on the identical day that OCR receives a regulated entity’s breach report?
- Is OCR’s 2016 ransomware steering relevant to the Change Healthcare cyberattack?
- Are coated entities which might be affected by the cyberattack involving Change Healthcare and UHG required to file breach notifications?
- What HIPAA breach notification duties do coated entities have with respect to the Change Healthcare cyberattack?
- What HIPAA breach notification duties do enterprise associates have with respect to the Change Healthcare cyberattack?
The brand new FAQs on the Change Healthcare Cybersecurity Incident could also be considered at: https://www.hhs.gov/hipaa/for-professionals/special-topics/change-healthcare-cybersecurity-incident-frequently-asked-questions/index.html
The HHS Breach Portal: Discover to the Secretary of HHS Breach of Unsecured Protected Well being Info could also be discovered at: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
OCR is dedicated to implementing the HIPAA Guidelines that defend the privateness and safety of peoples’ well being info. Steering concerning the Privateness Rule, Safety Rule, and Breach Notification Guidelines can be discovered on OCR’s web site.
In the event you imagine that your or one other particular person’s well being info privateness or civil rights have been violated, you’ll be able to file a criticism with OCR at https://www.hhs.gov/ocr/complaints/index.html.
GIPHY App Key not set. Please check settings