CBC Health News

New HIPAA FAQs Released by HHS in Response to Change Healthcare Cyber Attack

Jun 14, 2024

New HIPAA FAQs Released by HHS in Response to Change Healthcare Cyber Attack

 

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has updated its FAQ webpage following the Change Healthcare cybersecurity incident. First published on April 19, 2024, this page offers important information about the Health Insurance Portability and Accountability Act of 1996 (HIPAA) rules and the cybersecurity breach that affected Change Healthcare, a part of UnitedHealth Group (UHG), and many other healthcare organizations.

OCR enforces HIPAA's Privacy, Security, and Breach Notification Rules. These rules require covered entities—such as health plans, healthcare clearinghouses, and most healthcare providers—and their business associates to protect Personal Health Information (PHI). They also outline how to notify HHS and affected individuals if a breach happens. The updated FAQs help clarify these rules and offer guidance on handling and reporting cybersecurity incidents.

This blog covers recent HHS updates post-Change Healthcare cyber incident. It outlines HIPAA rules for PHI protection and offers breach notification guidance for healthcare.

HIPAA Breach Notification: FAQs Addressing Responsibility Updates

The FAQ updates clarify the responsibility for notifying HHS, affected individuals, and, when required, the media about breaches.

The FAQs specifically state that:

  • Covered entities impacted by the Change Healthcare breach can authorize Change Healthcare to manage breach notifications.
  • Only one entity, the covered entity or Change Healthcare, is responsible for issuing breach notifications.
  • Covered entities have no additional HIPAA breach notification obligations if Change Healthcare notifies breaches according to HIPAA Rules.

Fortifying Cybersecurity Protocols after the Change Healthcare Incident

Following the Change Healthcare cybersecurity incident, OCR urges HIPAA-covered entities such as health plans, insurers, healthcare providers, and their business partners to review their cybersecurity measures promptly. This ensures the protection of health information. While many employers may not directly handle PHI from their health plans, those engaging third-party vendors like Third-party Administrators (TPAs) and Pharmacy Benefit Managers (PBMs) should thoroughly assess and confirm these vendors' cybersecurity protocols during the selection process. Employers should also establish comprehensive business associate agreements that incorporate sufficient security safeguards for electronic PHI.

PROACTIVE MEASURES

Taking Action in Response to Cybersecurity Concerns

With OCR's emphasis on securing electronic PHI, employers should take the following actions:

  • Review Current Cybersecurity Measures: Employers accessing PHI from their health plans should consider their existing cybersecurity protocols and implement necessary updates to upgrade protection.
  • Evaluate Third-party Vendors: Even if they do not directly handle PHI, employers should examine the cybersecurity practices of prospective Third-party Administrators (TPAs) or Pharmacy Benefit Managers (PBMs) during the selection process.
  • Strengthen Business Associate Agreements: Employers must ensure that their agreements with business associates include strong security provisions to safeguard electronic PHI effectively.

COMPLIANCE SUPPORT

Accessible Resources for Every Business

Protecting PHI is a major focus for OCR. To assist covered entities and business associates in defending their systems against cyberattacks, OCR offers a range of resources, including:

Enhancing Healthcare Data Security:

Key Insights and Practical Measures for Safeguarding PHI with CBC

The recent updates from HHS and OCR regarding the Change Healthcare cyber incident highlight the importance of HIPAA compliance and cybersecurity in the healthcare sector. The FAQs provide valuable guidance on breach notification responsibilities, while OCR's focus on reviewing and enhancing cybersecurity measures reflects the urgency of protecting Personal Health Information (PHI).

Covered entities and their business associates should take proactive measures to strengthen cybersecurity protocols and ensure compliance with HIPAA rules. This includes reviewing current cybersecurity measures, evaluating third-party vendors' security practices, and enhancing business associate agreements. For additional support and resources, OCR offers various tools and guidance materials to help organizations safeguard electronic PHI and mitigate cyber threats effectively.

Custom Benefit Consultants (CBC), Inc. offers expert solutions and resources to help organizations strengthen cybersecurity and achieve HIPAA compliance. Our team of professionals specializes in providing user-friendly HIPAA compliance programs and guided security assessments. Contact us today to learn more about how we can assist you in safeguarding PHI and mitigating cyber threats effectively.

Recent Blog Posts:

Critical Illness Insurance: Top Reasons Families Should Consider

Why Families Should Consider Critical Illness Insurance - Top Reasons

Read More »
IRS Expands HDHP Preventive Care Benefits List

IRS Expands List of Preventive Care Benefits for HDHPs

Read More »
How Hospital Indemnity Insurance Can Improve Employee Satisfaction and Retention

How Hospital Indemnity Insurance Can Improve Employee Satisfaction and Retention

Read More »
Why Small Businesses Consider Level-funded Health Plans?

Why Small Businesses Should Consider Level-funded Health Plans

Read More »
Key Employee Loyalty Insights for Small Business Owners

What Employee Loyalty Reports Reveal for Small Business Owners: Top Insights

Read More »
How to Find the Best Health Insurance Companies for 2025

Find the Best Health Insurance Companies for 2025

Read More »
How Health Insurance Supports Large Group Workforce Success

How Comprehensive Health Insurance Benefits Enhance Large Group Workforce Success

Read More »
Blog Archives »


Kenneth Bahl

Kenneth Bahl

Kenneth Bahl is the President of Custom Benefit Consultants, Inc., where he has played a pivotal role in leading the company’s mission to create sustainable healthcare solutions that not only address modern challenges but also deliver meaningful savings. With over two decades of experience in the field, Kenneth’s expertise in benefits administration and employee benefits analysis has been instrumental in the company's success. Under his leadership, Custom Benefit Consultants, Inc. has become a trusted partner for employers seeking innovative solutions to meet the needs of their teams. In addition to his leadership role at Custom Benefit Consultants, Inc., Kenneth is also a key player at Control Source, Inc., where he has helped redefine administrative solutions for clients. Through the company’s advanced technology platform, which includes absence management, billing administration, and other dynamic services, Kenneth has enabled businesses to reduce legal risks, lower costs, and enhance operational efficiency. His work ensures that these scalable solutions seamlessly integrate with company culture and branding, positively impacting both employee experience and the company’s bottom line.

Education

Kenneth holds a degree in Healthcare Administration, which laid the foundation for his extensive career in the healthcare benefits sector. His academic background, combined with years of hands-on experience, has given him the expertise to navigate the complexities of employee benefits and help organizations optimize their benefits programs.

Personal Life

Outside of his professional endeavors, Kenneth enjoys a fulfilling family life. He values the balance between his dynamic career and his growing family, which now includes six grandchildren. This personal connection enriches his perspective on the importance of supporting individuals and organizations in ways that foster long-term success, well-being, and positive relationships

© 2025 CBC. All Rights Reserved. | Terms of Service | Privacy Policy | Interest-Based Ads | Data Requests

Language Assistance:

Spanish / Español
Russian / русский

Polish / Polskie

Japanese / 日本語

Chinese / 中文

French Creole-Haitian Creole / Franse - Kreyòl

Portuguese / Português

German / Deutsche

Vietnamese / Tiếng Việt

Arabic / العربية

French / Français

Persian-Farsi / فارسی

Korean / 한국어

Tagalog-Filipino

Italian / italiano

More Languages...

Attention: This website is operated by Custom Benefit Consultants, Inc. (CBC), Ken Bahl, NPN: 4579133 and is not the public Health Insurance Marketplace website available under the federal Affordable Care Act and related state laws. In offering this website, CBC is required to comply with all applicable federal laws, including the standards established under 45 CFR 155.220(c) and (d) and standards established under 45 CFR 155.260 to protect the privacy and security of personally identifiable information. This website may not display all data on Qualified Health Plans being offered in your state through the government's Health Insurance Marketplace website. To see all available data on Qualified Health Plan options in your state, go to the government's Health Insurance Marketplace website at HealthCare.gov.

Custom Benefit Consultants, Inc./CBC Benefit & Insurance Services are licensed insurance agents. Insurance plans are offered by licensed insurance companies or health maintenance organizations. Health insurance plans on the CBC Marketplace are brokered and /or serviced by CBC Benefit & Insurance Services; CA License #: 0D75486

If you would like assistance in another language, please visit Healthcare.gov or contact us at (855) 332-3821 to access our language line.

All insurance products are issued by licensed insurance companies and made available to applicants through Custom Benefit Consultants, Inc./CBC Benefit & Insurance Services, which receives a commission from insurers to distribute these products. Your insurance policy, not the information on this site, determine the applicable terms and conditions of the insurance product. Neither Custom Benefit Consultants, Inc./CBC Benefit & Insurance Services nor its affiliates guarantee the services of any insurance company.

Read more