The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has updated its FAQ webpage following the Change Healthcare cybersecurity incident. First published on April 19, 2024, this page offers important information about the Health Insurance Portability and Accountability Act of 1996 (HIPAA) rules and the cybersecurity breach that affected Change Healthcare, a part of UnitedHealth Group (UHG), and many other healthcare organizations.
OCR enforces HIPAA's Privacy, Security, and Breach Notification Rules. These rules require covered entities—such as health plans, healthcare clearinghouses, and most healthcare providers—and their business associates to protect Personal Health Information (PHI). They also outline how to notify HHS and affected individuals if a breach happens. The updated FAQs help clarify these rules and offer guidance on handling and reporting cybersecurity incidents.
This blog covers recent HHS updates post-Change Healthcare cyber incident. It outlines HIPAA rules for PHI protection and offers breach notification guidance for healthcare.
The FAQ updates clarify the responsibility for notifying HHS, affected individuals, and, when required, the media about breaches.
The FAQs specifically state that:
Following the Change Healthcare cybersecurity incident, OCR urges HIPAA-covered entities such as health plans, insurers, healthcare providers, and their business partners to review their cybersecurity measures promptly. This ensures the protection of health information. While many employers may not directly handle PHI from their health plans, those engaging third-party vendors like Third-party Administrators (TPAs) and Pharmacy Benefit Managers (PBMs) should thoroughly assess and confirm these vendors' cybersecurity protocols during the selection process. Employers should also establish comprehensive business associate agreements that incorporate sufficient security safeguards for electronic PHI.
Taking Action in Response to Cybersecurity Concerns
With OCR's emphasis on securing electronic PHI, employers should take the following actions:
Accessible Resources for Every Business
Protecting PHI is a major focus for OCR. To assist covered entities and business associates in defending their systems against cyberattacks, OCR offers a range of resources, including:
The recent updates from HHS and OCR regarding the Change Healthcare cyber incident highlight the importance of HIPAA compliance and cybersecurity in the healthcare sector. The FAQs provide valuable guidance on breach notification responsibilities, while OCR's focus on reviewing and enhancing cybersecurity measures reflects the urgency of protecting Personal Health Information (PHI).
Covered entities and their business associates should take proactive measures to strengthen cybersecurity protocols and ensure compliance with HIPAA rules. This includes reviewing current cybersecurity measures, evaluating third-party vendors' security practices, and enhancing business associate agreements. For additional support and resources, OCR offers various tools and guidance materials to help organizations safeguard electronic PHI and mitigate cyber threats effectively.
Custom Benefit Consultants (CBC), Inc. offers expert solutions and resources to help organizations strengthen cybersecurity and achieve HIPAA compliance. Our team of professionals specializes in providing user-friendly HIPAA compliance programs and guided security assessments. Contact us today to learn more about how we can assist you in safeguarding PHI and mitigating cyber threats effectively.
Kenneth Bahl is the President of Custom Benefit Consultants, Inc., where he has played a pivotal role in leading the company’s mission to create sustainable healthcare solutions that not only address modern challenges but also deliver meaningful savings. With over two decades of experience in the field, Kenneth’s expertise in benefits administration and employee benefits analysis has been instrumental in the company's success. Under his leadership, Custom Benefit Consultants, Inc. has become a trusted partner for employers seeking innovative solutions to meet the needs of their teams. In addition to his leadership role at Custom Benefit Consultants, Inc., Kenneth is also a key player at Control Source, Inc., where he has helped redefine administrative solutions for clients. Through the company’s advanced technology platform, which includes absence management, billing administration, and other dynamic services, Kenneth has enabled businesses to reduce legal risks, lower costs, and enhance operational efficiency. His work ensures that these scalable solutions seamlessly integrate with company culture and branding, positively impacting both employee experience and the company’s bottom line.
Kenneth holds a degree in Healthcare Administration, which laid the foundation for his extensive career in the healthcare benefits sector. His academic background, combined with years of hands-on experience, has given him the expertise to navigate the complexities of employee benefits and help organizations optimize their benefits programs.
Outside of his professional endeavors, Kenneth enjoys a fulfilling family life. He values the balance between his dynamic career and his growing family, which now includes six grandchildren. This personal connection enriches his perspective on the importance of supporting individuals and organizations in ways that foster long-term success, well-being, and positive relationships