Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Cyberattack Threats Represent Significant Risk for Hospitals and Healthcare Entities

By John W. Kaveney & Meredith C. Sherman on June 19, 2022
Email this postTweet this postLike this postShare this post on LinkedIn

In light of the ongoing conflict in Ukraine and the consequential global impacts and destabilization, the Department of Health and Human Services (HHS) continues to caution about escalating threats of cyberattacks. In early March 2022, HHS issued a bulletin warning those in the U.S. healthcare sector of the potential threats of cyberattacks by Russia and those aligned with it.

In particular, HHS warned of threats by one of the most prominent cybercriminal groups to publicly support Russia, the Conti ransomware operators. Historically, this group has been known to target U.S. healthcare organizations with threats including Managed Service Provider compromises, big game hunting, multi-stage attacks (leveraging other malpractice variants as part of the attack), and double and triple extortion (data theft combined with a ransomware attack). Healthcare providers of all sizes and types should therefore continue to be familiar with the various types of potential attacks, which are discussed in the HHS bulletin.

To assist our healthcare sector clients, we have previously written about steps taken by the federal government to help private entities stay vigilant, including the passage of the Strengthening American Cybersecurity Act and the Statement by President Biden on our Nation’s Cybersecurity. Entities in the healthcare sector would be well advised to remain on guard and continue to implement protocols and other measures to protect their organizations from cyberattacks.

Photo of John W. Kaveney John W. Kaveney

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory…

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory support. He represents a diverse roster of healthcare entities, including for-profit and nonprofit hospitals and health systems, academic medical centers, individual physicians and physician groups, ambulatory surgery centers, ancillary service providers, medical billing companies, skilled nursing and rehabilitation facilities, behavioral health centers and pharmacies.

John advises on Medicaid reimbursement matters before the New Jersey Division of Medical Assistance and Health Services (DMAHS), which administers the state’s Medicaid programs, and handles Medicare reimbursement disputes, both in New Jersey and in numerous other states, before the federal Provider Reimbursement Review Board (PRRB).

In the area of corporate compliance, John supports clients on matters including the implementation of new, and the assessment and improvement of existing, compliance programs. He assists healthcare clients in navigating compliance audits, internal investigations, and governmental investigations related to compliance issues, including potential violations of the federal Stark Law, Anti-Kickback Statute (AKS), and Civil Monetary Penalties law (CMP). He further provides general guidance concerning compliance and regulatory matters under state and federal healthcare laws.

On issues related to information privacy and cybersecurity at the intersection of healthcare law, John assists providers with issues arising under the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH). This includes the implementation and assessment of privacy and security policies and procedures to ensure the proper protection and utilization of protected health information (PHI) both by healthcare providers and the business associates with which they contract. In addition, he represents healthcare clients in investigating, reporting, and remediating information breaches and the liability such breaches create under various information privacy and security laws.

John also counsels healthcare providers with professional licensure issues and advises hospitals and health systems regarding their medical staff bylaws and corresponding policies and procedures, as well as assisting with internal investigations of medical staff members and the corresponding disciplinary process. He further provides legal guidance related to New Jersey’s involuntary commitment laws, and provides representation in civil litigation.

John serves as Editor-In-Chief of Healthcare Perspectives, Greenbaum’s blog covering issues of interest to the healthcare industry.

Results may vary depending on your particular facts and legal circumstances.

Contact information:

jkaveney@greenbaumlaw.com | 973.577.1796 | vCard | LinkedIn

For more information visit the Greenbaum, Rowe, Smith & Davis LLP website.

Read more about John W. KaveneyEmail
Show more Show less
Photo of Meredith C. Sherman Meredith C. Sherman

Partner, Litigation

Meredith assists clients in navigating complex, commercial litigation including shareholder disputes, securities litigation, business valuation disputes, construction cases, condominium cases, employment matters and financial services matters.

She takes a comprehensive and multi-faceted approach to representing clients engaged in a broad range

…

Partner, Litigation

Meredith assists clients in navigating complex, commercial litigation including shareholder disputes, securities litigation, business valuation disputes, construction cases, condominium cases, employment matters and financial services matters.

She takes a comprehensive and multi-faceted approach to representing clients engaged in a broad range of industries, including the manufacturing, construction, pharmaceutical, higher education, investment, and brokerage sectors.

Meredith’s experience includes supporting banking clients in investigations related to global regulatory sanctions, anti-money laundering compliance, alleged manipulation of benchmark interest rates, and in a broad range of government inquiries and subpoena responses.

Results may vary depending on your particular facts and legal circumstances.

Contact information:

msherman@greenbaumlaw.com | 732.476.2672 | vCard  | LinkedIn

For more information visit the Greenbaum, Rowe, Smith & Davis LLP website.

Email
Show more Show less
  • Posted in:
    Health Care and Life Sciences
  • Blog:
    Healthcare Perspectives
  • Organization:
    Greenbaum, Rowe, Smith & Davis LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo