Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

OCR Reminds Providers of the Significant Threat of Cyber-Attacks and Provides Helpful Overview of Key Security Factors to Keep in Mind

By John W. Kaveney on November 7, 2022
Email this postTweet this postLike this postShare this post on LinkedIn

In recognition of National Cybersecurity Awareness Month, the Office of Civil Rights (OCR) issued its October 2022 Cybersecurity Newsletter addressing best practices and tips for compliance with HIPAA’s Security Rule. The Newsletter discussed the ever-increasing need for members of the healthcare industry to be vigilant in their practices, as research shows a 42% increase in cyber-attacks in the first half of 2022 compared to 2021, and a 69% increase in cyber-attacks targeting the healthcare sector alone. Moreover, OCR reported that in 2021, 74% of the reported breaches involved hacking/IT incidents. As a result, OCR has identified hacking as the greatest threat to the privacy and security of protected health information (PHI) in the healthcare sector.

These statistics underscore the importance of providers ensuring that their HIPAA programs are in full compliance with the law. OCR notes the significance of entities ensuring they have sufficient plans in place to: (1) identify security incidents; (2) respond to security incidents; (3) mitigate harmful effects of security incidents; and (4) document security incidents and their outcomes in compliance with the HIPAA Security Rules. The Newsletter provides helpful summaries of key items to keep in mind when planning to address each of these key tasks.

Moreover, the OCR underscores the importance of forming a security incident response team prior to the identification of a potential cybersecurity incident or breach. Having a trained and organized team is critical to ensure that when an incident does occur, as is almost certain in any organization, the team is prepared to take action with an appropriate and timely response.

When forming a security incident response team, factors that should be considered in identifying a well-rounded group include sufficient expertise, those with sufficient lines of communication to key individuals, ensuring key internal groups are represented (i.e., management, IT, legal, public affairs, etc.), and identifying key services that the team will need to provide as part of their duties.

The value of a well-prepared security incident response protocol is best summed up in the Newsletter’s conclusion, which states, “The policies and procedures regulated entities create to prepare for and respond to security incidents can pay dividends in the long run with faster recovery times and reduced compromises of ePHI. A well thought-out, well-tested security incident response plan is integral to ensuring the confidentiality, integrity, and availability of a regulated entity’s ePHI.”

With the pandemic, the struggling economy, and so many other issues impacting providers and consuming their daily attention, it is easy to become complacent and/or overlook the constant threats that cyber-attacks pose to the healthcare sector. The OCR’s Newsletter serves as a key reminder of that threat and provides a helpful overview of key areas for providers to review in assessing the sufficiency of their respective HIPAA programs.

Photo of John W. Kaveney John W. Kaveney

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory…

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory support. He represents a diverse roster of healthcare entities, including for-profit and nonprofit hospitals and health systems, academic medical centers, individual physicians and physician groups, ambulatory surgery centers, ancillary service providers, medical billing companies, skilled nursing and rehabilitation facilities, behavioral health centers and pharmacies.

John advises on Medicaid reimbursement matters before the New Jersey Division of Medical Assistance and Health Services (DMAHS), which administers the state’s Medicaid programs, and handles Medicare reimbursement disputes, both in New Jersey and in numerous other states, before the federal Provider Reimbursement Review Board (PRRB).

In the area of corporate compliance, John supports clients on matters including the implementation of new, and the assessment and improvement of existing, compliance programs. He assists healthcare clients in navigating compliance audits, internal investigations, and governmental investigations related to compliance issues, including potential violations of the federal Stark Law, Anti-Kickback Statute (AKS), and Civil Monetary Penalties law (CMP). He further provides general guidance concerning compliance and regulatory matters under state and federal healthcare laws.

On issues related to information privacy and cybersecurity at the intersection of healthcare law, John assists providers with issues arising under the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH). This includes the implementation and assessment of privacy and security policies and procedures to ensure the proper protection and utilization of protected health information (PHI) both by healthcare providers and the business associates with which they contract. In addition, he represents healthcare clients in investigating, reporting, and remediating information breaches and the liability such breaches create under various information privacy and security laws.

John also counsels healthcare providers with professional licensure issues and advises hospitals and health systems regarding their medical staff bylaws and corresponding policies and procedures, as well as assisting with internal investigations of medical staff members and the corresponding disciplinary process. He further provides legal guidance related to New Jersey’s involuntary commitment laws, and provides representation in civil litigation.

John serves as Editor-In-Chief of Healthcare Perspectives, Greenbaum’s blog covering issues of interest to the healthcare industry.

Results may vary depending on your particular facts and legal circumstances.

Contact information:

jkaveney@greenbaumlaw.com | 973.577.1796 | vCard | LinkedIn

For more information visit the Greenbaum, Rowe, Smith & Davis LLP website.

Read more about John W. KaveneyEmail
Show more Show less
  • Posted in:
    Health Care and Life Sciences, Privacy and Cybersecurity
  • Blog:
    Healthcare Perspectives
  • Organization:
    Greenbaum, Rowe, Smith & Davis LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo