Editor’s Note: The massive data breach impacting 190 million Americans through UnitedHealth’s Change Healthcare division underscores the critical vulnerabilities in healthcare cybersecurity. As one of the most extensive breaches in U.S. history, this incident highlights the urgent need for stronger
A Flurry of Healthcare Sector Cybersecurity Regulatory Developments in 2024
2024 was a record year for cyberattacks in the healthcare sector. According to the Breach Portal maintained by the U.S. Department of Health and Human Services (“HHS”) Office of Civil Rights (“OCR”), to date this year, there have been more…
HIPAA Gets a Potential Counterpart in HISAA
How Secure is Your Health Data and Why Does it Matter?
@media screen and (max-width: 1023px){section[data-id=”block_c1d63bbc27697d9a41de1aa79a5758f1″]{ }}@media screen and (min-width: 1024px) and (max-width: 1365px){section[data-id=”block_c1d63bbc27697d9a41de1aa79a5758f1″]{ }}@media screen and (min-width: 1366px){section[data-id=”block_c1d63bbc27697d9a41de1aa79a5758f1″]{ }}
…
Massive Data Breach at Change Healthcare Highlights Critical Cybersecurity Flaws
Editor’s Note: This article covers the recent landmark ransomware attack on Change Healthcare, a UnitedHealth Group unit, which exposed sensitive health and personal information for over 100 million Americans. This breach, executed by the ALPHV/BlackCat ransomware group, has become the…
CMS Announces 120-day Exception Period for No Surprises Act Independent Dispute Resolution
Under the No Surprises Act, “open negotiation” is the period of time during which payers must disclose to providers important information regarding the claim at issue. On June 14, 2024, CMS announced a 120-calendar-day exception period, the open negotiation period…
2024 HIPAA Developments
Over the course of the past few months, the Office of Civil Rights (OCR) and the Office of the National Coordinator for Health Information Technology (ONC), both of which are divisions of the U.S. Department of Health and Human Services…
2024 HIPAA Developments
Over the course of the past few months, the Office of Civil Rights (OCR) and the Office of the National Coordinator for Health Information Technology (ONC), both of which are divisions of the U.S. Department of Health and Human Services…
Who’s On First? Confusion Continues About Who Should be Reporting the Change Healthcare PHI Breaches
On May 31, 2024, the Office of Civil Rights (OCR) released “updates” to its HIPAA FAQs regarding the Change Healthcare cybersecurity incident. In its Press Release, OCR pointed out that it updated its FAQs to specifically address questions it…
Form 8-K and Cybersecurity Events
When a company experiences a cybersecurity incident it must make a complex materiality judgment to determine if an Item 1.05 Form 8-K is required. The Form 8-K instructions state:
Item 1.05 Material Cybersecurity Incidents.
-
-
- If the registrant experiences a cybersecurity
-
…








