OCR Announces Third Ransomware Settlement as Threats Continue to Rise

Rivkin Radler LLP
Contact

Rivkin Radler LLP

 

On July 1, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced that Heritage Valley Health System, a provider in Pennsylvania, Ohio and West Virginia, agreed to pay $950,000 to resolve potential violations of the HIPAA Security Rule. Heritage Valley’s alleged violations included failure to conduct a risk analysis to determine potential risks and vulnerabilities to electronic protected health information (ePHI), failure to implement a contingency plan to respond to emergencies, and failure to implement policies to allow only authorized users to access ePHI.

As part of the settlement, Heritage Valley must implement a corrective action plan that will be monitored by OCR for three years, and must resolve the potential violations identified by OCR.

Providers should take heed that if an organization is the subject of a bad actor’s cyberattack, the responsibility ultimately remains with the covered entity and its business associates to ensure that adequate safeguards and preventive measures are in place and to respond appropriately to each contingency. OCR investigates all HIPAA breaches affecting more than 500 individuals and some breaches affecting fewer, and providers should be proactive and ready to show OCR all of the measures they have taken to prevent such an attack.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Rivkin Radler LLP

Written by:

Rivkin Radler LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Rivkin Radler LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide