OCR Releases Checklist On What To Do Following A Cyber Attack

Harris Beach Murtha PLLC
Contact

Since the WannaCry ransomware virus spread rapidly across the globe, businesses, both large and small, are again focusing on cyber-security. In a previous bulletin, we detailed five things that a business can do to help prevent a cyber-attack. However, in the unfortunate event that your business experiences a cyber-attack affecting protected health information, this bulletin provides guidance from the Department of Health and Human Services Office for Civil Rights ("OCR") regarding what you must do.

On June 8, 2017, OCR released a checklist for covered entities and business associates (together referred to as "entities" herein) to use when responding to a cyber-attack. While some might find the checklist to be very simple, it does two important things:

  • Serves as a reminder that OCR is taking cyber-attacks on protected health information very seriously; and
  • Serves as a further reminder to entity leadership that taking certain steps following a cyber-attack is essential to minimizing the entity’s exposure.

If ever investigated, OCR will consider all of an entity’s mitigation efforts and will certainly begin by making sure an entity "checked all boxes" on the checklist, as appropriate. In short, this checklist provides that entities:

  • Must execute their response and mitigation procedures and contingency plans;
  • Should report the crime to appropriate law enforcement agencies;
  • Should report all cyber threat indicators to federal and information-sharing and analysis organizations; and
  • Must report the breach to affected individuals, OCR and the media, if appropriate, within the prescribed time frames.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Harris Beach Murtha PLLC

Written by:

Harris Beach Murtha PLLC
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Harris Beach Murtha PLLC on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide