HHS OCR Settles Four HIPAA Ransomware Investigations Affecting More Than 427,000 Individuals
The U.S. Department of Health and Human Services Office for Civil Rights, also known as OCR, has announced four separate HIPAA settlements involving ransomware breaches. Together, these breaches affected more than 427,000 people and exposed unsecured electronic protected health information, also called ePHI. These settlements are an important reminder for healthcare providers, health plans, healthcare clearinghouses, and business associates. Ransomware is not just an information technology problem. It is also a HIPAA compliance problem when patient or member information is placed at risk. Ransomware is a type of malicious software that can lock or encrypt an organization’s data. The attacker then [...]