cognitive cybersecurity intelligence

News and Analysis

Search

Change Healthcare has responsibility to notify patients data breach, says OCR

The US Department of Health and Human Services’ Office for Civil Rights (OCR) has updated its FAQ page on Change Healthcare’s cybersecurity incident, reiterating that affected individuals must be informed about the breach. It also said that only one entity needs to issue breach notifications, preventing duplicative letters. This follows a cyber attack on UnitedHealth Group. The Federal Trade Commission is considering expanding its Health Breach Notification Rule to cover previously exempt entities.

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts