decisionhealth Newsletters, Part B News - 2016 Issue 8 (August)
OCR: Ransomware attack is presumed a reportable breach under HIPAA
Subscribe or sign in to view the full article.
Article Overview
This article covers federal HIPAA guidance on ransomware incidents, including how the Office for Civil Rights views these attacks, when a risk analysis may be required, and how breach notification and security rule considerations can come into play. It is relevant for health care providers, compliance teams, privacy and security officers, and business associates who need to understand the general reporting and risk-management implications of a ransomware event.
Why This Topic Matters
Ransomware incidents can trigger privacy, security, and notification responsibilities under HIPAA, affecting compliance workflows, incident response, and organizational risk. The article helps readers understand why these events are treated as high-priority legal and operational matters in health care.
What You Will Learn
- How federal HIPAA guidance addresses ransomware incidents
- Why ransomware events may be evaluated as potential breaches
- What broad factors are considered in a HIPAA risk analysis
- How breach notification and security rule responsibilities can be implicated
- Why encrypted or otherwise secured information is treated differently under the guidance
Who Should Read This
- Health care providers
- Covered entities
- Business associates
- HIPAA compliance staff
- Privacy officers
- Security officers
- Health information management professionals
- Healthcare legal counsel
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com