Ep. 19 - What to Do When Your Business Associate Suffers a Ransomware Attack

Dentons
Contact

Dentons

A Decision-Tree for Evaluating Your HIPAA Reporting Obligations

Please see Podcast here.

The healthcare industry remains a popular target for ransomware attacks. If you haven’t been impacted by a ransomware attack, it’s likely only a matter of time before someone you do business with or buy services from is impacted.

Ransomware attacks present some unique issues when it comes to HIPAA breach reporting, including whether a breach has occurred and whether it’s reportable to regulators and patients. When the ransomware attack affects your business associate, it may be months before you’re provided with information relating to the attack, and the information you are provided with may be limited. Yet, as the covered entity, HIPAA makes it your responsibility to assess whether a breach has occurred and if so, whether it’s required to be reported to regulators, patients, and in some cases, the media.

We frequently receive inquiries from providers who have received communications from their business associates notifying them that a ransomware attack has occurred but take the position the attack did not result in a reportable breach. Providers receiving this type of communication may be tempted to rely on their business associate’s assessment and conclude no further action is needed. However, doing so poses a risk to the provider as the covered entity who is ultimately responsible for ensuring reportable breaches are appropriately reported.

What should a provider do in this circumstance? The one thing it should NOT do is do nothing. When a provider receives this type of communication, it should conduct its own analysis and risk assessment, making sure to document its rationale and decision-making. Check out this week’s podcast, and our free decision-tree resource below, for how to evaluate whether a ransomware attack suffered by a business associate is a reportable breach under HIPAA.

Ransomware-Breach-Decision-Tree

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Dentons | Attorney Advertising

Written by:

Dentons
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Dentons on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide