Feds Clarify Responsibilities For Data Breach Notification Related To Change Healthcare Cyber-Attack
On May 31, 2024, the Office of Civil Rights (OCR) within the federal Department of Human Services (HHS) clarified which entities are responsible for performing data breach notifications related to the Change Healthcare cyber-attack in late February 2024. The clarification pertains to the requirements of the Health Insurance Portability and Accountability Act (HIPAA) that covered entities notify HHS, affected individuals, and in some cases, the media in the case of a data breach.
In the FAQ, OCR noted the following:
Covered entities affected by the Change Healthcare breach may delegate to Change Healthcare the tasks of providing the required . . .