The Office for Civil Rights recently announced settlements with four individual practices for $1,165,000 ($225,000 to $375,000 per practice) due to ransomware attacks, which, collectively exposed the PHI of over 427,000 patients. See OCR Settles Four Ransomware Investigations. Learning from the mistakes of others is a valuable tool. In each practice presented, the Government highlights each practices' failure to foresee and forestall with proper safeguards, notably, after each practice had engaged in self-reporting...
"Regional Women’s Health Group, LLC (“RWHG”), doing business as Axia Women’s Health, is a network of women’s health care providers in New Jersey, Pennsylvania, Ohio, Indiana, and Kentucky. The ransomware breach affected 37,989 individuals. The types of ePHI affected by the breach included names, addresses, dates of birth, SSNs, driver’s license numbers, diagnoses or conditions, lab results, and medications. RWHG reported in December 2020 that an unauthorized third-party gained access to its IT network and potentially exfiltrated data from RWHG’s electronic medical record database housing patient ePHI. OCR’s investigation found that RWHG failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI. In addition to committing to corrective actions, RWHG paid $320,000 to OCR.
Assured Imaging Affiliated Covered Entities (“Assured Imaging”) is a medical imaging and screening service provider with corporate headquarters in Arizona and California. The ransomware breach affected 244,813 individuals. The types of affected ePHI included patient names, addresses, dates of birth, diagnosis and conditions, lab results, medications, and treatment information. Assured Imaging reported in May 2020 that a server on its network was infected with ransomware. OCR’s investigation determined that Assured Imaging had impermissibly disclosed PHI, failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI, and failed to timely notify affected individuals of the breach. In addition to committing to corrective actions, Assured Imaging paid $375,000 to OCR.
Consociate, Inc., doing business as Consociate Health (“Consociate”) is a third-party administrator of employee-sponsored benefit programs that provides health plan administration, plan analytics and consulting services to HIPAA covered entities as a business associate. Approximately 136,539 individuals were affected by the ransomware breach. Affected ePHI included names, addresses, dates of birth, driver’s license numbers, SSNs, credit card/bank account numbers, and diagnoses or conditions. Consociate reported in November and December 2021 that some of its information systems had been encrypted in a ransomware attack. Consociate subsequently learned that, after a successful phishing attack in July 2020, the threat actor gained access to a server that held ePHI. OCR’s investigation determined that Consociate had failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by Consociate. In addition to committing to corrective actions, Consociate paid $225,000 to OCR.
Star Group, L.P. Health Benefits Plan (“SG Health Plan”) is the self-funded employee benefits plan of a Connecticut-based energy provider. About 9,316 individuals were affected by the ransomware breach. Affected ePHI included names, addresses, dates of birth, SSNs, and health insurance information, such as member identification numbers, claims data, and benefit selection information. SG Health Plan reported in October 2021 that an unauthorized actor deployed ransomware on SG Health Plan’s information system and exfiltrated PHI. OCR’s investigation determined that SG Health Plan had impermissibly disclosed PHI and failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI. In addition to committing to corrective actions, SG Health Plan paid $245,000 to OCR."
See - https://www.hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html.
Notably, OCR has recognized ransomware as the most frequently reported breach, and is actively monitoring and fining practices who are not properly protecting their patient information. To be clear on what "Ransomware" is - for those who are unfamiliar, it is exactly what the name suggests - you are held ransom by hackers accessing your system and holding you hostage from it - often times demanding payment before they give you the "key" or code to access your own system - different than a straight up theft, where they steal data and threaten to or actually leak that data somewhere - usually the dark web - a real cyber location.
Okay, so what can you do? First, DO NOT pay or negotiate with the hackers – there may be no real way to discern 100% what they have accessed / stolen / exposed. Instead, report. Immediately, to the appropriate authorities.
Second, contact your IT support and attorney, immediately - same time as step 1. Depending on the threat, we will develop a proper response.
How can you be proactive and avoid entirely? Good question, and, unfortunately, the "avoid entirely", is not a guarantee, however, we can certainly provide guidance that will SIGNIFICANTLY reduce your exposure.
Start by reviewing your current security measures. Practices often become victims of ransomware attacks where they fail to proactively implement safeguards outlined in the HIPAA security rule, or to conduct routine maintenance to ensure those safeguards are still actively working as intended.
This means:
Conducting routine security assessments to determine potential risks and vulnerability of your online systems – these assessment must be documented to keep track of your compliance and changes in security measures.
Develop, implement, and maintain a risk management plan to address identified risks and vulnerabilities – this is usually where we also include emergency protocols in the case of breach (i.e., server or website is placed in maintenance mode, and all access is restricted until the system is reconfigured and protected)
Ensure all transmissions of PHI (yes, even via e-mail) are encrypted.
Provide all team members HIPAA training on the Practices specific policies for protection of PHI – training should be provided annually, and where a breach is due to an employee (i.e., took picture where patient information was seen, sent e-mail to wrong patient, etc.)
Having qualified and competent IT vendors (who are familiar with HIPAA and the requirements of the Security Rule) – IT will ensure your online platforms are properly protected (authentication, proper firewalls, backup systems, emergency protocols, etc).
Having proper Insurance - Cyber insurance provides coverage for the exact scenarios we are describing, and I recommend you confirm you are covered. This is a key insurance product recommended for all practices!
Reality - there are no guarantees against a cyber attack, however, you can limit your exposure. Happy to connect and talk through next steps if you are looking for a place to start... If this is NOT a familiar topic, call to set up a free 15 minutes with us to start a walk through. Check out the HealthIT website as a first stop - https://healthit.gov/privacy-security/security-risk-assessment-tool/.
