Employer health plans face HIPAA fallout after ransomware breaches
Two settlements recently announced by the US Department of Health and Human Services’ Office for Civil Rights send a clear message to employer-sponsored group health plans: Ransomware attacks may originate outside the organization, but HIPAA accountability remains within it.
Both cases involve employer-sponsored group health plans that were victims of ransomware attacks that led to the breach of electronic protected health information (ePHI). In each case, some 10,000 individuals were affected. The information exposed included names, addresses, dates of birth, Social Security numbers, health insurance information, member identification numbers, claims data, and benefit selection information.
OCR’s investigations found that the self-funded plans failed to conduct an accurate and thorough risk analysis to identify potential risks and vulnerabilities around the confidentiality, integrity, and availability of the ePHI. Both faced financial penalties — one agreed to pay $450,000, and the other agreed to pay $245,000. Both also entered into a two-year corrective action plan requiring OCR oversight of risk analysis, policies and procedures, training, and related compliance measures.
These settlements signal a notable enforcement focus on health plans’ HIPAA obligations to mitigate cyber risks. While OCR routinely enters into settlement agreements with other HIPAA-regulated entities, enforcement actions against employer-sponsored group health plans remain relatively rare, making these developments especially noteworthy for plan sponsors.
These cases serve as a reminder that HIPAA requires employer plan sponsors to conduct and document a risk analysis identifying where ePHI may be located within the organization and to develop an effectively designed risk management plan. Even when a breach is caused by a malicious actor, OCR expects the plan to have had sufficient safeguards in place before the incident occurred.
OCR recommends that regulated entities, including health plans, take the following steps to mitigate or prevent cyber threats:
- Identify where ePHI exists in the organization, including how ePHI enters, flows through, and leaves the organization’s information systems.
- Periodically conduct and update, as needed, a risk analysis and develop and implement a risk management plan to address identified risks to the confidentiality, integrity, and availability of ePHI.
- Ensure audit controls are in place to record and examine information system activity.
- Implement regular review of information system activity.
- Use mechanisms to authenticate information to ensure only authorized users are accessing ePHI.
- Encrypt ePHI in transit and at rest to guard against unauthorized access when appropriate.
- Incorporate lessons learned from incidents into the organization’s overall security management process.
- Provide workforce members with regular HIPAA training that is specific to the organization and to the workforce members’ respective job duties.
Going forward, proactive risk assessments, documented safeguards, and ongoing risk management are essential to reducing both breach risk and enforcement exposure.