The HHS Office for Civil Rights is standing firm on its recent guidance that business associates of covered entities may also be responsible for breach notifications, coming as health care stakeholders brace for expected future cyberattacks that could result in disclosure of sensitive personal information. Hospitals and physicians are pressing OCR to clarify that United Health Group is singularly responsible for notifying patients and the government of instances of sensitive personal data being disclosed from the Change Healthcare cyberattack, saying...