OCR Still Asserts Associates Responsible For Breach Notifications

By Cara Smith / May 24, 2024 at 5:48 PM
The HHS Office for Civil Rights is standing firm on its recent guidance that business associates of covered entities may also be responsible for breach notifications, coming as health care stakeholders brace for expected future cyberattacks that could result in disclosure of sensitive personal information. Hospitals and physicians are pressing OCR to clarify that United Health Group is singularly responsible for notifying patients and the government of instances of sensitive personal data being disclosed from the Change Healthcare cyberattack, saying...


Not a subscriber? Sign up for 30 days free access to exclusive, detailed reporting on drug pricing reforms, Medicaid policy, FDA news and much more.