OCR Sees Uptick in Ransomware Incidents

by | Nov 4, 2024 | Government Enforcement, HIPAA, HIPAA Security, Security & Cybersecurity

OCR recently concluded three investigations, which resulted in settlement payments relating to ransomware incidents. The agency noted that there has been a 264% uptick in large ransomware breaches since 2018.

The first settlement was reached with Cascade Skin and Eye Centers in Washington state, which experienced a ransomware attack that affected nearly 300,000 files containing ePHI. The terms of the settlement were reached after Cascade agreed to pay $250,000 and entered into a corrective action plan with the agency.

The second settlement was for $500,000 with Plastic Surgery Associates of South Dakota. Multiple workstations and servers were infected with ransomware, affecting the records of over 10,000 patients. The company was ultimately not able to restore the data on the affected servers.

The third settlement was reached with the Bryan County Ambulance Authority in Oklahoma. The Authority’s network was attacked by ransomware, which exposed data from over 14,000 individuals.

In all three instances, OCR found that the entities that encountered the cybersecurity incidents had not conducted a compliant risk analysis and did not sufficiently monitor their health information systems’ activity. The corrective action plans for all three companies include conducting a thorough risk analysis and implementing a risk management plan to address the risks and vulnerabilities identified.

As cybersecurity threats, including ransomware, become increasingly common, OCR encourages all health care providers and other entities who are subject to HIPAA to proactively evaluate and mitigate potential risks and vulnerabilities through an accurate and thorough risk analysis.

Sources:

Share this:

If you are not a subscriber to our backend Legal HIE compliance library, download our Table of Contents here to check out all of the tools, checklists, whitepapers, sample policies we make available to our members to help their organizations comply with Information Blocking, HIPAA, 42 CFR Part 2, Data Breaches and more. Ready to subscribe now? Click here to review our subscription options.

Archives