Clarity Sought on HIPAA Breach Reporting Requirements for Change Healthcare Data Breach

The HHS’ Office for Civil Rights has published a FAQ on its website that includes guidance on the HIPAA breach reporting requirements for the Change Healthcare data breach. The FAQ explains that in the event of a breach of electronic protected health information, it is ultimately the responsibility of each covered entity to ensure that individual notification letters are sent to the affected individuals, including when a data breach occurs at a business associate. OCR also explained that the covered entity may delegate the responsibility of issuing individual notifications to the business associate.

More than 100 industry groups, including the American Medical Association (AMA) and the College of Healthcare Information Management Executives (CHIME), have written to OCR seeking more clarity on the breach reporting obligations for the data breach at Change Healthcare and have asked for OCR to issue a statement confirming that Change Healthcare or its parent company UnitedHealth Group (UHG) will be issuing notifications.

UHG has yet to confirm the number of individuals affected, although when pushed for a figure at a recent hearing, UHG CEO Andrew Witty said the data breach could affect 1 in 3 Americans. The affected providers have already suffered considerable financial hardship as a result of the prolonged outages at Change Healthcare, and it is unreasonable to also place a breach notification burden on them for a data breach that was not their fault and happened at another company.

UHG has offered to “make notifications and undertake related administrative requirements on behalf of any provider or customer,” to “help ease reporting obligations on other stakeholders whose data may have been compromised as part of this cyberattack.” The industry groups have asked OCR to publicly confirm that the breach reporting requirements for the Change Healthcare data breach will be the sole responsibility of Change Healthcare/UHG. “It would be a quick and straightforward matter for OCR to confirm publicly that the HIPAA breach notification and reporting requirements are applicable to UHG and not to the affected providers,” wrote the authoring groups in the letter. “Given the well documented state of chaos in the provider community in the wake of this breach, OCR’s silence on this point is disappointing.”

OCR investigates all large data breaches to determine whether they were caused by non-compliance with the HIPAA Rules, although it can take several months for investigations to be initiated. Due to the unprecedented disruption caused by the Change Healthcare ransomware attack and the potential for the breach to be colossal, OCR rapidly initiated an investigation. OCR explained this in a Dear Colleague letter but also took the opportunity to remind the affected providers of their obligations under HIPAA. OCR explained that Change Healthcare and UHG were the primary focus of the investigation, but the reminder about HIPAA compliance for the affected providers has caused considerable concern. The industry groups have called for OCR to “publicly state that their breach investigation and immediate efforts at remediation will be focused on Change Healthcare, and not the providers affected by Change Healthcare’s breach.”

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/