OCR settles four HIPAA ransomware cases affecting 427k
On April 23, 2026, the HHS Office for Civil Rights announced four HIPAA Security Rule settlements tied to separate ransomware investigations...
1 min read
Hoala Greevy
May 17, 2017
To keep our pulse on the HIPAA industry, we subscribe to the U.S. Department of Health and Human Services' HIPAA Security Rule Distribution List. This past week we've seen a lot of activity on the list, so I'm sharing some of it via this post. The reasons behind its surge in activity of course, are the WannaCry ransomware attacks.
SEE RELATED: 3 Key Lessons Learned From WannaCry Ransomware Cyberattacks
As outlined in its online ransomware fact sheet, HHS presumes a breach in the case of a ransomware attack. The entity must determine whether such a breach is a reportable breach no later than 60 days after the entity knew or should have known of the breach.
SEE RELATED: FACT SHEET: Ransomware and HIPAA [HHS]
Ransomware guidance also includes important information about ransomware and how compliance with the HIPAA Security Rule helps entities prepare for ransomware attacks. This includes regard to contingency planning. OCR has shared its FAQ on sharing of cyber threat indicators here.
Important Note: If the data is not encrypted by the entity to at least NIST specifications when the ransomware attack is deployed, then OCR presumes a breach occurred, due to the ransomware attack. As such, the Covered Entity or Business Associate would need to prove that the ePHI was encrypted when the attack occurred and the ransomware containerized (or encrypted again) already-encrypted ePHI.
SEE ALSO: HIPAA Breach Notification Rule
On April 23, 2026, the HHS Office for Civil Rights announced four HIPAA Security Rule settlements tied to separate ransomware investigations...
In December, Forbes published “10 Cybersecurity Predictions That Will Define 2026,” stating that the “cybersecurity landscape is entering its most...
The Health Insurance Portability and Accountability Act (HIPAA) was enacted in 1996 to protect sensitive patient health information from being...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.