The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
#166 The Latest News About the Change Healthcare Security Breach
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Earlier this year, Change Healthcare, a division of United Health Group, experienced a security breach that affected many dental practices in the U.S. The Protected Health Information of numerous patients was exposed in the breach. Join the Divas as we discuss how the investigation is progressing, and what dental practices need to know about patient notifications required by the HIPAA Breach Notification Rule.
Resources:
- Change Healthcare Consumer Support Page https://bit.ly/3XHc2D6
- Department of Health and Human Services (DHHS) Statement Regarding the Cyberattack on Change Healthcare. https://bit.ly/3RIMP7t
- DHHS Letter to Healthcare leaders on the Cyberattack on Change Healthcare https://bit.ly/4ckpGAy
- Olivia Wann Blog - Important Information on the Change Healthcare Cybersecurity Incident https://bit.ly/3VNITnc
- The HIPAA Journal - Change Healthcare Starts Notifying Entities Affected by February Ransomware Attack https://bit.ly/3XMiKHE
Welcome!
SPEAKER_01I'm Leslie Cannon. I'm Mary Gavoni.
SPEAKER_02I'm Linda Harvey. I'm Olivia Juan, and together we are the Compliance Divas. Welcome to the Compliance Divas podcast. My name is Olivia Juan, and I'll be your moderator today. In today's episode, we're talking about the status of change healthcare data breach and notification requirements. As the Compliance Divas, we bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. Please subscribe to the Compliance Divas podcast through your favorite podcast channel or visit our website, thecompliancedivas.com. Any resources that we mentioned during the podcast can be found on our website. Please submit your co your questions to support at thecompliancedivas.com and don't forget to give us a like. So as you're aware, Change Healthcare experienced a cyber attack earlier this year. And if you don't already know, Change Healthcare is actually owned by United Health Group. And Change Healthcare manages healthcare technology connected to processing, insurance claims, and billing. And this includes the popular ones such as Dentrex, Practice Works, Eagle Soft, Soft Dent, Open Dental, and many more companies. So they basically serve as the business associate to your dental practice. So it would be helpful to review your business associate agreements that you have in place. And so the Office of Civil Rights enforces the HIPAA privacy, security, and breach notification rules, which triggers notification of this breach, as we're talking about in this example. So I wanted to talk with Mary about what they are supposed to do. Thanks, Olivia.
SPEAKER_01Many dental practices are not aware that there are notification requirements if there has been a breach, either directly in their practice, or as what happened through change healthcare. So there's three types of notifications that need to be performed in the case of a breach of protected health information. The first is individual notice. So that means contacting individual patients, or maybe it is an individual family to let them know that their information has been breached. Covered entities have to provide this notice in written format, first class mail, or they could do it by email if the affected individual has agreed to receive notices electronically. So if you don't have an agreement from your patients that they can receive notices from you through email, then you have to send this out through the snail mail to your patients. This needs to be done as soon as possible after it's discovered or at least within 60 days from the time of discovery. But if your state has specific requirements for breach notification, and about a handful of states do, then you have to follow their timeline, and it may be a shorter timeline for notifying individuals. The next notification is a media notification. If there are more than 500 individuals in a state or a particular jurisdiction, then you need to send essentially a press release or a notification that they can broadcast in popular media. So a local TV station or a local newspaper, which isn't exactly the best marketing for your practice, but you need to make those notifications. And then the final notification in case of a breach is to the Department of Health and Human Services. And that again must be done as soon as possible after the discovery or no later than 60 days, if it's 500 or more individuals. If it's fewer than 500 individuals, then you don't have to do it until 60 days after the end of the year in which the breach occurred. So I would guess most practices, and Olivia Leslie, you can weigh in on this. I would guess most of them would fall in that 500 individuals category, whether it's an individual patient or a family. And so they're going to have to do that within that 60-day time frame.
SPEAKER_02Yeah, so that's that's a lot of information to mentally digest. So thanks for pointing out about the 60 days from discovery on a federal level, check with the state because they have different timelines that may be much shorter than 60 days, notifying the Department of Health and Human Services and media outlets. So it a lot goes into it, Mary, as you pointed out. And I wanted to mention that the business associate agreement, think of it as a contract. And so these dental offices that have been collecting business associate agreements, inside of that agreement, it spells out, you know, what happens if there's a breach. And so it's important to review these agreements. But what we understand at this time right now is that the dental office can delegate to change healthcare the task of providing HIPAA breach notification. And that's great because this is so expensive to do this process. And if change healthcare performs the required breach notifications and it's consistent with what the law requires, then the dental office wouldn't have any reporting. So considering that, Leslie, what are dental offices waiting on at this point?
SPEAKER_00Well, you know, Olivia, recently the associate director at Optum, Shelly Violet, was contacted and she indicated that they are conducting an investigation and there is no final incident report available at this time. So at this time, to ease the reporting obligations on stakeholders whose data may have been compromised as part of this cyber attack, United Health Group has offered to make the notifications and undertake related administrative requirements on behalf of any customer. Now, Ms. Vile also further indicated that they would do the appropriate notifications in the most efficient way possible as required by law. And this would include some form of direct mail or website notification, as well as other notices required by HIPAA and applicable state laws. And she hopes to provide additional information very soon on an opt-out process to ease the burden on dental practices. And I think that's really where a lot of folks come to us, Olivia, is they want to know what is it that we need to do as the dental practice to notify our patients and ongoing, just like we see on the TV shows, can't say anything, because it's an ongoing investigation.
SPEAKER_02Thanks, Leslie, for all that information. So the only thing we know to do is to say current with the Department of Health and Human Services information that they're providing. And it is interesting that you know Change Healthcare has not provided breach notification to the department concerning this breach. So we're we're interested to see how all of this plays out and concerned. And I can tell you this: if you don't already have cyber insurance, you better get it because we look at how vulnerable data is and how expensive it is to address these issues. And so we want to stay on top of it, make sure you've got your business associate agreements in place, and stay tuned with our podcast. We'll keep you up to date as the information comes down the pipeline.
SPEAKER_01And as an additional point of information for our listeners, on June 25th, Change Healthcare announced that they will be doing breach notification to the affected stakeholders in July. So you should be receiving some information, as we talked about before, the opt-out. In other words, that you would leave the notification to Change Healthcare to contact your patients on your behalf. So be on the lookout for that.
SPEAKER_02You know, as the compliance divas, we bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. We missed Linda Harvey this week, but we look forward to having her next week on next week's edition. If you have any questions, please submit them to support at the compliance divas.com, and we will provide you with the references for this episode in the show notes. Thanks again for tuning in. We're the compliance divas.