How often should your benefits group have HIPAA training?
Cybersecurity remains a key concern for everyone, but health plans and other entities covered by HIPAA should take particular care to have regular privacy training, especially in light of recent events.
On March 13, the Department of Health and Human Services’ Office for Civil Rights (OCR) announced that it was opening an investigation into the cyberattack of Change Healthcare, a unit of UnitedHealth Group, in order to determine whether Change Healthcare and UnitedHealth Group complied with their HIPAA obligations.
This investigation follows OCR’s announcement in February of a $4.75 million settlement with Montefiore Medical Center to address a malicious insider cyberattack.
As these announcements make clear, cybersecurity remains a key concern for HIPAA covered entities, and a focus of OCR investigations.
In order to ensure that they are satisfying their HIPAA obligations, covered entities should take a number of steps to mitigate or prevent cyber threats, including some or all of the following:
- Reviewing all vendor and contractor relationships to ensure business associate agreements are in place;
- Integrating risk analysis and risk management processes;
- Using multi-factor authentication, where applicable;
- Encrypting protected health information, as appropriate; and
- Providing regular training to workforce members in protecting privacy and security.
Health plans and plan sponsors should discuss their HIPAA obligations with #ERISA counsel.