Recent settlements in two HIPAA investigations involving ransomware attacks emphasize the importance of robust HIPAA compliance practices. In both instances, hackers were able to install ransomware on the covered entities’ systems that allowed them to access individuals’ PHI. Both covered entities had to pay a settlement and enter into a corrective action plan.

Under the corrective action plans, each covered entity is required to:

  1. conduct a risk analysis,
  2. develop and implement a risk management plan
  3. develop and maintain written policies and procedures, and
  4. train workforce members on HIPAA policies and procedures

Plan sponsors and healthcare providers should work with ERISA counsel to ensure that they are up to date on the latest HIPAA requirements, including any necessary revisions to their policies and procedures. It is crucial that workforce members receive adequate training on HIPAA compliance matters, including cybersecurity.

Plan sponsors and healthcare providers should also coordinate with ERISA counsel to determine whether any changes are necessary for existing HIPAA notices and/or policies and procedures regarding reproductive health information.

Copies of the resolution agreements are available: