HHS Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation for $10,000
ID: e41a3985-74f7-5d6b-80a6-c169e0f8aabd
STIX ID: report--e41a3985-74f7-5d6b-80a6-c169e0f8aabd
Feed Name: DataBreaches.Net
Threat Score
HHS OCR announced a settlement with Northeast Surgical Group after a March 2023 ransomware attack encrypted and exfiltrated PHI for 15,298 patients; NESG will pay $10,000 and undergo a two-year corrective action plan to address HIPAA Security Rule deficiencies, including conducting a risk analysis, implementing risk management, updating policies and procedures, and training staff, while OCR reiterates recommended cybersecurity practices for HIPAA-covered entities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
