Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Media
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Financial Services
    • Healthcare
    • Higher Education
    • Infrastructure
    • Manufacturing
    • Nonprofit Organizations
    • Real Estate
    • Sports & Stadiums
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • DEI Strategic Services

      Providing our clients with legal, strategic, and practical advice to make transformational changes in their organizations.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Articles
    4. OCR announces its third enforcement action involving ransomware

      Articles

    Article / Healthcare

    OCR announces its third enforcement action involving ransomware

    July 17, 2024

    LinkedInX (Twitter)EmailCopy URL

    By Ethan Domsten and Valerie MontaguePhilip Cramer, a legal intern in Nixon Peabody’s Healthcare practice and a 2026 JD candidate at Loyola University Chicago School of Law and assisted with the preparation of this article.

    The latest HIPAA enforcement reminds healthcare providers, health plans, and other entities regulated under HIPAA to ensure compliance with the Security Rule, including the importance of workforce training, in the face of increasing hacking events and ransomware attacks.

    On July 1, 2024, the US Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a $950,000 settlement with Heritage Valley Health System (Heritage Valley), marking OCR’s third ever settlement for alleged HIPAA Security Rule violations discovered after a ransomware attack. Heritage Valley, a health system providing services in Pennsylvania, Ohio, and West Virginia, experienced the ransomware attack in June 2017. Following media reports of the incident, OCR initiated a compliance review in October 2017 that concluded nearly seven years later with this settlement.

    As the result of its investigation into Heritage Valley’s compliance with the HIPAA Security Rule, OCR identified several potential violations, including the failure to conduct risk analyses to identify potential risks and vulnerabilities to electronic protected health information (ePHI) in its systems and the failure to implement a contingency plan to respond to ransomware attacks and other emergencies. Additionally, OCR found that Heritage Valley failed to adopt policies and procedures that would limit access to ePHI solely to authorized users.

    As part of the resolution agreement, Heritage Valley agreed to pay a monetary settlement of $950,000. Similar to OCR’s first ransomware settlement, the resolution agreement includes a three-year corrective action plan (CAP), which expands upon the two-year CAP that is more typical in OCR enforcement actions. Heritage Valley’s CAP will permit OCR to monitor its progress in conducting a thorough risk analysis; implementing a risk management plan that addresses and mitigates security risks and vulnerabilities identified in the risk analysis; developing and implementing policies and procedures that comply with the HIPAA Security Rule, specifically referencing seven particular HIPAA Security Rule topics; and training its workforce on Heritage Valley’s HIPAA policies and procedures.

    In this latest HIPAA enforcement action, OCR notes that reported large breaches involving ransomware attacks increased by 264% over the past six years and that ransomware is one of the primary cyber threats to healthcare organizations. In its release describing the settlement with Heritage Valley, OCR provided several recommendations to mitigate and prevent cyber threats, one of which encourages the provision of regular training of the entity’s workforce to reinforce their role in protecting the privacy and security of health data. The CAP also provides insight into what OCR considers to be best practices for HIPAA training. The CAP requires training to be conducted at least annually. Workforce members must certify that they received the training, and the certification should state the date of the training. The CAP requires that the health system retain the course materials, and that the training materials are reviewed at least annually and updated to reflect (1) changes in laws or HHS guidance, (2) any issues discovered during an audit or another review, and (3) any other developments relevant to the HIPAA training. OCR also requires the health system to provide OCR with the length of the training sessions and a schedule of when the system held the training(s).

    Heath systems and all entities regulated under HIPAA should not only maintain a robust HIPAA compliance program, but also ensure that their workforce understands the nuances of these compliance obligations through training. Adhering to the training modification, cadence, and documentation requirements articulated in the Heritage Valley CAP will allow a HIPAA-regulated entity to not only provide in-depth training to its workforce, but to easily detail to OCR the specifics of such training if audited or investigated.

    OCR Action

    Practices

    HealthcareHealthcare Regulatory & ComplianceDigital Health & TelemedicineWorkplace Policies, Procedures & Training

    Insights And Happenings

    • Alert

      OCR continues enforcement of HIPAA Right of Access Initiative

      Aug 14, 2024
    • Alert

      AB-3129 Targets Private Equity Investment in California

      Aug 2, 2024
    • Alert

      Rhode Island enacts data privacy law

      July 26, 2024
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Cookie Preferences
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Purchase Order Terms & Conditions
    • Nixon Peabody International LLC
    • PAL
    © 2025 Nixon Peabody. All rights reserved