Ransomware Resources for HIPAA Regulated Entities

Written by Reed Tinsley | September 23, 2021

Ransomware Resources for HIPAA Regulated Entities

The HHS Office for Civil Rights (OCR) is sharing the following information to ensure that HIPAA regulated entities are aware of the resources available to assist in preventing, detecting, and mitigating breaches of unsecured protected health information caused by hacking and ransomware.

HHS Health Sector Cybersecurity Coordination Center Threat Briefs

Sector and Threat Briefs

HHS Resources on Section 405(d) of the Cybersecurity Act of 2015

  • Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients
  • Cybersecurity Reports and Tools

OCR Guidance

HHS Security Risk Assessment Tool

CISA Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches

CISA Ransomware Guide

FBI Resources

OCR Cybersecurity Newsletters

Reminder

A ransomware attack may result in a breach of unsecured protected health information that triggers reporting requirements under the HIPAA Breach Notification Rule.  HIPAA covered entities and business associates should review OCR’s ransomware guidance for information regarding potential breach notification obligations following a ransomware attack.

About the Author

Reed Tinsley CPA

This article is written by Reed Tinsley, a Houston, TX-based CPA with over 30 years of experience advising physicians and medical practices across Texas and the United States. Reed holds certifications as a Certified Valuation Analyst (CVA), Certified Healthcare Business Consultant (CHBC), and Certified Financial Planner (CFP), specializing exclusively in the healthcare sector. He is a published author, nationally recognized speaker, and trusted advisor to physicians on accounting & tax, practice management, and financial planning. Schedule a Free Consultation.

Have questions? I’m here to help.