HHS Reaches Second Ever Settlement for Ransomware Attack

The settlement involved a cyberattack that occurred back in 2019.

By HFT Staff


The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a settlement under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) with Green Ridge Behavioral Health, LLC, a Maryland-based practice that provides psychiatric evaluations, medication management and psychotherapy. OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules, which sets forth the requirements that HIPAA covered entities (most health care providers, health plans, and health care clearinghouses) and their business associates must follow to protect the privacy and security of protected health information. The settlement resolves an investigation following a ransomware attack that affected the protected health information of more than 14,000 individuals. This marks the second settlement that OCR has reached with a HIPAA regulated entity for potential violations identified during an investigation following a ransomware attack. 

In February 2019, Green Ridge Behavioral Health filed a breach report with OCR stating that its network server had been infected with ransomware resulting in the encryption of company files and the electronic health records of all patients. OCR’s investigation found evidence of potential violations of the HIPAA Privacy and Security Rules leading up to and at the time of the breach. Other findings included that Green Ridge Behavioral Health failed to: 

  • Have in place an accurate and through analysis to determine the potential risks and vulnerabilities to electronic protected health information; 
  • Implement security measures to reduce risks and vulnerabilities to a reasonable and appropriate level; and 
  • Have sufficient monitoring of its health information systems’ activity to protect against a cyber-attack. 

Under the terms of the settlement, Green Ridge Behavioral Health agreed to pay $40,000 and implement a corrective action plan that will be monitored by OCR for three years. The plan identifies steps that Green Ridge Behavioral Health will take to resolve potential violations of the HIPAA Privacy and Security Rules and to protect electronic protected health information, including: 

  • Conducting a comprehensive and thorough analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information; 
  • Designing a risk management plan to address and mitigate security risks and vulnerabilities found in the risk analysis; 
  • Reviewing, and as necessary, developing, or revising its written policies and procedures to comply with the HIPAA Rules; 
  • Providing workforce training on HIPAA policies and procedures; 
  • Conducting an audit of all third-party arrangements to ensure appropriate business associate agreements are in place, where applicable; and 
  • Reporting to OCR when workforce members fail to comply with HIPAA. 


February 27, 2024


Topic Area: Information Technology , Security


Recent Posts

Avoiding Mistakes in Healthcare Site Selection

Actionable strategies for healthcare systems and medical groups navigating today’s constrained real estate market.


Can Rural Hospitals Be Saved?

More than 700 rural hospitals nationwide face the risk of closure. A new report highlights solutions that could improve long-term sustainability.


Ascension Saint Thomas Breaks Ground on Hospital and Health Campus in Tennessee

The new hospital will open with 44 inpatient beds and will be designed to expand to 132 beds as community needs grow.


The Hidden Risks of QAC Disinfectants in Healthcare Facilities

Quaternary ammonium compounds are a popular disinfectant choice, but they may be causing more harm than good. A review outlines the problems with QACs and offers a solution.


Sprinkler Compliance: Navigating Code Mandates, Renovation Triggers and Patient Safety

As CMS deadlines approach and renovation projects accelerate, healthcare facility managers must understand how NFPA 101, state fire codes and sprinkler design strategies intersect.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

 
 
 
 

Healthcare Facilities Today membership includes free email newsletters from our facility-industry brands.

Facebook   Twitter   LinkedIn   Posts

Copyright © 2023 TradePress. All rights reserved.