HIPAA Enforcement Action Against Employer-Sponsored Health Plan for Ransomware Attack
A self-funded employer-sponsored group health plan settled with OCR after a ransomware attack resulted in a breach of electronic protected health information.
On April 23, 2026, the HHS’s Office for Civil Rights (“OCR”) announced a settlement with a self-funded employer-sponsored group health plan (the “Plan”) following a ransomware attack that resulted in a breach of electronic protected health information (“PHI”). Under the settlement, the Plan agreed to pay $245,000 to OCR and to implement a two-year corrective action plan.... By: Haynes Boone
Related News
SEC Proposes Optional Semiannual Reporting on New Form 10-S
Unknown15 minutes ago
Renonciation à recettes par une société de capitaux au bénéfice de ses associés : la conformité à l’objet social ne fait pas obstacle à l’acte anormal de gestion
Unknownabout 1 hour ago
Mind the Gap: Disability Leaves, Pension Contributions, and the Cost of Ambiguity
Unknownabout 1 hour ago