Becker's Healthcare April 26, 2024
The Medical Group Management Association is seeking clarity from the HHS’ Office for Civil Rights regarding who carries the burden of providing HIPAA-required breach notifications to both the federal government and affected patients following the Change Healthcare cyberattack.
The MGMA said in an April 25 letter to the office that is encouraged by recent public statements from Change’s parent company UnitedHealth Group committing to “provide appropriate notifications” and stating it “has offered to make notifications and undertake related administrative requirements on behalf of any provider or customer.”
“At the same time, no prudent medical group can rely on vague promises in a press release containing no specifics with respect to either timing or implementation. To our knowledge, no...