On May 20, 2024, the American Medical Association and more than 100 other organizations issued a joint letter to Health and Human Services (HHS) Secretary Xavier Becerra concerning the February 21, 2024 reported cyber incident involving Change Healthcare. The letter requested clarity from the HHS Office of Civil Rights (OCR) “around reporting responsibilities and [to] assure affected providers that reporting and notification obligations will be handled by Change Healthcare.” Further, the letter asked OCR to “publicly state that its breach investigation and immediate efforts at remediation will be focused on Change Healthcare, and not the providers affected by Change Healthcare’s breach.”

The groups who authored the letter have concerns that the required HIPAA breach reporting and notification requirements following this incident could fall upon providers rather than being the sole obligation of Change Healthcare or its parent companies, Optum and UnitedHealth Group. Thus, these groups are seeking further clarification and guidance for the provider community.

As the OCR continues its ongoing investigation, it is anticipated that additional information and clarification will be provided by the government. We will keep you advised accordingly.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of John W. Kaveney John W. Kaveney

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory…

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory support. He represents a diverse roster of healthcare entities, including for-profit and nonprofit hospitals and health systems, academic medical centers, individual physicians and physician groups, ambulatory surgery centers, ancillary service providers, medical billing companies, skilled nursing and rehabilitation facilities, behavioral health centers and pharmacies.

John advises on Medicaid reimbursement matters before the New Jersey Division of Medical Assistance and Health Services (DMAHS), which administers the state’s Medicaid programs, and handles Medicare reimbursement disputes, both in New Jersey and in numerous other states, before the federal Provider Reimbursement Review Board (PRRB).

In the area of corporate compliance, John supports clients on matters including the implementation of new, and the assessment and improvement of existing, compliance programs. He assists healthcare clients in navigating compliance audits, internal investigations, and governmental investigations related to compliance issues, including potential violations of the federal Stark Law, Anti-Kickback Statute (AKS), and Civil Monetary Penalties law (CMP). He further provides general guidance concerning compliance and regulatory matters under state and federal healthcare laws.

On issues related to information privacy and cybersecurity at the intersection of healthcare law, John assists providers with issues arising under the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH). This includes the implementation and assessment of privacy and security policies and procedures to ensure the proper protection and utilization of protected health information (PHI) both by healthcare providers and the business associates with which they contract. In addition, he represents healthcare clients in investigating, reporting, and remediating information breaches and the liability such breaches create under various information privacy and security laws.

John also counsels healthcare providers with professional licensure issues and advises hospitals and health systems regarding their medical staff bylaws and corresponding policies and procedures, as well as assisting with internal investigations of medical staff members and the corresponding disciplinary process. He further provides legal guidance related to New Jersey’s involuntary commitment laws, and provides representation in civil litigation.

John serves as Editor-In-Chief of Healthcare Perspectives, Greenbaum’s blog covering issues of interest to the healthcare industry.

Results may vary depending on your particular facts and legal circumstances.

Contact information:

jkaveney@greenbaumlaw.com | 973.577.1796 | vCard | LinkedIn

For more information visit the Greenbaum, Rowe, Smith & Davis LLP website.