skip to main content

This page has been archived and is no longer being updated regularly.

Change Healthcare cybersecurity breach notification issues

APA Services continues to closely monitor the ongoing developments associated with the Change Healthcare cybersecurity breach. This update focuses on breach notification issues

APA Style leaf logo Cite This Article in APA Style
American Psychological Association. (2024, July 10). Change Healthcare cybersecurity breach notification issues. https://www.apaservices.org/practice/legal/managed/change-healthcare-cybersecurity-attack

A digital screen with padlock icons

APA Services continues to closely monitor the ongoing developments associated with the Change Healthcare cybersecurity breach. An article in the July/August issue of APA’s Monitor on Psychology discussed the dire financial problems for practitionerslogin required caused by the unprecedented February cyberattack on Change Healthcare (Change). This update focuses on breach notification issues under HIPAA:

  • the breach notices that Change plans to start sending in late July to patients whose information was breached in the cyberattack, as well as Change’s investigation and preliminary notice leading up to those notices; and
  • clarification from the Centers for Medicare and Medicaid Services (CMS) indicating that few, if any, psychologists in independent practice would also be required to send breach notifications.

Updates from Change

In late June, Change reported that its investigation of the impacts of the cyberattack was 90% complete. On about June 20, it issued a “substitute breach notificationopens in new window” on its website and to the media. This is essentially a preliminary notice about what Change knows about the breach and what further actions it intends to take, as well as what support it will offer to “affected individuals.” In HIPAA parlance, that means patients whose protected health information has been breached.

That notification indicates that beginning in late July, Change will begin mailing breach notifications to those individuals for whom Change has sufficient address information. Change has not stated how many affected individuals have been identified but repeated its April statement that “impacted data could cover a substantial proportion of people in America.”

What information was breached?

The substitute notice states that Change cannot confirm exactly what data has been affected for each impacted individual. But information involved may have included contact information (such as name, address, date of birth, phone number, and email) and some of the following information:

  • health information (such diagnoses, care and treatment, providers, medicines, and test results);
  • billing, claims, and payment information (such as payment cards, financial and banking information, payments made, and balance due);
  • other personal information such as Social Security numbers, driver’s licenses or state ID numbers, or passport numbers; and
  • health insurance information.

(For a more complete list, see the substitute notice.) As of the date of the substitute notice, Change had not yet seen evidence that any full medical records were breached. Change notes that the breached information may be different among individuals impacted.

Given Change’s general statements about what specific data has been breached, there seems to be the possibility that individual notifications will not specify whether the breached data was connected with any particular provider.

Talking to your patients

You are likely to have patients who receive the substitute breach notification or individual notifications and may look to you for guidance, although they may not know whether their information from your practice was specifically involved in the breach. You should be prepared to help them cope with this potentially upsetting news and uncertainty about what information of theirs has been breached. You can support them in taking steps to safeguard their information. Be prepared to explain your office’s connection to Change Healthcare (to the extent that you understand it), whether via your electronic health records or billing vendor, or by submitting claims to an insurance company.

To answer patients’ questions effectively, it is important that you are apprised of what happened, what data may have been compromised, as well as the recommended actions a patient can take. Those actions include reviewing financial statements for unusual activity, utilizing credit monitoring services that Change will make available free of charge, and implementing fraud alerts. A more complete list is at the end of the substitute notice.

Notices to Change’s customers

The substitute notice also indicates that on June 20, Change would start notifying its customers (such as insurers and practice management vendors) if any data from them was involved in the breach. TherapyNotes, for example, reports being notified that patient data from TherapyNotes was not included in the breach.

Independent practice breach notifications

Earlier statements from U.S. Department of Health and Human Services (HHS) suggested that health care providers (including psychologists) whose patient data was breached might also have to send breach notices to patients. Fortunately, it appears that few, if any, psychologists in independent practice will have to do so.

In an April 25 letter to HHS (PDF, 62KB)opens in new window, APA Services argued that breach notification obligations should be on Change as the entity that discovered breach—not on psychologists with no direct connection to or knowledge of the breach. In response, CMS confirmed that the obligation to ensure that breach notification occurs is on the HIPAA-covered entity that discovered the breach.

The capacity in which many psychologists’ information went to Change is where Change acted as a clearinghouse for practice management entities like TherapyNotes and Simple Practice, connecting those entities with insurers and other payers. In that clearinghouse capacity, Change appears to be acting as a HIPAA-covered entity that would be directly responsible for breach notification.

HHS clarified that discovering the breach could include being notified of the breach by their business associate (see below for details regarding who is a business associate). In most cases, Change does not serve as a direct business associate of independent practices, and we are not aware of any independent psychology practices that had a business associate relationship with Change. Accordingly, we expect that such practices would not be receiving any notice from Change as their business associate (like the notices to Change’s customers described above) that would count as discovering the breach and therefore triggering a practice’s obligation to conduct breach notifications themselves.

(Any practice that did receive such a notice from Change as their business associate has the option to ensure that notification occurs by delegating that responsibility back to Change or could send their own notices within 60 days of receiving notice from Change. See FAQs 6 and 7 in HHS’ May 31 FAQsopens in new window. For psychologists in larger organizations, there may be a compliance department that will be handling any needed notifications.)

Who is a business associate?

A “business associate” is an entity outside of your practice to whom you send protected health information so that they can provide services to you or on your behalf (for example, a billing service, accountant, IT service, lawyer, or accountant). Business associates are generally not other providers or payers. You, as a health care practice, are required to have a business associate agreement with your business associates. For further information see HHS guidanceopens in new window.

APA Services will continue to monitor this situation and update practitioners as we learn more information.

The content I just read:

You may also like