In late June, Change reported that its investigation of the impacts of the cyberattack was 90% complete. On about June 20, it issued a “substitute breach notificationopens in new window” on its website and to the media. This is essentially a preliminary notice about what Change knows about the breach and what further actions it intends to take, as well as what support it will offer to “affected individuals.” In HIPAA parlance, that means patients whose protected health information has been breached.
That notification indicates that beginning in late July, Change will begin mailing breach notifications to those individuals for whom Change has sufficient address information. Change has not stated how many affected individuals have been identified but repeated its April statement that “impacted data could cover a substantial proportion of people in America.”
What information was breached?
The substitute notice states that Change cannot confirm exactly what data has been affected for each impacted individual. But information involved may have included contact information (such as name, address, date of birth, phone number, and email) and some of the following information:
- health information (such diagnoses, care and treatment, providers, medicines, and test results);
- billing, claims, and payment information (such as payment cards, financial and banking information, payments made, and balance due);
- other personal information such as Social Security numbers, driver’s licenses or state ID numbers, or passport numbers; and
- health insurance information.
(For a more complete list, see the substitute notice.) As of the date of the substitute notice, Change had not yet seen evidence that any full medical records were breached. Change notes that the breached information may be different among individuals impacted.
Given Change’s general statements about what specific data has been breached, there seems to be the possibility that individual notifications will not specify whether the breached data was connected with any particular provider.
Talking to your patients
You are likely to have patients who receive the substitute breach notification or individual notifications and may look to you for guidance, although they may not know whether their information from your practice was specifically involved in the breach. You should be prepared to help them cope with this potentially upsetting news and uncertainty about what information of theirs has been breached. You can support them in taking steps to safeguard their information. Be prepared to explain your office’s connection to Change Healthcare (to the extent that you understand it), whether via your electronic health records or billing vendor, or by submitting claims to an insurance company.
To answer patients’ questions effectively, it is important that you are apprised of what happened, what data may have been compromised, as well as the recommended actions a patient can take. Those actions include reviewing financial statements for unusual activity, utilizing credit monitoring services that Change will make available free of charge, and implementing fraud alerts. A more complete list is at the end of the substitute notice.
Notices to Change’s customers
The substitute notice also indicates that on June 20, Change would start notifying its customers (such as insurers and practice management vendors) if any data from them was involved in the breach. TherapyNotes, for example, reports being notified that patient data from TherapyNotes was not included in the breach.