Change Healthcare has published a substitute data breach notice stating that notifications will be sent out to affected entities and individuals on July 20th.
Change Healthcare recently updated its website with a breach notice regarding a cyberattack that occurred in February 2024. The company will begin mailing notification letters to affected individuals on July 20, 2024. The data review is nearly complete, though more individuals may still be identified as affected.
On June 20, Change Healthcare released a notice of a data breach, revealing important details regarding the cyberattack while also revealing new information regarding what data was impacted. Change Healthcare also confirmed that they had begun notifying affected entities and will begin sending breach notifications to individual victims in late July.
Go deeper: Change Healthcare begins sending breach notification
Key points from the notice include:
According to Change Healthcare (CHC), the notice was released to “provide customers and individuals with information about the criminal cyberattack on CHC systems and to share resources available to people who believe their personal data potentially being impacted.” They further mentioned that they are nearing the completion of their review of individual details, which might have been affected by the incident. “CHC is providing this notice now to help individuals understand what happened, let them know that their information may have been impacted, and give them information on steps they can take to protect their privacy, including enrolling in two years of complimentary credit monitoring and identity theft protection services if they believe that their information may have been impacted.”
See also: HIPAA Compliant Email: The Definitive Guide
HIPAA's Breach Notification Rule mandates covered entities and their business associates to notify affected individuals, the Secretary of Health and Human Services, and, in some cases, the media when there is a breach of unsecured protected health information (PHI). This rule aims to protect patients' privacy and ensure they are informed about potential risks to their personal and health information. CHC’s notification to affected entities and individuals is a demonstration of its compliance with these regulations, reflecting its commitment to transparency and accountability.
Learn more: Navigating HIPAA’s Breach Notification Rule
A data breach occurs when unauthorized individuals gain access to sensitive, protected, or confidential data, often resulting in the exposure or theft of this information. This can include personal information, financial data, health records, and more.
Commonly targeted information includes:
Individuals affected by a data breach may face: