OCR Releases Breach Reports

Feb. 21, 2023
According to a Feb. 17 press release, the HHS Office for Civil Rights released two reports to Congress for 2021 to help regulated entities comply with HIPAA Privacy, Security, and Breach Notification Rules

On Feb. 17, the HHS Office for Civil Rights (OCR) released two Reports to Congress for 2021, entitled “HIPAA Privacy, Security, and Breach Notification Rule Compliance” and “Breaches of Unsecured Protected Health Information.” According to a press release, the reports aim to help regulated entities better comply with the requirements of the HIPAA Privacy, Security, and Breach Notification Rules.

The reports share steps taken by OCR to investigate complaints, breach reports, and compliance reviews surrounding potential HIPAA violations. The reports have data on the numbers of HIPAA cases investigated, areas of noncompliance, and insights into current cybersecurity trends.

The press release states that “The 2021 Report to Congress on ‘HIPAA Privacy, Security, and Breach Notification Rule Compliance’ identifies the number of complaints received, the method by which those complaints were resolved, the number of compliance reviews initiated by OCR, and the outcome of each review.”

“Breaches of Unsecured Protected Health Information” highlights the number and kind of breaches of unsecured protected health information (PHI) that were reported to the Secretary of HHS during calendar year 2021 and the actions taken in response. The report also stresses the continued need for regulated entities to improve compliance with the HIPAA Security Rule requirements, including:

  • risk analysis and risk management
  • information system activity review
  • audit controls
  • access controls

“These compliance concerns were identified as areas needing improvement in 2021 OCR breach investigations,” the report adds. “As it was the previous three years, hacking/IT incidents remain the largest category of breaches occurring in 2021 affecting 500 or more individuals, and affected the most individuals, comprising 75 percent of the reported breaches.  Network servers is the largest category by location for breaches involving 500 or more individuals.”

OCR director Melanie Fontes Rainer was quoted in the release saying that “The healthcare industry is one of the most diverse industries in our economy, and OCR is responsible for enforcing the HIPAA Rules to support greater privacy and security of individuals’ protected health information. We will continue to provide guidance and technical assistance on compliance with the HIPAA Rules, as well as a vigorous enforcement program to address potential HIPAA violations.”

Sponsored Recommendations

+++SPONSORED CONTENT+++ Telehealth: Moving Forward Into the Future

Register now to explore two insightful sessions that delve into the transformative potential of telehealth and virtual care management solutions.

Telehealth: Moving Forward Into the Future

Register now to explore two insightful sessions that delve into the transformative potential of telehealth and virtual care management solutions.

How Gen AI is driving efficiency in the ED

Discover how Gen AI is revolutionizing efficiency in the Emergency Department (ED), enhancing patient care, and alleviating staffing challenges. Join Microsoft and Valley View...

7 Steps to Sharpen Your Healthcare Revenue Cycle

If you manage a healthcare revenue cycle, you know the road to quick, complete payments is rocky. Using decades of industry expertise and real-world data, we’ll help you develop...