HHS OCR HIPAA Audit Phishing Email Alert - Bim Group

HHS OCR HIPAA Audit Phishing Email Alert

In recent months, the Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) notified business associates of their inclusion in Phase 2 HIPAA Audits. On November 28, 2016, and November 30, 2016, the OCR issued listserv announcements warning covered entities and their business associates about a phishing email disguised as an OCR official communication.

The phishing email asks recipients to click on a link regarding possible inclusion in the HIPAA Privacy, Security, and Breach Rules Audit Program and directs individuals to a non-governmental website that markets a firm’s cybersecurity services. The phishing email originates from the email address OSOCRAudit@hhs-gov.us and directs individuals to a URL at http://www.hhs-gov.us; the firm is not associated with the HHS OCR.

Be aware that all official communications regarding the HIPAA Audit Program are sent to selected auditees from the email address OSOCRAudit@hhs.gov. If a covered entity or business associate has a question as to whether it has received an official communication from OCR regarding a HIPAA audit, please contact OCR via email at OSOCRAudit@hhs.gov.

The official HHS site for information about the HIPAA Privacy, Security, and Breach Notification Audit Program is http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/.

11/30/2016

 stars
The UBA Compliance Advisors help you to stay up to date on regulatory changes to help simplify your job and mitigate compliance risk.

This information is general and is provided for educational purposes only. It reflects UBA’s understanding of the available guidance as of the date shown and is subject to change. It is not intended to provide legal advice. You should not act on this information without consulting legal counsel or other knowledgeable advisors.

 UBApartnerfirm

Recent Insights

April 22, 2024
News

Do You Know Where Your Employees Are? Managing Taxes for a Growing Remote Workforce

READ TIME: 5 MINUTES Remote work remains a growing focus of employers with employees increasingly seeking jobs that permit remote or hybrid work arrangements. Though the flexibility and benefits of remote work for employees is highly desired, it comes with some additional considerations and potential tax complications for the employer. State Income Tax Withholding Considerations […]
Read more
April 22, 2024
COBRA, Compliance Alert

Group Health Plan Guide to COBRA

The Consolidated Omnibus Budget Reconciliation Act (COBRA) gives workers and their families who lose their health benefits due to job loss, reduction in hours, death, divorce, and other life events the right to choose to temporarily continue health benefits provided by their group health plan. This guide includes: Employers required to offer COBRA Plan types […]
Read more
April 8, 2024
HIPAA

Timely Responses Required for Requests under HIPAA’s Right of Access Rule

READ TIME: 4 MINUTES On December 15, 2023, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR), announced a settlement under the Health Insurance Portability & Accountability Act (HIPAA) Right of Access Rule. This penalty illustrates that the Right of Access Rule remains a focus of HHS and that health […]
Read more
April 8, 2024
Compliance Alert

March 2024 Compliance Recap

READ TIME: 7 MINUTES ACA reporting is in its first year of the required electronic reporting for employers filing ten or more returns annually. Employers and employees must make changes to HSAs by the April 15 deadline. Employers of all sizes continued to prepare for the June 1 RxDC Reporting using the newly released instructions. […]
Read more