Plastic Surgery Associates of South Dakota in Sioux Falls recently settled with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) for $500,000 due to a ransomware cybersecurity breach. This settlement is OCR’s sixth enforcement action involving ransomware amid an alarming increase in cyberattacks in the healthcare sector.
Ransomware is a type of malicious software (malware) that encrypts an organization’s data, blocking access until a ransom is paid to the attacker. Since 2018, ransomware breaches have surged by 264%, making it the most common threat in healthcare. Attackers often gain access through vulnerabilities such as weak passwords, using brute-force attacks, or exploiting remote access tools.
OCR’s investigation found multiple failures by Plastic Surgery Associates of South Dakota to comply with HIPAA Security Rule standards. These included:
The HIPAA Security Rule mandates that covered entities conduct SRAs at least once annually. This requirement aligns with other federal programs and compliance regulations, highlighting the need for proactive assessments. Failing to do so exposes healthcare providers to significant risks and penalties.
Taino Consultants Inc. has been a leader in conducting SRAs for nearly 30 years. Their expertise ensures that healthcare providers meet HIPAA requirements through thorough risk analyses and tailored risk management plans. EPI Compliance offers comprehensive solutions, including training programs and compliance management, that align with CAP requirements such as policy revisions, incident response planning, and workforce training.
By leveraging the services of Taino Consultants Inc. and EPI Compliance, healthcare organizations can strengthen their security posture, mitigate potential risks, and remain compliant with HIPAA standards. These services are crucial, especially as cyber threats grow more sophisticated and frequent.