There’s a loophole in Health and Human Services requirements forhealth care facilities to report cyberattacks and hospitals and health care centers are takingfull advantage of it.

How does this happen? According to a Wall Street Journalreport, if client medical or financial data arelocked away by ransomware in an attack and have not beenpublicly exposed, the attack need not be reported.

The trouble with this is medical facilities, even if they paythe ransom, can be shut out of the data for weeks — as happened toMaryland’s MedStar Health, as it took three weeks to get everythingup and running — with doctors taking notes by hand and lab resultscoming in late.

Continue Reading for Free

Register and gain access to:

  • Breaking benefits news and analysis, on-site and via our newsletters and custom alerts
  • Educational webcasts, white papers, and ebooks from industry thought leaders
  • Critical converage of the property casualty insurance and financial advisory markets on our other ALM sites, PropertyCasualty360 and ThinkAdvisor
NOT FOR REPRINT

© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.