Four things to know:
1. The office said healthcare organizations are receiving postcards with information about a mandatory HIPAA compliance risk assessment. The postcards appear to be sent from the Office for Civil Rights, but they are fraudulent.
2. The postcards claim to be from the secretary of compliance in the HIPAA compliance division of the Office for Civil Rights, which does not exist.
3. Typically, the postcards are sent to the healthcare organization’s HIPAA privacy and security officers and direct those individuals to a website link for more information about a risk assessment. The postcards also provide a number to call and email address to contact.
4. The website provided for the HIPAA requirements is not a governmental website.
More articles on cybersecurity:
Arkansas medical center fires nurse for inappropriately accessing 772 patients’ medical records
Nearly 34,000 patients’ info exposed after email hack at U of Maryland Medical Center faculty practice plan
San Antonio hospital accidentally posts information of 1,200 patients online: 4 details
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.