OCR Crackdown: Ransomware Settlement Exposes Data Security Risks and Reporting Failures
The U.S. Department of Health and Human Services, Office for Civil Rights (OCR) has recently announced its first settlement agreement related to a ransomware attack. Interestingly, it was not the ransomware incident itself which spurred OCR’s enforcement action. Instead, the trigger likely came from the regulated entity’s failure to detect and subsequently report the breach…