The letters have started. On June 20, Change Healthcare began mailing written breach notifications to individuals whose information was taken in the February cyberattack, and it has posted a substitute notice on its website describing what happened and what data may be involved: names, contact information, dates of birth, health insurance details, diagnoses, test results, medications, claims and payment information, and in some cases Social Security or driver's license numbers. The company still says the review is not finished and that more letters will follow over the coming months.
For a practice, this is the point where a national news story becomes a compliance file with your name on it. Under HIPAA, Change Healthcare is a business associate. Your patients' information passed through it because you, or your billing vendor, or your practice management vendor, sent claims there. The breach notification obligation to your patients belongs to you as the covered entity, even though the breach happened somewhere else. The question this month is what you do with that obligation, and the answer needs to be written down, dated and signed by someone who is allowed to make it.
Key takeaways
- Change is a business associate; the duty to notify your patients is yours, and OCR has said you may delegate the task to Change but not the responsibility.
- Delegation requires an affirmative act: a written request to Change or UnitedHealth and a saved confirmation, not an assumption that it is being handled.
- The HIPAA clock runs from discovery; record the date you learned your patients' data was involved and keep the notice that told you.
- State breach laws are a separate layer with their own definitions, deadlines and attorney general notices, and delegation under HIPAA does not automatically satisfy them.
- Your front desk will hear from patients before your compliance officer does; give them a one-page script.
What OCR has said
On May 31, the HHS Office for Civil Rights updated its frequently asked questions on the Change Healthcare incident. The important points, in our reading: covered entities affected by the breach may delegate the task of providing HIPAA breach notifications to Change Healthcare, so that patients receive one letter rather than several. Only one entity needs to complete the notifications to individuals, to HHS and, where required, to the media. If the covered entity delegates, it should be able to show that it did so. And the covered entity remains responsible for making sure notification happens; delegation is a way of performing the duty, not a way of transferring it. OCR also indicated that it would not treat a covered entity's notification obligations as running before the business associate had told it that its data was involved, which is why the date of that notice matters so much.
UnitedHealth has said it will handle notifications on behalf of providers who ask it to. That is the offer. Whether to accept it is your decision, and you need to make it deliberately.
The decision, and how to document it
| Option | What you do | Record to keep |
|---|---|---|
| Delegate to Change Healthcare | Confirm in writing with Change or UnitedHealth that they will notify your affected patients, HHS and media as required | The written confirmation, the date, who authorized it, and copies of the notice content when available |
| Notify patients yourself | Obtain the list of your affected individuals from Change, send letters within the required timeframes, report to HHS | The list, the letter template, mailing proof, HHS submission confirmation |
| Wait and see | Not a compliant option once you know your patients are affected | Do not choose this |
Most independent practices will delegate, and we think that is reasonable. Change has the data on who was affected; you probably do not, at least not yet. But delegation requires an affirmative act. An email to your account contact that says "we are delegating breach notification for our affected patients to Change Healthcare under the OCR guidance, please confirm" is enough to start. Save the reply. If you reached Change only through a vendor, send the same request to the vendor and ask them to confirm what they have arranged with Change on your behalf.
The clock, in case you do not delegate
If you decide to notify patients yourself, or if delegation falls through, the HIPAA Breach Notification Rule sets the deadlines. They run from discovery, and for a breach at a business associate, discovery is generally treated as the date the business associate notified you, or the date you should reasonably have known.
| Notice | Who receives it | Deadline | Notes |
|---|---|---|---|
| Individual notice | Each affected patient, by first-class mail or by email if the patient agreed | Without unreasonable delay, and no later than 60 days after discovery | Substitute notice on a website or in media if 10 or more addresses are bad |
| HHS notice, 500 or more individuals | OCR breach portal | Same 60 days | Posted publicly on the OCR breach list |
| HHS notice, fewer than 500 | OCR breach portal | Within 60 days after the end of the calendar year in which the breach was discovered | Keep the log all year |
| Media notice | Prominent media outlets in a state or jurisdiction | Same 60 days | Only if more than 500 residents of that state are affected |
The practical problem is the list. Without a list of your affected individuals from Change, you cannot send individual notices and cannot know which HHS category you fall in. That is the strongest argument for delegation, and it is also why you should ask Change or your vendor for the list even if you delegate, so that your own records show who was affected when a patient asks in two years.
The rest of the compliance file
- Find the business associate agreement. If you contracted with Change directly, you have one. If you reached Change through your practice management vendor or billing company, your BAA is with them, and their BAA is with Change. Know which it is, because it determines who you are asking for information and who owes you a breach report under the agreement. Read the breach notification clause; many BAAs promise notice within a set number of days, and yours may already have been missed.
- Record the date you learned your data was involved. HIPAA timeframes run from discovery. For a breach at a business associate, discovery can be argued from the date the business associate notified you. Keep the notice, and if it arrived by portal message or email, print it.
- Update your risk analysis. Your HIPAA security risk analysis should reflect that a business associate suffered a breach affecting your patients, what you learned about your own dependency on that vendor, and what you decided to do about it. This is the document OCR asks for first in any investigation.
- Prepare the staff. Patients will call your office with the Change letter in hand, and your front desk will be the first person they reach. A one-page script matters more than a policy binder here.
- Check state law. Many states have their own breach notification statutes with different definitions and timelines, and some require notice to the state attorney general. Several state definitions turn on Social Security or driver's license numbers, which Change says were involved for some people. Delegation under HIPAA does not automatically satisfy a state requirement. This is where a conversation with counsel is worth the hour.
What to tell patients who call
Keep it short and truthful. Yes, the letter is real. The breach happened at Change Healthcare, a company that processes insurance claims for most of the health care system, not at our office. We do not have the details of exactly which of your records were involved; the letter and the phone number in it are the source for that. Change is offering credit monitoring; here is where it says how to enroll. If you see claims on your insurance statement for services you did not receive, call your insurer and let us know. Do not speculate about what was taken and do not promise that nothing bad will happen. Log each call with the date and the patient's name, because those calls are evidence that your patients were affected and that you responded.
Mistakes we are already seeing
Practices that assume their billing company has handled the notification question when nobody has asked the billing company. Practices that send their own letter to every patient "to be safe", which produces duplicate notices, confused patients and a HIPAA report for a breach they cannot describe. Practices with no record at all of when they learned about the incident, which turns a simple timeline question into a problem. And practices that treat the substitute notice on Change's website as if it were notice to them; it is notice to individuals, and it does not tell you which of your patients are on the list.
Questions we hear
Do we have to report this to HHS ourselves?
If you delegate to Change and Change files the report covering your patients, OCR's guidance indicates a second report is not needed. Keep proof that the delegation was made and accepted. If you do not delegate, the reporting duty is yours, with the 500-or-more and fewer-than-500 rules in the table above.
We switched clearinghouses in March. Does that change anything?
Not for data that was already at Change on February 21. It does mean you now have a new business associate, and you should have a signed BAA with them dated before the first claim went through. If you do not, fix that this week; a BAA signed after the fact is better than none, and the gap should be noted in the risk analysis.
Should we stop working with vendors that used Change?
Honestly, most practices should not make that decision on this basis alone. Nearly every vendor touched Change. The better question is whether your vendors can tell you, in writing, how they protect your data and what their own incident plan is. If they cannot answer in a week, that is the signal. Our RCM audit includes a review of the BAAs and access arrangements around your billing, and it is a reasonable place to start if you have never inventoried them.
What to do this month
- Decide, in a dated memo signed by the privacy officer or owner, whether to delegate notification to Change Healthcare.
- Send the delegation request to Change, UnitedHealth or your vendor, and file the confirmation with the memo.
- Locate the BAA that covers your path to Change and write down the date you first learned your patients' data was involved.
- Ask for the list of your affected individuals even if you delegate, and store it with the compliance file.
- Give the front desk the one-page script and a call log.
- Ask counsel whether your state's breach law requires anything beyond HIPAA, including attorney general notice, and put the answer in the file.
