Cyberattack update: NCPA joins NACDS to push HHS to exempt pharmacies from breach notifications

NCPA May 7, 2024

NCPA joined NACDS in submitting comments to the Department of Health and Human Services urging the agency to require Change Healthcare and UnitedHealth Group to make any breach notifications relating to the recent cyber-attack, not pharmacies and other downstream victims of this attack, unless such victims otherwise elect to provide notice themselves. “We believe that requiring pharmacies to report breach notifications in these situations will perplex patients and add needless expenses to pharmacies, who have suffered greatly from this attack,” NCPA and NACDS wrote in the May 6 letter. Read the letter in full here and stay tuned to qAM for more on the fallout from the February cyber-attack.

NCPA