Doctors Management Services Inc Resolution Agreement and Corrective Action Plan HHSgov
pAn official website of the United States governmentppHeres how you knowpp
Official websites use gov
A gov website belongs to an official government organization in the United States
pp
Secure gov websites use HTTPS
A lock LockA locked padlock or https means youve safely connected to the gov website Share sensitive information only on official secure websites
ppResolution AgreementppI RecitalsppOn April 22 2019 OCR opened an investigation based on a breach report from DMS a practice management company that acts as a business associate to several covered entities The report stated that approximately 206695 individuals were affected when the DMS network server was infected with GandCrab ransomware The initial unauthorized access to the network occurred on April 1 2017 however DMS did not detect the intrusion until December 24 2018 after ransomware was used to encrypt their filesppHHS investigation indicated that the following conduct occurred Covered ConductppII Terms and Conditionspp ppFor Doctors Management Services Inc DMSpps
Timothy DiBona
Chief Executive Officer
Doctors Management Services Inc ppDatepp ppFor US Department of Health and Human Servicespps
Susan M Pezzullo Rhodes
Regional Manager New England Region
Office for Civil Rights ppDate pp ppAppendix AppCorrective Action PlanppBetween theppUS Department of Health and Human ServicesppAndppDoctors Management Services Inc DMSpp ppI PreambleppDMS hereby enters into this Corrective Action Plan CAP with the United States Department of Health and Human Services Office for Civil Rights HHS Contemporaneously with this CAP DMS is entering into the Agreement with HHS and this CAP is incorporated by reference into the Agreement as Appendix A DMS enters into this CAP as part of consideration for the release set forth in paragraph II8 of the Agreement Capitalized terms without definition in this CAP shall have the same meaning assigned to them under the AgreementppII Contact Persons and SubmissionsppIII Effective Date and Term of CAPppThe Effective Date for this CAP shall be calculated in accordance with paragraph II14 of the Agreement Effective Date The period for compliance Compliance Term with the obligations assumed by DMS under this CAP shall begin on the Effective Date of this CAP and end three 3 years from the Effective Date unless HHS has notified DMS under Section VIII hereof of its determination that DMS breached this CAP In the event of such a notification by HHS under Section VIII hereof the Compliance Term shall not end until HHS notifies DMS that it has determined that the breach has been cured After the Compliance Term ends DMS shall still be obligated to a submit the final Annual Report as required by section VI and b comply with the document retention requirement in section VII Nothing in this CAP is intended to eliminate or modify DMSs obligation to comply with the document retention requirements in 45 CFR 164316b and 164530jppIV TimeppIn computing any period of time prescribed or allowed by this CAP all days referred to shall be calendar days The day of the act event or default from which the designated period of time begins to run shall not be included The last day of the period so computed shall be included unless it is a Saturday a Sunday or a legal holiday in which event the period runs until the end of the next day which is not one of the aforementioned daysppV Corrective Action Obligationspp DMS agrees to the followingppVI Training Report and Annual ReportsppVII Reportable EventsppVIII Document RetentionppDMS shall maintain for inspection and copying and shall provide to HHS upon request all documents and records relating to compliance with this CAP for six 6 years from the Effective Date ppIX Breach ProvisionsppDMS is expected to fully and timely comply with all provisions contained in this CAPpp ppFor Doctors Management Services Inc DMSpps
Timothy DiBona
Chief Executive OfficerppDateppFor US Department of Health and Human ServicesppsppSusan M Pezzullo Rhodes
Regional Manager New England Region
Office for Civil RightsppDateppReceive the latest updates from the Secretary Blogs and News Releasespp200 Independence Avenue SW
Washington DC 20201
Toll Free Call Center 18776966775p
Official websites use gov
A gov website belongs to an official government organization in the United States
pp
Secure gov websites use HTTPS
A lock LockA locked padlock or https means youve safely connected to the gov website Share sensitive information only on official secure websites
ppResolution AgreementppI RecitalsppOn April 22 2019 OCR opened an investigation based on a breach report from DMS a practice management company that acts as a business associate to several covered entities The report stated that approximately 206695 individuals were affected when the DMS network server was infected with GandCrab ransomware The initial unauthorized access to the network occurred on April 1 2017 however DMS did not detect the intrusion until December 24 2018 after ransomware was used to encrypt their filesppHHS investigation indicated that the following conduct occurred Covered ConductppII Terms and Conditionspp ppFor Doctors Management Services Inc DMSpps
Timothy DiBona
Chief Executive Officer
Doctors Management Services Inc ppDatepp ppFor US Department of Health and Human Servicespps
Susan M Pezzullo Rhodes
Regional Manager New England Region
Office for Civil Rights ppDate pp ppAppendix AppCorrective Action PlanppBetween theppUS Department of Health and Human ServicesppAndppDoctors Management Services Inc DMSpp ppI PreambleppDMS hereby enters into this Corrective Action Plan CAP with the United States Department of Health and Human Services Office for Civil Rights HHS Contemporaneously with this CAP DMS is entering into the Agreement with HHS and this CAP is incorporated by reference into the Agreement as Appendix A DMS enters into this CAP as part of consideration for the release set forth in paragraph II8 of the Agreement Capitalized terms without definition in this CAP shall have the same meaning assigned to them under the AgreementppII Contact Persons and SubmissionsppIII Effective Date and Term of CAPppThe Effective Date for this CAP shall be calculated in accordance with paragraph II14 of the Agreement Effective Date The period for compliance Compliance Term with the obligations assumed by DMS under this CAP shall begin on the Effective Date of this CAP and end three 3 years from the Effective Date unless HHS has notified DMS under Section VIII hereof of its determination that DMS breached this CAP In the event of such a notification by HHS under Section VIII hereof the Compliance Term shall not end until HHS notifies DMS that it has determined that the breach has been cured After the Compliance Term ends DMS shall still be obligated to a submit the final Annual Report as required by section VI and b comply with the document retention requirement in section VII Nothing in this CAP is intended to eliminate or modify DMSs obligation to comply with the document retention requirements in 45 CFR 164316b and 164530jppIV TimeppIn computing any period of time prescribed or allowed by this CAP all days referred to shall be calendar days The day of the act event or default from which the designated period of time begins to run shall not be included The last day of the period so computed shall be included unless it is a Saturday a Sunday or a legal holiday in which event the period runs until the end of the next day which is not one of the aforementioned daysppV Corrective Action Obligationspp DMS agrees to the followingppVI Training Report and Annual ReportsppVII Reportable EventsppVIII Document RetentionppDMS shall maintain for inspection and copying and shall provide to HHS upon request all documents and records relating to compliance with this CAP for six 6 years from the Effective Date ppIX Breach ProvisionsppDMS is expected to fully and timely comply with all provisions contained in this CAPpp ppFor Doctors Management Services Inc DMSpps
Timothy DiBona
Chief Executive OfficerppDateppFor US Department of Health and Human ServicesppsppSusan M Pezzullo Rhodes
Regional Manager New England Region
Office for Civil RightsppDateppReceive the latest updates from the Secretary Blogs and News Releasespp200 Independence Avenue SW
Washington DC 20201
Toll Free Call Center 18776966775p