The short version
- Health care is a top target in Washington. It filed 332 of the 1,675 breach notices in Attorney General records, 24% of recent notices, and 114 ransomware notices.
- Two sets of rules apply to a breach. HIPAA's Breach Notification Rule for protected health information, and Washington's breach law, which requires Attorney General notice even when HIPAA governs.
- Not all your data is HIPAA data. Website tracking, marketing lists, and wellness services may fall under Washington's My Health My Data Act instead.
- Your vendors are your risk. The 2024 Change Healthcare ransomware attack showed a claims vendor's outage can stop a practice's revenue.
- Coverage features to insist on: regulatory defense and penalties, dependent business interruption, ransomware without a low sublimit, and privacy liability that covers wrongful collection.
What Washington's breach data shows for health care
From Trella Commercial's analysis of Washington Attorney General breach notices:
| Measure | Health care |
|---|---|
| Breach notices filed, 2015 to 2026 | 332 |
| Share of recent notices (July 2023 to July 2026) | 24% |
| Share of health care breaches caused by cyberattacks | 72% |
| Ransomware notices | 114 |
| Notices reaching the Attorney General more than 30 days after discovery (since March 2020) | 89% |
Across all sectors, 37% of notices involved medical information and 28% involved health insurance ID numbers. The late-filing share for health care partly reflects HIPAA's longer timeline, explained below.
HIPAA and Washington law: which rules apply
| Requirement | HIPAA Breach Notification Rule | Washington (RCW 19.255) |
|---|---|---|
| What it covers | Unsecured protected health information held by covered entities and business associates | Personal information of Washington residents, including medical information and health insurance IDs |
| When it is a breach | Presumed a breach unless a risk assessment shows a low probability the information was compromised | Unauthorized acquisition that compromises personal information, unless not reasonably likely to cause harm |
| Notice to individuals | Without unreasonable delay, no later than 60 calendar days after discovery | No more than 30 calendar days after discovery |
| Notice to the government | HHS: at the same time as individual notice for 500 or more people; annually, within 60 days after year end, for fewer than 500 | Attorney General when more than 500 Washington residents are notified |
| Media notice | Prominent media outlets when more than 500 residents of a state are affected | Only as part of substitute notice |
| Business associates and vendors | Must notify the covered entity without unreasonable delay, no later than 60 days | Must notify the data owner immediately |
How they fit together: under RCW 19.255.030, a HIPAA covered entity that complies with the federal rules is deemed compliant with Washington's law for protected health information, but must still notify the Washington Attorney General, on HIPAA's timeline.
Data that is not protected health information, such as employee records or a separate retail or wellness line, follows Washington's 30-day rule. See Washington data breach notification law.
The My Health My Data Act gap
Washington's My Health My Data Act exempts protected health information governed by HIPAA, but a practice often collects health-related data outside HIPAA:
- Website tracking pixels and analytics on appointment and service pages
- Marketing lists and email campaigns about treatments
- Wellness, cosmetic, or retail services offered outside the covered practice
- Apps or patient portals run by vendors with their own data practices
For one practice's experience, see the dental practice story.
That data can bring consent and privacy claims under the Act. Check that your cyber policy's privacy liability covers wrongful collection claims and does not exclude tracking technologies. See Washington's My Health My Data Act.
Vendor outages: the Change Healthcare lesson
In February 2024, a ransomware attack on Change Healthcare, a major medical claims and payment processor, disrupted claims processing and payments for providers nationwide. Many practices had no breach of their own but lost cash flow for weeks.
The coverage that addresses that is dependent business interruption: lost income when a vendor you rely on goes down. For a practice, list the vendors you cannot operate without:
- Practice management and electronic health records
- Claims clearinghouse and payment processing
- Imaging and lab systems
- Scheduling, reminders, and patient communications
- Phone and internet
Ask whether your policy covers each type, whether it covers vendor accidents as well as attacks, and what the sublimit is. More in cyber business interruption.
Coverage features that matter most for practices
| Feature | Why it matters for health care | What to check |
|---|---|---|
| Breach response | Health breaches mean HIPAA and state notices, call centers, and monitoring | Whether costs erode the main limit |
| Regulatory defense and penalties | HHS Office for Civil Rights and state Attorney General investigations follow health breaches | Whether "privacy regulations" include HIPAA and state law, and insurability of fines |
| Ransomware and extortion | Health care is a frequent ransomware target | Sublimits and coinsurance on extortion |
| Business interruption | A down schedule or billing system stops revenue | Waiting period and period of restoration |
| Dependent business interruption | Clearinghouse and practice software outages | Vendor types covered and sublimit |
| Privacy liability | Patients sue after exposure | Coverage for wrongful collection and tracking claims |
| Social engineering | Fake vendor invoices and payroll changes | Sublimit vs your largest payments |
| PCI | Patient card payments | Only if you store or process card data directly |
What insurers ask health practices
Beyond the standard controls (see what a cyber insurance application asks), expect questions about:
- Number of patient records, current and former
- Whether patient data is encrypted, including on laptops and imaging devices
- HIPAA risk assessments and policies
- Business associate agreements with vendors
- Medical devices or imaging systems on your network running old software
- Who has remote access, including vendors that support your systems