H-ISAC TLP White Threat Bulletin: Misleading Postcard Disguised as Official OCR Communication

On April 26, 2021, HHS Office for Civil Rights in Action (OCR) was made aware of postcards being sent to healthcare organizations advising recipients that they are required to participate in a “Required Security Risk Assessment” which can be completed at www[.]hsaudit.org. The link directs individuals to a non-governmental website marketing consulting services.

Please be advised that these postcard notifications did not come from OCR or the US Department of Health and Human Services. The misleading communication is from a private entity – it is NOT an HHS/OCR communication. Suspected incidents of individuals posing as federal law enforcement should be reported to the Federal Bureau of Investigation.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

Senior Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272