HHS alerted hospitals and health systems of someone posing as an Office for Civil Rights investigator to get patient health information, the American Hospital Association warned.
In a notice last week, the association said HIPAA-covered entities should notify their staff. All OCR investigators have email addresses end with @hhs.gov. If staff receive a phony email, they should ask for a confirming email from the hhs.gov email account.
The OCR has halted many investigations. In March, President Donald Trump announced that his administration would not be enforcing HIPAA penalties.