#hipaa

[ follow ]
#data-breach

100m Americans' data breached in biggest US healthcare hacks ever

Change Healthcare's cyberattack exposed 100 million patients, marking the largest health information breach in U.S. history.

Atlanta Women's Health Group notifying patients of April 2023 data breach

Atlanta Women's Health Group (AWHG) notified over 30,000 patients of a data breach that occurred in April 2023.
The breach resulted in the unauthorized access of files containing patients' protected health information.
It is unclear why it took AWHG until January 2024 to notify patients, despite HIPAA and HITECH requiring notification within 60 days of discovery.

Your data has been breached ... again ... this time by NY Presbyterian Hospital

The NewYork-Presbyterian Hospital has settled for $300,000 after failing to protect patient data.
The hospital's website used tracking tools that disclosed visitors' health information to third-party tech companies.

Douglas County Health & Human Services notifies patients that former employee accessed their records inappropriately

Unauthorized access to HIPAA data by a county employee was revealed six months after the discovery, highlighting issues in data security and accountability.

Health insurance giant Kaiser notifies millions of a data breach | TechCrunch

Kaiser Foundation Health Plan notified 13.4 million residents of a data breach involving unauthorized access to a network server.

100m Americans' data breached in biggest US healthcare hacks ever

Change Healthcare's cyberattack exposed 100 million patients, marking the largest health information breach in U.S. history.

Atlanta Women's Health Group notifying patients of April 2023 data breach

Atlanta Women's Health Group (AWHG) notified over 30,000 patients of a data breach that occurred in April 2023.
The breach resulted in the unauthorized access of files containing patients' protected health information.
It is unclear why it took AWHG until January 2024 to notify patients, despite HIPAA and HITECH requiring notification within 60 days of discovery.

Your data has been breached ... again ... this time by NY Presbyterian Hospital

The NewYork-Presbyterian Hospital has settled for $300,000 after failing to protect patient data.
The hospital's website used tracking tools that disclosed visitors' health information to third-party tech companies.

Douglas County Health & Human Services notifies patients that former employee accessed their records inappropriately

Unauthorized access to HIPAA data by a county employee was revealed six months after the discovery, highlighting issues in data security and accountability.

Health insurance giant Kaiser notifies millions of a data breach | TechCrunch

Kaiser Foundation Health Plan notified 13.4 million residents of a data breach involving unauthorized access to a network server.
moredata-breach
#data-breaches

HHS OCR Imposes a $548,265 Penalty Against Children's Hospital Colorado for HIPAA Violations

HHS imposed a $548,265 penalty on Children's Hospital Colorado for multiple HIPAA breaches affecting thousands of patients over multiple years.

HHS OCR settles charges that Inmediata Health Group exposed 1.6 million patients' PHI online

Health care entities must proactively secure patient information to prevent unauthorized online access, as per HHS OCR announcements.

HHS Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation for $90,000

HHS announced a settlement with Bryan County Ambulance Authority for a ransomware attack, marking the first enforcement of the Risk Analysis Initiative.

2nd Settlement Triggered by 2017 Ransomware Attack Costs WA Practice $100K; 'Not a Breach'

The Cascade Eye and Skin Centers settlement reflects ongoing enforcement actions related to HIPAA Security Rule violations, particularly amid increasing ransomware attacks in healthcare.

HHS OCR Imposes a $548,265 Penalty Against Children's Hospital Colorado for HIPAA Violations

HHS imposed a $548,265 penalty on Children's Hospital Colorado for multiple HIPAA breaches affecting thousands of patients over multiple years.

HHS OCR settles charges that Inmediata Health Group exposed 1.6 million patients' PHI online

Health care entities must proactively secure patient information to prevent unauthorized online access, as per HHS OCR announcements.

HHS Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation for $90,000

HHS announced a settlement with Bryan County Ambulance Authority for a ransomware attack, marking the first enforcement of the Risk Analysis Initiative.

2nd Settlement Triggered by 2017 Ransomware Attack Costs WA Practice $100K; 'Not a Breach'

The Cascade Eye and Skin Centers settlement reflects ongoing enforcement actions related to HIPAA Security Rule violations, particularly amid increasing ransomware attacks in healthcare.
moredata-breaches
#data-protection

HHS Office for Civil Rights Settles Ransomware Cybersecurity Investigation for $500,000

Increase in ransomware attacks highlights vulnerabilities in healthcare data security compliance with HIPAA.

Boosting HIPAA Compliance in EHR Systems with Privacy-by-Design

Incorporating Privacy by Design in EHR systems is vital for enhancing patient confidentiality and data protection.

Hospitals' legal win shows HIPAA's limits in shielding patient data

The recent legal decision enables hospitals to use tracking technologies, potentially exposing patient data to marketers and online brokers.

HHS Office for Civil Rights Settles Ransomware Cybersecurity Investigation for $500,000

Increase in ransomware attacks highlights vulnerabilities in healthcare data security compliance with HIPAA.

Boosting HIPAA Compliance in EHR Systems with Privacy-by-Design

Incorporating Privacy by Design in EHR systems is vital for enhancing patient confidentiality and data protection.

Hospitals' legal win shows HIPAA's limits in shielding patient data

The recent legal decision enables hospitals to use tracking technologies, potentially exposing patient data to marketers and online brokers.
moredata-protection
#cybersecurity

HHS' Office for Civil Rights Settles Malicious Insider Cybersecurity Investigation for $4.75 Million

Montefiore Medical Center settles with HHS for potential HIPAA violations
Data security failures led to employee stealing and selling patients' protected health information

OCR Releases Cybersecurity Video: Ransomware Update

OCR has released a video to educate HIPAA-regulated organizations on combating ransomware and emphasizes the role of HIPAA Security Rule compliance.

HHS Office for Civil Rights Imposes a $1.19 Million Penalty Against Gulf Coast Pain Consultants for HIPAA Security Rule Violations

Gulf Coast Pain Consultants faces a $1.19 million penalty for significant HIPAA Security Rule violations due to unauthorized access by a former contractor.

HHS' Office for Civil Rights Settles Malicious Insider Cybersecurity Investigation for $4.75 Million

Montefiore Medical Center settles with HHS for potential HIPAA violations
Data security failures led to employee stealing and selling patients' protected health information

OCR Releases Cybersecurity Video: Ransomware Update

OCR has released a video to educate HIPAA-regulated organizations on combating ransomware and emphasizes the role of HIPAA Security Rule compliance.

HHS Office for Civil Rights Imposes a $1.19 Million Penalty Against Gulf Coast Pain Consultants for HIPAA Security Rule Violations

Gulf Coast Pain Consultants faces a $1.19 million penalty for significant HIPAA Security Rule violations due to unauthorized access by a former contractor.
morecybersecurity

Grey's Anatomy Recap: The Petty Olympics

The episode explores the rampant disregard for HIPAA and other institutional rules that characters of Grey's Anatomy regularly ignore.

New Privacy Measure Could Help Safeguard Reproductive Healthcare - Non Profit News | Nonprofit Quarterly

The new Final Rule under HIPAA provides enhanced federal privacy protections for reproductive health care.

Three recent breach disclosures remind of us how seldom timely breach notification is enforced under HITECH

Patient data breaches exceeded HIPAA notification deadline.
McDonald Hopkins reported discovery date discrepancy.

HIPAA protects health data privacy, but not in the ways most people think

The P in HIPAA stands for portability, not privacy
HIPAA has limitations in terms of covered entities and covered data

Texas AG's pursuit of transgender medical records stirs privacy concerns

Texas Attorney General Ken Paxton is demanding medical records from health-care providers outside of Texas who may have treated transgender youth from Texas.
Paxton's use of a HIPAA exception for law enforcement investigations may allow him to obtain the records he is seeking.

Attorney General James Secures $300,000 from NewYork-Presbyterian Hospital for Failing to Protect Patient Data

New York Attorney General Letitia James secured $300,000 from NewYork-Presbyterian Hospital for violating HIPAA by disclosing healthcare information of website visitors.
The hospital used advertising tools on its website that collected and shared private and personal information with third-party tech companies.

HHS' Office for Civil Rights Settles First Ever Phishing Cyber-Attack Investigation

Lafourche Medical Group has settled with the U.S. Department of Health and Human Services following a cybersecurity breach that affected nearly 35,000 patients.
The breach was the result of a phishing attack, highlighting the vulnerability of healthcare systems to this type of cyber threat.
This settlement marks the first resolution by OCR involving a phishing attack under HIPAA Rules.

If you're in Rock County, Wisconsin, do NOT read this post. Absolutely do not read this post.

The IT Director and Corporation Counsel of Rock County, Wisconsin are withholding information about a September ransomware attack from the public.
The county is required to notify affected individuals and the U.S. Department of Health and Human Services (HHS) within 60 days of discovering the breach.

Marjorie Taylor Greene rages at HIPAA prosecution despite her past support for HIPAA - LGBTQ Nation

Rep. Marjorie Taylor Greene misinterprets HIPAA and argues against her own bill, highlighting inconsistencies in her understanding of medical privacy.

Applying The 'Would Your Mother Approve?' Rule To Online Ad Tracking | AdExchanger

Enforcing existing federal consumer privacy laws like ECPA and HIPAA can address privacy concerns without the need for new legislation.
[ Load more ]