Protected Health Information

Renown Health Falls Victim to Elekta Data Breach, PHI Exposed

by Jill McKeon

Renown Health in Nevada announced that its patients’ protected health information (PHI) was exposed through an April data breach of its business associate, Elekta. Over 40 other health systems...

UofL Health Data Breach Occurs After PHI Sent to Wrong Email

by Jill McKeon

UofL Health in Louisville, Kentucky sent notification letters to over 40,000 patients explaining that their protected health information (PHI) was accidentally sent to the wrong email address in a...

Scripps Health Ransomware Attack Leads to Class-Action Lawsuits

by Jill McKeon

Scripps Health in San Diego, California is facing two class-action lawsuits after a recent ransomware attack that led to EHR downtime and disruptions in care. The plaintiffs claim that the attack was...

Disclosed OpenClinic Flaws Pose Remote Code Execution, PHI Risk

by Jessica Davis

Researchers from Bishop Fox Labs discovered four vulnerabilities in the OpenClinic application, an open-source health records management software, which could allow an attacker to read patient...

Millions of Medical Images Exposed, as US Fails to Secure PACS Flaws

by Jessica Davis

In the Fall of 2019, a damning report from ProPublica outlined a massive healthcare exposure: millions of medical images generated from Picture Archiving and Communication Systems (PACS) were left...

Search Engines May Expose Patient Health Information, ACR warns

by Jessica Davis

New search engine capabilities may inadvertently expose patient identifiers and other protected health information, according to a warning from the American College of Radiology...

Hackers Access PHI During Mat-Su Surgical Ransomware Attack

by Jessica Davis

Arkansas-based Mat-Su Surgical Associates (MTA) is notifying 13,136 current patients and some current or former patients of Valley Surgical Associates that their protected health information was viewed...

OCR Shares COVID-19 PHI, Data Sharing Guidance for First Responders

by Jessica Davis

The Office for Civil Rights released guidance for how protected health information on patients exposed or infected with COVID-19 can be shared with first responders, such as law enforcement,...

Massive SingHealth Data Breach Caused by Lack of Basic Security

by Jessica Davis

Singapore’s July 2018 personal data breach of 1.5 million SingHealth patients, including Prime Minister Lee Hsien Loong, was caused by bad system management, a lack of employee training, and...

New York Suspends Nurse for HIPAA Violation Affecting 3K Patients

by Fred Donovan

The state of New York has suspended Martha Smith-Lightfoot, a former nurse at the University of Rochester Medical Center (URMC), for a HIPAA violation. Smith-Lightfoot admitted to disclosing PHI when...

Perils of Healthcare Phishing and What You Can Do About It

by Fred Donovan

The old stereotype used to be that doctors didn’t work on Wednesday because they were out playing golf or fishing. Today, healthcare phishing is no joke to doctors, many of whom work on Wednesdays and weekends, or for other...

KS Healthcare Organization Fined over Unsecured Patient Data

by Elizabeth Snell

Topeka, Kansas-based Pearlie Mae’s Compassion and Care LLC recently agreed to pay an $8,750 civil penalty after allegations that it had unsecured patient data in one of its office...

How HIPAA Rules Apply with Law Enforcement Investigations

by Elizabeth Snell

HIPAA rules are meant to protect patient information, but what happens when there is a law enforcement investigation? Are police officers allowed to demand PHI without a warrant? That issue was...

Medical Record Security Key Focus in Indiana Senate Bill

by Elizabeth Snell

Database owners are now required to ensure medical record security by safeguarding healthcare data stored in their systems, according to a recently updated Indiana bill. Senate Bill 549 changed the...