HIPAA and Compliance News

LA Patient Privacy Incident Discloses COVID-19 Vaccine Status 

by

An accidental patient privacy event shared online the COVID-19 vaccination status of over 4,000 Los Angeles County...

California Updates Health Facility Data Breach Requirements 

by

California is tightening up its health facility data breach regulations and recently issued an update to its administrative penalties and reporting requirements.  The newly...

Connecticut’s Updated Cybersecurity Law Now Protects Patient Data 

by

A newly signed Connecticut cybersecurity law will now allow for the protection of patient data and other private health information.  An Act Concerning Data Privacy...

Colorado Governor Signs The Colorado Privacy Act Into Law  

by

Colorado Governor Jared Polis signed the Colorado Privacy Act (CPA) into law on July 8, adding protections for Colorado consumer’s data and...

HHS Warns Health PACS: Patient Data Vulnerable to Cyber Exploitation 

by

Health PACS are vulnerable to hackers that could expose millions of patients' private health information, according to a new alert from the Department of Health &...

Report: Privacy Concerns With Apps Used For Opioid Addiction Treatment

by

A reported released by the ExpressVPN Digital Security Lab on July 7 revealed privacy concerns with ten smart phone apps used in...

Data Breach Exposes One Medical Customer Email Addresses

by

Customers of One Medical, a direct paid, membership-based primary care practice, inadvertently had their email addresses shared with fellow customers.  “We are...

Ohio Hospital HIPAA Violation Goes Unnoticed for Over a Decade

by

Aultman Health Foundation in Ohio announced the termination of an unnamed employee who committed a HIPAA violation that put patient EHRs and personally identifiable information (PII) at risk. For over...

OCR Settles With West Virginia-Based DELC for HIPAA Right of Access Failure

by

The Department of Health and Human Services Office for Civil Rights announced it reached a settlement with West Virginia specialist Diabetes, Endocrinology & Lipidology Center (DELC) for $5,000, to...

GAO: Insurers Limiting Coverage in Attack-Laden Sectors, Like Healthcare

by

A recent Government Accountability Office report shows that industries experiencing an onslaught of cyberattacks, like healthcare, may face another concerning challenge: Some cyber insurers...

OCR Settles with AEON Clinical for $25K Over Multiple HIPAA Failures

by

Peachstate Health Management, doing business as AEON Clinical Laboratories, has settled with the Department of Health and Human Services Office for Civil Rights for $25,000 and agreed to a...

HHS’ Proposed HIPAA Right of Access Changes: CHIME, ABHW Weigh in

by

CHIME and the Association for Behavioral Health and Wellness sent letters to the Department of Health and Human Services, in response to proposed changes to HIPAA. Among a range of concerns are...

NIST Seeks Feedback on Guide to Implementing HIPAA Security Rule

by

NIST announced it plans to update its Introductory Resource Guide for Implementing the HIPAA Security Rule and is seeking comment from industry stakeholders on proposed changes, including insights into...

Breach Victims File Class Action Lawsuit Against Einstein Healthcare

by

Einstein Healthcare Network is facing a class-action lawsuit, following the August 2020 hack of several employee email accounts. The breach victims claim the Pennsylvania-based health system failed to...

COVID-19, Info Blocking Provisions: Time for HIPAA Compliance Checkup

by

The information blocking provisions of the 21st Century Cures Act officially went into effect this week, putting into focus the Department of Health and Human Services’ regulatory and compliance...

OCR Settles With NJ Specialist for Over HIPAA Right of Access Failure

by

The Department of Health and Human Services Office for Civil Rights announced it reached a settlement with Village Plastic Surgery (VPS) to resolve potential violations of the HIPAA right of access...

Arbour Hospital Pays OCR $65K Over HIPAA Right of Access Violation

by

The Department of Health and Human Services announced it reached a $65,000 settlement with Massachusetts-based Arbour Hospital, which resolved potential violations of the HIPAA right of access...

HHS Extends Comment Period for HIPAA Privacy Rule Changes

by

The Department of Health and Human Services Office for Civil Rights announced it has extended the comment period for proposed changes to the HIPAA Privacy Rule. Proposed in December 2020, the changes...

Patients Sue Wilmington Surgical For Netwalker Ransomware Data Leak

by

A lawsuit has been filed against Wilmington Surgical Associates in response to a ransomware attack in October. Allegedly, the Netwalker hacking group stole a trove of 13GB of data from the North...

$70K OCR Penalty for Sharp Health Over HIPAA Right of Access Failures

by

California-based Sharp HealthCare, doing business as Sharp Rees-Stealy Medical Centers (SRMC), has agreed to a corrective action plan and to pay the Office for Civil Rights a $70,000 civil monetary...