Healthcare Information Security

HIPAA Technical Safeguards

Secure healthcare communication in a mobile environment

by Andy Nieto

Mobile technology has undoubtedly advanced, as today’s smartphone possesses more computing power than NASA did when we first put man on the moon. Power without purpose, however, is chaos and privacy and security are not ancillary...

Employees file class suit against UPMC following data breach

by Patrick Ouellette

Employees affected by the University of Pittsburgh Medical Center (UPMC) data breach have filed a class action lawsuit against UPMC and its payroll vendor, Ultimate Software Group. The suit says that UPMC and the vendor breached its duty...

HHS deals out largest-ever $4.8M HIPAA violation settlement

by Patrick Ouellette

The Department of Health and Human Services (HHS) announced yesterday that it had handed out $4.8 million worth of HIPAA fines to New York and Presbyterian Hospital (NYP) and Columbia University (CU) after they submitted a joint breach...

OCR dismisses Walgreens ‘Well Experience’ HIPAA complaint

by Patrick Ouellette

The Office for Civil Rights (OCR) has officially completed its investigation into the Walgreens “Well Experience” program and dismissed the complaint filed by the activist group, Change to Win (CtW), after finding CtW’s patient...

Molina Healthcare contractor mail error exposes patient data

by Patrick Ouellette

Molina Healthcare, a multi-state healthcare organization, reported on Friday that a postcard mailing error in March had resulted in 5,261 former members’ Social Security numbers being inadvertently exposed. According to the...

UMass Memorial Medical sends out patient data breach notices

by Patrick Ouellette

After taking nearly two months to flesh out a patient data breach involving inappropriate internal access, UMass Memorial Medical Center (UMMMC) of Worcester, Mass. announced this week that it had alerted more than 2,400 affected patients...

Centura Health alerts 1,000 patients of phishing attack

by Patrick Ouellette

A data breach involving Mercy Regional Medical Center of Durango, Colo. exemplifies the stark reality that phishing attacks have become more complex and difficult for even the most shrewd of users to pick out. Mercy employees, according...

Boston Medical Center transcription service exposes PHI

by Patrick Ouellette

Once it learned that 15,000 patients’ data had been exposed on its transcription service vendor’s website, Boston Medical Center (BMC) fired MDF Transcription Services and has sent breach notification letters to patients. The...

Health data breach roundup: Tufts Health Plan, Iowa DHS

by Patrick Ouellette

Data breaches of all different shapes, sizes and victims are being reported on an almost daily basis, so it can be difficult to stay up to date on the latest breach incidents. HealthITSecurity.com has compiled a list of the latest breaches...

Coordinated Health data breach may impact 700 patients

by Patrick Ouellette

Coordinated Health reported this week that a data breach involving a stolen laptop belonging to an employee may have affected up to 700 patients. According to poconorecord.com, an employee in Bethlehem had left the laptop in their car and...

Managing healthcare network security and BYOD needs

by Patrick Ouellette

Though there’s never a true winner in the “ease of use” v. security debate, coming to a happy medium between the two can present challenges for healthcare organizations. This is especially the case when dealing with the...

Reviewing Concentra Health and QCA HIPAA breach CAPs

by Patrick Ouellette

We learned yesterday that two HIPAA covered entities, Concentra Health Services and QCA Health Plan, had come to individual monetary agreements with the Office for Civil Rights (OCR) to settle HIPAA violations. Those resolutions included...

Concentra, QCA Health Plan agree to HIPAA breach settlements

by Patrick Ouellette

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) sent out a release today detailing two entities’ settlements for HIPAA Privacy and Security Rule violations involving unencrypted laptop...

Kentucky passes state data breach notification law

by Patrick Ouellette

Following Kentucky Auditor of Public Accounts (APA) Adam H. Edelen explaining in detail back in January why Kentucky needed a breach notification law, the state recently became the 47th to ratify data breach notification legislation. On...

UPMC alerts employees of data breach, fraud activity

by Patrick Ouellette

The University of Pittsburgh Medical Center (UPMC) reported that as many as 27,000 employees’ may have been affected by a data breach it learned of in February. It appeared as though the compromised information was accessed with...

LewisGale Regional Health System experiences data breach

by Patrick Ouellette

LewisGale Regional Health System of Salem, Va. recently reported a multi-state data breach that affected 400 patients, 40 of which were under LewisGale’s care. The breach, wdbj7.com reported, occurred in LewisGale’s billing...

Mobile health IT security: Bolstering technology with policy

by Patrick Ouellette

One way or another, mobile devices are finding their way into healthcare organizations’ four walls and onto their networks. Each organization’s mobile needs vary based on size and available resources and many have come a long...

University Urology of Tenn. releases data breach statement

by Patrick Ouellette

University Urology, P.C. of Knoxville, Tenn. released a statement on April 11 that detailed how 1,144 patients’ data had been exposed in 2013 and early 2014. Though the information was limited to patient names and addresses,...

Texas nonprofit advocacy group tells 2,934 of PHI breach

by Patrick Ouellette

An Austin, Texas nonprofit advocacy group for children with developmental disabilities, EveryChild, Inc., recently announced that it has informed 2,934 families of a potential data breach, according to mysanantonio.com. The group learned...

La Palma Intercommunity Hospital announces 2012 data breach

by Patrick Ouellette

Following a year and a half delay, La Palma Intercommunity Hospital recently announced that it has alerted an unknown number of patients of a September 2012 internal data breach that may have compromised their data. However, according to...

X

SIGN UP and gain free access to articles, white papers, webcasts and exclusive interviews on

HIPAA Compliance
BYOD
Cybersecurity
Data Breaches
Ransomware

Our privacy policy


no, thanks

Continue to site...