Patient Privacy

OIG: VA Staff Hid Privacy, Security Risks of AI Health Data Project

by Jessica Davis

Two employees of the Department of Veterans Affairs concealed and made false representations about the privacy and security risks of a 2016 AI health data project between the agency and Flow...

Fertility App Premom Sued Over Alleged Data Sharing with China

by Jessica Davis

Easy Healthcare Corp., the owner of fertility app Premom, is being sued by an app user, over claims the company shared personal data with third-party data collection firms in China -- without user...

Philly DA Investigating Possible COVID-19 Vaccine Privacy Violation

by Jessica Davis

The Philadelphia Department of Public Health abruptly ended its contract with Philly Fighting COVID, tasked with the city’s COVID-19 vaccine distribution, over allegations that the startup...

Hackers Leak COVID-19 Vaccine Data Stolen During EU Regulator Breach

by Jessica Davis

The European Medicines Agency discovered hackers have posted online the COVID-19 vaccine data exfiltrated during an earlier cyberattack on the EU regulator. As previously reported, the hacked server...

OCR Guide on HIPAA-Compliant PHI Disclosures Via HIEs, Amid COVID-19

by Jessica Davis

The Office for Civil Rights recently released guidance for covered entities and business associates on HIPAA-permitted disclosures of protected health information through the use of health information...

FTC Reaches Settlement with SkyMed for 2019 Consumer Data, PHI Breach

by Jessica Davis

The FTC reached a settlement with SkyMed that requires the Nevada-based provider of emergency services to implement a comprehensive information security program, which will resolve allegations stemming...

Third-Party Vendor Dental Care Alliance Breach Impacts 1M Patients

by Jessica Davis

Third-party vendor, Dental Care Alliance, recently began notifying hundreds of its clients that a near-monthlong system hack potentially breached the protected health information and payment card...

$4.2M Settlement Proposed in Kalispell Regional Breach Lawsuit

by Jessica Davis

A proposed $4.2 million settlement has been reached in the lawsuit filed against Kalispell Regional Healthcare (KRH) and the 130,000 patients affected by a monthslong data breach reported by...

Ohio Medical Center Pays OCR $65K for HIPAA Right of Access Failure

by Jessica Davis

The University of Cincinnati Medical Center in Ohio has agreed to a $65,000 settlement and a corrective action penalty with the Office for Civil Rights to resolve a potential violation of the...

Millions of Medical Images Exposed, as US Fails to Secure PACS Flaws

by Jessica Davis

In the Fall of 2019, a damning report from ProPublica outlined a massive healthcare exposure: millions of medical images generated from Picture Archiving and Communication Systems (PACS) were left...

Medical Device Vendor Zoll Sues IT Firm Over Breach Affecting 277K

by Jessica Davis

Medical device vendor Zoll filed a lawsuit with the US District Court of Massachusetts against IT service vendor Barracuda Networks, after an error during a server...

OCR Settles with Psychiatric Provider for HIPAA Right of Access Violation

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it reached a $25,000 settlement with California-based Riverside Psychiatric Medical Group...

$350K Proposed Settlement Reached in Saint Francis Data Breach Lawsuit

by Jessica Davis

Missouri-based Saint Francis Healthcare System has reached a proposed $350,000 lawsuit settlement with the patients impacted by a ransomware attack on Ferguson Medical Group (FMG). Saint Francis...

Wakefern, ShopRite Pay New Jersey $235K for Fraud Act, HIPAA Violations

by Jessica Davis

The New Jersey Division of Consumer Affairs and NJ Attorney General Gurbir Grewal announced a settlement with Wakefern Food Corp and two associated ShopRite supermarkets to resolve...

350M Voicemails, Health Details Exposed by Misconfigured Database

by Jessica Davis

Comparitech researchers discovered a trove of Broadvoice databases containing more than 350 million customer records, including names, contact details, and in some...

NY Spine Settles with OCR for $100K Over HIPAA Right of Access Violation

by Jessica Davis

The Office for Civil Rights announced yet another settlement under the 2019 HIPAA Right of Access Initiative. NY Spine Medicine will pay the agency $100,000 and agreed to a corrective...

Dignity Health to Pay OCR $160K for HIPAA Right of Access Failure

by Jessica Davis

Arizona-based Dignity Health, doing business as St. Joseph’s Hospital and Medical Center (SJHMC), has agreed to corrective actions and a $160,000 enforcement action with the...

Premera Pays OCR $6.85M to Settle HIPAA Violations, Breach of 10.4M

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights settled with Premera Blue Cross for $6.85 million and a corrective action plan, after an audit into the insurer’s...

Patient Breach Victims File Lawsuits Against Assured Imaging, BJC Health

by Jessica Davis

The patients impacted by two separate data breaches of Assured Imaging and BJC Healthcare have filed lawsuits against the providers, alleging security failings were behind...

OCR Settles with 5 Providers Over HIPAA Right of Access Violations

by Jessica Davis

The Office for Civil Rights closed investigations and announced settlements with five providers over separate HIPAA right of access violations, which brings the total number of...