Policy and Regulation

CA State Legislature Passes Bill to Protect Abortion Data Privacy

by Jill McKeon

The California State Legislature passed a bill (AB 1242) that would protect abortion data privacy by preventing out-of-state law enforcement officers from executing search warrants on California-based...

US Treasury Sanctions Crypto Exchange For Aiding Ransomware Payments

by Jill McKeon

The US Department of the Treasury announced its first ever sanction against a cryptocurrency exchange SUEX for its alleged role in facilitating ransomware payments for cybercriminals. The...

How Can Congress Aid Healthcare Cybersecurity, Fight Ransomware?

by Lisa Gentes-Hunt

Healthcare is a prime target of ransomware and needs assistance to face digital thieves, according to several witnesses that testified before Congress this...

HSCC to Biden: Invest in Healthcare Cybersecurity, Partnerships

by Jessica Davis

The Healthcare and Public Health Sector Coordinating Council is urging the Biden Administration to invest in a structured healthcare cybersecurity partnership through the American Rescue Plan, to...

Humana, Cotiviti Sued After Insider-Related Healthcare Data Breach

by Jessica Davis

A proposed class action lawsuit has been filed against insurance giant Humana and its vendor Cotiviti following a healthcare data breach impacting 65,000 patients, which was caused by an...

Judge Approves Nebraska Medicine Data Breach Lawsuit Settlement

by Jessica Davis

A judge for the US District Court of Nebraska has approved a preliminary settlement in the data breach lawsuit filed against Nebraska Medicine in February 2021. However, most of the terms have...

DOJ, White House Take Aim at Critical Infrastructure Ransomware Attacks

by Jessica Davis

This week, the White House and the Department of Justice announced efforts to improve the coordination of investigations into ongoing ransomware attacks and data extortion efforts, while urging private...

GAO: Insurers Limiting Coverage in Attack-Laden Sectors, Like Healthcare

by Jessica Davis

A recent Government Accountability Office report shows that industries experiencing an onslaught of cyberattacks, like healthcare, may face another concerning challenge: Some cyber insurers...

Universal Health Services Lawsuit: 2 Claims Dismissed, Citing Lack of Harm

by Jessica Davis

The US District Court for Pennsylvania’s Eastern District recently dismissed two out of three claims made in a lawsuit filed against Universal Health Services, citing a lack of harm. The...

Biden’s Executive Order to Boost Threat Sharing, Supply Chain Security

by Jessica Davis

President Joe Biden signed an executive order on Wednesday that takes aim at the country’s infrastructure cybersecurity weaknesses and is designed to bolster threat sharing between the government...

HHS’ Proposed HIPAA Right of Access Changes: CHIME, ABHW Weigh in

by Jessica Davis

CHIME and the Association for Behavioral Health and Wellness sent letters to the Department of Health and Human Services, in response to proposed changes to HIPAA. Among a range of concerns are...

PA Health Dept Sued; Investigation Looms, After Contact Tracing Breach

by Jessica Davis

The Pennsylvania Department of Health and its third-party contractor Insight Global have been sued, after reports that its COVID-19 contact tracing app exposed the sensitive data of at least 72,000...

MA AG Questions Retail Pharmacy Use of Patient COVID-19 Vaccine Data

by Jessica Davis

After reports that personally identifiable information is being unnecessarily collected from patients seeking the COVID-19 vaccine, Massachusetts Attorney General Maura Healy sent a letter to...

Google Sued, Lawsuit Claims COVID-19 Contact Tracing Tool Exposes Data

by Jessica Davis

Two individuals who used California’s state public health COVID-19 contact tracing app have filed a lawsuit against its developer, Google, claiming the tool exposes user data and violated their...

Breach Victims File Class Action Lawsuit Against Einstein Healthcare

by Jessica Davis

Einstein Healthcare Network is facing a class-action lawsuit, following the August 2020 hack of several employee email accounts. The breach victims claim the Pennsylvania-based health system failed to...

VA Health Records Protocols Probed, Following Sexual Harassment Reports

by Jessica Davis

A group of 50 Congressional members sent a letter to Department of Veterans Affairs Secretary Denis McDonough, after multiple reports of sexual harassment claims made by women veterans and employees....

GAO Audit Finds HHS Information Security Program “Not Effective”

by Jessica Davis

An evaluation of the Department of Health and Human Services against Federal Information Security Modernization Act of 2014 (FISMA) principles found the agency’s information security program...

586K Trinity Health Patients Added to Accellion Tally, as Lawsuits Pile Up

by Jessica Davis

Michigan-based Trinity Health recently notified 586,869 patients that their data was compromised during the hack on Accellion’s File Transfer Application (FTA). As the breach tally continues to...

COVID-19, Info Blocking Provisions: Time for HIPAA Compliance Checkup

by Jessica Davis

The information blocking provisions of the 21st Century Cures Act officially went into effect this week, putting into focus the Department of Health and Human Services’ regulatory and compliance...