Policy and Regulation

Amazon Sued for Hosting Florida Provider’s Stolen Healthcare Data

by Jessica Davis

SalusCare, on behalf of its patients, has sued an unnamed hacker and Amazon Web Services. According to the lawsuit, AWS is hosting healthcare data allegedly stolen from the Florida mental...

41 States Settle with AMCA Over 2019 Data Breach Affecting 21M Patients

by Jessica Davis

The Retrieval-Masters Creditors Bureau, d/b/a American Medical Collection Agency reached a with 41 state attorneys general, which could lead to a $21 million fine, to resolve a multistate investigation...

Proposed Data Privacy Bill Creates Federal Data Standard, Empowers FTC

by Jessica Davis

Rep. Suzan Delbene, D-Washington, introduced a national consumer data privacy bill, which would create a federal data privacy standard and supersede the patchwork of state laws. The proposed...

HHS Extends Comment Period for HIPAA Privacy Rule Changes

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it has extended the comment period for proposed changes to the HIPAA Privacy Rule. Proposed in December 2020, the changes...

Congress Urges FTC Crackdown on Health Apps Via Breach Notice Rule

by Jessica Davis

A group of three Congressional members from New Jersey are urging the Federal Trade Commission to utilize its Health Breach Notification Rule to crack down on mobile health apps that share personal...

White House: SolarWinds Hack Impacted 9 Fed Agencies, 100 Entities

by Jessica Davis

At a White House press briefing on Wednesday, Deputy National Security Advisor for Cyber and Emerging Technology Anne Neuberger confirmed that the SolarWinds Orion compromise claimed nine federal...

DOJ Indicts WannaCry Creators, as Global Feds Impact Egregor Efforts

by Jessica Davis

In two separate actions this week, federal efforts have stymied global cybercriminal activities. The Department of Justice indicted the creators of WannaCry, while transnational government cyber...

Patients Sue Wilmington Surgical For Netwalker Ransomware Data Leak

by Jessica Davis

A lawsuit has been filed against Wilmington Surgical Associates in response to a ransomware attack in October. Allegedly, the Netwalker hacking group stole a trove of 13GB of data from the North...

FDA Names First Acting Director of Medical Device Cybersecurity

by Jessica Davis

The Food and Drug Administration recently named Kevin Fu as the agency’s first Acting Director of Medical Device Cybersecurity in its Center for Devices and Radiological Health. Fu is an...

US Fertility Sued Over Ransomware Attack, Health Data Exfiltration

by Jessica Davis

US Fertility (USF) has been sued by the individuals impacted by its September ransomware attack, after the threat actors gained access to the third-party vendor’s network for a month and...

Proposed Public Health Emergency Bill Targets COVID-19 Tech Privacy

by Jessica Davis

A group of Democratic Senators and Congressional membersproposed legislation meant to tackle the privacy and security issues tied to technologies used for the COVID-19 response, including contact...

Judge Dismisses Brandywine Urology Breach Lawsuit, Citing Lack of Harm

by Jessica Davis

A healthcare data breach lawsuit against Brandywine Urology Consultants has been dismissed by the Delaware Superior Court, as the victims failed to provide evidence of injuries or losses caused by the...

Fertility App Premom Sued Over Alleged Data Sharing with China

by Jessica Davis

Easy Healthcare Corp., the owner of fertility app Premom, is being sued by an app user, over claims the company shared personal data with third-party data collection firms in China -- without user...

Netwalker Ransomware Site, Emotet Botnet Taken Down in Global Effort

by Jessica Davis

Two of the most prolific cyber threats have been disrupted by global Federal efforts this week. The notorious Emotet botnet was taken down through a global collaboration, while the FBI and the...

Philly DA Investigating Possible COVID-19 Vaccine Privacy Violation

by Jessica Davis

The Philadelphia Department of Public Health abruptly ended its contract with Philly Fighting COVID, tasked with the city’s COVID-19 vaccine distribution, over allegations that the startup...

Patient Sues Rady Children’s Hospital Over Blackbaud Data Breach

by Jessica Davis

A guardian of a patient whose information was included in last year's Blackbaud data breach has sued Rady Children’s Hospital over the incident. Blackbaud is a third-party vendor of the...

OCR Lifts HIPAA Penalties for Use of COVID-19 Vaccine Scheduling Apps

by Jessica Davis

The Office for Civil Rights announced another enforcement discretion amid the pandemic, lifting penalties for potential HIPAA violations related to the good faith use of online or web-based scheduling...

Judge Vacates $4.3M OCR Penalty Against MD Anderson Over Data Loss

by Jessica Davis

The US Court of Appeals for the Fifth Circuit has vacated the $4.3 million civil monetary penalty against the University of Texas MD Anderson Cancer Center after two years and several lost appeals. The...

HIPAA Safe Harbor Bill Becomes Law; Requires HHS to Incentivize Security

by Jessica Davis

President Donald Trump officially signed HR 7898 into law on January 5. The HIPAA Safe Harbor bill amends the HITECH act to require the Department of Health and Human Services to incentivize best...

FTC Reaches Settlement with SkyMed for 2019 Consumer Data, PHI Breach

by Jessica Davis

The FTC reached a settlement with SkyMed that requires the Nevada-based provider of emergency services to implement a comprehensive information security program, which will resolve allegations stemming...