Policy and Regulation

Health IT Groups Laud Proposed Bill Incentivizing Best Practice Security

by Jessica Davis

Several health IT industry stakeholder groups have issued support of legislation recently passed by the House Energy and Commerce Committee. The proposed HR 7898 bill would require the Department...

HHS Proposes HIPAA Privacy Rule Changes, Improving Right of Access

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights released a set of proposed changes to the HIPAA Privacy Rule, which take aim at Right of Access rules and are designed to reduce...

$4.2M Settlement Proposed in Kalispell Regional Breach Lawsuit

by Jessica Davis

A proposed $4.2 million settlement has been reached in the lawsuit filed against Kalispell Regional Healthcare (KRH) and the 130,000 patients affected by a monthslong data breach reported by...

Final HHS Rules Provide Safe Harbor for Cybersecurity Tech Donations

by Jessica Davis

The Department of Health and Human Services published two final rules on Friday designed to reduce regulatory barriers and improve care coordination, which both contain safe harbor provisions that will...

Blackbaud Faces Another Lawsuit, as More Healthcare Victims Reported

by Jessica Davis

Another class-action lawsuit has been filed against Blackbaud following a ransomware attack that breached the data of more than 10 million individuals from well over 100 companies. In recent weeks, the...

NY Specialist Pays OCR $15K for HIPAA Right of Access Failures

by Jessica Davis

The Office for Civil Rights announced it reached a settlement with Rajendra Bhayani, MD, a private practice otolaryngology specialist based in Regal Park, New York for $15,000 and a corrective action...

Medical Device Vendor Zoll Sues IT Firm Over Breach Affecting 277K

by Jessica Davis

Medical device vendor Zoll filed a lawsuit with the US District Court of Massachusetts against IT service vendor Barracuda Networks, after an error during a server...

Zoom Reaches Settlement with FTC Over Misleading Security Practices

by Jessica Davis

The Federal Trade Commission reached a settlement with Zoom to resolve allegations that the company engaged in misleading security practices. The use of the videoconferencing platform...

$350K Proposed Settlement Reached in Saint Francis Data Breach Lawsuit

by Jessica Davis

Missouri-based Saint Francis Healthcare System has reached a proposed $350,000 lawsuit settlement with the patients impacted by a ransomware attack on Ferguson Medical Group (FMG). Saint Francis...

Wakefern, ShopRite Pay New Jersey $235K for Fraud Act, HIPAA Violations

by Jessica Davis

The New Jersey Division of Consumer Affairs and NJ Attorney General Gurbir Grewal announced a settlement with Wakefern Food Corp and two associated ShopRite supermarkets to resolve...

DOJ Indicts Russian Hackers Behind 2017 NotPetya Malware Attack

by Jessica Davis

The Department of Justice announced the indictment of six Russian-backed hackers behind the global 2017 NotPetya malware attack. Though the cyberattack began on a...

UHS Health System Ransomware Attack, Security Probed by Senator

by Jessica Davis

Sen. Mark Warner, D-Virginia, sent a letter to Universal Health Services CEO Alan Miller, demanding answers into the health system’s cybersecurity policies in light of the September...

CHS Settles with 28 States for $5M Over 2014 Data Breach of 6.1M

by Jessica Davis

Tennessee-based Community Health Systems (CHS) reached a $5 million settlement with 28 states to resolve an investigation into its massive data breach that impacted 6.1 million patients...

Treasury Dept: Ransomware Payment Facilitation Could Be Sanction Risk

by Jessica Davis

The US Department of Treasury’s Office of Foreign Assets Control (OFAC) issued an advisory on the potential sanction risks associated with companies that facilitate ransomware...

Anthem Settles with 44 States for $40M Over 2014 Breach of 78.8M

by Jessica Davis

A multi-state coalition made up of 44 states and Washington, D.C reached a $39.5 million settlement with Anthem, to resolve breach claims stemming from the...

Blackbaud Confirms Hackers Stole Some SSNs, as Lawsuits Increase

by Jessica Davis

The ransomware hackers behind the massive Blackbaud ransomware attack and subsequent data breach likely had access to more unencrypted data than previously disclosed, including bank account...

Senators Probe VA After Data Breach Affecting 46K Veterans, Providers

by Jessica Davis

A group of Democratic Senators led by Jon Tester, D-Montana, is demanding answers from the Department of Veterans Affairs after a reported data breach that impacted the personal and...

Patient Breach Victims File Lawsuits Against Assured Imaging, BJC Health

by Jessica Davis

The patients impacted by two separate data breaches of Assured Imaging and BJC Healthcare have filed lawsuits against the providers, alleging security failings were behind...

Patient Data Privacy Lawsuit Against Google, UChicago Dismissed

by Jessica Davis

The patient data privacy lawsuit brought against Google and the University of Chicago Medical Center was dismissed by a federal judge in Illinois on September 4, ruling that patient who filed the...

CDT, eHI Unveil Draft Consumer Health Data Privacy Framework

by Jessica Davis

The Center for Democracy and Technology (CDT) and eHealth Initiative and Foundation (eHI) released its draft consumer health data privacy framework designed to define data in need...