Latest Posts › PHI

Share:

Oregon Health & Science University pays $2.7M penalty for data breaches

Oregon Health & Science University (OHSU) has agreed to settle alleged HIPAA violations involving two separate data breaches with the Office for Civil Rights (OCR) for $2.7 million. In the span of three months in 2013,...more

Physical security still an issue: Pruitt Health suffers breach in break-in

The importance of physical security and the risk associated with the unauthorized access to or loss of paper records is clear from recent experiences of Pruitt Health in South Carolina. On March 2, 2016, an intruder...more

OCR levies first fine ever directly against business associate

Our predictions that the Office for Civil Rights (OCR) will become more aggressive with audits, investigations, and fines against HIPAA business associates has come true. On June 24, 2016, the OCR announced that it has...more

Massachusetts General Hospital vendor Patterson Dental Supply reports breach of 4,300 patient records

Patterson Dental Supply, Massachusetts General Hospital’s (MGH) vendor that provides software to the hospital to manage dental practice information, has reportedly admitted that approximately 4,300 of MGH’s patient records...more

Illinois data breach law amended and includes new twists

Governor Bruce Rauner signed several new provisions into law amending Illinois’ Personal Information Privacy Act, including health insurance and medical information into the definition of personal information that triggers...more

EMR company settles with FTC for posting physician surveys that contained health information on its website

Cloud-based electronic medical record (EMR) company Practice Fusion has agreed to settle an enforcement action with the FTC that alleges that it misled consumers when it solicited reviews of their doctors. The FTC alleges...more

Medical Records of NFL Players Taken in Theft of Unencrypted Laptop

A Washington Redskins trainers’ unencrypted laptop was located in a backpack that was stolen on April 15th. Unfortunately, the laptop contained medical exam results for NFL Combine attendees since 2004, which is estimated to...more

Newest Ponemon study released on health care data breaches

The Ponemon Institute has recently released its Sixth Annual Benchmark Study on Privacy & Security of Healthcare Data. The study has included business associates for the past two years. The study included information received...more

Intermedix data breach class action case dismissed

We previously reported that Intermedix was sued in a class action lawsuit regarding the data breach involving millions of patient records....more

Joint Commission lifts ban on physicians texting patient orders

The Joint Commission, which is the national accrediting organization for health care organizations, has long banned physicians using text messages to place orders for patient care due to data security concerns. In 2011, the...more

Raleigh Orthopedic Clinic settles with OCR for $750,000 for lack of business associate agreement

Consistent with the settlement the OCR agreed to with North Memorial Health Care of Minnesota, the Office for Civil Rights has settled its investigation of Raleigh Orthopaedic Clinic, P.A. (Raleigh Orthopaedic) for $750,000....more

Wyoming Medical Center victim of phishing scheme affecting 3,184 patients

Phishing incidents in February that may have compromised the data of 3,184 patients, including their names, dates of birth, medical record and account numbers, dates of service and medical information is causing Wyoming...more

OCR issues audit protocol and targets over 800 entities—business associates too

The Office for Civil Rights (OCR) has issued its revamped audit protocol for its second phase of auditing covered entities and business associates’ compliance with the HIPAA Privacy, Security and Breach Notification Rules....more

21st Century Oncology data breach litigation update

We previously reported that 21st Century Oncology suffered a data breach affecting 2.2 million patients and has been sued in at least two class action lawsuits following notification to the patient....more

FTC, ONC, OCR and FDA release online tool for mobile health app developers

While attending the International Association of Privacy Professionals annual global event, and listening to Chairwoman Edith Ramirez discuss the Federal Trade Commission’s (FTC) concerns about consumer privacy, the FTC, the...more

21st Century Oncology faces second class action suit for data breach of 2.2M records

We previously reported that 21st Century Oncology (21st Century) experienced a data breach of up to 2.2 million patient records that compromised the names, Social Security numbers and health and diagnostic information. It...more

MedStar Health newest healthcare victim of cyber-attack

MedStar Health has announced that it has shut down its electronic medical record system after confirming that it has been struck with malware....more

Class action suit filed against 21st Century Oncology for data breach

We previously reported that 21st Century Oncology had suffered a data breach and notified 2.2 million patients that it had been the victim of a hacking that exposed the names, Social Security numbers, physicians’ names,...more

Feinstein Institute hit with $3.9M fine from OCR for HIPAA violations

Following the investigation of a self-reported data breach involving the loss of an unencrypted laptop containing the protected health information (PHI) of 13,000 individuals, the OCR slammed the New York based biomedical...more

OCR announces new round of HIPAA audits—get ready now

The Office for Civil Rights (OCR) has been stating publicly that it will gear up for its second round of HIPAA audits for some time, and the time has come. The OCR has officially started the next round of audits of covered...more

Third healthcare entity becomes the victim of ransomware

The list of healthcare entities that have become (and will become) victims of ransomware is rapidly growing. The predictions from experts are that the list will grow exponentially into the future. Last week, Methodist...more

OCR fines MN hospital system $1.55 million for not having BAA with billing vendor

On March 16, 2016, the Office for Civil Rights (OCR) issued a press release announcing that it has settled its investigation of North Memorial Health Care System (NMHCS), located in Minnesota, for $1.55 million saying that...more

New Ponemon report says healthcare organizations getting hit by cyber-attacks monthly

Confirming what we are seeing in the field, the Ponemon Institute recently released a new report of a poll of 535 healthcare IT and IT security professionals that sets forth a dismal state of affairs around data security and...more

LA Department of Health hit with ransomware

Days after hackers held Hollywood Presbyterian’s health information hostage, the Los Angeles County Health Department was hit with a ransomware attack that reportedly affected five computers. According to the Health...more

Deadline to self-report 2015 HIPAA breaches is Monday, February 29

As we stated in last week’s Insider, Monday, February 29, 2016, is the last day to self-report under 500 breaches of unsecured protected health information to the Office for Civil Rights (OCR) through the online breach...more

187 Results
 / 
View per page
Page: of 8

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide