calHIPAA

Promoting HIPAA Compliance For Over 20 Years

  • HIPAA News
  • HIPAA Advice
  • HIPAA Compliance
    • HIPAA Law
  • HIPAA Violations
    • HIPAA Penalties
    • Social Media HIPAA Violation Examples
  • HIPAA Training
  • About calHIPAA
HomeHIPAA News

HIPAA News

The HIPAA News category delivers timely and authoritative updates on the latest developments in HIPAA regulations and enforcement. This section is dedicated to providing healthcare professionals, compliance officers, and business associates with critical information on recent regulatory changes, legal rulings, and enforcement actions related to the protection of protected health information (PHI).

Our news coverage focuses on significant events and trends within the healthcare industry that impact HIPAA compliance. By staying informed on these developments, you can better anticipate regulatory shifts and ensure that your organization remains compliant with evolving privacy and security requirements under HIPAA.

Microsoft and NCCoE Collaboration on Creating Guidelines for Using a Reliable Enterprise Patch Management Strategy

October 21, 2019 Christine Garcia

The National Institute of Standards and Technology (NIST) National Cybersecurity Center of Excellence (NCCoE) and Microsoft launched a new project to create guidance on the development and implementation of an effective patch management strategy. After […]

Ransomware Guidance Updated by FBI in Response to the Extent of U.S. Ransomware Epidemic

October 18, 2019 Christine Garcia

A new report from Emsisoft, a New Zealand-based cybersecurity company, exposed the magnitude of ransomware usage in cyberattacks in America. 2019’s first 9 months had 621 reports of ransomware attacks on government agencies, healthcare companies, […]

Gartner Releases the 2019 Market Guide for Cloud Service Providers to Healthcare Delivery Organizations

October 17, 2019 Christine Garcia

The 2019 Market Guide for Cloud Service Providers to Healthcare Delivery Organizations (HDOs) has been published by Gartner. It includes a study of the healthcare cloud market and points out how the cloud may be […]

Proofpoint Report Shows Which Cyber Threat Do Healthcare Companies Mostly Encounter

October 17, 2019 Christine Garcia

A new Proofpoint report provides ideas on the cyber threats that healthcare companies run into and the most prevalent attacks that bring about healthcare data breaches. Proofpoint’s 2019 Healthcare Threat Report reveals the evolving threat […]

More Patient Data Compromised in the Hunt Regional Healthcare May 2018 Data Breach

October 16, 2019 Christine Garcia

Hunt Regional Healthcare based in Texas learned that a May 2018 cyberattack was more extensive than earlier thought. The FBI informed Hunt Regional on May 14, 2019 that an advanced, targeted cyberattack hit its systems […]

The First Healthcare-Specific Professional Cybersecurity Certification Program in the United States

October 14, 2019 Christine Garcia

The University of Texas at Austin McCombs School of Business introduced a special healthcare-specific professional cybersecurity certificate program. The professional leadership and educational program is the first healthcare targeted cybersecurity certification program to be made […]

Three DCH Health System Temporarily Shuts Down Because of Ransomware Attack

October 11, 2019 Christine Garcia

Three of DCH Health System’s hospitals in Alabama were forced not to accept new patients other than those in a critical state due to a ransomware attack. The staff in DCH Regional Medical Center in […]

CHI Health Ransomware Attack Impacts 48,000 Patients of Lakeside Orthopedic Clinic

October 10, 2019 Christine Garcia

CHI Health in Omaha, NE, a 14-hospital health system, had a ransomware attack, which led to the potential exposure of the protected health information (PHI) of close to 48,000 patients. CHI Health became aware of […]

Data Breach Expenditures Decreased by Over Fifty Percent With an Internal Security Operations Center Set Up

October 9, 2019 Christine Garcia

On behalf of Kaspersky Lab, a B2B International survey recently performed confirmed there is an increase in the average expense of a data breach at the enterprise-level from $1.23 million (2018) to $1.41 million. The […]

Another Phishing Attack Hits the Cancer Treatment Centers of America

October 8, 2019 Christine Garcia

Cancer Treatment Centers of America (CTCA) is informing some patients about the exposure of their protected health information (PHI) because of a phishing-related email security breach at its Southeastern Regional Medical Center, which happened on […]

More Cybercriminals Today Use Vendor Email Compromise Attacks

October 7, 2019 Christine Garcia

There has been an increase in the number of business email compromise (BEC) attacks in the United States. According to Symantec, an average of 6,029 businesses received BEC emails in the last 12 months and […]

Dental Practice To Pay $10,000 for Impermissible Discolsure of PHI on Yelp

October 4, 2019 Christine Garcia

The Department of Health and Human Services’ Office for Civil Rights consented to a negotiation with Elite Dental Associates concerning its HIPAA violation case relating to the impermissible disclosure of protected health information (PHI) of […]

FDA Issues Warning URGENT/11 for Cybersecurity Vulnerabilities Found in Medical Devices

October 3, 2019 Christine Garcia

Armis Security researchers found 11 vulnerabilities in the Interpeak IPnet TCP/IP Stack, which is a third-party software part utilized in some medical devices and hospital networks. The DHS Cybersecurity and Infrastructure Security Agency (CISA) received […]

Potential Compromise of PHI Due to Cybersecurity Breach at North Florida OB-GYN

October 2, 2019 Christine Garcia

North Florida OB-GYN located in Jacksonville, FL found out that hackers acquired access to selected parts of its computer system holding personal and health information of patients and infected the system with a virus that […]

Wood Ranch Medical Totally Shut Down Operations Due to Ransomware Attack

October 1, 2019 Christine Garcia

A damaging ransomware attack on Wood Ranch Medical in Simi Valley, CA caused its irreversible shutting down on December 17, 2019. The attack took place on August 10, 2019 and the ransomware corrupted the servers. […]

Senator Rand Paul Initiates National Patient Identifier Repeal Act

September 30, 2019 Christine Garcia

Sen. Rand Paul, M.D., (R-Kentucky) has announced a new bill that tries to once and for all take away the HIPAA national patient identifier provision considering the privacy problems in using such a system. At […]

Indiana Authorities Found 2,246 Abandoned Fetal Remains and Medical Documents

September 27, 2019 Christine Garcia

Dr. Ulrich Klopfer operated three abortion clinics in Indiana, but the clinics were closed down upon the suspension of his license in 2015. After his passing away on September 3, 2019, his family members discovered […]

Senate Didn’t Support the Lifting of the Ban to Fund the National Patient Identifier

September 26, 2019 Christine Garcia

The Department of Health and Human Services (HHS) is banned from expending any of its funds for the creation and launch of a national patient identifier, although there was anticipation that the prohibition will eventually […]

New Data Breach Notification Rule for Medical Insurance Companies in Maryland

September 25, 2019 Christine Garcia

Starting October 1, 2019, medical insurance companies and related services must inform the Maryland Insurance Administration (MIA) in case a breach of insureds’ personal data occurs. The change in legislation is applicable to health plans, […]

Vulnerabilities in WLAN Software Used in Philips IntelliVue Portable Patient Monitors

September 24, 2019 Christine Garcia

Philips IntelliVue WLAN firmware had been found to have two vulnerabilities that affected some IntelliVue MP monitors. The vulnerabilities can be exploited by hackers to install malicious software that could have an effect on data […]

Ransomware Attack on Campbell County Health Caused Serious Interruption to Patient Services

September 23, 2019 Christine Garcia

A ransomware attack on Campbell County Health located in Gillette, WY resulted in the disablement of hospital systems, which prevented access to patient information. The attack began in early in the morning of September 20, […]

400 Million Medical Images Are Publicly Accessible on the Internet Via Unsecured PACS

September 20, 2019 Christine Garcia

Based on a recent investigation by ProPublica, Bayerischer Rundfunk (a German public broadcaster), and Greenbone Networks (vulnerability and analysis firm, 24.3 million medical images in medical image storage systems are publicly accessible on the internet […]

NCCoE Issued a Mobile Device Security Guidance for Corporate-Owned Personally Enabled Devices

September 19, 2019 Christine Garcia

The National Cybersecurity Center of Excellence (NCCoE) created a new draft NIST mobile device security guidance to assist companies to minimize the risks presented by corporate-owned personally enabled (COPE) devices. Mobile devices permit personnel to […]

Phishing Attacks on Fraser and East Central Indiana School Trust Impacted Almost 6,000 Individuals’ PHI

September 17, 2019 Christine Garcia

A phishing attack on East Central Indiana School Trust (ECIST) resulted in the exposure of some protected health information (PHI) of over 3,200 people. On May 19, 2019, an ECIST employee was misled into sharing […]

82% of Healthcare Providers Using IoT Devices Have Encountered a Cyberattack

September 13, 2019 Christine Garcia

According to the Global Connected Industries Cybersecurity Survey conducted by Irdeto, a Swedish software company, 82% of healthcare companies utilizing Internet-of-Things (IoT) devices were attacked via one of those devices in the past year. Irdeto […]

OMB Finds the HHS Information Security Program as Ineffective

September 11, 2019 Christine Garcia

The Office of Management and Budget (OMB) submitted its annual audit report to Congress concerning the cybersecurity status of federal agencies, as ordered by the Federal Information Security Modernization Act of 2014 (FISMA). OMB examined […]

Most Patients Are Willing to Share Their EHR Data for Research, But Not Everything

September 9, 2019 Christine Garcia

A new research study published in JAMA Network Open revealed that many patients are okay with sharing their EHR data and biospecimens for research purposes; however, the majority of patients would like to limit the […]

Why Immediate Data Breach Notifications Are Very Important to Customers

September 6, 2019 Christine Garcia

When healthcare providers encounter a data breach, breach victims will naturally be annoyed and upset. People provide their data to healthcare organizations with the understanding that they implement safeguards to protect that information. Whenever patients […]

Two Phishing Attacks on Hospitals Impact Over 15,000 Patients

September 5, 2019 Christine Garcia

A phishing attack on Artesia General Hospital in Artesia, NM resulted to the compromise of 13,905 patients’ protected health information (PHI). The hospital detected the breach on June 18, 2019 when it was discovered that […]

Recent HIPAA Enforcement Activity Reviewed in the Beazley Breach Insights Report

September 4, 2019 Christine Garcia

The agency assigned to implement HIPAA compliance is the Department of Health and Human Services’ Office for Civil Rights. Only a handful of HIPAA violations were issued financial penalties prior to 2016. Then, the number […]

Phishing Attack on NCH Healthcare System Resulted in the Compromise of 73 Email Accounts

September 3, 2019 Christine Garcia

The last phishing attack on Bonita Springs, an NCH Healthcare System based in Florida, highlighted the great importance of providing healthcare employees with security awareness training. Bonita Springs detected the attack on June 14, 2019 […]

Motions Filed by UCMC and Google to Dismiss Lawsuit Over HIPAA Privacy Violation

September 2, 2019 Christine Garcia

On June 26, a University of Chicago Medical Center (UCMC) patient filed legal action against UCMC and Google with regards to an alleged privacy violation involving the disclosure of protected health information (PHI) without de-identifying […]

Cyberattacks on NCH Healthcare System and Ohio Eye Care Provider

August 30, 2019 Christine Garcia

A phishing attack on NCH Healthcare System in Naples, FL resulted in the exposure of patient information. NCH Healthcare knew about the suspicious activities on its payroll system on June 14, 2019. A third-party computer […]

DPA Fined Skellefteå School for Using Facial Recognition Technology

August 29, 2019 Christine Garcia

The Swedish Data Protection Authority (DPA) issued its first financial penalty for a General Data Protection Regulation (GDPR) violation. A high school in Skellefteå was issued a 200,000 SEK fine (€19,000/$21,000) for conducting a pilot […]

Unsecured Databases Compromised the PHI Amarin and Medico Clients

August 28, 2019 Christine Garcia

An unsecured database online contains the personal data of individuals who exhibited an interest in Vascepa®, a cholesterol drug that Amarin Pharma manufactures. The database contained information including complete names, telephone numbers, email addresses, home […]

PHI of 10,000 Massachusetts General Hospital Patients Exposed Due to Data Breach

August 27, 2019 Christine Garcia

Massachusetts General Hospital (MGH) discovered recently the unauthorized access of the computer applications utilized by its Department of Neurology researchers. The person behind the breach could potentially access the protected health information (PHI) of around […]

Box of Documents From Western Connecticut Health Network and Arizona State University Students’ Information Exposed

August 26, 2019 Christine Garcia

Nuvance Health informed some Western Connecticut Health Network (WCHN) patients concerning their protected health information (PHI) exp. CHN sent to the Connecticut State Department of Public Health a package of medical documents on June 11, […]

Reasons Behind the Targeted Hacking in the Healthcare Industry

August 23, 2019 Christine Garcia

The healthcare industry is being attacked with more data breaches. Why do hackers want to target the healthcare industry? FireEye came up with a new report to provide answers to this question. FireEye researchers analyzed […]

UnityPoint Health Data Breach Lawsuit Partly Dismissed by Federal Judge

August 22, 2019 Christine Garcia

The Western District of Wisconsin US District Court has partly dismissed the class-action data breach lawsuit that UnityPoint Health is facing. In February 2018, employees of UnityPoint Health received phishing emails and responded to them. […]

Unsecured Amarin and Medico Database Resulted in Potential PHI Disclosure

August 21, 2019 Christine Garcia

A database which comprises of the personal information of men and women who expressed interest in Vascepa®, a cholesterol drug manufactured by Amarin Pharma, was exposed online. The database, which a third party vendor maintained, […]

Breach of Almost 45,000 PHI at Integrated Regional Laboratories, Bayview Dental and Mid-Valley Behavioral Care Network

August 20, 2019 Christine Garcia

Florida’s Integrated Regional Laboratories (IRL) is informing about 30,000 patients regarding the potential compromise of their protected health information (PHI) as a result of the American Medical Collection Agency (AMCA) data breach, which was discovered […]

medRxiv Study Reveals Many Healthcare Providers Do Not Comply with HIPAA Right of Access

August 19, 2019 Christine Garcia

medRxiv, a health manuscript archiving firm, recently conducted a study which revealed the prevalent noncompliance with the HIPAA right of access. The researchers of this study mailed 51 healthcare providers requesting for medical record and […]

Breaches at Ohio Eye Care Provider and NCH Healthcare System Potentially Compromised Patient PHI

August 16, 2019 Christine Garcia

Eye Care Associates, a fully integrated eye care provider in the northeast Ohio region, had a ransomware attack in late July which led to the inaccessibility of its computer systems. Two weeks after the attack, […]

Hackers Demand a Ransom Paymet of $1 Million from Grays Harbor Community Hospital

August 15, 2019 Christine Garcia

The ransomware attack on Grays Harbor Community Hospital in Aberdeen, WA continues to cause problems after its attack two months ago. The attackers asked for $1 million ransom payment in exchange for the encryption unlock […]

MU Health Faces Lawsuit Over Phishing Attack in May 2019

August 14, 2019 Christine Garcia

Because of a phishing attack on April 2019, the University of Missouri Health Care (MU Health) is charged with a lawsuit. MU Health found out on May 1, 2019 the one week unauthorized access of […]

$145 Million Settlement Proposal of Allscripts to Resolve Its HIPAA and HITECH Act Violations

August 13, 2019 Christine Garcia

Allscripts Healthcare Solutions proposed a preliminary settlement to resolve the violations of HIPAA, the Anti-Kickback Statute and the electronic health record (EHR) incentive program of the HITECH Act by the electronic health record (EHR) firm […]

Over 522,000 Patients Impacted by Ransomware Attacks on Puerto Rico Healthcare Providers

August 12, 2019 Christine Garcia

Bayamón Medical Center and Puerto Rico Women and Children’s Hospital had a ransomware attack which affected over 500,000 patients living in Bayamón, Puerto Rico. A press release on July 19, 2019 explained the discovery by […]

PHI of Over 522,000 Puerto Rico Patients Impacted by Ransomware Attack

August 9, 2019 Christine Garcia

Bayamón Medical Center and Puerto Rico Women and Children’s Hospital were attacked by ransomware, which affected more than half a million patients from Bayamón, Puerto Rico. A press release on July 19, 2019 mentioned the […]

Using the Emergency Text Notification System and HIPAA Compliance

August 8, 2019 Christine Garcia

Businesses governed by HIPAA regulations need to be mindful whenever using emergency text notification systems and ensure not to disclose Protected Health Information (PHI) without authorization. It can be quite difficult to adhere to HIPAA […]

VA OIG Report Reveals Security Violations Associated With Medical Device Workarounds

August 6, 2019 Christine Garcia

The Department of Veteran Affairs Office of Inspector General (VA OIG) inspected a California VA medical center recently and found security vulnerabilities linked to medical device workarounds as well as non-compliance with Veterans Health Administration […]

31.6 Million Healthcare Records Breached in First Half of 2019

August 5, 2019 Christine Garcia

The healthcare industry has had a particularly bad first six months. The many reports of data breaches and the volume of healthcare records exposed every day are very concerning. The trend this 2019 is over […]

Northwood Inc Phishing Attack Compromised the PHI of 15,000 Patients

August 2, 2019 Christine Garcia

A HIPAA business associate from Madison Heights, MI, Northwood Inc., reported hacking of one of its employee’s email account and potential viewing or acquisition of sensitive patient information. Northwood Inc knew about the breach on […]

Netherlands Haga Hospital Penalized €460,000 for GDPR Data Breach

August 1, 2019 Christine Garcia

The first GDPR data breach fine has been issued by Authoriteit Persoonsgegevens, the GDPR data protection authority in the Netherlands, to Haga Hospital in the Hague. The hospital is to pay a GDPR fine of […]

Wise Health System Phishing Attack Exposed 35,899 Patients’ PHI

July 29, 2019 Christine Garcia

Patients of Wise Health System in Decatur, TX received notification regarding the potential exposure of their protected health information (PHI) because of a phishing attack. About 35,899 patients were affected by the breach. The phishing […]

2019 Data Breach Cost Study Shows Skyrocketing U.S. Healthcare Data Breach Costs

July 26, 2019 Christine Garcia

The 2019 Cost of a Data Breach Report of Ponemon Institute/IBM Security has been published. It is a detailed study of the reported data breaches in 2018. It revealed the continuous increase of data breach […]

AMCA Breach Also Affected Penobscot Community Health Center Patients

July 25, 2019 Christine Garcia

Another healthcare provider confirmed that it was affected by the American Medical Collection Agency (AMCA) security breach. An unauthorized access of AMCA’s systems resulted to a breach of the protected health information (PHI) of its […]

Equifax Settlement of Data Breach Case Costs up to $700 Million

July 24, 2019 Christine Garcia

Equifax has decided to resolve its federal data breach case by paying at least $575 million. The settlement could possibly go up to $700 million plus the need to make significant improvements to its security […]

Data Breaches at Edgepark Medical Supplies and Cancer Treatment Centers of America

July 23, 2019 Christine Garcia

Edgepark Medical Supplies (EMS) discovered on May 13, 2019 that an unauthorized person access the account of some of its customers accounts and altered their addresses causing a redirection of their orders to different delivery […]

New Idaho Patient Rights Rules Being Implemented in Idaho Hospitals

July 22, 2019 Christine Garcia

Idaho is giving patients new rights as hospitals implement the new rules. The Idaho Department of Health and Welfare (IDHW) is implementing the rules which began July 1, 2019. IDHW stated that patient advocacy groups […]

ICO’s Proposed $123 Million Penalty to Marriott for its GDPR Violation

July 19, 2019 Christine Garcia

Just a few days after expressing the intention to issue a penalty to British Airways the amount of £183 million ($230 M) for its 383-million records breach, the United Kingdom’s Information Commissioner’s Office (ICO) is […]

Email Account Hack on Adirondack Health Impacts PHI of 25,000 Patients

July 18, 2019 Christine Garcia

Adirondack Health Vermont notified about 25,000 patients regarding the potential exposure of their protected health information (PHI) due to hacking. The potentially compromised information include the patients’ names, birth dates, healthcare insurance member numbers or […]

HHS Announces Partial Waiver of HIPAA Sanctions and Penalties in Louisiana

July 17, 2019 Christine Garcia

The U.S. Department of Health and Human Services (HHS) Secretary has declared a partial waiver of HIPAA sanctions and penalties in Louisiana because of the damage that Tropical Storm Barry likely caused when it hit […]

ICO Issued Notice of Intent to Fine British Airways’ £183 Million GDPR Penalty

July 16, 2019 Christine Garcia

UK Information Commissioners Office (ICO), which is the GDPR supervisory authority, issued the biggest GDPR penalty to British Airways amounting to £183.39 million or $228 million for failure to employ security controls that led to […]

Premera Blue Cross to Pay $10 Million to Settle Multi-State Action Lawsuit

July 15, 2019 Christine Garcia

Premera Blue Cross agreed to pay $10 million to settle a multi-state data breach lawsuit that involved 30 state attorneys general. The alleged violations of state and federal laws resulted to a breach of 10.4 […]

Nemadji Research Corporation Breach Impacts Over 1,000 Patients of Essential Health

July 12, 2019 Christine Garcia

Essentia Health is an integrated health system providing services in the states of Minnesota, North Dakota, Wisconsin and Idaho. Notifications sent to over 1,000 Essentia Health patients stated that some of their protected health information […]

Phishing Attack on California Business Associate Compromised PHI of 14,591 DHS Patients

July 11, 2019 Christine Garcia

Nemadji Research Corporation, doing business under the name of California Reimbursement Enterprises, released information regarding the unauthorized person who accessed the email account of an employee. There is potential exposure of the protected health information […]

Vulnerability in GE Aestiva and Aespire Anesthesia Machines Identified

July 10, 2019 Christine Garcia

GE Aestiva and Aespire Anesthesia devices were found to have an improper authentication vulnerability. These devices are typically used in hospitals all over America. The CVE-2019-10966 vulnerability can allow an attacker to remotely change the […]

Survey Results on Consumers Attitude About Medical Device Security

July 9, 2019 Christine Garcia

A recent nCipher Security survey explored the value consumers put on their health information privacy and security. The survey had 1,300 U.S. consumers as participants and looked into their attitudes toward online personal privacy, sharing […]

2017 Microsoft Outlook Vulnerability Targeted by Threat Group APT33

July 8, 2019 Christine Garcia

Hackers exploited a two-year-old vulnerability in Microsoft Outlook targeting U.S. government networks. A warning issued by U.S. Cyber Command talked about the active exploitation of vulnerability CVE-2017-1174 and installation of remote access Trojans and other […]

Medical Student Sues Hospital and University for Unauthorized Use of PHI in Teaching

July 5, 2019 Christine Garcia

A medical student is filing a lawsuit against Marshall University and Cabell Huntington Hospital because some of his protected health information (PHI) was impermissibly disclosed to a class of students. The medical student, which the […]

Recall of Medtronic Insulin Pumps Because of Cybersecurity Vulnerabilities

July 4, 2019 Christine Garcia

Alerts regarding the cybersecurity vulnerabilities discovered in several Medtronic insulin pumps were released by the United States Computer Emergency Readiness Team (US-CERT) and the Food and Drug Administration (FDA). The vulnerable insulin pumps connect to […]

Small Healthcare Providers Struggle to Adopt Healthcare Cybersecurity Best Practices

July 3, 2019 Christine Garcia

According to a recent study, larger healthcare providers are more inclined to have fully developed, sophisticated cybersecurity defenses, whereas smaller healthcare providers struggle to implement cybersecurity best practices. KLAS and CHIME conducted the study and […]

Franciscan Health Employee Unauthorized Access and Abandoned Boxes of Medical Records in Chatham, Chicago Exposed PHI

July 2, 2019 Christine Garcia

Franciscan Health located in Mishawaka, IN found out that a former staff committed unauthorized access of the protected health information (PHI) of around 2,200 patients. In a routine privacy review, Franciscan Health learned about the […]

UChicago Charged With Illegal Disclosure of Patient Information to Google

July 2, 2019 Christine Garcia

A former UChicago Medicine patient filed a lawsuit claiming that his medical information along with those of hundred other patients were shared with Google with no prior authorization. The lawsuit accuses UChicago Medical Center, UChicago […]

9-Year PHI Breach Reported by Dominion National

June 28, 2019 Christine Garcia

Virginia-based Dominion National, which is an insurance company, health plan manager, and administrator of dental and vision benefits, learned that a data breach affected the personal information of individuals connected to the services it provides. […]

Estes Park Health Paid Ransom Two Times to Get All File Decryption Keys

June 27, 2019 Christine Garcia

Estes Park Health (EPH) located in Colorado was attacked by ransomware, which extensively encrypted files all across its network. EPH discovered the ransomware attack on June 2, 2019 when employees noticed and reported the computers’ […]

Patient Care Coordinator Sentenced to 1 Year Imprisonment for HIPAA Violation

June 26, 2019 Christine Garcia

A patient care coordinator previously employed at the University of Pittsburgh Medical Center (UPMC) received a one-year imprisonment term for accessing patient healthcare records and utilizing that data for malicious damages. Sue Kalina, 62, living […]

Risk of Wiper Malware Attacks by Iranian Threat Actors Increasing

June 25, 2019 Christine Garcia

The Director of the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) gave a warning after a surge in ‘Iranian regime actors’ cyberattacks. Christopher C. Krebs gave the warning as tensions build up […]

CCI Study Reveals More Healthcare Data Breaches Involve Server Vulnerabilities

June 24, 2019 Christine Garcia

Cybercriminals that locate and exploit vulnerabilities to access healthcare networks and patient information are increasing their activities. The last two months were the worst and second worst months in terms of number of healthcare data […]

About 60 Assisted Living Facilities and 78,000 Patients’ Prescription Data Affected by Breaches

June 22, 2019 Christine Garcia

A ransomware attack on Tenx Systems, a company providing software for assisted living communities, impacted over 60 facilities that utilize the software program. Also known as ResiDex Software, Tenx Systems stated the attack happened on […]

645,000 People Impacted by Oregon Department of Human Services Phishing Breach

June 20, 2019 Christine Garcia

A phishing attack on the Oregon Department of Human Services (ODHS) resulted to the potential compromise of the personal information of 645,000 clients. The phishing attack began on January 9, 2019, which got 9 ODHS […]

21,000 Patients Impacted By Ransomware Attack on Shingle Springs Health and Wellness Center

June 19, 2019 Christine Garcia

A recent ransomware attack on Shingle Springs Health and Wellness Center (SSHWC) located in Placerville, CA resulted to the potential compromise of the protected health information (PHI) of 21,513 patients. SSHWC found out on April […]

Mental Health Awareness Webinar Hosted by Rave Mobile Safety on June 18, 2019

June 18, 2019 Christine Garcia

Rave Mobile Safety is hosting a webinar on June 18, 2019 that seeks to give better understanding of mental health problems, the difficulties community members encounter in relation to mental health conditions, and how to […]

Urology Practice Pays Ransom Worth $75,000 to Restore Computer Systems Access

June 17, 2019 Christine Garcia

An extreme ransomware attack on N.E.O Urology based in Boardman, OH impacted all of its IT system. The ransomware brought about extensive file encryption and prevented the healthcare provider from accessing its computers and patient […]

Phishing Attack on Union Labor Life Insurance Exposed 87,400 Patients’ PHI

June 14, 2019 Christine Garcia

A phishing attack on Union Labor Life Insurance (ULLI), a subsidiary of Ullico Inc., resulted to the exposure of 87,000 plan members’protected health information (PHI). Data exposure happened because an employee responded to a phishing […]

Breaches at Takai, Hoover & Hsu and Navicent Health Ended Up With a Fired Nurse and 10,970 Patient PHI Exposed

June 13, 2019 Christine Garcia

An ex-employee of a healthcare provider based in Germantown, MD is alleged to have accessed the protected health information (PHI) of approximately 16,542 patients. The information was allegedly given to a third party to be […]

Lawsuits and Investigations Related to the AMCA Data Breach

June 12, 2019 Christine Garcia

Ever since reports regarding the massive data breach at American Medical Collection Agency (AMCA) became known, over 12 lawsuits had been submitted by breach victims. Quest Diagnostics formally reported the breach on June 3, 2019 […]

LabCorp Patients Also Impacted by AMCA Breach

June 11, 2019 Christine Garcia

News reports spoke of the American Medical Collection Agency (AMCA) data breach that brought about the compromise of 11.9 million Quest Diagnostics patient records. Current news cite another healthcre company affected by the AMCA breach. […]

SSNs of Delta Health Systems Plan Members Exposed Over the Internet

June 10, 2019 Christine Garcia

Turlock Irrigation District in California is notifying its employees who are members of their employer-sponsored health plan regarding the exposure of some of their protected health information (PHI) online due to a business associate error. […]

Misconfiguration Exposed Over 1.68 Million Records at University of Chicago Medicine

June 9, 2019 Christine Garcia

The huge data breaches lately which included the breach at Quest Diagnostics affecting 11.9 million records and the breach at LabCorp affecting 7.7 million records. Now, University of Chicago Medicine announced a data breach with […]

Patient Allowed to Sue Hospital and Employee for Privacy Violation by Vermont Supreme Court

June 6, 2019 Christine Garcia

The Vermont Supreme Court issued a ruling permitting a patient to take legal action against a hospital and nurse for privacy violation, irrespective of Vermont law and the HIPAA law that do not allow private […]

Microsoft Issues Fresh BlueKeep Alert: Public Exploits Exist and the Pending Attacks

June 5, 2019 Christine Garcia

Microsoft issued another warning regarding the BlueKeep vulnerability in Remote Desktop Services (CVE-2019-0708) after publishing online proof-of-concept exploits for the vulnerability. Microsoft issued fixes for the vulnerability on May 14, 2019. Patches were also made […]

$74 Million Settlement Proposed to Premera Blue Cross Proposed to Settle Class Action Lawsuit for $74 Million

June 4, 2019 Christine Garcia

In March 2015, health insurer Premera Blue Cross in Seattle reported a major data breach that affected close to 10.6 million plan members. The breach happened in 2014 and a wide range of information was […]

Phishing Attack on People Inc. and OS Inc. Impact Patient PHI

June 3, 2019 Christine Garcia

People Inc. is a non-profit health and human services firm located in Western New York providing services to elderly people and people with developmental disabilities. A phishing attack on the organization affected roughly 1,000 persons. […]

PHI Exposed at Medical Oncology Hematology Consultants and Health Net of California Breaches

June 1, 2019 Christine Garcia

Medical Oncology Hematology Consultants (MOHC), a Newark,DE based cancer treatment center, suffered an email security breach that lead to the compromise of the protected health information (PHI) of some patients. MOHC published a substitute breach […]

HELP Committee’s Call For the Consideration of Good Faith Efforts to Strengthen Cybersecurity in HHS’ HIPAA Enforcement Activities

May 30, 2019 Christine Garcia

Many view the HHS’ Office for Civil Rights’ enforcement of HIPAA compliance as excessively punitive. Compliance investigations after receiving complaints or data breaches reports usually result to the discovery of HIPAA Rules violations and sizable […]

Medical Informatics Engineering To Resolve Multi-State Lawsuit With Payment of $900,000 Financial Penalty

May 29, 2019 Christine Garcia

A recent announcement requires Medical Informatics Engineering (MIE) to pay a financial penalty amounting to $900,000 to resolve a multi-state lawsuit over the HIPAA violations linked to a breach of 3.9 million records in 2015. […]

Microsoft Released Patches to Fix Vulnerabilities That Could Cause Malware Attacks Similar to the WannaCry Attacks

May 28, 2019 Christine Garcia

Microsoft released a patch on May 14, 2019 for fixing a ‘wormable’ vulnerability found in Windows, which is the same as the vulnerability exploited by attackers in the WannaCry ransomware attacks in May 2017. The […]

What are the HIPAA Fines That Can be Issued to Business Associates?

May 27, 2019 Christine Garcia

Ever since the implementation of the requirements of the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 in the 2013 Omnibus Final Rule by the Department of Health and Human Services, […]

Medical Informatics Engineering Settles its HIPAA Breach Case for $100,000

May 25, 2019 Christine Garcia

Medical Informatics Engineering, Inc (MIE) settled with the HHS’ Office for Civil Rights its HIPAA violation case by paying $100,000. MIE provides electronic medical record software and services in Indiana. Its case of serious data […]

Posts pagination

« 1 … 8 9 10 … 12 »
  • Site Map
  • About calHIPAA
  • Privacy Policy
  • Editorial Policy
  • Terms & Conditions
  • Cookie Policy
  • Diversity & Inclusion Policy
  • Jobs at calHIPAA

CalHIPAA is a registered trademark. © Copyright 2003 to 2024 calHIPAA. All rights reserved.