HIPAA Blog

A discussion of medical privacy issues buried in political arcana

Monday, July 14, 2025

400 large breaches in first half of 2025

›
400 Large Breaches so far in 2025: HHS has announced that during the first six months of 2025, there were 400 "large" breaches (...
Tuesday, July 08, 2025

Deer Oaks HIPAA Fine

›
Deer Oaks , a HIPAA covered healthcare provider that provides behavioral health services primarily to residents in nursing homes and other f...
Friday, June 20, 2025

Finally! Biden administration's HIPAA abortion stupidity negated

›
Finally!! Biden Administration's HIPAA Abortion Stupidity Negated: As I previously wrote about at length, the asinine Biden Administrat...
Monday, May 26, 2025

Memorial Day Catch-Up Post

›
Happy Memorial Day! Sorry I've not posted in forever, and when I do it's few and far between, but it has been a very busy spring and...
Wednesday, May 21, 2025

Kettering Health (Ohio) Ransomware Event

›
Kettering Health (Ohio) Ransomware Event: Kettering Health, which operates 9 hospitals and a handful of other sites in and around Dayton, O...
Friday, March 21, 2025

Email Remains Leading Security Risk Area

›
Email As a Data Breach Vector:  Almost 200 healthcare organizations suffered a cyberbreach involving their email systems over the last year...
Friday, March 14, 2025

Information-blocking news: EMR company must allow client's BAs to access PHI

›
Information-blocking news: EMR company must allow client's BAs to access PHI:  I must admit I haven't been following this at all, bu...

PE-owned healthcare entities need to improve cybersecurity

›
PE-owned healthcare entities need to improve cybersecurity: I hate to say it, but at this point cybersecurity protections are more importan...
Friday, February 21, 2025

Warby Parker

›
Warby Parker Pays $1.5 to Settle HIPAA Violation I wasn't involved in this matter , so I don't have inside information and I'm j...
Tuesday, January 28, 2025

Change Healthcare's Breach Victim Count Reaches 190,000,000

›
Change Healthcare's Breach Victim Count Reaches 190,000,000.   US population is about 340 million, which means the breach affected about...
Tuesday, January 21, 2025

Texas HHSC Suffers Breach

›
Texas Health and Human Services Commission Suffers HIPAA Breach: If you haven't figured it out yet, anyone with health data is potential...
Thursday, January 09, 2025

PHI Deletion Nets $337,750 Fine

›
PHI Deletion Nets $337,750 Fine: This is a bit of an odd one: a Florida HIPAA business associate, USR Holdings, discovered that an unauthori...

9th Ransomware Case: Virtual Private Network Solutions

›
9th Ransomware Case: Virtual Private Network Solutions:   HHS has entered into a settlement agreement with a HIPAA business associate who wa...

OCR's January 2025 "Dear Colleague" letter (slightly OT)

›
OCR's January 2025 "Dear Colleague" letter (slightly off-topic): As you know, the Office for Civil Rights is the HIPAA enforce...
Wednesday, January 08, 2025

Elgon ransomware settlement

›
HHS Issues 8th Fine Related to Ransomware:   Elgon Information Systems has agreed to an $80,000 settlement with OCR in relation to a ransomw...
Monday, December 30, 2024

Recent enforcement actions

›
Recent OCR Enforcement Actions:  I've been pretty lazy on the blogging front lately, and let a bunch of items stack up, particularly no...

Biden Administration Proposes New Cybersecurity Requirements

›
Biden Administration Proposes New Cybersecurity Requirements for Healthcare Organizations: Encryption and network compliance checks are inc...
Monday, December 23, 2024

Ascension's May 2024 data breach affected 5.6 million people

›
Ascension breach affects 5.6 million: Ascension Health's May 2024 ransomware incident may have c ompromised PHI of 5.6 million people ,...
Tuesday, December 17, 2024

›
  OCR and Abortion: If you're wondering if OCR is going to try to jump into enforcement actions of the soon-to-be-implemented (and likel...
Wednesday, December 11, 2024

The Blinding, Amazing Stupidity of Xavier Becerra's HHS

›
The Blinding, Amazing Stupidity of Xavier Becerra's HHS.   OK, there are plenty examples of this, but the one I'm wrestling with rig...
Monday, November 18, 2024

Ransomware is the Biggest Problem Now

›
Ransomware is the Biggest HIPAA Issue Facing the Healthcare Industry: According to a survey recently conducted by Sophos , 67% of all healt...

$250,000 Ransomware Settlement -- Cascade Eye and Skin Centers

›
Recent Ransomware settlement:  OK, I've sort of fallen down on the job here keeping the HIPAABlog updated, but I'm going to try to d...
Friday, October 04, 2024

Providence Medical Institute Ransomware Breach Draws Quarter Million Dollar Fine

›
Providence Medical Institute Ransomware Fine: Providence Medical Institute has been fined $240,000 by OCR for HIPAA violations in connecti...
Monday, September 16, 2024

Using Indian or Other Overseas Tech Companies Can Be Tricky

›
Offshore Outsourcing of Tech Services Can Be Problematic: A few weeks ago, HHS removed two Obamacare enrollment companies from accessing th...
Wednesday, August 21, 2024

3rd Ransomware settlement: Heritage Valley (PA)

›
Great Write-Up on OCR's 3rd Ransomware Settlement: Theresa Defino of Report on Patient Privacy has an excellent article on the recently...
Thursday, August 01, 2024

Baim Clinical Research Ransomware Event

›
Baim Institute for Clinical Research Suffers Ransomware event and Data Disclosure: According to this analysis by Safety Detectives , Baim ...

OneBlood Hit by Ransomware Attack

›
OneBlood Blood Donation Center Hit by Ransomware Attack: The blood donation and distribution organization, which supports 350 hospitals acro...
Wednesday, July 24, 2024

2024 HIPAA breaches

›
2024 Will Be Big:   I have a feeling 2024 will be a record year for data breaches, both in number of breaches overall and the size of the b...
Thursday, July 11, 2024

Change Healthcare

›
  Change Healthcare Updates its Breach Notice. They added a timeline , apparently, and are going to finally start sending notices to affecte...
Tuesday, July 09, 2024

New MOVEit vulnerabilities uncovered

›
If you're using MOVEit, you should PATCHit first: Lots of folks in the healthcare industry use MOVEit for file transfers; about a year a...
Tuesday, July 02, 2024

Geisinger data breach impacted 1.2 million people

›
Geisinger data breach impacted 1.2 million people: This breach is interesting because it's a disgruntled former employee of a vendor wh...

OCR settles ransomware and cybersecurity investigation involving Heritage Valley Health for $950,000

›
OCR settles ransomware and cybersecurity investigation involving Heritage Valley Health for $950,000: This is the 3rd settlement of a ranso...

New Social Engineering Schemes Target Healthcare

›
New Social Engineering Schemes Target Healthcare: The FBI and HHS are warning healthcare industry participants warning healthcare industry ...
Monday, June 24, 2024

Federal Court Blocks HHS Rule Prohibiting Use of Web Tracking Technologies Such as Google Pixel

›
Federal Court Blocks HHS Rule Prohibiting Use of Web Tracking Technologies Such as Google Pixel :  As you probably know, HHS has issued guid...
Friday, May 24, 2024

CentroMed: Lightning Strikes Twice

›
CentroMed: Lightning Strikes Twice: It's a dumb aphorism that "lightning never strikes twice."  Lightning is always more likel...
Tuesday, May 21, 2024

HHS, ARPA-H announce UPGRADE program to automate cybersecurity for healthcare entities

›
HHS, ARPA-H announce UPGRADE program to automate cybersecurity for healthcare entities: The Advanced Research Projects Agency for Health (a ...
Tuesday, May 14, 2024

H-ISAC warns about Black Basta

›
AHA and H-ISAC Issue Black Basta Warning: The American Hospital Association and the Health Information Sharing and Analysis Center (H-ISAC)...
Monday, May 13, 2024

Ascension Health Cyber Attack

›
Ascension Hit With Ransomware Attack: The story is still breaking, but Ascension Health was the victim of a cyberattack that affected its E...
Thursday, May 02, 2024

Change Breach: Size Matters

›
Size Matters: Just how big is the Change Healthcare breach?  Over 100 million Americans may be affected.   I rode in a 150-mile bike ride b...
Tuesday, April 23, 2024

Bad Spring for United Healthcare

›
United Healthcare: It's been a bad spring for UHC: their pharmacy order and clearinghouse subsidiary Change Healthcare suffered one of t...
Wednesday, April 17, 2024

Monument's pixel tracking technology FTC settlement

›
Tracking Technologies: In the latest news on the use of website tracking technologies such as Google Pixel, Monument Health has entered into...
Sunday, March 31, 2024

OCR Settles 47th Right of Access Case with Phoenix Healthcare of Oklahoma

›
Another "Right of Access" Settlement:  OCR has entered into its 47th settlement with a HIPAA covered entity or business associat...
Wednesday, March 20, 2024

Cybersecurity budgets for healthcare organizations

›
Do Healthcare Organizations Cheap Out on Cybersecurity Spending?   That's the question Modern Healthcare asks (subscription required). ...
Thursday, March 14, 2024

Ransomware happens, healthcare hardest hit.

›
Ransomware Hits Healthcare Harder: If you've been living under a rock, you may not know this, but healthcare is the hardest-hit industry...

HHS is now investigating the Change cyberattack

›
HHS steps in: HHS has s tarted its own investigation into the Change hack; expect a record-setting fine.  I'll predict at least $25 mi...
Monday, March 11, 2024

Change Cyberattack

›
Change Cyberattack: I guess everyone's finally going to le arn what a "health care clearinghouse" is. They've always bee...
Tuesday, March 05, 2024

HHS statement on Change Healthcare cyberattack

›
HHS Statement on Change Healthcare Cyberattack: In HIPAA-adjacent news, . . .   Unless you've been buried in a snowbank somewhere, you...
Monday, February 26, 2024

OCR Issues First HIPAA Fine Related to a Ransomware Attack (Lafourche)

›
LaFourche Medical Group pays $480,000 to settle ransomware attack affecting 35.000 patients: An emergency and occupational medicine practice...

HHS announces data blocking penalties

›
[Note: This should have been posted early January -- I just noticed it was still in Draft] HHS announces data blocking penalties: The infor...

OCR Settles Second Ransomware Case with Green Ridge Behavioral Health

›
Second OCR Ransomware Incident Settlement Announced: OCR has e ntered into a settlement agreement relating to a ransomware incident, this t...
›
Home
View web version

About Me

Jeff
View my complete profile
Powered by Blogger.