Whitelist Only Feature Added to Cisco Umbrella
Cisco has announced it has added a new whitelist only feature to Cisco Umbrella. The whitelist only option allows organizations to restrict Internet access to a small number of secure websites, and block access to the rest of the Internet. User are able to access the whitelist only option via their Umbrella dashboard. When the whitelist only option is set, all domains will be blocked by default and will be inaccessible. Any attempt made by an end user to visit a website that has not been added to the whitelist will be blocked before a connection is made. Any individual that attempts to access an unauthorized website would be presented a block page or the user could be directed to a specific URL. The setting can be applied to an existing rule or a new rule can be created. The whitelist only option can be set for the entire organization, for a particular network, for user groups, individual users or certain devices. The whitelist option will disable category lists and blocklists and will only allow sites to be added via allow lists. The whitelist can be used for domains or URLs....
24,000 Patients Impacted by Emory Healthcare Data Breach
Emory Healthcare (EHC) has discovered a former employee obtained the protected health information of several thousand EHC patients and uploaded the data to a Microsoft Office 365 OneDrive account, where it could potentially be accessed by other individuals. The former employee was a physician at Emory Healthcare, who now works for the University of Arizona (UA) College of Medicine. EHC says patient information was taken without authorization and without its knowledge. EHC was alerted to the incident by the University of Arizona, and received a list of affected individuals on October 18, 2017. The OneDrive account could only be accessed by the physician, other former EHC physicians now at UA, UA staff who investigated the incident, and potentially a limited number of other UA staff members who had a specific type of UA email account. PHI was not exposed on the Internet and no other individuals are believed to have been able to view the information. UA hired a third-party forensic team to conduct an investigation, although no evidence was uncovered to suggest patient information was...
Jones Memorial Hospital Alerts Patients to Ongoing Cyberattack
University of Rochester Medicine’s Jones Memorial Hospital in Wellsville, NY is currently experiencing a cyberattack that has caused unexpected downtime. The attack is understood to have started on Wednesday December 27 and has caused disruption to some of its information services. At the time of writing, the nature of the cyberattack is unclear and it has yet to be resolved. The cyberattack is limited to Jones Memorial Hospital. No other locations have been impacted. While some systems are unavailable, Jones Memorial Hospital has announced on its website that the financial and medical information of its patients does not appear to have been compromised. If the investigation concludes that there has been a breach of health information, patients will be notified accordingly. Further information on the attack will also be posted on the hospital’s website as and when new information becomes available. The hospital notified law enforcement and the New York State Department of the attack when its systems went down. Hospital IT staff are being assisted by the IT departments at the...
2017 HIPAA Enforcement Summary
Our 2017 HIPAA enforcement summary details the financial penalties paid by healthcare organizations to resolve HIPAA violation cases investigated by the Department of Health and Human Services’ Office for Civil Rights (OCR) and state attorneys general. 2017 saw OCR continue its aggressive pursuit of financial settlements for serious violations of HIPAA Rules. There have been 9 HIPAA settlements and one civil monetary penalty in 2017. In total, OCR received $19,393,000 in financial settlements and civil monetary penalties from covered entities and business associates to resolve HIPAA violations discovered during the investigations of data breaches and complaints. Last year, there were 12 settlements reached with HIPAA-covered entities and business associates, and one civil monetary penalty issued. In 2016, OCR received $25,505,300 from covered entities to resolve HIPAA violation cases. Summary of 2017 HIPAA Enforcement by OCR Listed below are the 2017 HIPAA enforcement activities of OCR that resulted in financial penalties for HIPAA-covered entities and their business associates....
Scrub Nurse Fired for Photographing Employee-Patient’s Genitals
A scrub nurse who took photographs of a patient’s genitals and shared the images with colleagues has been fired, while the patient, who is also an employee at the same hospital, has filed a lawsuit seeking damages for the harm caused by the incident. The employee-patient was undergoing incisional hernia surgery at Washington Hospital. She alleges in a complaint filed in Washington County Court that while she was unconscious, a scrub nurse took photographs of her genitals on a mobile phone and shared the photographs with co-workers. Photographing patients without their consent is a violation of HIPAA Rules, and one that can attract a significant financial penalty. Last Year, New York Hospital settled a HIPAA violation case with the Department of Health and Human Services’ Office for Rights and paid a financial penalty of $2.2 million. In that case, a television crew had been authorized to film in the hospital, but consent from the patients in the footage had not been obtained. In the Washington Hospital HIPAA breach, the patient, identified in the lawsuit only as Jane Doe, claims...



