Class Action Lawsuit against Allscripts Filed following Ransomware Attack
Last week, a ransomware attack against the EHR vendor Allscripts resulted in thousands of healthcare providers being unable to access patient data or use the e-prescription service. Already, a class action lawsuit against Allscripts has been filed by Florida-based Surfside Non-Surgical Orthopedics. Allscripts provides EHR and e-prescription services to 2,500 hospitals and 19,000 post-acute care organizations. Last week, a new variant of SamSam ransomware infected the company´s data centers in Raleigh and Charlotte, NC, leaving several application offline for up to 1,500 clients. Microsoft and Cisco incident response teams helped the company restore its e-prescribing service by Saturday; but, for many clients, the Allscripts PRO EHR system is still unavailable or experiencing outages. An Allscripts spokesperson has been unable to confirm when a full restore will be completed. The Class Action Lawsuit against AllScripts The class action lawsuit against Allscripts was filed in the United States District Court for the Northern District of Illinois where the company is based. It alleges...
Lightning Likely to Strike Twice for Victims of Ransomware Attacks
A new report commissioned by online security company Sophos has revealed that victims of ransomware attacks are likely to experience further attacks within a year. The report confirms the healthcare industry is at the greatest risk of suffering multiple ransomware attacks. In order to compile the report – “The State of Endpoint Security Today” – the research company Vanson Bourne surveyed 2,700 IT managers in organizations of 100 to 5,000 users across the US, Canada, Mexico, France, Germany, UK, Australia, Japan, India, and South Africa. The results of the survey make unpleasant reading: 54% of the surveyed organizations were victims of one or more ransomware attacks in the last year. Of the organizations that were victims of ransomware attacks, there was an average of two attacks per organization. The median financial impact per affected organization amounted to $133,000 (including ransom paid, downtime, rectification costs, etc.). The financial impact for the top 3% of organizations suffering a successful ransomware attack was between $6.6 million and $13.3 million....
Breach Notification Bill Passes South Dakota Senate Judiciary Committee
At present, South Dakota is one of two states that do not have breach notification laws (Alabama being the other), but that could soon change if proposals passed by the Senate Judiciary Committee last Tuesday are enacted by the South Dakota State Legislature. The proposed bill – SB 62 (PDF) – would amend Chapter 22-40 of the Codified Laws relating to identity crimes, and require companies maintaining computerized information about South Dakota residents to inform consumers of “unauthorized acquisition” of their personal data. If enacted, the bill stipulates residents have to be informed within sixty days of discovery of a breach unless the company and the State Attorney General´s Office determine the breach will unlikely cause harm to those whose data has been acquired without authorization. Under the proposed laws, extensions to the sixty-day limit are allowed if more time is required for law enforcement agencies to investigate the breach; and, if the breach involves more than 250 South Dakota residents, companies must notify consumer reporting agencies of the timing,...
Eligible Hospitals Must Now Use QNet for Meaningful Use Attestation
The Centers for Medicare & Medicaid Services (CMS) has recently issued a reminder that eligible hospitals and Critical Access Hospitals (CAHs) participating in Electronic Health Record Incentive Schemes must use the QualityNet Secure Portal (QNet) to submit Meaningful Use attestations in 2018. Back in October, CMS announced it was transitioning Meaningful Use attestations to QNet. Previously two separate systems had been used for attestations and reporting clinical quality measures; but, in order to simplify reporting requirements and streamline data submissions, the QNet portal would be used for both from January 2nd 2018. From October, eligible hospitals and CAHs new to QNet had the opportunity to enroll on the system and get used to how it worked, while existing QNet users were advised to add an MU role to their accounts. From the beginning of this month, the QNet system opened for attestations relating to the 2017 calendar year. The attestation period closes on February 28th. Different Processes for Medicare and Medicaid Hospitals Although attempting to simplify the...
KLAS Rates QliqSOFT ‘Top Performing Vendor’ in its 2017 Secure Communications Report
The Healthcare IT data and insights company KLAS Research has released the 2017 KLAS Secure Communications Report. The report examines current levels of adoption of secure communications platforms in the healthcare industry together with how those solutions are performing in a clinical setting. KLAS Reports are relied upon by healthcare organizations to provide in-depth information on the best IT solutions on the market, saving providers valuable time when searching for a suitable IT solution to meet their needs. To create its reports, KLAS Research analysts interview healthcare providers and gather feedback on the performance of software solutions, how easy they are to implement and use, the level of service and support offered by solution providers, and what healthcare providers think of the solutions. KLAS also identifies the market leaders and solution providers that have gone the extra mile and have incorporated a comprehensive range of features into their software solutions to better serve the healthcare industry. The 2017 KLAS Secure Communications Report covers 15 top...



