Massive Healthcare Fraud Takedown Sees 412 Charged for $1.3 Billion in Fraudulent Billings
Last week, the United States Department of Justice announced the largest healthcare fraud action to date. 412 individuals were charged, including 115 doctors, nurses and other medical professionals for their roles in healthcare fraud schemes. 120 doctors and other medical professionals were charged for prescribing opioids and other dangerous narcotics. The HHS has also initiated suspension actions against 295 doctors, nurses and pharmacists. The charges aggressively targeted individuals responsible for fraudulent Medicaid, Medicaid and TRICARE billings, although this year also saw a focus on doctors and other medical professionals that have been fueling the opioid epidemic by illegally distributing opioids and pother powerful narcotics. Approximately 91 Americans lose their lives each day due to opioid overdoses. The bust was a joint operation by the Department of Justice, FBI, Medicaid Fraud Strike Force, DEA, U.S Attorney’s Office and the Department of Health and Human Services. A joint announcement about the bust was made by Attorney General Jeff Sessions and HHS Secretary Tom...
Are You Blocking Ex-Employees’ PHI Access Promptly?
A recent study commissioned by OneLogin has revealed many organizations are not doing enough to prevent data breaches by ex-employees. Access to computer systems and applications is a requirement while employed, but many organizations are failing to block access to systems promptly when employees leave the company, even though ex-employees pose a significant data security risk. Blocking access to networks and email accounts when an employee is terminated or otherwise leaves the company is one of the most basic security measures, yet all too often the process is delayed. 600 IT employees who had some responsibility for security in their organization were interviewed for the study and approximately half of respondents said they do not immediately terminate ex-employees’ network access rights. 58% said it takes longer than a day to delete ex-employees’ login credentials. A quarter of respondents said it can take up to a week to block access, while more than one in five respondents said it can take up to a month to deprovision ex-employees. That gives them plenty of time to gain access...
Ransomware Attack Investigation Reveals 15-Month Security Breach
A ransomware attack on Peachtree Neurological Clinic (PNC) in Atlanta, GA resulted in the encryption of sensitive data. Since PNC had backed up its data, it was possible to restore the affected files without paying the ransom. Following any ransomware attack it is important to conduct a forensic analysis of systems to ensure all traces of the ransomware have been removed and no backdoors have been installed. PNC performed scans of its system and confirmed that the malware had been removed; however, the scans revealed that its systems had been accessed by unauthorized individuals between February 2016 and May 2017. Cybercriminals have been known to gain access to organizations’ systems and install ransomware when there is no further need for access, but it is unclear whether the same individuals were responsible for both security breaches. PNC found no evidence to suggest that the ransomware attack involved the exfiltration of data, but it was not possible to determine with any degree of certainty whether access to protected health information was gained in the initial attack. PNC...
Rosalind Franklin University of Medicine and Science Phishing Attack Sees PHI Compromised
The protected health information of 859 patients of Rosalind Franklin University of Medicine and Science (RFU) has been compromised and potentially been viewed/stolen. The information was stored in two email accounts that were accessed by unauthorized individuals in May. Access to the email accounts was gained after employees responded to phishing emails. The phishing attack occurred on May 10, 2017 prompting a full investigation. The malicious actors behind the phishing scam gained access to one email account for less than a day and the second email account for a period of 9 days. Access to the second email account was blocked on May 19. Third party security experts were brought in to assist with the investigation to help determine the full extent of the security breach. RFU is now certain that unauthorized access to sensitive data has been blocked. Part of the investigation involved checking all messages in the compromised email accounts for protected health information. The investigation confirmed that the compromised PHI was limited to patients’ names, addresses, dates of...
Funding for ONC Office of the Chief Privacy Officer to be Withdrawn in 2018
The cuts to the budget of the Office of the National Coordinator for Health Information Technology (ONC) mean the agency must make some big changes, one of which will be the withdrawal of funding for the Office of the Chief Privacy Officer. ONC National Coordinator Don Rucker, M.D., has confirmed that the office will be closed out in fiscal year 2018. Deven McGraw, the Deputy Director for Health Information Privacy, has been serving as Acting Chief Privacy Officer until a permanent replacement for Lucia Savage is found, following her departure in January. It is now looking highly unlikely that a permanent replacement will be sought. One of the key roles of the Chief Privacy Officer is to ensure that privacy and security standards are addressed and health data is appropriately protected. The Chief Privacy Officer also advises the National Coordinator for Health IT on privacy and security policies covering electronic health information. However, Rucker does not believe it is necessary for the ONC to have an office dedicated to privacy and security as other agencies in the HHS could...



