Lua Recognized by Aragon Research for Strategy and Performance
Aragon Research has named Lua a Contender in its in 2015 Tech Spectrum for Mobile Collaboration. Aragon Research assesses companies based on their strategy and performance and produces a market evaluation tool that represents emerging and mature markets and vendors in graphical form. Being included in the Contender category confirms Lua has a solid business strategy that is driving the company forward. Aragon Research also recently named Lua one of the top three hottest vendors of 2015 in its Hot Vendor in Mobile Collaboration report. Mobile collaboration is now a necessity for most businesses to provide support to an increasingly mobile workforce. Without mobile communication apps such as Lua’s HIPAA-compliant mobile-first communication solution, it would be impossible to provide remote workers with the same level of support as those based in hospitals and other healthcare facilities. “Mobile collaboration apps like Lua are making it easier for people to interact with internal and external colleagues and partners on any device without barriers,” said David Mario Smith, Research...
10M-Record Cyberattack Reported by NY Health Insurer
Another massive health insurer data breach has been discovered; one which has potentially affected up to ten million health plan members. Excellus BlueCross BlueShield, a health insurer based in Western New York, along with its affiliates – Lifetime Healthcare Companies, Lifetime Benefit Solutions, Lifetime Health Medical Group, Lifetime Care, Univera Healthcare, and the MedAmerica Companies – have all reportedly been affected. Data Access was First Gained in 2013 The data breach was discovered on August 5, 2015. An investigation was immediately launched, which revealed that as many as ten million individuals had been affected, with the hackers having first gained access to the data more than 18 months ago. Access to the confidential data of plan members is believed to have been first gained on December 23, 2013, giving the perpetrators plenty of time to use the data. However, even though the data was potentially stolen such a long time ago, according to the insurer, no evidence of inappropriate use has so far been discovered. High Risk of Identity Theft and Insurance...
OCR HIPAA Compliance Audits to Commence in 2016
The new Deputy Director for Information Privacy at the Department of Health and Human Services’ Office for Civil Rights has been adjusting to life at the OCR since her appointment earlier this year, but until now she has not given an interview to the news media. However, she recently gave an exclusive interview to the Security Media Group, in which she cast some light on planned OCR activities, including the upcoming HIPAA compliance audits. Deven McGraw Gives First News Media Interview McGraw spoke with HealthcareInfoSecurity’s Executive Editor, Marianne Kolbasuk McGee, and was quizzed on OCR enforcement activities, current and future OCR initiatives, and was asked the question that is on everyone’s lips at the moment: When will the HIPAA compliance audits take place? A Shortage of Resources has been McGraw’s Biggest Challenge The program of random HIPAA audits was penciled in for 2014; however the sheer scale of the job has caused problems. Audits take a considerable amount of time and resources, something which the OCR lacks. McGraw confirmed that the current...
Microsoft Issues Warning over Effectiveness of EHR Data Encryption
Researchers at Microsoft have recently issued a paper questioning the effectiveness of EHR data encryption. A warning has been issued to healthcare providers about security vulnerabilities in some electronic medical record systems, which have been shown to leak information, even when data encryption software is used. The results of the study are due to be presented at the ACM Conference on Computer and Communications Security next month, although the research paper can be viewed now, ahead of the ACM presentation. During the study, Microsoft researchers successfully managed to view patient data that included names, race, age, hospital admission information and other data, by exploiting security vulnerabilities. The paper cites four methods that can be used by hackers to gain access to the Protected Health Information of patients. The researchers were so concerned about the high risk of data exposure, it was deemed necessary to issue a warning to healthcare providers and other HIPAA-covered entities that were using CryptDB based protections. They were told in no uncertain terms to...
Healthcare Workers Risk Data Exposure from Smartphone Gambling Apps
Healthcare providers and other HIPAA-covered entities operating Bring Your Own Device (BYOD) schemes will be aware that the use of mobile devices carries risks; however, a recent study has highlighted just how risky unauthorized apps can be, with employees’ use of Smartphone gambling apps deemed to be especially risky. If healthcare workers are allowed to use their own personal devices for work purposes, policies must be put in place covering the permitted use of apps on the device. Apps must be assessed, and employees informed of the applications which can be used securely on the devices. While an app may never be used for work purposes, if it is installed on a device, security vulnerabilities in that app could potentially be exploited by hackers. An app could therefore be used to gain access to the data stored on the device, or the computer network that the device connects to. New Study Highlights Data Security Risk from Gambling Apps A recent study conducted by the security company Veracode, suggests that the average-sized company has at least one gambling app being used by...



