Study Highlights Importance of Conducting Regular Malware Scans
Concentrating resources on improving protections for computer networks will make it harder for hackers to gain access to protected data; however, according to a report from Vectra Networks, there is a high probability hackers are already inside. In a recent security test, all computer networks analyzed showed some evidence of a targeted intrusion having already taken place. Vectra analyzed the computer networks and end point devices of 40 enterprises, and each network was found to include some indicators of a targeted attack, regardless of the size of the network. Over a quarter of a million devices were analyzed by the network security company as part of the study. Stages of a Malware Attack Infection The first stage involves infection of a PC or other device, using a targeted attack such as a spear phishing campaign, or a more random means of spreading the malware: Infecting websites for example. Once code has been downloaded onto a target machine, hackers can start to make changes to the system. Command and Control The first phase of the attack proper occurs when a foothold in a...
2015 Most Wired Benchmarking Survey Reveals Data Security is Main Focus for Hospitals
Each year the American Hospital Association (AHA) assesses the state of health IT by conducting a survey of U.S hospitals. This week the results of the 17th Annual Healthcare’s ‘Most Wired’ Survey were published. The survey data show hospitals are serious about data security, with theft prevention and breach detection at the top of many hospitals’ priority lists for the year. After analysis of the responses, the “Most Wired” hospitals, those that had reached the required standard of health IT planning and implementation, were crowned winners. 338 hospitals qualified for consideration, with the results of the vote announced and published in the July issue of Hospitals & Health Networks magazine. Healthcare’s ‘Most Wired’ Survey The benchmarking survey measures the pace of information technology adoption in the healthcare industry, and examines how IT is being leveraged to improve quality and safety, business and administrative management processes as well as clinical integration and interoperability. The VMware-sponsored survey was conducted in partnership with...
HIPAA-Altering Cures Bill Passed by House of Representatives
The controversial 21st Century Cures Bill was unanimously passed by the House Energy and Commerce Committee in May, and on Friday July 10, 2015, the U.S House of Representatives passed the Bill with a count of 344 to 77. 21st Century Cures Bill to Remove Obstacles in the Way of Medical Research Medical research and innovation is being hampered by HIPAA, according to proponents of the 21st Century Cures Bill. The new Act aims to remove these and other barriers, to help advance America’s search for new ways to tackle the advance of superbugs, antibiotic-resistant bacteria and the deadly viruses now threatening the health of U.S citizens. The Cures Bill has received some criticism in its short history. Privacy advocates object to the wide range of data that can potentially be shared; information currently under the protection of HIPAA. It is feared that the bill could weaken HIPAA protections if it becomes law. If that happens, HIPAA Rules would certainly need to be changed. HIPAA Changes Necessary as a Result of the Cures Bill At present, the HIPAA Privacy Rule restricts the use and...
Mailing Error Causes Howard University Privacy Breach
Howard Hospital in Washington D.C has announced a mailing error resulted in letters containing patient names, account numbers and the dates of past visits being sent to the wrong recipients. In this instance, only a limited amount of data was exposed. No financial information, insurance details, health data or Social Security numbers were compromised in the incident. The privacy violation was caused by a data error, according to a statement issued by the hospital. Howard Hospital’s Faculty Practice Plan had contracted two companies to – California Healthcare Medical Billing, Inc. and JP Recovery Services, Inc. – to send notification letters to patients advising them that their medical bills had not been paid. The letters were sent to individuals as instructed; however a data error resulted in patients sharing the same surnames being sent letters intended for other recipients. In total 1,445 letters were sent to incorrect individuals. The university has reviewed the incident and will be taking steps to prevent similar privacy breaches occurring in the future. This breach may...
New OCR HIPAA Settlement: St. Elizabeth Medical Center to Pay $218,400 for Violations
Yesterday, the Department of Health and Human Services’ Office for Civil Rights (OCR) announced a HIPAA settlement has been reached with St. Elizabeth Medical Center (SEMC) for violations of HIPAA Privacy, Security, and Breach Notification Rules. The settlement for HIPAA violations was reached with SEMC for violations that led to a document sharing system data breach that exposed 498 records, and a data breach involving the theft of a flash drive containing unencrypted data of 595 patients. The number of records exposed was relatively low compared to some of the recent “mega data breaches”, but the OCR deemed the offenses leading to the security incidents to be serious enough to warrant a financial penalty. This OCR HIPAA settlement shows how important it is to make HIPAA compliance a priority. Data breaches may not always be preventable, but HIPAA violation penalties are. Privacy, Security, and Breach Notification Rule Violations Uncovered The initial HIPAA violation was uncovered in November 2012, when a complaint was received by the OCR alerting it to potential non-compliance...



