What is MSP in Healthcare?
The term MSP in healthcare most often relates to Managed Service Providers who support healthcare staffing, supply medical equipment, or manage multi-vendor IT services on behalf of healthcare organizations. HIPAA compliance plays a role in all three versions of MSP in healthcare, but has the biggest impact on providers of managed IT services. When a healthcare organization engages the services of a healthcare MSP, it is usually for one of three purposes. The first purpose is to support healthcare staffing. This involves a healthcare staffing MSP placing a healthcare professional or allied health professional in a healthcare organization on a short-term or a temp-to-hire contract to cover a staffing shortage. In this scenario, the responsibility for HIPAA compliance is shared three ways: The healthcare organization has the responsibility for training temporary members of the workforce on its HIPAA policies and procedures and security awareness. Healthcare professionals and allied health professionals have the responsibility for understanding the basics of HIPAA before taking a...
Endue Software Confirms Data Breach Affecting Multiple Providers
Cybersecurity incidents have been announced by Endue Software, Whitman County Public Hospital District No. 3, Palo Verde Hospital, and Northern California Children’s Therapy Center. Endue Software Endue Software, an infusion management platform provider, has recently confirmed it has been affected by a cyberattack that involved unauthorized access to patient data. In its April 11, 2025, substitute breach notice, Endue Software explained that unauthorized access to some of its systems was identified on February 17, 2025. The forensic investigation confirmed that an unauthorized actor gained access to some of its systems for a brief period on February 16, 2025. While the window of opportunity was short, files were copied from its systems during that time. Since February, Endue Software has been reviewing the compromised data to determine which clients and patients have been affected. It has now been confirmed that the compromised data included patients’ full names, addresses, dates of birth, Social Security numbers, and medical record numbers. It is unclear how many of...
What is Considered a Breach of HIPAA?
A breach of HIPAA is considered to be any acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of the protected health information. It is important to understand what is considered a breach of HIPAA – and how breaches differ from violations of HIPAA – to avoid penalties for non-compliance with the Breach Notification Rule. The text of HIPAA is very clear about what is considered a breach of HIPAA – § 164.402 of the Breach Notification Rule defining a breach as “the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of this part [the HIPAA Privacy Rule] which compromises the security or privacy of the protected health information.” When a breach of HIPAA is identified, Covered Entities must notify affected individuals within sixty days. The notification must include a description of the breach, the nature of information that was acquired, accessed, used, or disclosed, and advice about what steps individuals should take to protect themselves from...
Who is Not Covered by OSHA?
The categories of workers not covered by federal OSHA include volunteers and temporary workers, self-employed workers, family members of farm workers, workers in industries regulated by an agency other than OSHA, and state and local government employees. However, in states with OSHA-approved State Plans, different regulations may apply. Volunteers & Temporary Workers Volunteers are generally not covered by OSHA – but there are exceptions. Volunteer firefighters may be covered by OSHA if they are remunerated for time spent serving the community, covered by workers’ compensation, or regarded as public employees by the state or local government with jurisdiction over the location they volunteer in. There are also some special cases in which an agency has adopted an OSHA standard as one of its own and included volunteers in the coverage. For example, when the Environmental Protection Agency adopted OSHA’s Hazardous Waste and Emergency Response standard, the Agency applied the standard to both paid and uncompensated workers. Temporary workers that are paid by either an employer or a...
Alternate Solutions Health Network Notifies Patients About May 2024 Email Breach
Email accounts have been compromised at four HIPAA-regulated organizations: Alternate Solutions Health Network in Ohio; Park Royal Hospital in Florida; 90 Degree Benefits in Minnesota; and the Charleston Fire Department in West Virginia. Almost 107,000 individuals have been affected. Alternate Solutions Health Network, Ohio Alternate Solutions Health Network, LLC, a Kettering, Ohio-based provider of home healthcare services, has identified unauthorized access to an employee’s email account that contained patient data. It is unclear for how long the threat actor had access to the account or when the breach was detected; however, it has taken almost a year for the affected individuals to be notified. Alternate Solutions Health Network explained in its substitute breach notice that the forensic investigation confirmed that the account was breached on or around May 30, 2024. When the breach was detected, the account was secured, and third-party cybersecurity professionals were engaged to investigate the incident. “After an extensive investigation and manual document review, we...



