New York Neurology Practice Pays $25,000 to Resolve Alleged Risk Analysis Violation
The HHS’ Office for Civil Rights (OCR) has announced another settlement to resolve an alleged violation of the risk analysis implementation specification of the HIPAA Security Rule. Comprehensive Neurology PC, a small neurology practice in New York City that specializes in diagnosing and treating neurological conditions such as dementia, Parkinson’s disease, epilepsy, and memory loss, has agreed to settle the alleged violation and pay a $25,000 financial penalty. The alleged HIPAA violation was identified by OCR during an investigation of a 2020 data breach that involved unauthorized access to the electronic protected health information (ePHI) of 6,800 individuals. OCR was informed of the data breach on December 17, 2020. Comprehensive Neurology discovered it had been attacked with ransomware on December 14, 2020, when staff were prevented from accessing patients’ medical records. The forensic investigation confirmed that the ePHI of 6,800 individuals had been exposed and potentially stolen in the attack, including names, clinical information, health insurance information,...
Communication Between Doctors and Nurses
Accurate and efficient communication between doctors and nurses is a key component of providing high quality care to patients because, when there is not effective communication, care standards fall. Poor communication between doctors and nurses is common in hospitals, but there are strategies and technologies that can be adopted to improve communication between these two groups of healthcare professionals. Problems Arising from Poor Communication Effective communication is a key requirement to collaborative workflow in all industries, but more so in healthcare where there needs to be constant collaboration. Healthcare is now delivered by multidisciplinary teams that can include dozens of healthcare professionals across a week-long hospital stay. When there is poor communication between these healthcare professionals, patients ultimately suffer. That could mean a longer stay in hospital, a slower recovery, or a miscommunication could have far more serious consequences for the patient and the healthcare provider. According to research conducted by The Joint Commission (TJC), almost...
OSHA and HIPAA Compliance
Ensuring OSHA and HIPAA compliance simultaneously requires healthcare organizations to integrate workplace safety measures and health data privacy protections seamlessly, addressing the physical and digital aspects of healthcare while safeguarding both employee well-being and patient confidentiality. OSHA and HIPAA compliance are both essential despite being separate standards. Although separate, there are broad similarities in terms of reporting, recordkeeping, and enforcement. OSHA compliance requires implementing workplace safety measures to protect healthcare workers from hazards, such as exposure to infectious diseases, while also ensuring the safe handling of medical equipment and hazardous substances. This may include providing personal protective equipment (PPE), establishing protocols for handling biohazardous materials, and maintaining a safe environment within healthcare facilities. HIPAA compliance focusses on safeguarding the privacy and security of patient health information. It requires stringent controls on access to electronic health records (EHRs), secure data...
SOC 2 Compliance Checklist
A SOC 2 compliance checklist – also known as a SOC 2 audit checklist or SOC 2 assessment checklist – is a set of guidelines, measures, and best practices an organization can implement and follow to prepare for a SOC 2 audit. As the nature of SOC 2 audits can vary from organization to organization, there is no one-size-fits-all checklist for SOC 2 compliance. SOC 2 is a voluntary compliance standard developed in 2010 by the American Institute of Certified Public Accountants (AICPA). Organizations wishing to demonstrate compliance with the standard undergo an SOC 2 compliance audit conducted by an AICPA-certified public accountant or by an audit firm commissioned by AICPA. The resulting SOC 2 compliance report can then be shared with third parties to prove the organization has implemented controls to secure its systems and data. In the healthcare industry, an SOC 2 compliance report does not guarantee compliance with the standards of the HIPAA Security Rule because the controls mapped to the SOC 2 compliance audit are discretionary. Nonetheless, it can be beneficial for Covered...
ELENOR-Corp Ransomware Group Targets Healthcare with New Mimic Ransomware Variant
The healthcare sector is being targeted by a new ransomware group called ELENOR-corp, according to the cybersecurity firm Morphisec. Researchers determined that ELENOR-corp was using a new version of Mimic ransomware (version 7.5), a ransomware strain first identified in 2022. The new ransomware variant was identified during an incident investigation at a healthcare victim and appears to be linked to a previous Clipper malware infection. Clipper malware is a Python-based clipboard hijacker used for credential theft. The malware is thought to have allowed re-entry to the victim’s environment. The malware took daily snapshots of user activity and was installed along with a cryptocurrency miner. The researchers determined with a high degree of probability that Clipper malware had been deployed by the same threat actors. Initial access was gained around a week before the ransomware payload was deployed. After gaining access to the healthcare provider’s environment, the group moved laterally and compromised multiple servers via Remote Desktop Protocol (RDP), using tools such as Process...



