HSCC Recommends Consultation Process on Healthcare Cybersecurity Improvements
The Health Sector Coordinating Council (HSCC) Cybersecurity Working Group (CWG) has urged the Trump administration to initiate a series of structured consultations and workshops with healthcare industry stakeholders to obtain consensus on a modernized healthcare cybersecurity policy, rather than implement the proposed changes to the HIPAA Security Rule. In January this year, the HHS’ Office for Civil Rights (OCR) published a Notice of Proposed Rulemaking (NPRM) in the Federal Register outlining changes to the HIPAA Security Rule to improve healthcare cybersecurity. The NPRM ran to almost 400 pages and significantly expanded the cybersecurity requirements for HIPAA-regulated entities, including annual HIPAA Security Rule compliance audits, a comprehensive network map and asset inventory, a plan to restore critical systems within 72 hours, and verification that business associates have implemented the necessary technical safeguards. The comment period for the NPRM recently closed, and Tim Noonan, OCR’s Deputy Director for Health Information Privacy, Data, and Cybersecurity, confirmed...
Hacking Incidents Reported by Georgia Urology and Millennium Home Health Care
Georgia Urology and Millennium Home Health Care have identified hacking incidents involving unauthorized access to patient data. Blue Shield of California has reported an incident involving the exposure of plan member information to other individuals on the same plan. Georgia Urology Georgia Urology, the largest urology practice in Atlanta and the Southeastern United States, has recently disclosed a data security incident that may have involved unauthorized access to the personal and protected health information of 12,398 patients. Suspicious activity was identified in two employee email accounts on or around October 25, 2024. The email accounts were immediately secured, and third-party cybersecurity experts were engaged to investigate the activity. Unauthorized access to the email accounts was confirmed, and the accounts were reviewed to determine the extent of data exposure. That process was completed on March 5, 2025. Georgia Urology determined that the security incident was limited to the email accounts and that the emails and attachments in the accounts may have been viewed or...
Survey Shows Management Support for Compliance Activities Correlates with Fewer Data Breaches
One of the objectives of the 2024/25 HIPAA Journal Annual Survey was to identify challenges to HIPAA compliance. Several challenges were identified relating to management support, particularly in smaller organizations with 200 or fewer employees. The data which led to these observations was further analyzed to see what impact management support has on HIPAA compliance. The 2024/25 HIPAA Journal Annual Survey was an anonymous survey conducted at the beginning of the year among subscribers to The HIPAA Journal newsletter. Because subscribers to The HIPAA Journal newsletter tend to be more “compliance aware,” the majority of responses to questions relating to compliance, data security, and training were what might be expected. However, an analysis of the responses to the final three questions relating to workplace culture, management support, and organizational commitment to enforcing HIPAA policies revealed that many smaller organizations operate in environments that are not conducive to HIPAA compliance. The three questions were: Do you believe your workplace culture encourages...
Anti-Kickback Training for Healthcare Professionals
Anti-kickback training for healthcare professionals is an essential element of a compliance training program and is mandated for all members of an organization’s workforce as well as First Tier, Downstream, and Related Entities (FDRs) if the organization participates in a Medicare Part C or Part D program. The Anti-Kickback Statute was one of several measures introduced in the 1970s to combat fraud, waste, and abuse in healthcare. The Statute prohibits anyone from offering, soliciting, paying, or receiving “remuneration” in return for a business transaction that is ultimately paid for by a publicly funded health program. The Statute not only applies to anybody directly involved in the transaction, but also to anybody who facilitates the transaction. Because the term “remuneration” not only applies to cash payments but to “anything of value”, it is important that all members of a healthcare organization’s workforce undergo anti-kickback training in order to avoid scenarios in which an employee inadvertently accepts a gift in return for a favor. In scenarios such as these, not only...
173,000 Patients Affected by Chord Specialty Dental Partners Email Data Breach
CDHA Management, LLC and Spark DSO, LLC, which do business as Chord Specialty Dental Partners, have recently notified the U.S. Department of Health and Human Services’ Office for Civil Rights about a data breach that involved unauthorized access to the protected health information of up to 173,430 individuals. The Tennessee-based dental service organization provides business and operational support services to more than 60 dental practices in Indiana, Delaware, New Jersey, Pennsylvania, Tennessee, and Virginia. On or around September 11, 2024, suspicious activity was identified in an employee email account. Third-party digital forensics specialists were engaged to investigate the activity and confirmed that an unauthorized third party had gained access to several employee email accounts from August 19, 2024, to September 25, 2024. A comprehensive and time-intensive review of the affected accounts was recently concluded, and it was confirmed that names, addresses, Social Security numbers, driver’s license numbers, bank account information, payment card information, dates of birth,...



