Cyberattack Announced by Carolina Arthritis Associates
Data breaches have recently been announced by Carolina Arthritis Associates in North Carolina, Jaime Schwartz MD in California, Somnia in New York, and the California healthcare staffing agency Aya Healthcare. Carolina Arthritis Associates, North Carolina Carolina Arthritis Associates in Wilmington, North Carolina, has confirmed via its legal counsel that it fell victim to a cyberattack in September 2024 that caused network disruption and potentially involved unauthorized access to patient data. Some of that data may have been copied by an unauthorized third party, including names, birth dates, treatment/procedure information, medical record numbers, provider names, and Social Security numbers. The attack was detected on September 27, 2024, and the third party cybersecurity experts engaged to investigate the incident determined that files may have been exfiltrated on or around September 27, 2024. All exposed files were reviewed through programmatic and manual processes, which concluded on January 21, 2025. Individual notification letters were mailed to the affected individuals on...
What is the CCPA HIPAA Exemption?
The CCPA HIPAA exemption consists of two clauses in the California Consumer Protection Act that exempts HIPAA covered entities from complying with the Act and subsequent amendments enacted by the California Privacy Rights Act. The CCPA HIPAA exemption also applies to business associates in respect of Protected Health Information created, received, maintained, or transmitted by a business associate on behalf of a covered entity. The California Consumer Privacy Act (CCPA) is a state law that enhances the privacy rights of Californian residents. The CCPA applies to all businesses that collect California residents’ personal information that have gross revenues in excess of $25 million per year, that buys, receives, or sells the personal information of 100,000 or more Californian residents or households, or that earns more than half of its annual revenue from selling California residents’ personal information. The CCPA gives California residents the right to know what information is being collected from them and how it is used or shared. It also gives California residents the rights to...
What are the Physical Safeguards of HIPAA’s Security Rule?
The Physical Safeguards of HIPAA’s Security Rule are the standards and implementation specifications that must be applied when applicable “to protect a covered entity’s or business associate’s electronic information systems and related buildings and equipment, from natural and environmental hazards, and unauthorized intrusion.’’ As with many areas of HIPAA compliance, it is necessary to factor in other regulatory requirements when complying with the Physical Safeguards of HIPAA’s Security Rule. Depending on the nature of an organization’s activities, these can include CMS’ Emergency Preparedness Rule, OSHA’s Fire Prevention and Response Standards, and local building and safety codes. It is also necessary to comply with the Physical Safeguards of HIPAA’s Security Rule in the context of the Security Rule’s General Rules (§164.306). These require covered entities and business associates to: Ensure the confidentiality, integrity, and availability of all electronic Protected Health Information (PHI) created, received, maintained, or transmitted. Protect against any reasonably...
Email Accounts Compromised at Four Healthcare Orgs
Email accounts have been compromised at Restorix Health in New York, INTERLINK Health Services in Oregon, RxSight in California, and Fillmore County Hospital in Nebraska, and patient data has been exposed. Restorix Health Restorix Health, a Tarrytown, New York-based wound care solutions company, discovered on May 30, 2024, that an employee email account had been subjected to unauthorized access. The investigation confirmed the breach was limited to a single account, and the forensic investigation revealed the account was accessed between May 7, 2024, and May 29, 2024. The review of the account was completed on November 27, 2024, and confirmed that some protected health information had been exposed. The affected healthcare partners were notified on December 18, 2024, and it has been confirmed that 38,553 individuals were affected. The data varied from individual to individual and may have included names, dates of birth, driver’s license numbers, government identification numbers, passport numbers, Social Security numbers, patient ID numbers, medical information, prescription...
Data Breaches Announced by Central New York Cardiology & Park Place Pediatric Dentistry
Central New York Cardiology has experienced a cyberattack involving unauthorized access to patient data, and an unencrypted laptop computer has been stolen from an employee of Park Place Pediatric Dentistry in Texas. Central New York Cardiology Central New York Cardiology fell victim to a cyberattack in December 2024 in which hackers accessed its network and potentially viewed or obtained patient data. The forensic investigation confirmed that the hackers could access parts of its network from December 26, 2024, to December 30, 2024. The file review is ongoing, and at the time of the breach announcement, the total number of affected individuals had not been determined; however, Central New York Cardiology has confirmed that the information compromised in the incident likely included first and last names together with one or more of the following: address, date of birth, driver’s license number, Social Security number, diagnosis/condition, health insurance information, provider name, other treatment information, and/or financial account information. Central New York Cardiology has...



