Is HIPAA Training Required Annually?
Yes, HIPAA training is required annually because it is a best practice to schedule HIPAA annual refresher training. This is required in case additional training has not been necessary due to a change in policies, the outcome of a risk assessment, the enforcement of a sanctions policy, or a corrective action plan following the notification of a data breach. Is HIPAA Training Required Annually? The HIPAA text does not provide a deadline for providing training and incorporates flexibility to make it easier for healthcare organizations to fit training into busy workflows. The HIPAA Privacy Rule states “A covered entity must train all members of its workforce on the policies and procedures with respect to protected health information,” and training should be provided “as necessary and appropriate for the members of the workforce to carry out their functions within the covered entity.” In addition to initial training, a covered entity must provide training when “functions are affected by a material change in the policies or procedures.” That means further training is required when...
58% of Ransomware Attacks Involve Compromised Perimeter Security Appliances
A new report from the cyber insurance and security services provider Coalition has revealed the most common initial access vectors in ransomware attacks. Based on an analysis of claims, Coalition determined the most commonly exploited technology was compromised perimeter security devices such as a virtual private network or firewall, which were involved in almost 6 out of 10 ransomware attacks. The most commonly compromised products were perimeter security appliances from Fortinet, Cisco, SonicWall, and Palo Alto Networks. Around 2 out of 10 attacks involved remote desktop software, with Microsoft’s Remote Desktop Protocol (RDP) accounting for 80% of attacks involving this type of technology. Email was the third most exploited technology, with the majority of email-related compromises due to social engineering attempts such as phishing. The most common attack vector was compromised credentials, typically for RDP and VPNs, which provide threat actors with privileged access to internal networks. An analysis of activity logs revealed 42% of attacks involved brute force tactics, where...
HIPAA Compliance Logo
Covered Entities Can Show Patients They Respect HIPAA Privacy Rights The HIPAA logo is closely associated with respecting patient privacy and patient HIPAA rights. A HIPAA entity can use a HIPAA compliance logo to indicate to patients that their patient rights under HIPAA are respected. There is no official HIPAA logo, so The HIPAA Journal has developed a number of logos that can be used by HIPAA Covered Entities to show patients that they care about patient rights and comply with HIPAA. The objective is to promote HIPAA awareness among patients. Usage rights for the logos are granted without royalty under 2 conditions: Condition 1) the covered entity using the logo has a HIPAA compliance program that includes a full set of compliance policies and HIPAA training for employees Condition 2) there is a link to this article beside or on the logo to ensure that patients are aware of their HIPAA privacy rights: https://www.hipaajournal.com/hipaa-rights/ Click here to download the above logo Click here to download the above logo Click here to download the above logo Click here to...
15K Patients Potentially Affected by Insider Incident at New York Healthcare Provider
More than 15,000 patients of Stram Center for Integrative Medicine have potentially been affected by an insider incident, SSK Plastic Surgery has disclosed a 2024 cyberattack, and The Grove at Valhalla Rehabilitation and Nursing Center has been affected by a security incident at one of its vendors. Stram Center for Integrative Medicine Stram Center for Integrative Medicine in New York has notified 15,263 individuals about a security incident involving the misuse of a patient’s payment card information by a former employee. The employee was arrested in connection with the card misuse and Stram Center for Integrative Medicine is cooperating with the law enforcement investigation. Since there is a possibility that the employee’s misuse of the payment card was not an isolated incident, a review was conducted to identify all patients whose data could potentially have been accessed by the former employee during their employment. Stram Center for Integrative Medicine said it is unaware of misuse of any other patient’s information and no Social Security numbers were accessed by the...
Hillcrest Convalescent Center Announces 106K-Record Data Breach
Cyberattacks and data breaches have been announced by Hillcrest Convalescent Center in North Carolina, Bay Cove Human Services in Massachusetts, and SMC Corporation of America in Indiana. The Hillcrest incident involved the data of 106,194 individuals. Hillcrest Convalescent Center Hillcrest Convalescent Center in Durham, North Carolina has notified 106,194 individuals about a data security incident identified on June 27, 2024. Suspicious network activity was detected, and third-party cybersecurity experts were engaged to investigate and determine the nature and scope of the incident. They confirmed that an unauthorized third party had access to the network and acquired data from its systems. The data review was completed on February 13, 2025, and confirmed that names, dates of birth, Social Security numbers, medical information, treatment information, healthcare provider information, and health insurance information had been exposed. At the time of issuing notifications, Hillcrest Convalescent Center was unaware of any misuse of the affected data. The affected individuals have...



