March 1, 2025: Deadline for Submitting 2024 Data Breach Reports to OCR
The deadline for submitting reports of 2024 data breaches affecting fewer than 500 individuals to the HHS’ Office for Civil Rights (OCR) is March 1, 2025. Late filing of breach reports will put HIPAA-regulated entities at risk of a financial penalty for non-compliance with the HIPAA Breach Notification Rule. The HIPAA Breach Notification Rule requires HIPAA-regulated entities to report data breaches to OCR, issue notifications to the affected individuals, and – for breaches affecting 500 or more residents of a state or jurisdiction – notify prominent media outlets serving that state or jurisdiction. All notifications must be issued without unreasonable delay and no later than 60 days after the date of discovery of a data breach. If there is insufficient contact information for 10 or more individuals, a substitute breach notice must be placed on the home page of the entity’s website for at least 90 days or the notice must be provided to major print or broadcast media where the affected individuals likely reside. HIPAA-regulated entities have greater flexibility regarding...
Cyberattack on River Region Cardiology Affects Up to 500,000 Individuals
Cyberattacks have been reported by River Region Cardiology in Alabama and Delta County Memorial Hospital District in Colorado. Lucent Health Solutions in Tennessee has notified individuals who had their data exposed in an October 2, 2023 phishing attack. Cyberattack on River Region Cardiology Affects Up to 500,000 Individuals River Region Cardiology in Alabama has recently notified approximately half a million current and former patients that some of their protected health information was compromised in a September 2024 security incident. Unauthorized access to its systems was detected on September 16, 2024, with the investigation confirming a hacker accessed the network via the remote connection used by an unnamed vendor. The vendor’s remote connection was severed when the unauthorized access was detected. The review of the exposed files confirmed they contained full names, dates of birth, Social Security numbers, and patients’ sex, height, and weight. The breach was reported to the HHS’ Office for Civil Rights on December 11, 2024, as involving the protected health information of...
Over 1 Million Patients Affected by Community Health Center Data Breach
Community Health Center, a nonprofit healthcare provider in Middletown, Connecticut, has notified more than 1 million individuals about a recent data breach. Unauthorized activity was identified in its computer systems on January 2, 2025, and external cybersecurity experts were engaged to assist with the investigation and determine the nature and scope of the unauthorized activity. The investigation confirmed that a criminal hacker accessed its computer systems and exfiltrated data from its network. Community Health Center did not confirm whether a ransom demand was issued; however, explained that no data was deleted from its network and files were not encrypted, therefore the incident had no impact on daily operations. Community Health Center explained in the notification to the Maine Attorney General that “We believe we stopped the criminal hacker’s access within hours, and there is no current threat to our systems.” The Maine Attorney General breach notice states that the breach first occurred on October 14, 2024. The file review has now been completed and Community Health...
Is Google Drive HIPAA Compliant?
Google Drive is HIPAA compliant if it is used as part of a paid-for Google Workspace plan with the capabilities to support HIPAA compliance, or if it is used as part of a Google Workspace plan that is combined with other security measures to support HIPAA compliance. The free version of Google Drive cannot be used to store or share Protected Health Information (PHI) What is Google Drive? Google Drive is a file storage and synchronization service that enables Google customers to store files in the cloud so they can be accessed and shared remotely. The service automatically synchronizes changes to files stored in the cloud to facilitate multi-user collaboration and multi-user editing. It can also be configured to enable teams to work on a project simultaneously. The service can be used as a standalone service or as a key component of a Google Workspace plan. Workspace plans include productivity tools such as Google Docs, Sheets, and Slides, and communication tools such as Google Meet, Chat, and Gmail. Depending on which plan is subscribed to, businesses also benefit from security and...
Is G Suite HIPAA Compliant?
G Suite is HIPAA compliant provided organizations subscribe to a Google Workspace Business Account that includes the capabilities to support HIPAA compliance and provided the capabilities are configured to support compliance with HIPAA. It will also be necessary for a system administrator to agree to Google’s Business Associate Addendum to the Service Agreement. Note: The name of G Suite was changed to Google Workspace in 2020. As many people still refer to Workspace under its former name, this article has been updated to reflect the changes since 2020 while still maintaining G Suite references. In June 2022, any organizations still using the former free G Suite legacy edition were migrated to a paid-for Google Workspaces subscription. Making G Suite HIPAA Compliant (by default it isn’t) When an organization subscribes to a G Suite (Workspace) account, there are four options to choose from. These start with the feature limited Business Starter Plan and go up to the G Suite Enterprise Plan. The choice of options depends on whether G Suite services will be used to create, collect,...



