Berry, Dunn, McNeil & Parker Agree to $7.25 Million Data Breach Settlement
Berry, Dunn, McNeil & Parker, LLC (BerryDunn) has agreed to settle a class action lawsuit that alleged negligence for failing to prevent a data breach that affected more than 1.1 million individuals. BerryDunn has agreed to establish a $7.5 million settlement fund to cover attorneys’ fees, legal costs, expenses, and claims from class members. BerryDunn is a Portland, ME-based accounting and consultancy firm that provides services to several industries, including health data analytics services to healthcare providers, health insurers, and government regulatory and healthcare policy agencies. The BerryDunn Health Analytics Practice Group contracted with a managed service provider, Reliable Networks of Maine, to manage its systems, and was notified on September 14, 2023, that there had been a breach of its systems. The investigation confirmed hackers had access to the personal and protected health information of 1,107,354 individuals, including their names, addresses, dates of birth, Social Security numbers, health insurance policy numbers, Medicare or Medicaid numbers, state or...
Robert F. Kennedy Jr. Sworn in as HHS Secretary
Robert F. Kennedy Jr. has been sworn in as the 26th Secretary of the Department of Health and Human Services (HHS), replacing Dr. Dorothy Fink, who was appointed as Acting Secretary of the HHS on January 20, 2025, and served for a little over 3 weeks. Kennedy is now responsible for administering and overseeing all HHS programs, operating divisions, and activities, including the National Institutes of Health (NIH), the Centers for Disease Control and Prevention (CDC), the U.S. Food and Drug Administration (FDA), and the Centers for Medicare and Medicaid Services (CMS). The HHS has a budget of nearly $2 trillion and is one of the federal government’s largest agencies. There has been strong opposition to the appointment of Kennedy as HHS Secretary with many considering him unqualified for the position. For decades RFK Jr. has spread conspiracy theories such as antidepressants contributing to the increase in school shootings, chemicals in the water supply making children transgender, and vaccines are unsafe and cause autism. Kennedy’s previous support of abortion rights was also a...
Is iCloud HIPAA Compliant?
iCloud is not HIPAA compliant and cannot be used to store, sync, or share media containing Protected Health Information (PHI) as – in its Terms of Service – Apple prohibits any use of iCloud services that would make it a business associate of a covered entity. However, covered entities can still use iCloud for other purposes than storing, syncing, or sharing media containing PHI. Cloud storage services are a convenient way of sharing and storing data. Since files uploaded to the cloud can be accessed from multiple devices in any location with an Internet connection, information is always at hand when it is needed. There are many cloud storage services to choose from, many of which are suitable for use by healthcare providers for storing and sharing ePHI. They include robust access and authentication controls and data uploaded to and stored in the cloud is encrypted. Logs are also maintained so it is possible to tell who accessed data, when access occurred, and what users did with the data once access was granted. iCloud is a cloud storage service that owners of Apple devices...
Republicans Form Working Group to Develop Federal Data Privacy Law
House Republicans have formed a working group to draft privacy legislation that will set federal privacy standards to replace the current patchwork of state laws. All previous efforts to introduce comprehensive federal privacy legislation have failed, and the absence of a federal privacy law has led to around 20 states introducing their own comprehensive data privacy laws. In 2022, the American Data Privacy and Protection Act (ADPPA) was billed as the best opportunity so far to set federal data privacy standards. While the ADPPA had strong bipartisan support, several elements of the bill proved problematic, including the preemption of state laws. The failure of ADPPA to get sufficient support led to the introduction of the American Privacy Rights Act of 2024, which eliminated some of the more problematic requirements of its predecessor. While both of these bills would have seen privacy protections greatly improved in many states, states such as California would have seen their privacy protections watered down. Neither bill made it to a House vote. Last month, more than three dozen...
Hackers Breach Systems of HIPAA-Regulated Entities in Missouri, Nevada, Texas & Wisconsin
Kansas City Hospice & Palliative Care in Missouri, Apex Custom Software in Texas, ARC Community Services in Wisconsin, and REMSA Health in Nevada have experienced hacking incidents that potentially involved unauthorized access to patient data. Kansas City Hospice Falls Victim to Black Suit Ransomware Attack Kansas City Hospice & Palliative Care in Missouri is notifying 3,621 individuals about a 2024 ransomware attack. Kansas City Hospice confirmed that third-party digital forensics experts were engaged to investigate the incident and determine the extent and scope of the unauthorized activity. While the attack disrupted certain IT systems, services continued to be provided to patients throughout the attack and recovery. The recovery process has now been completed, and steps are being taken to improve security. It is unclear exactly when the attack occurred, when it was detected, or the exact types of data compromised in the incident. On October 19, 2024, the Black Suit ransomware group added Kansas City Hospice to its data leak site, claiming 600+GB of data was stolen in...



