OSHA Terminates COVID-19 Rulemaking and Works on Standard Addressing a Broader Range of Infectious Diseases
The Occupational Safety and Health Administration (OSHA) has abandoned efforts to establish a final COVID-19 safety standard to ensure workers in healthcare settings are protected from COVID-19. OSHA issued an Emergency Temporary Standard (ETS) on June 21, 2021, after determining that COVID-19 posed a grave danger to healthcare workers. At that point, almost half a million healthcare workers had contracted COVID-19, and more than 1,600 healthcare workers had died as a result of COVID-19 infections. After issuing the ETS, OSHA received petitions from industry associations including the American Nurses Association, International Association of Fire Chiefs, and National Nurses United (NNU) urging OSHA to adopt a permanent standard to protect healthcare workers from COVID-19 and to also issue a separate standard covering a broader range of infectious diseases. OSHA submitted a draft final COVID-19 rule to the White House Office of Management and Budget on December 7, 2022; however, on April 10, 2023, House Joint Resolution 7 was signed into law by President Biden terminating the...
Email Accounts Compromised at LifeBridge Health
LifeBridge Health has discovered unauthorized access to employee email accounts. Effortless Office Enterprises has suffered a cyberattack, and Han Van Duong, M.D. has experienced a break-in and theft of laptop computers containing patient data. LifeBridge Health LifeBridge Health in Maryland has discovered unauthorized access to several employee email accounts. The breach was detected on November 12, 2024, and the forensic investigation determined that the email accounts had been compromised between August 27, 2024, and September 21, 2024. The breach was limited to email accounts, with no other systems affected. File attachments and emails in the account were reviewed and found to contain patient information. The types of information involved varied from individual to individual and may have included names plus one or more of the following: dates of birth, dates of service, Social Security numbers, medical record numbers, health insurance claim numbers, and limited treatment information. Individual notifications were mailed to the affected individuals on January 10, 2025, and...
Is WeTransfer HIPAA Compliant?
WeTransfer is not HIPAA compliant and cannot be used to upload and send or receive files that include Protected Health Information – even if the service is used inside a HIPAA compliant file sharing service. However, there are several HIPAA-compliant alternatives to WeTransfer that organizations can use to securely transmit large files – albeit not so quickly, and not for free. WeTransfer is a file sharing service that is popular with individuals and organizations for its fast photo and video file sharing capabilities. In the healthcare industry, these capabilities would be particularly useful for sharing high resolution images between healthcare providers in order to facilitate collaboration, accelerate diagnoses, and support medical training One of the reasons for WeTransfer being so popular is that the service has excellent security features. These include two-factor authentication, encryption in transit and at rest, and password-protected access. In addition, WeTransfer is a Dutch company that complies with Dutch data protection laws and the GDPR. It is also ISO/IEC 27001...
Wolf Haldenstein Confirms 3.4 Million-record Data Breach
The New York City law firm Wolf Haldenstein Adler Freeman & Herz LLP (Wolf Haldenstein) has suffered a major data breach involving the personal and protected health information of 3,445,537 individuals, according to a breach notice recently submitted to the Maine Attorney General. Several states publish data breach summaries on the website of their Office for the Attorney General; however, many do not list how many individuals were affected, or only list the number of victims in their respective states. Maine lists the total number of individuals affected plus the number of state residents, in this case, 3,220 Maine residents. The breach report has revealed the scale of the data breach – one of the largest data breaches to occur at a law firm. Wolf Haldenstein has offices in New York, Chicago, Nashville, and San Diego and specializes in complex litigation, including assisting clients with data breach litigation. A cyberattack on its network was suspected on December 13, 2023, when suspicious network activity was identified. Immediate steps were taken to contain the incident and...
North Carolina Hospice Discovers 58,000-Record Data Breach
Data breaches have been announced by AuthoraCare Collective in North Carolina, Lifetime Psychiatry in Missouri, and McNall & Associates in Alaska. AuthoraCare Collective AuthoraCare Collective, a nonprofit hospice in Greensboro, North Carolina, suffered a cyberattack in August 2024. Technical issues related to systems in its network were identified on August 22, 2024. Assisted by third-party IT forensics experts, it was determined that an unauthorized actor gained access to its systems between August 18 and August 22, 2024. The investigation confirmed on October 21, 2024, that the protected health information of up to 58,019 individuals was accessed or acquired. The review of the affected files confirmed they contained names, medical diagnoses, prescription information, Social Security numbers, and demographic information. Notifications were mailed to the affected individuals in January 2025, and complimentary credit monitoring services have been offered to individuals whose Social Security numbers were involved. Lifetime Psychiatry Lifetime Psychiatry, LLC, in St. Peters, MO,...



