Cyberattack on River Region Cardiology Affects Up to 500,000 Individuals
Cyberattacks have been reported by River Region Cardiology in Alabama and Delta County Memorial Hospital District in Colorado. Lucent Health Solutions in Tennessee has notified individuals who had their data exposed in an October 2, 2023 phishing attack. Cyberattack on River Region Cardiology Affects Up to 500,000 Individuals River Region Cardiology in Alabama has recently notified approximately half a million current and former patients that some of their protected health information was compromised in a September 2024 security incident. Unauthorized access to its systems was detected on September 16, 2024, with the investigation confirming a hacker accessed the network via the remote connection used by an unnamed vendor. The vendor’s remote connection was severed when the unauthorized access was detected. The review of the exposed files confirmed they contained full names, dates of birth, Social Security numbers, and patients’ sex, height, and weight. The breach was reported to the HHS’ Office for Civil Rights on December 11, 2024, as involving the protected health information of...
Over 1 Million Patients Affected by Community Health Center Data Breach
Community Health Center, a nonprofit healthcare provider in Middletown, Connecticut, has notified more than 1 million individuals about a recent data breach. Unauthorized activity was identified in its computer systems on January 2, 2025, and external cybersecurity experts were engaged to assist with the investigation and determine the nature and scope of the unauthorized activity. The investigation confirmed that a criminal hacker accessed its computer systems and exfiltrated data from its network. Community Health Center did not confirm whether a ransom demand was issued; however, explained that no data was deleted from its network and files were not encrypted, therefore the incident had no impact on daily operations. Community Health Center explained in the notification to the Maine Attorney General that “We believe we stopped the criminal hacker’s access within hours, and there is no current threat to our systems.” The Maine Attorney General breach notice states that the breach first occurred on October 14, 2024. The file review has now been completed and Community Health...
Is Google Drive HIPAA Compliant?
Google Drive is HIPAA compliant if it is used as part of a paid-for Google Workspace plan with the capabilities to support HIPAA compliance, or if it is used as part of a Google Workspace plan that is combined with other security measures to support HIPAA compliance. The free version of Google Drive cannot be used to store or share Protected Health Information (PHI) What is Google Drive? Google Drive is a file storage and synchronization service that enables Google customers to store files in the cloud so they can be accessed and shared remotely. The service automatically synchronizes changes to files stored in the cloud to facilitate multi-user collaboration and multi-user editing. It can also be configured to enable teams to work on a project simultaneously. The service can be used as a standalone service or as a key component of a Google Workspace plan. Workspace plans include productivity tools such as Google Docs, Sheets, and Slides, and communication tools such as Google Meet, Chat, and Gmail. Depending on which plan is subscribed to, businesses also benefit from security and...
Is G Suite HIPAA Compliant?
G Suite is HIPAA compliant provided organizations subscribe to a Google Workspace Business Account that includes the capabilities to support HIPAA compliance and provided the capabilities are configured to support compliance with HIPAA. It will also be necessary for a system administrator to agree to Google’s Business Associate Addendum to the Service Agreement. Note: The name of G Suite was changed to Google Workspace in 2020. As many people still refer to Workspace under its former name, this article has been updated to reflect the changes since 2020 while still maintaining G Suite references. In June 2022, any organizations still using the former free G Suite legacy edition were migrated to a paid-for Google Workspaces subscription. Making G Suite HIPAA Compliant (by default it isn’t) When an organization subscribes to a G Suite (Workspace) account, there are four options to choose from. These start with the feature limited Business Starter Plan and go up to the G Suite Enterprise Plan. The choice of options depends on whether G Suite services will be used to create, collect,...
HIPAA Compliant Computer Disposal
The requirement for HIPAA compliant computer disposal applies to any electronic device that is used to create, receive, maintain, transmit or access electronic Protected Health Information (ePHI), and any electronic media on which ePHI has been stored. However, although the HIPAA Security Rule states what the requirement is, guidance to support compliance with the requirement is long out of date. When the HIPAA Security Rule was published, it was deliberately technology neutral. Consequently, many of the standards and implementation specifications are just as applicable now as they were then. This has the advantage of supporting consistency in HIPAA compliance, but also has the disadvantage of creating compliance issues when guidance published to support compliance is out of date. The requirement for HIPAA compliant computer disposal – and the guidance provided to support the requirement – are an example of when taking a twenty year old implementation specification out of context can create a compliance issue. This is because the only implementation specification relating to...



