Billing Support Vendor Notifies 701K Patients About December 2023 Data Breach
Medusind, a Florida-based revenue cycle management vendor and practice management software provider, has recently started notifying individuals about a security breach detected more than a year ago. According to the notification letters, the unauthorized access occurred on December 23, 2023, and was detected and blocked the same day. A third-party cybersecurity firm was engaged to investigate the breach, and evidence was found of data exfiltration. The review of the affected files has now been completed, and notification letters have been mailed. Medusind is offering the affected individuals two years of complimentary credit monitoring and identity theft protection services. Information potentially compromised in the incident includes health insurance and billing information, debit/credit card numbers or bank account information, health information such as medical history, medical record number, or prescription information, government identification such as Social Security number, taxpayer ID, driver’s license number, or passport number), and other personal information such as date...
OCR Resolves Multiple Security Rule Failures with USR Holdings with $337,750 Settlement
It has been a busy end to the year for the HHS’ Office for Civil Rights (OCR) concerning HIPAA enforcement. By mid-December, OCR had announced 16 settlements and civil monetary penalties to resolve alleged violations of the HIPAA Rules; however, OCR Director Melanie Fontes Rainer announced in her end-of-year wrap-up of OCR accomplishments that there had been 22 HIPAA enforcement actions last year, three of which were announced this week. Earlier this week, OCR announced two settlements to resolve ransomware-related investigations that uncovered risk analysis failures – an $80,000 settlement with Elgon Information Systems and a $90,000 settlement with Virtual Private Network Solutions. On January 8, 2025, OCR announced that a $337,750 settlement had been agreed with the Florida business associate, USR Holdings, LLC, to resolve multiple alleged violations of the HIPAA Security Rule. USR Holdings is a holding company that owns and manages primary mental health and substance abuse treatment facilities in Florida, Maryland, and Kentucky. In its capacity as a HIPAA business...
OCR Settles Ransomware Attack Investigation with Virtual Private Network Solutions for $90,000
The HHS’ Office for Civil Rights (OCR) has announced another settlement to resolve an investigation of a ransomware attack. Virtual Private Network Solutions will pay a financial penalty of $90,000 after being found to have failed to conduct a HIPAA-compliant risk analysis. This is the 9th OCR ransomware investigation to result in a financial penalty for noncompliance with the HIPAA Security Rule, and the third HIPAA penalty under OCR’s risk analysis enforcement initiative. OCR received a notification from Virtual Private Network Solutions, a Virginia-based provider of data hosting and cloud services, about a ransomware attack discovered on October 31, 2021. Virtual Private Network Solutions filed the breach report on behalf of 12 affected covered entity clients on December 30, 2021, involving the protected health information of 6,400 individuals. Data compromised in the incident included names, addresses, dates of birth, driver’s license information, social security numbers, other identifiers, claim information, bank account numbers, other financial information,...
What is a HIPAA Compliant Video Chat?
A HIPAA compliant video chat is an online, face-to-face conversation with a person – or persons – who it is permitted to disclose Protected Health Information to, and that is conducted via a platform that supports HIPAA compliance and in a manner that is HIPAA compliant. However, exceptions to this definition may exist for a variety of reasons. Video chats in healthcare have many valuable uses. They can make healthcare more accessible for patients, support collaboration between healthcare providers, and reduce the costs of healthcare delivery. Video chats can also be recorded and referred back to in the future, used as training resources for medical students, or included in webinars that increase public health awareness. However, when Protected Health Information (PHI) is disclosed in a video chat by a HIPAA covered entity, it is important the video chat is HIPAA compliant. This means that the recipient of PHI must be permitted to receive it, that the platform on which the video chat is conducted supports HIPAA compliance, and that the nature of the disclosure complies...
408,000 Individuals Affected by Cyberattacks on NY & WY Orthpaedics Specialists
More than 408,000 individuals have been affected by data breaches at two orthopaedic healthcare providers: Excelsior Orthopaedics in New York (394,752 records) and Teton Orthopaedics in Wyoming (13,409 records). Excelsior Orthopaedics, New York The orthopaedics and sports medicine specialists, Excelsior Orthopaedics, in Amherst, New York, have recently confirmed a major data breach involving the protected health information of up to 394,752 individuals. On June 23, 2024, unusual activity was identified within its IT systems. An investigation was launched to determine the cause of the activity, which revealed an unauthorized third party had accessed certain systems and viewed or copied the data of current and former patients and employees of Excelsior Orthopaedics and related entities, including Northtowns Orthopaedics in Buffalo and Buffalo Surgery Center in Amherst, the latter has submitted a report to the HHS Office for Civil Rights indicating 64,000 of its patients were affected. Third-party data mining experts were engaged to determine the individuals affected and the types of...



