HHS Publishes Final Rules Implementing Interoperability and Information Blocking Provisions
The Department of Health and Human Services (HHS) issued two final rules related to interoperability and information blocking. The final rules clarify when healthcare providers can provide electronic information and certain activities that are not considered information blocking, amend exceptions to previously published information blocking rules, and aim to make sharing health information easier and more secure. The first final rule was issued on December 11, 2024, and implements provisions related to the Trusted Exchange Framework and Common Agreement (TEFCA) that were proposed in August 2024 in the Health Data, Technology, and Interoperability: Patient Engagement, Information Sharing, and Public Health Interoperability (HTI-2) proposed rule. TEFCA is a nationwide Federal framework required by the 21st Century Cures Act that allows healthcare organizations to easily share health information securely while allowing patients to control what information about them is shared. The provisions implemented by the final rule are intended to advance equity, innovation, and...
Is Qualtrics HIPAA Compliant?
The issue with answering the question is Qualtrics HIPAA compliant is that, although the “experience management” platform appears to support HIPAA compliance, configuring and using the platform in a HIPAA compliant manner looks more complicated than some Covered Entities will be comfortable with. For those who struggle with fancy terminology, Qualtrics is an online platform that enables businesses to create and send surveys, obtain customer/employee feedback, and address satisfaction issues using analytics and AI-powered automation. As an engagement and response tool, Qualtrics is a very advanced option. But is Qualtrics HIPAA compliant? Certainly, Qualtrics appears to be HIPAA compliant in its role as a Business Associate to a Covered Entity. It has multiple security certifications – including self-certified compliance with the HiTRUST CSF Framework – and is willing to enter into a Business Associate Agreement with a Covered Entity if the platform is going to be used for collecting, storing, or transmitting PHI. Qualtrics doesn’t provide previews of its Business...
Luxottica Agrees $250,000 Settlement to Resolve Data Breach Litigation
Luxottica, the world’s largest eyewear company, has agreed to settle class action data breach litigation related to a 2020 hacking incident that involved unauthorized access to an appointment scheduling application that contained the personal and protected health information of more than 829,000 patients of its eye care partners. The unauthorized access occurred between August 5 and August 9, 2020, and the affected individuals were notified in November of that year. The breached data included names, health information, financial information, and Social Security numbers. Several individuals affected by the data breach took legal action seeking damages and restitution. The lawsuits were consolidated into a single action – In re: Luxottica of America Inc. Data Security Breach Litigation – in the District Court for the Southern District of Ohio. The lawsuits alleged Luxottica failed to implement reasonable and appropriate safeguards, and had those measures been implemented, the data breach could have been prevented. Luxottica maintains there was no wrongdoing but chose to settle...
Health Sector Warned About Ongoing Credential Harvesting Campaigns
The Health Sector Cybersecurity Coordination Center (HC3) has issued an updated Analyst Note about credential harvesting, which includes a warning about an active credential harvesting campaign targeting grantees in the health sector. The cybersecurity Cofense has also issued an alert about a credential harvesting campaign spoofing the email security companies Proofpoint, Mimecast, and Virtru. Credential harvesting is a term covering the collection of login credentials – usernames and passwords – by malicious actors, either for use in future cyberattacks or to sell on or trade with other threat actors. The theft of the credentials of a single user can have far-reaching consequences. One only needs to look at the February 2024 ransomware attack on Change Healthcare to see the huge harm that can be caused. The ransomware attack on Change Healthcare saw an affiliate of the BlackCat ransomware group steal an estimated 100 million healthcare records. The credentials of a low-level customer support employee were obtained by a ransomware affiliate. The credentials had been posted on...
Texas Attorney General Sues New York Doctor for Providing Abortion Pills to Texas Resident
Texas Attorney General Ken Paxton has filed a lawsuit in the District Court of Collin County, Texas, against a New York doctor accused of mailing abortion pills to a Texas telemedicine patient, in violation of multiple state laws. Dr. Margaret Daley Carpenter, co-founder of the Abortion Coalition for Telemedicine, is alleged to have prescribed abortion medications to a 20-year-old patient in Collin County Texas, knowing the woman lived in Texas, which prohibits physicians and medical suppliers from providing abortion-inducing medications via the mail service or courier delivery. The State of Texas Health & Safety Code requires any physician performing or inducing an abortion to be licensed to practice medicine in the state of Texas and they must hold admitting privileges at a hospital no further than 30 miles from the location where the abortion procedure takes place. The Texas Admin Code requires physicians who treat patients or prescribe medications to Texas residents through telehealth services to hold a valid Texas medical license. Dr. Carpenter does not have a license to...



