UT Southwestern Medical Center Data Breach Affects 43,000 Patients
UT Southwestern Medical Center (UTSW) in Texas has recently reported an email-related unauthorized access/disclosure incident to the HHS’ Office for Civil Rights (OCR) involving the protected health information of up to 43,048 patients. The substitute breach notice on its website explains that UTSW was made aware of the privacy incident on October 10, 2024. Members of the workforce were using a third-party calendar management tool which inadvertently allowed the vendor to access certain calendars and, in some cases, the calendars included patients’ protected health information. The investigation revealed employees had added patient data to the third-party tool which included names, dates of birth, medical record numbers, phone numbers, date(s) of planned services, medical diagnoses, lab test results, medication information, insurance benefits information, and, for certain patients, partial social security numbers. The breach notice does not state for how long the calendar tool was used by employees, whether UT Southwestern Medical Center had expressly permitted employees to use the...
Survey Reveals 65% of Employees Take Security Shortcuts
Organizations invest in cybersecurity solutions and develop policies and procedures to ensure compliance and minimize risk, only for employees to circumvent those policies and security measures. The scale of the problem was highlighted by a recent survey conducted by Censuswide on behalf of the security and access management vendor, CyberArk. The survey explored employee behaviors and was conducted in October 2024 on more than 14,000 employees in a wide range of job roles and various verticals in the US, UK, France, Germany, Australia, and Singapore. Almost all surveyed employees had some form of privileged access or access to sensitive data, and all employees accessed business-critical applications using corporate devices. 80% of employees also admitted to accessing work applications using their personal devices. While employers may have Bring Your Own Device (BYOD) policies allowing personal devices to be used for work purposes, personal devices typically lack security controls and pose a security risk. For instance, 36% of employees who said they use a personal device for work...
ConnectOnCall Announces 914K-Record Data Breach
ConnectOnCall.com – a Delaware-based business associate and Phreesia subsidiary that provides a communication platform for connecting healthcare providers with patients – has suffered a major data breach affecting up to 914,138 individuals. Healthcare providers use the ConnectOnCall platform to improve their after-hours call process and enhance patient communications. On May 12, 2024, ConnectOnCall identified suspicious activity within its platform and launched an investigation that confirmed that a threat actor had access to the CallOnConnect platform and certain data contained within the application. Third-party cybersecurity experts were engaged to investigate the security incident and determine the extent of the unauthorized activity. The investigation revealed the threat actor had access to the platform for three months between February 16, 2024, and May 12, 2024. ConnectOnCall said the platform was immediately taken offline when the security incident was detected, security controls were assessed and enhanced, and the platform was restored in phases in a more...
HHS Publishes Final Rule Modifying HIPAA NCPDP Retail Pharmacy & Medicaid Pharmacy Subrogation Standards
The U.S. Department of Health and Human Services has published a final rule modifying the Health Insurance Portability and Accountability Act (HIPAA) National Council for Prescription Drug Programs (NCPDP) Retail Pharmacy Standards and the Medicaid Pharmacy Subrogation Standard. Modifications to these HIPAA standards were proposed by the HHS in November 2022 to support more robust data exchange, improve coordination of benefits, and provide expanded financial fields to eliminate the need to manually enter free text, split claims, or prepare and submit a paper Universal Claim Form. The key modifications adopted in the Final Rule are: NCPDP Telecommunication Standard Implementation Guide, Version D, Release 0 (Version D.0) replaced with NCPDP Telecommunication Standard Implementation Guide, Version F6 NCPDP Batch Standard Implementation Guide, Version 1, Release 2 (Version 1.2) replaced with NCPDP Batch Standard Implementation Guide, Version 15 NCPDP Batch Standard Medicaid Subrogation Implementation Guide, Version 3, Release 0 (Version 3.0) replaced with NCPDP Batch Standard...
OSHA Publishes Workplace Injury and Illness Data for Calendar Year 2023
The Occupational Safety and Health Administration (OSHA) has published comprehensive data on workplace injuries and illnesses in calendar year 2023. The data was collected via OSHA’s Injury Tracking Application from more than 91,000 workplaces and includes more than 890,000 workplace injuries and illnesses. The data set includes employer names, locations, descriptions of injuries and illnesses, objects/substances involved, workers’ activities prior to incidents occurring, and the conditions and circumstances that led to workers sustaining injuries and illnesses in the workplace. The personally identifiable information of employees has been redacted to ensure their privacy. OSHA publishes the data to allow employers, workers, customers, and members of the public to make informed decisions about safety and health at specific establishments, including injury risks at specific places of work. Researchers, public health officials, and others can use the data to learn about the nature of workplace injuries and illnesses and identify trends at the local, state, and national levels....



