What is the CCPA HIPAA Exemption?
The CCPA HIPAA exemption consists of two clauses in the California Consumer Protection Act that exempts HIPAA covered entities from complying with the Act and subsequent amendments enacted by the California Privacy Rights Act. The CCPA HIPAA exemption also applies to business associates in respect of Protected Health Information created, received, maintained, or transmitted by a business associate on behalf of a covered entity. The California Consumer Privacy Act (CCPA) is a state law that enhances the privacy rights of Californian residents. The CCPA applies to all businesses that collect California residents’ personal information that have gross revenues in excess of $25 million per year, that buys, receives, or sells the personal information of 100,000 or more Californian residents or households, or that earns more than half of its annual revenue from selling California residents’ personal information. The CCPA gives California residents the right to know what information is being collected from them and how it is used or shared. It also gives California residents the rights to...
What are the Physical Safeguards of HIPAA’s Security Rule?
The Physical Safeguards of HIPAA’s Security Rule are the standards and implementation specifications that must be applied when applicable “to protect a covered entity’s or business associate’s electronic information systems and related buildings and equipment, from natural and environmental hazards, and unauthorized intrusion.’’ As with many areas of HIPAA compliance, it is necessary to factor in other regulatory requirements when complying with the Physical Safeguards of HIPAA’s Security Rule. Depending on the nature of an organization’s activities, these can include CMS’ Emergency Preparedness Rule, OSHA’s Fire Prevention and Response Standards, and local building and safety codes. It is also necessary to comply with the Physical Safeguards of HIPAA’s Security Rule in the context of the Security Rule’s General Rules (§164.306). These require covered entities and business associates to: Ensure the confidentiality, integrity, and availability of all electronic Protected Health Information (PHI) created, received, maintained, or transmitted. Protect against any reasonably...
Email Accounts Compromised at Four Healthcare Orgs
Email accounts have been compromised at Restorix Health in New York, INTERLINK Health Services in Oregon, RxSight in California, and Fillmore County Hospital in Nebraska, and patient data has been exposed. Restorix Health Restorix Health, a Tarrytown, New York-based wound care solutions company, discovered on May 30, 2024, that an employee email account had been subjected to unauthorized access. The investigation confirmed the breach was limited to a single account, and the forensic investigation revealed the account was accessed between May 7, 2024, and May 29, 2024. The review of the account was completed on November 27, 2024, and confirmed that some protected health information had been exposed. The affected healthcare partners were notified on December 18, 2024, and it has been confirmed that 38,553 individuals were affected. The data varied from individual to individual and may have included names, dates of birth, driver’s license numbers, government identification numbers, passport numbers, Social Security numbers, patient ID numbers, medical information, prescription...
Data Breaches Announced by Central New York Cardiology & Park Place Pediatric Dentistry
Central New York Cardiology has experienced a cyberattack involving unauthorized access to patient data, and an unencrypted laptop computer has been stolen from an employee of Park Place Pediatric Dentistry in Texas. Central New York Cardiology Central New York Cardiology fell victim to a cyberattack in December 2024 in which hackers accessed its network and potentially viewed or obtained patient data. The forensic investigation confirmed that the hackers could access parts of its network from December 26, 2024, to December 30, 2024. The file review is ongoing, and at the time of the breach announcement, the total number of affected individuals had not been determined; however, Central New York Cardiology has confirmed that the information compromised in the incident likely included first and last names together with one or more of the following: address, date of birth, driver’s license number, Social Security number, diagnosis/condition, health insurance information, provider name, other treatment information, and/or financial account information. Central New York Cardiology has...
New York Labor Union Settles Data Breach Lawsuit for $6 Million
The New York-based labor Union, UNITE HERE, has agreed to pay $6 million to resolve a consolidated class action lawsuit that alleged a failure to implement appropriate cybersecurity measures to protect the sensitive data it held. On October 20, 2023, UNITE HERE identified unauthorized access to its systems. Hackers were determined to have breached its network and gained access to files containing the personal and protected health information of members of certain local unions and health funds. It was not possible to determine exactly how many people were affected, so the decision was taken to send notification letters to all 791,273 potentially affected members. Data compromised in the incident included names, Social Security numbers, driver’s licenses, state identification numbers, alien registration numbers, tribal identification numbers, passport numbers, birth certificates, dates of birth, marriage licenses, signatures, financial account information, and medical information. Class action lawsuits were filed by union members, which were consolidated into a single lawsuit –...



