Texas Health and Human Services Commission Fires Multiple Employees Over 3.5-Year Privacy Breach
The Texas Health and Human Services Commission (HHSC) has identified HIPAA Privacy Rule violations by multiple agency employees, who have been discovered to have accessed the records of 61,104 individuals who received agency services without a legitimate work reason for doing so and without authorization from HHSC. The data impermissibly accessed includes full names, home addresses, telephone numbers, dates of birth, Medicaid and Medicare numbers, Social Security numbers, financial information, employment information, benefits information, health insurance information, and medical, certificate, license, and other personal information. The types of information accessed vary from individual to individual. HHSC said the unauthorized access was detected on November 21, 2024, and the internal investigation determined that the unauthorized access occurred between June 2021 and December 2024. HSCC did not initially disclose the number of agency employees involved, the reasons for the unauthorized access, how the privacy breaches were identified, or why it took so long to discover the...
Iowa Doctor Jailed for Unauthorized Medical Record Access
An Iowa doctor who accessed the medical records of current and former romantic partners without authorization, and shared an unauthorized photograph of a patient with his mother via Snapchat has been jailed for the HIPAA violations. Dr. Gabriel Alejandro Hernandez-Roman, age 31, from Isla Verde, Puerto Rico was discovered to have accessed individuals’ medical records without authorization in June 2023 after an anonymous complaint was filed with a hospital where he worked alleging he was entering into romantic relationships with patients, impermissibly accessing their medical records, and threatening them. The complaint was investigated and the privacy violations were confirmed. When one of the women discovered Dr. Hernandez-Roman had viewed her medical records, he asked her to advise the hospital that she had given him permission to access her records. Dr. Hernandez-Roman accessed the medical records of another woman without authorization, including her medical records when she was a minor and her adult psychological records. He also took a photograph of a patient’s prolapsed...
HIPAA Security Rule Checklist
A HIPAA Security Rule checklist helps covered entities, business associates, and other organizations subject to HIPAA compliance to fulfil the requirements of the Security Standards for the Protection of Electronic Protected Health Information (better known as the HIPAA Security Rule). Complying with the Security Rule Standards can reduce the likelihood of HIPAA violations and data breaches attributable to human error and bad actors. Introduction to the HIPAA Security Rule The HIPAA Security Rule in Part 164 Subpart C of the HIPAA Administrative Simplification Requirements consists of regulations, standards, and implementation specifications that have the objective of ensuring the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI) created, collected, maintained, or transmitted by covered entities, business associates, and other organizations subject to HIPAA compliance. All organizations subject to HIPAA must comply with the “applicable” Security Rule regulations, standards, and implementation specifications. However, because the...
Ransomware Groups Claim 13% More Healthcare Victims in 2024
International law enforcement operations against the prolific ransomware-as-a-service (RaaS) groups LockBit and ALPHV/BlackCat resulted in infrastructure seizures and caused significant disruption to their operations; however, the threat from ransomware continues largely unabated. While law enforcement agencies deny any involvement in the shutdown of the ALPHV/BlackCat group, its disappearance and the ongoing disruption caused to the LockBit group by Operation Cronos in early 2024 has left a gap that other ransomware groups have expanded to fill. Past affiliates of those groups have jumped ship, joining other ransomware groups such as RansomHub, which increased its attacks last year to take the top spot as the most prolific ransomware group. The difficulty in taking down RaaS groups has been highlighted in the annual Ransomware and Cyber Threat Report from GuidePoint Security’s Research and Intelligence Team (GRIT). As the researchers explained, despite these largely successful law enforcement operations, ransomware attacks continue to be conducted in large numbers. It is possible...
HHS-OIG Settles Alleged EMTALA Violations with Tennessee and Missouri Health Systems
Two investigations by the Department of Health and Human Services Office of Inspector General (HHS-OIG) of potential violations of the Emergency Medical Treatment and Labor Act (EMTALA) have been settled with penalties of $97,500 and $258,464 to resolve the alleged EMTALA violations. Under EMTALA, hospitals that accept Medicare payments are required to provide a medical screening examination (MSE) appropriate for the patient’s condition to any patient presenting at the hospital, regardless of their legal status, citizenship, or ability to pay. The patient must be provided with stabilizing treatment, except with informed consent, and the patient may not be transferred without stabilizing treatment unless the patient’s condition requires a transfer to a hospital that is better equipped to administer the stabilizing treatment. The first case concerned a patient who presented at Memorial Health Care System in Chattanooga, Tennessee, in December 2021. According to HHS-OIG, a known diabetic patient presented at Memorial’s Emergency Room seeking treatment; however, had a verbal...



