OCR Settles Ransomware Attack Investigation with Virtual Private Network Solutions for $90,000
The HHS’ Office for Civil Rights (OCR) has announced another settlement to resolve an investigation of a ransomware attack. Virtual Private Network Solutions will pay a financial penalty of $90,000 after being found to have failed to conduct a HIPAA-compliant risk analysis. This is the 9th OCR ransomware investigation to result in a financial penalty for noncompliance with the HIPAA Security Rule, and the third HIPAA penalty under OCR’s risk analysis enforcement initiative. OCR received a notification from Virtual Private Network Solutions, a Virginia-based provider of data hosting and cloud services, about a ransomware attack discovered on October 31, 2021. Virtual Private Network Solutions filed the breach report on behalf of 12 affected covered entity clients on December 30, 2021, involving the protected health information of 6,400 individuals. Data compromised in the incident included names, addresses, dates of birth, driver’s license information, social security numbers, other identifiers, claim information, bank account numbers, other financial information,...
What is a HIPAA Compliant Video Chat?
A HIPAA compliant video chat is an online, face-to-face conversation with a person – or persons – who it is permitted to disclose Protected Health Information to, and that is conducted via a platform that supports HIPAA compliance and in a manner that is HIPAA compliant. However, exceptions to this definition may exist for a variety of reasons. Video chats in healthcare have many valuable uses. They can make healthcare more accessible for patients, support collaboration between healthcare providers, and reduce the costs of healthcare delivery. Video chats can also be recorded and referred back to in the future, used as training resources for medical students, or included in webinars that increase public health awareness. However, when Protected Health Information (PHI) is disclosed in a video chat by a HIPAA covered entity, it is important the video chat is HIPAA compliant. This means that the recipient of PHI must be permitted to receive it, that the platform on which the video chat is conducted supports HIPAA compliance, and that the nature of the disclosure complies...
408,000 Individuals Affected by Cyberattacks on NY & WY Orthpaedics Specialists
More than 408,000 individuals have been affected by data breaches at two orthopaedic healthcare providers: Excelsior Orthopaedics in New York (394,752 records) and Teton Orthopaedics in Wyoming (13,409 records). Excelsior Orthopaedics, New York The orthopaedics and sports medicine specialists, Excelsior Orthopaedics, in Amherst, New York, have recently confirmed a major data breach involving the protected health information of up to 394,752 individuals. On June 23, 2024, unusual activity was identified within its IT systems. An investigation was launched to determine the cause of the activity, which revealed an unauthorized third party had accessed certain systems and viewed or copied the data of current and former patients and employees of Excelsior Orthopaedics and related entities, including Northtowns Orthopaedics in Buffalo and Buffalo Surgery Center in Amherst, the latter has submitted a report to the HHS Office for Civil Rights indicating 64,000 of its patients were affected. Third-party data mining experts were engaged to determine the individuals affected and the types of...
OCR Agrees $80K Settlement with Elgon Information Systems to Resolve Risk Analysis Failure
The HHS’ Office for Civil Rights (OCR) has announced its first HIPAA enforcement of the year to resolve alleged violations of the HIPAA Rules. Elgon Information Systems, a Massachusetts provider of electronic medical records and billing support services, has settled the investigation and paid an $80,000 penalty. This was OCR’s 8th investigation of a ransomware-related data breach and its second enforcement action under its risk analysis enforcement initiative. On March 31, 2023, Elgon Information Systems identified an intrusion when a ransom note was found demanding payment. The internal investigation revealed the ransomware group gained access to its network on March 25, 2023, through open ports on its firewall. The hackers had access to the electronic protected health information (ePHI) of 31,248 individuals including names, addresses, dates of birth, Social Security numbers, driver’s license numbers, and clinical information such as diagnoses, health conditions, and medications. OCR investigated and determined that Elgon Information Systems had failed to conduct a comprehensive...
$8 Million Settlement Agreed in MU Health Care Data Breach Lawsuit
University of Missouri Health Care (MU Health Care) has agreed to pay $8 million to resolve a class action lawsuit over a 2020 data breach that saw unauthorized individuals gain access to employee email accounts containing patients’ protected health information. Two lawsuits were filed in response to the email breach, the first on October 9, 2020, on behalf of MU Health Care patient Casey Bumbales and a second on January 20, 2021, by patient Amanda Kunkelman, both of whom had their sensitive data compromised in the phishing attack. Since the lawsuits made similar allegations and were based on the same facts, they were consolidated into a single action, Bumbales, et al. v. Curators of the University of Missouri, d/b/a MU HEALTH CARE in the Circuit Court of Boone County, Missouri Circuit Division. An email phishing attack saw email accounts compromised between May 4, 2020, and May 6, 2020. MU Health Care reported the breach to the HHS Office for Civil Rights as affecting 189,736 individuals. An email breach was also reported to OCR in June 2020 that affected 5,074 individuals and...



