Tampa General Hospital Settles Data Breach Lawsuit for $6.8M
Tampa General Hospital has agreed to pay $6,800,000 to resolve a class action lawsuit related to a 2023 cyberattack that involved unauthorized access to systems containing the protected health information of more than 2 million patients. The intrusion was detected on May 31, 2023, and the forensic investigation confirmed that hackers had access to its network for almost three weeks between May 12 and May 30, 2023. During that time the hackers exfiltrated files containing patient data such as names, dates of birth, contact information, Social Security numbers, health insurance information, and limited treatment information. The breach was initially thought to affect around 1.2 million patients but was later reported to the HHS’ Office for Civil Rights as affecting up to 1,313,636 patients. The breach report was then amended to state that up to 2,430,920 individuals had been affected. Several class action lawsuits were filed and consolidated into a single action – DiPierro, et al. v. Florida Health Sciences Center Inc. d/b/a Tampa General Hospital – in the 13th Judicial Circuit...
New York Data Breach Notification Requirements Updated
In late December 2024, the Governor of New York, Kathy Hochul, signed two bills into law updating the New York data breach notification requirements under New York’s general business law (§ 899-aa). The bills expand the definition of personal information and set a time limit for issuing notifications. Prior to the law change, notifications had to be issued by companies that experienced a breach of system security that resulted in unauthorized access to the personal data of New York residents or if it was reasonably believed to have resulted in unauthorized access to the personal data of New York residents. Those notifications had to be issued to the affected individuals and the state Attorney General, Department of State, and the Division of State Police “in the most expedient time possible and without reasonable delay.” Effective immediately, a time limit has been stipulated for issuing those notifications, which must now be sent within 30 days of the discovery of a breach. The Department of Financial Services has also been added to the list of entities to be notified. The law...
Examples of Avoidable HIPAA Violations by Employers
Examples of HIPAA violations by employers are easy to find because almost every avoidable HIPAA violation is indirectly attributable to an employer’s failure to implement adequate privacy and security measures, failure to effectively train members of the workforce, or failure to monitor HIPAA compliance. Over the next few years, these failures may become expensive for employers in – or providing a service to – the healthcare industry. Employers in their role as a covered entity or business associate have the ultimate responsibility for HIPAA compliance. They are responsible for complying with all applicable federal and state regulations, for developing workplace policies and procedures, and for ensuring the policies and procedures are complied with. While these responsibilities may sometimes be delegated to a third party, employers are usually responsible for selecting the third party. When avoidable HIPAA violations occur, they represent a compliance failure by an employer. Although the violations most often manifest as a data breach, unauthorized access to PHI, or an...
Colorado Fertility Center Ransomware Attack Affects 80,000 Patients
Conceptions Reproductive Associates of Colorado has suffered a ransomware attack, hacking incidents have been reported by Lexington Diagnostic Center, In-Home Attendant Services, and Youth Eastside Services, and email accounts have been compromised at Summit Medical Group. Conceptions Reproductive Associates of Colorado The fertility clinic, Conceptions Reproductive Associates of Colorado, has recently confirmed that it was the victim of a ransomware attack that involved unauthorized access to its network and the theft of the information of up to 80,000 current and former patients and their partners. The incident was detected in mid-April when disruption was caused to some of its legacy computer systems. Incident response procedures were immediately implemented, the intrusion was reported to law enforcement, and an investigation was launched to determine the nature and extent of the unauthorized activity. The investigation confirmed that the ransomware group gained access to certain legacy systems earlier in the month and exfiltrated data. The file review has recently been...
HIPAA Administrative Safeguards
Compared to the specific HIPAA administrative safeguards of the Security Rule (the Administrative, Physical, and Technical Safeguards), most other references to safeguards in the text of HIPAA are intentionally flexible to accommodate the different types of covered entities and business associates that have to comply with them. While this flexibility means it can be easier for some organizations to comply with the HIPAA safeguards, other organizations may find the lack of direct guidance unhelpful. To demonstrate the difference between the safeguards of the Security Rule and the safeguards of the Privacy Rule, we have provided a synopsis of the Security Rule Administrative, Physical, and Technical Safeguards to compare against the safeguards mentioned in the Privacy Rule Administrative Requirements. There is also a section relating to the Organization Requirements of the Privacy and Security Rules – both of which include further HIPAA administrative safeguards. HIPAA Security Rule Safeguards The HIPAA Security Rule is dominated by the Administrative, Physical, and Technical...



