ConnectOnCall Announces 914K-Record Data Breach
ConnectOnCall.com – a Delaware-based business associate and Phreesia subsidiary that provides a communication platform for connecting healthcare providers with patients – has suffered a major data breach affecting up to 914,138 individuals. Healthcare providers use the ConnectOnCall platform to improve their after-hours call process and enhance patient communications. On May 12, 2024, ConnectOnCall identified suspicious activity within its platform and launched an investigation that confirmed that a threat actor had access to the CallOnConnect platform and certain data contained within the application. Third-party cybersecurity experts were engaged to investigate the security incident and determine the extent of the unauthorized activity. The investigation revealed the threat actor had access to the platform for three months between February 16, 2024, and May 12, 2024. ConnectOnCall said the platform was immediately taken offline when the security incident was detected, security controls were assessed and enhanced, and the platform was restored in phases in a more...
HHS Publishes Final Rule Modifying HIPAA NCPDP Retail Pharmacy & Medicaid Pharmacy Subrogation Standards
The U.S. Department of Health and Human Services has published a final rule modifying the Health Insurance Portability and Accountability Act (HIPAA) National Council for Prescription Drug Programs (NCPDP) Retail Pharmacy Standards and the Medicaid Pharmacy Subrogation Standard. Modifications to these HIPAA standards were proposed by the HHS in November 2022 to support more robust data exchange, improve coordination of benefits, and provide expanded financial fields to eliminate the need to manually enter free text, split claims, or prepare and submit a paper Universal Claim Form. The key modifications adopted in the Final Rule are: NCPDP Telecommunication Standard Implementation Guide, Version D, Release 0 (Version D.0) replaced with NCPDP Telecommunication Standard Implementation Guide, Version F6 NCPDP Batch Standard Implementation Guide, Version 1, Release 2 (Version 1.2) replaced with NCPDP Batch Standard Implementation Guide, Version 15 NCPDP Batch Standard Medicaid Subrogation Implementation Guide, Version 3, Release 0 (Version 3.0) replaced with NCPDP Batch Standard...
OSHA Publishes Workplace Injury and Illness Data for Calendar Year 2023
The Occupational Safety and Health Administration (OSHA) has published comprehensive data on workplace injuries and illnesses in calendar year 2023. The data was collected via OSHA’s Injury Tracking Application from more than 91,000 workplaces and includes more than 890,000 workplace injuries and illnesses. The data set includes employer names, locations, descriptions of injuries and illnesses, objects/substances involved, workers’ activities prior to incidents occurring, and the conditions and circumstances that led to workers sustaining injuries and illnesses in the workplace. The personally identifiable information of employees has been redacted to ensure their privacy. OSHA publishes the data to allow employers, workers, customers, and members of the public to make informed decisions about safety and health at specific establishments, including injury risks at specific places of work. Researchers, public health officials, and others can use the data to learn about the nature of workplace injuries and illnesses and identify trends at the local, state, and national levels....
HHS-OIG Expects to Recover $7.13 Billion in FY 2024
The Department of Health and Human Services Office of Inspector General (HHS-OIG) expects to recoup $7.13 billion in recoveries and receivables in FY 2024 from its investigations and audits, according to its Fall 2024 semiannual report to Congress. Those funds came from 1,548 criminal and civil enforcement actions against individuals and companies suspected of engaging in crimes targeting HHS programs and the people they serve. In many cases, the investigations resulted in civil monetary penalties and criminal convictions, with 3,234 individuals added to the HHS-OIG exclusion list having been barred from participating in federal healthcare programs. The $7.13 billion includes around $4 billion in recoveries and receivables from investigations and audits conducted in the 6-month period between April 1, 2024, and September 30, 2024. The June 2024 National Health Care Fraud Enforcement Action saw HHS-OIG, the Department of Justice, and Federal, State, and local law enforcement partners charge 193 individuals for their roles in fraud schemes, including fraudulent billing for products...
FDA Urges Blood Establishments to Improve Their Security Posture Following Spate of Ransomware Attacks
The Food and Drug Administration (FDA) has issued an alert advising blood suppliers and transfusion services about a spate of ransomware attacks that disrupted healthcare systems and blood establishment operations. All blood establishments have been urged to take steps to strengthen their cybersecurity practices and test and improve their incident response and contingency plans. Computer systems are used at all stages of the manufacturing, processing, labeling, and distribution of blood and blood products. Cyberattacks such as ransomware incidents that disrupt those highly interconnected computer systems can affect the safety and availability of the blood supply. The disruption caused by these attacks can last several days to several months, severely affecting the manufacturing and distribution of blood, blood products, and source plasma. In June 2024, a ransomware attack on Synnovis, a pathology service provider to the UK’s National Health Service, disrupted testing services and blood matching, initially causing a shortage of type-O blood supplies in London and then nationwide....



