CMS Confirms 3.1 Million Individuals Affected by MOVEit Hack on Wisconsin Physicians Service
The Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) has reported a data breach to the HHS that has affected 3,112,815 individuals. The data breach was the same one the CMS and Wisconsin Physicians Service Insurance Corporation (WPS) announced earlier this month – the exploitation of a zero day vulnerability in the MOVEit Transfer solution by the Clop group in a mass exploitation event in May 2023, as detailed in the post below. In the announcement, the CMS and WPS stated that notifications were being issued to 946,801 individuals. The same day the announcement was made (September 6, 2024), the CMS submitted a breach report to the HHS on behalf of its business associate, WPS. That breach portal now shows that more than three times as many individuals were affected than the CMS and WPS said they were notifying. The CMS explained the discrepancy in the figures as being due to WPS holding the data of individuals who had deceased, and also that WPS had collected the data of many individuals as part of its work for the CMS who were...
Elitecare Emergency Hospital Confirms 24,750-Record Data Breach
Data breaches have recently been reported by Elitecare Emergency Hospital in Texas, Welcome Health in California, and Maryville Academy in Illinois. Elitecare Emergency Hospital, Texas Elitecare Emergency Hospital in League City, TX, has notified 24,754 patients about a recent cybersecurity incident. Suspicious activity was detected within its network on July 10, 2024. Systems were turned off to prevent any further impact and third-party cybersecurity experts were engaged to investigate the breach. On July 17, 2024, it was confirmed that an unauthorized individual had accessed patients’ protected health information. It was not possible to determine the exact types of data that were accessed for each individual; however, the breach involved data such as names, addresses, dates of birth, phone numbers, and email addresses along with one or more of the following: health insurance information, Medicare/Medicaid numbers, medical record numbers, provider names, diagnoses, medications, test results, treatment information, billing and claims information, Social Security numbers,...
siParadigm Notifies 26,500 Patients About PHI Exposure
The New Jersey lab testing and diagnostic service provider, siParadigm, is notifying 26,534 individuals about the exposure of some of their protected health information. On June 11, 2024, siParadigm identified unauthorized access to its computer network. Its incident response procedures were initiated, and third-party cybersecurity experts were engaged to help secure its network, harden security, and investigate the breach. The investigation confirmed that files related to diagnostics and related services were stored on the parts of the network that were accessed; however, no evidence has been found to indicate any sensitive information has been misused. The types of information exposed included names, addresses, dates of birth, Social Security numbers, and medical information. While there are no indications that the exposed data will be misused, the affected individuals have been offered complimentary credit monitoring services. siParadigm said it is focused on enhancing cyber preparedness and will update its policies and procedures and provide further security awareness training...
OSHA Considering Exempting Volunteer Fire Departments from Proposed Emergency Response Standard
The Department of Labor’s Occupational Safety and Health Administration (OSHA) has responded to criticism of its proposed Emergency Response Standard and the negative impact it is likely to have on volunteer fire departments. Following the terrorist attacks on September 11, 2024, government agencies were directed to strengthen their preparedness to respond to acts of terrorism, major disasters, and other emergencies. OSHA reviewed its standards that were applicable to the safe conduct of emergency response and disaster recovery activities and identified gaps in protections for emergency responders and disaster recovery workers. After submitting a Request for Information, OSHA published a Notice of Proposed Rulemaking on February 5, 2024, proposing several changes that were intended to improve safety and health. The Emergency Response Standard is due to replace the Fire Brigades Standard and addresses a broader scope of emergency responders and seeks to better protect them from a variety of occupational hazards. Comments were accepted until May 6, 2023, with the deadline extended...
What is Meaningful Use in Healthcare?
Meaningful use in healthcare is a term used to describe the requirements adopted and subsequently amended by HHS’ Centers for Medicare and Medicaid Services (CMS) in order for eligible healthcare providers to qualify for incentive payments under the HITECH Act’s “Promotion of Health Information Technology” provisions. When Congress passed the American Recovery and Reinvestment Act of 2009 (ARRA), the Act contained two Titles relevant to explaining what is meaningful use in healthcare. The first Title – Division A Title XIII, or the Health Information Technology for Economic and Clinical Health Act (HITECH) – led to the development of standards for certified Electronic Health Records (EHRs). The second Title – Division B Title IV, or Medicare and Medicaid Health Information Technology; Miscellaneous Provisions – incentivized the adoption and meaningful use of certified EHRs. It also authorized the Secretary of Health and Human Services (HHS) to penalize Medicare and Medicaid providers who did not comply with the meaningful use requirements within five years. HITECH and...



