Atrium Health Discovers Historic Use of Tracking Technologies on its Patient Portal
Charlotte, NC-based Atrium Health has recently informed almost 600,000 patients about a privacy breach related to the use of online tracking technologies on its patient portal. Tracking technologies, such as pixels, are code snippets that record browsing/usage data, such as the pages visited while on a website and other user interactions. The data collected by these tools can also be used to serve individuals with personalized ads. In June 2022, a report by The Markup/STAT revealed one-third of the top 100 U.S. hospitals had these tools installed, and another study indicated that 99% of hospitals had tracking tools on their websites that captured identifying user data and transferred that data to third-party tech firms such as Meta Platforms and Google without users’ knowledge or consent. Atrium Health informed patients that when the use of these tools on healthcare websites was called into question in 2022, an internal investigation was launched to determine whether the tracking tools had been added to its patient portal, and Atrium Health was satisfied that was not the case....
Gastroenterology, Cardiology, and Nursing Care Providers Suffer Cyberattacks
Cyberattacks have recently been announced by Connecticut GI and Gastroenterology Associates of Fairfield, Cardiology Associates of Mobile, and Pavilion of Bridgeview. Patient Data Stolen in Cyberattack on Connecticut GI & Gastroenterology Associates of Fairfield Connecticut GI and Gastroenterology Associates of Fairfield have recently confirmed that the protected health information of 10,568 patients was stolen in a security breach in June 2024. The clinics learned on June 19, 2024, that an unauthorized individual had accessed servers between June 5 and June 7, 2024, and copied data. Action was immediately taken to prevent any further unauthorized access to its servers and a review of the affected data was initiated, which confirmed that names and financial account information had been stolen. Notification letters were mailed to the affected individuals on or around November 26, 2024, and complimentary credit monitoring services have been made available. The clinics are reviewing information security measures and are working to implement additional technical safeguards....
Is Box HIPAA Compliant?
Box is HIPAA compliant and can be used to store, manage, and share files and folders containing Protected Health Information provided an organization subscribes to an Enterprise or Enterprise Plus Plan, configures Box to support HIPAA compliance, and enforces organizational policies to meet HIPAA compliance requirements. In addition, it will be necessary to agree to Box’s Business Associate Agreement in order to make the use of Box HIPAA compliant. What is Box? Box is a cloud storage and content management service that supports collaboration and file-sharing. Users can share files, invite others to view, edit, or upload content. Box can be used for personal use; however, businesses need to sign up for either a Business, Enterprise, or Enterprise plus account (Note: It is necessary to sign up for an Enterprise or Enterprise Plus account to use Box in compliance with HIPAA). Is Box Covered by the Conduit Exception Rule? The HIPAA conduit exception rule was introduced to allow HIPAA covered entities to use certain communications channels without having to obtain a business...
What Does PHI Stand For?
PHI stands for Protected Health Information – a term is commonly referred to in connection with the Health Insurance Portability and Accountability Act (HIPAA) and associated legislation such as the Health Information Technology for Economic and Clinical Health Act (HITECH). Generally, PHI stands for any data relating to a patient, a patient´s healthcare, or the payment for that healthcare that is created, received, stored, or transmitted by HIPAA-covered entities and their business associates. HIPAA-covered entities are mostly healthcare providers, health plans, and healthcare clearinghouses, while their business associates are third-party service providers who have access to Protected Health Information in order to provide a service to or on behalf of the covered entity. These entities must implement measures to protect against the unauthorized disclosure, amendment or destruction of Protected Health Information as stipulated by the HIPAA Privacy Rule. The Department of Health & Human Services´ Office for Civil Rights has defined PHI as any Individually Identifiable...
Is SharePoint HIPAA Compliant?
SharePoint is HIPAA compliant and can be used to maintain and share PHI when used as part of an Office 365 or Microsoft 365 Enterprise plan that supports HIPAA compliance, if the online storage service is configured to comply with the HIPAA access control requirements, and a Business Associate Agreement is entered into with Microsoft. This post explains more about what is necessary to make SharePoint HIPAA compliant and suitable for use in the healthcare industry. What is SharePoint? SharePoint is a web-based document management and storage system and one of the leading collaborative platforms on the market, used by 78% of Fortune 500 companies. The platform is based on Microsoft’s OpenXML document standard and therefore integrates seamlessly with Microsoft Office. SharePoint offers many of the same functions as Google Drive and Dropbox, although SharePoint is a much more powerful platform and can also be used for internet portals, intranet sites, and can form the basis of a CRM system. With such a wide range of functions it is naturally a good fit for healthcare...



