Survey Finds Over 90% of Organizations Now Provide Annual HIPAA Refresher Training
A recent survey conducted by The HIPAA Journal reveals that over 90% of organizations now provide annual HIPAA refresher training to all staff exposed to protected health information (PHI). This encouraging statistic underscores a growing commitment to HIPAA compliance, though the survey’s context suggests some caution in interpreting the results. The survey targeted subscribers of The HIPAA Journal newsletter, a group inherently invested in HIPAA compliance. These individuals likely represent organizations with well-established privacy and security protocols. This respondent profile could skew the results toward higher reported compliance rates compared to the broader healthcare industry. Despite this potential bias, the findings highlight the significance placed on regular HIPAA training. In an era of increasing cybersecurity threats and regulatory scrutiny, continuous education on PHI protection is critical for reducing the risk of data breaches and compliance violations. HIPAA Training for Employees Our training provides employees with a clear and practical understanding of...
Email Account Breaches Reported by Atlantic Orthopaedic Specialists & York County, PA
Email account breaches have been reported by Atlantic Orthopaedic Specialists in Virginia and York County in Pennsylvania. The account breach at Atlantic Orthopaedic has affected more than 15,000 individuals. York County has yet to determine how many individuals have been affected. Atlantic Orthopaedic Specialists, Virginia Vann Virginia Center for Orthopaedics, doing business as Atlantic Orthopaedic Specialists, has identified unauthorized access to a corporate email account. The security incident was detected on August 6, 2024, and third-party cybersecurity experts were engaged to assist with the investigation. The investigation confirmed there had been unauthorized access to a single email account between June 20, 2024, and August 6, 2024. During that time, it is possible that sensitive information was viewed or acquired. The review of the account concluded on October 28, 2024, when it was confirmed that the account contained the protected health information of 15,264 individuals. The information exposed varied from individual to individual and may have included full names along...
OnePoint Patient Care Data Breach Affects 1.7 Million Individuals; Ransom Group Leaks Data
On October 14, 2024, OnePoint Patient Care notified the HHS’ Office for Civil Rights (OCR) about a hacking-related data breach that involved the protected health information of 795,916 individuals; however, on November 22, 2024, the Maine Attorney General was notified that the data breach affected more than twice the number of people – 1,741,152 individuals, including 99 Maine residents. Notification letters started to be mailed to the affected individuals on November 26, 2024. The notification to the Maine Attorney General does not include any additional information about the cyberattack or data breach, other than what is stated in our October 25, 2024 post below. Since the publication of that post, further information has come to light about the cause of the breach. The Inc Ransom group, a ransomware-as-a-service group that engages in double extortion tactics, has claimed responsibility for the attack. INC Ransom breaches networks, identifies sensitive data, exfiltrates that information, and then encrypts files. A ransom must be paid to obtain the keys to decrypt the...
Postmeds Agrees to $7.5 Million Settlement to Resolve Data Breach Lawsuit
The online pharmacy Postmeds Inc., which does business as Truepill, has agreed to settle a class action lawsuit filed in response to a 2023 data breach that affected 2,364,359 individuals. The plaintiffs’ proposed $7.5 million settlement was granted preliminary approval by the U.S. district court judge, Judge Haywood S. Gilliam, on Tuesday this week. Several class action lawsuits were filed in response to the data breach, which were consolidated into a single action – In Re: Post Meds, Inc. Data Breach Litigation – as they were based on the same facts and made similar claims. The consolidated lawsuit alleged that Postmeds failed to implement reasonable and appropriate security measures to protect the sensitive data it stored, which allowed a bad actor to gain access to its network and files used for pharmacy and fulfillment services. The consolidated lawsuit alleged negligence, breach of implied contract, unjust enrichment/quasi-contract, invasion of privacy-intrusion upon seclusion, and violations of the California Unfair Competition Law, California Confidentiality of...
OCR Settles Alleged Impermissible Disclosure of Reproductive Health Information
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its first enforcement action against a healthcare provider over an impermissible disclosure of an individual’s reproductive health information. In September 2023, OCR received a complaint from a female patient who alleged that the Pennsylvania medical practice, Holy Redeemer Family Medicine, had disclosed her protected health information to a prospective employer without authorization. According to the complaint, the information disclosed included her surgical history, obstetric history, gynecological history, and other sensitive reproductive health information. The patient said she had authorized the disclosure of one specific test result to the prospective employer, and that the test result had nothing to do with her reproductive health. OCR launched an investigation and determined that Holy Redeemer had disclosed the patient’s full medical record to the prospective employer; however, the patient had not given authorization for such a broad disclosure and there was no applicable...



