UMC Health Notifies Patients Affected by September Ransomware Attack
UMC Health System has started notifying patients that some of their protected health information was exposed in a recent ransomware attack. Unusual activity was identified within its computer network on September 26, 2024, when ransomware was deployed to encrypt files. The forensic investigation confirmed that the attacker had access to its network from September 16 to September 26. The attack caused an outage that lasted for around 3 weeks. On October 23, 2024, UMC Health confirmed that its clinics were accepting all patients, and all patient-facing systems had been brought back online. The forensic investigation confirmed that an unknown, unauthorized third party had accessed its network, including parts of the network containing patient information. That information may have been viewed or acquired before ransomware was used to encrypt files. UMC Health System has now reviewed the affected files and confirmed that they contain patients’ protected health information such as names, addresses, dates of birth, Social Security numbers, diagnoses, health insurance information,...
Bipartisan Senate Bill Seeks to Strengthen Healthcare Cybersecurity
A bipartisan bill has been introduced in the Senate that calls for the Department of Health and Human Services (HHS) to update the HIPAA regulations to strengthen cybersecurity across the healthcare sector and provide grants to help low-resourced healthcare organizations adopt cybersecurity best practices. The HHS is about to propose an update to the HIPAA Security Rule that will include new cybersecurity requirements. The updated rule is currently under review by the White House, and the HHS Office for Civil Rights (OCR) intends to publish the proposed rule before the end of the year. OCR has not disclosed what new requirements are being proposed, other than stating that the proposed rule includes substantial updates to the HIPAA Security Rule. The fate of the proposed rule will lie with the new administration. President Trump has stated that one of the aims of his administration is to eliminate certain regulations, although there is broad bipartisan support for improving healthcare cybersecurity. The Health Care Cybersecurity and Resiliency Act of 2024 was introduced by Sen Bill...
Why 71% of HIPAA Journal Newsletter Subscribers Conduct Annual HIPAA Compliance Reviews
Recently, we invited subscribers to The HIPAA Journal newsletter to take our new free HIPAA Compliance Assessment for HIPAA Covered Entities. An analysis of the results reveals that 71% of subscribers who took the assessment already conduct annual HIPAA compliance reviews. It should be noted that the people testing the assessment were subscribers to The HIPAA Journal newsletter, so they are already highly motivated about HIPAA compliance. The overall response rate would probably be much lower if the survey were conducted on a random sample of Covered Entities. HIPAA mandates HIPAA compliance reviews but does not specifically mandate that the reviews should be conducted annually. However, the regulations do require Covered Entities and Business Associates to review and modify the measures implemented to safeguard electronic Protected Health Information (§164.306(e)), and to conduct “periodic technical and nontechnical evaluations” to ensure policies and procedures implemented to comply with the HIPAA Security Rule are effective (§164.308(a)(8)). With regard to the frequency of...
HHS-OIG Recommends OCR Enhance its HIPAA Audit Program
The Department of Health and Human Services (HHS) Office of Inspector General (OIG) has conducted an audit of the HHS Office for Civil Rights (OCR) to assess whether OCR has fulfilled its requirement to conduct audits of HIPAA-regulated entities to assess compliance with the HIPAA Rules. A previous HHS-OIG audit in 2013 to assess compliance with the requirements of the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 to conduct HIPAA compliance audits found that OCR had not assessed the risks, established priorities, or implemented controls required by the HITECH Act. Since that audit, cyberattacks on healthcare organizations have been increasing every year and large data breaches are now being reported at a rate of more than 2 per day, which suggests the efforts of OCR to improve cybersecurity across the healthcare sector may not be effective and HIPAA-regulated entities may not be complying with the cybersecurity requirements of the HIPAA Security Rule. The HITECH Act requires the HHS to conduct periodic audits of HIPAA-regulated entities to...
Email Data Breaches Announced by 4 U.S. Healthcare Orgs
Unauthorized individuals have gained access to employee email accounts at four healthcare organizations over the summer, resulting in HIPAA email compliance breaches: HealthFund Solutions in Florida, Option Care Health in Illinois, and Liberty Endo and Numotion in New York. HealthFund Solutions HealthFund Solutions, LLC, a Florida-based health insurance solutions company, has discovered unauthorized access to an employee’s email account. The email account breach was detected on August 14, 2024, and after securing the account, a third-party digital forensics firm was engaged to investigate the incident. The investigation confirmed that unauthorized access was limited to a single email account, and on September 16, 2024, it was determined that the email account contained the protected health information of 5,198 individuals. Information compromised in the incident included names, addresses, dates of birth, Social Security numbers, medical information, and health insurance information. Notification letters were mailed to the affected individuals on November 15, 2024. While there has...



