Answers Demanded from DOL About State Agencies Tipping Off Employers About Surprise Inspections
Two House Democrats have written to Department of Labor (DOL) Acting Labor Secretary Julie Su demanding answers about credible allegations that California and South Carolina Occupational Safety and Health Administration (OSHA) agencies have been tipping off employers about workplace safety inspections. Reps. Bobby Scott (D-VA), ranking member of the House Committee on Education and the Workforce, and Alma Adams (D-NC), ranking member of the Workforce Protection Subcommittee, wrote the letter in response to recent news reports that suggest inspectors are notifying employers about upcoming inspections. One such report came from a legislative hearing in California where farm workers and their advocates alleged that Cal/OSHA had been providing advance notice of its “surprise” inspections to employers. When reports are received by state agencies about potential violations of the OSH Act that are putting employees at risk of harm, surprise inspections are conducted to assess compliance with safety and health regulations. If employers are provided with advance warning that they will be...
CISA & Partners Issue Guidance & Best Practices for Event Logging and Threat Detection
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), and their international partners have issued guidance on event logging and threat detection. HIPAA-regulated entities are required to implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information (ePHI) and to regularly review those logs to identify unauthorized activity. These include application logs of user activity in ePHI systems/applications, which capture information such as files opened, records accessed, and the creation, reading, editing, or deletion of records associated with ePHI, and system-level logs, which include successful and unsuccessful login attempts, devices used to log on, and the applications that were successfully or unsuccessfully accessed. The latest guidance from CISA and partners is aimed at medium to large organizations and includes...
Atlantic General Hospital Settles Data Breach Lawsuit for $2.25 Million
A $2.24 million settlement proposed by Atlantic General Hospital in Berlin, MD, to resolve a class action lawsuit stemming from a 2023 ransomware attack has received preliminary approval from the court. The nonprofit hospital, part of the Atlantic General Health System, discovered the ransomware attack on January 29, 2023, when files were encrypted. The attack caused disruption to patient services for several days due to the inability to access patient records and IT systems. The ransomware group had access to its network from January 20, 2023, to January 29, 2023. The initial findings of the investigation indicated around 30,400 individuals had been affected and notifications were issued on March 24, 2024; however, as the investigation progressed it became clear that more data was involved than previously thought, bringing the total affected up to 136,981. Data compromised in the attack included names, dates of birth, Social Security numbers, driver’s license numbers, health insurance information, medical histories, diagnosis and treatment information, and financial information....
Social Media in Healthcare
The use of social media in healthcare can be beneficial or risky depending on how it is used and how compliance with healthcare regulations is monitored. However, the compliant use of social media in healthcare does not necessarily guarantee benefits. Healthcare organizations should take this into account when developing a social media strategy. Before discussing the advantages and disadvantages of social media in healthcare, it is worth mentioning the effectiveness of social media for healthcare organizations. This is because there is some misinformation on the Internet about how social media can be a cost-effective marketing solution for the healthcare industry that builds a positive brand image and drives patient engagement. A reliable source of information about the effectiveness of social media is RivalIQ’s Annual Benchmark Report which breaks down social media effectiveness by industry and explains what works and what doesn’t. For the purposes of the Benchmark Report, the health industry is combined with the beauty industry – making the results appear much better than if the...
OCR: Don’t Neglect Physical Security Controls for ePHI
In its August 2024 cybersecurity newsletter, OCR reminded HIPAA-regulated entities that physical security measures such as facility access controls are essential for HIPAA Security Rule compliance, and should not be thought of as check-the-box items. Physical security measures are important and can prevent data breaches and disruption to patient care. The HIPAA Security Rule operationalizes the protections of the HIPAA Privacy Rule and establishes a set of standards for safeguarding electronic forms of protected health information (ePHI). HIPAA Security Rule compliance involves ensuring the confidentiality, integrity, and availability of ePHI, identifying and protecting against reasonably anticipated threats, protecting against reasonably anticipated uses and disclosures of ePHI, and ensuring compliance by the workforce. Over the past few years, the biggest threats to ePHI have come from cybercriminal groups and nation-state actors, who seek access to healthcare networks to steal ePHI and prevent access to ePHI and essential IT systems. While the majority of large data breaches are...



