H1, 2024 Healthcare Data Breach Report
Several major healthcare cyberattacks have been reported in the first half of 2024, including a ransomware attack on Ascension that took its electronic medical record system out of action for a month and a ransomware attack on Change Healthcare that caused massive disruption for providers across the country due to the unavailability of Change Healthcare’s platform. The amount of data stolen in the Change Healthcare attack is eye-watering, potentially the protected health information of 1 in 3 Americans – More than 110 million individuals. While these two data breaches could both be massive, at the time of publication, the scale of these data breaches has still not been confirmed. The Ascension data breach was reported to the HHS’ Office for Civil Rights (OCR) in July 2024 and only with a placeholder of 500 individuals due to the ongoing investigation, and while Change Healthcare has started sending notification letters, the breach has yet to be reported to OCR. About Our H1, 2024 Healthcare Data Breach Report The data on which our H1, 2024 Healthcare Data Breach Report is based...
What is PCI Compliance in Healthcare?
PCI compliance in healthcare means securing payment account data in compliance with the Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 when payment account data are maintained separately from Protected Health Information. The failure to comply with PCI DSS can result in the loss of merchant accounts, fines, and civil actions. The PCI DSS (Payment Card Industry Data Security Standard) is an information security standard designed to reduce payment card fraud by increasing security controls around cardholder data and sensitive authentication data. All organizations that process, store, and transmit payment account date are required to comply with PCI DSS unless a federal, state, or industry standard provides greater protection to payment account data than PCI DSS. In the healthcare industry, the HIPAA Administrative Simplification Regulations (“HIPAA”) protect the privacy and security of individually identifiable health information. Any non-health information stored in a designated record set with individually identifiable health information assumes the same protections...
HHS Restructures to Consolidate Technology, Cybersecurity, Data, AI, and HealthIT
The Department of Health and Human Services (HHS) has announced a major restructuring that will allow the department to streamline its operations and more effectively prioritize the use of digital and emerging capabilities such as artificial intelligence. Work related to technology, cybersecurity, and data has historically been distributed across three HHS departments: The Office of the National Coordinator for Health Information Technology (ONC), the Assistant Secretary for Administration (ASA), and the Administration for Strategic Preparedness and Response (ASPR). Opportunities in these areas have grown considerably in recent years, and now is the time to streamline operations and have all tech-centric work handled by a single HHS organization. The ONC will be renamed the Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC), which will be tasked with oversight of technology, data, and artificial intelligence policy and strategy, taking over these oversight roles from the ASA. ASTP/ONC will also be tasked...
Aveanna Healthcare Announces Breach of 11 Employee Email Accounts
The Georgia-based healthcare provider, Aveanna Healthcare, has recently announced that the email accounts of 11 employees have been accessed by an unauthorized third party, who gained access to the protected health information of 10,482 patients. This is the second email breach to be reported by Aveanna Healthcare in recent months. On March 15, 2024, Aveanna Healthcare reported an email breach to the HHS’ Office for Civil Rights that involved the protected health information of 65,482 patients. That incident involved unauthorized access to an employee email account on or around September 22, 2023. The latest breach was detected around a month after OCR was notified about the previous email breach. According to Aveanna Healthcare’s substitute breach notice, unusual activity was detected in the email accounts on April 17, 2024. Immediate action was taken to prevent further unauthorized access to the accounts and an investigation was launched to determine the nature and scope of the breach. On June 12, 2024, it was confirmed that protected health information was present in the...
HealthEquity Confirms Breach Involved PII of 4.3 Million Individuals
In early July, the HIPAA Journal reported on a data breach at the Draper, UT-based financial technology and business services company, HealthEquity. HealthEquity had disclosed in an 8-K filing with the Securities and Exchange Commission (SEC) that it had identified suspicious activity in the device of a business partner. The initial findings of the investigation indicated unauthorized access to the device and member information. HealthEquity has recently notified the Maine Attorney General about the incident and has confirmed that the personal identifying information (PII) of 4,300,000 individuals was exposed and potentially stolen, including the personal information of 13,480 Maine residents. HealthEquity, the parent company of WageWorks Inc. and Further Operations LLC, provides health savings account (HSA) services and other consumer-directed benefits solutions, including health reimbursement arrangements (HRAs). The company manages millions of HSAs, HRAs, and other benefit accounts. In the notification, HealthEquity explains that it was notified about a systems anomaly on March...



