Democratic Senators Propose Mandatory Cybersecurity Standards in Healthcare and Greater Accountability
Two Democratic senators have announced new legislation to update XI and XVIII of the Social Security Act to strengthen, increase oversight of, and compliance with security standards for health information. The proposed legislation will address healthcare infrastructure cybersecurity and ensure that serious financial penalties are imposed for compliance failures. The legislation – The Health Infrastructure Security and Accountability Act – was introduced by Senate Finance Committee Chair Ron Wyden (D-OR) and Senator Mark Warner (D-VA) and seeks to introduce minimum standards for cybersecurity to make it harder for cybercriminals to breach healthcare networks. Currently, the HHS’ Office for Civil Rights Breach Portal shows 394 large data breaches have been reported in 2024 that are attributed to hacking/IT incidents, and those breaches have affected more than 43 million individuals. In 2023, 602 data breaches were reported as hacking/IT incidents involving the healthcare records of more than 151 million individuals. These cyberattacks have delayed and disrupted patient care,...
Cascade Eye and Skin Centers Settles Alleged HIPAA Violations for $250,000
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has settled alleged HIPAA violations with the Washington healthcare provider Cascade Eye and Skin Centers, P.C. for $250,000. OCR launched an investigation of the privately-owned Washington healthcare provider after learning on May 26, 2017, that patient data had been exposed in a March 2017 ransomware attack. According to OCR, the ransomware group had access to a network server where 291,000 files containing patients’ protected health information were stored. The investigation uncovered one of the most common HIPAA compliance failures – the lack of a comprehensive, accurate, organization-wide risk analysis to identify potential risks and vulnerabilities to electronic protected health information (ePHI), as required by 45 C.F.R. § 164.308(a)(1)(ii)(A). OCR also determined there were insufficient reviews of activity in information systems that contained ePHI., as required by 45 C.F.R. § 164.308(a)(l)(ii)(D). Cascade Eye and Skin Centers was given the opportunity to settle the alleged HIPAA violations and...
2024 National Cybersecurity Awareness Month
October is National Cybersecurity Awareness Month – a month-long effort to raise awareness of the importance of cybersecurity and highlight security best practices. National Cybersecurity Awareness Month is led by the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance and this year’s theme is “Secure Our World.” The focus this year is to engage everyone in combating cyber threats by changing behaviors and creating healthy cyber habits. To help “Secure Our World,” there are four easy steps that everyone can take to stay safe online, protect their personal data, and make it harder for cybercriminals to succeed in their attacks. Recognize and Report Phishing Be constantly alert to potential threats such as unsolicited messages, requests for personal information, or credentials with unknown sources, and report suspicious messages immediately. Use Strong Passwords and a Password Manager Ensure that accounts are protected with strong passwords, including upper and lower case letters, numbers, and symbols, and...
Healthcare Most Targeted Industry in Mobile Phishing Campaigns
There has been an alarming increase in phishing attacks targeting enterprise mobile devices, according to the mobile security vendor Zimperium. Mobile phishing (missing) attacks target vulnerabilities in mobile devices, and cybercriminals are increasingly adopting a mobile-first strategy in their phishing campaigns. Targeting mobile devices makes sense, as nearly 67% of employees use personal devices for work, regardless of whether their company has a formal bring-your-own-device policy, and mobile devices often lack the security protections of desktops and laptops – 70% of businesses fail to adequately secure personal devices used for work purposes, according to Zimperium. Further, 71% of employees admitted to engaging in risky activities on their mobile devices. Risky practices include sideloading apps – downloading apps from unofficial stores – Zimperium reports that 1 in 4 Android devices face that issue. Users who download apps from unofficial stores are 200 times as likely to encounter malware. In 8.3% of malware detections on mobile devices, the infection was...
HHS-OIG Identifies Need for Increased Oversight of Remote Patient Monitoring
Remote patient monitoring allows patients to collect their own health data via connected medical devices that automatically transmit the data to their healthcare provider. Remote patient monitoring is broadly covered by Medicare for both chronic and acute conditions and can be incredibly useful in managing patients’ conditions. The use of remote patient monitoring in Medicare has increased dramatically in recent years. Between 2019 and 2022, the number of Medicare recipients receiving remote patient monitoring increased 10-fold, and billing for remote patient monitoring increased 20-fold. Both the HHS Office of Inspector General (HHS-OIG) and the Centers for Medicare and Medicaid Services (CMS) have voiced concerns about fraud related to remote patient monitoring. In 2023, OIG issued a consumer alert about unscrupulous companies contacting Medicare enrollees to sign them up for remote patient monitoring when there was no medical need for remote monitoring. While the patient is signed up and the company bills Medicare for providing the service, the monitoring never happens. Remote...



