More Than 50% of Healthcare Employees Fail a HIPAA Assessment, New Data Reveals
Businesses in the healthcare sector have a responsibility to minimise the risks of HIPAA violations, for the sake of their patients, staff and the organization as a whole. One way in which organizations can mitigate internal breaches is by ensuring that staff receive regular HIPAA training. However the number of internal breaches recorded each year would suggest that more needs to be done to ensure employees are HIPAA compliant. To investigate the standards of HIPAA training in the healthcare sector, The HIPAA Journal researchers have examined HIPAA assessment fail rates, the percentage of staff who have witnessed HIPAA violations, and how frequently training is being conducted in 2023. How many employees working with PHI fail a HIPAA assessment? More than half of employees working in the healthcare sector fail a HIPAA assessment. The data suggests that more than 50% of staff working with PHI do not have a comprehensive understanding of HIPAA regulations, and therefore require more training. Which area of HIPAA training sees the highest fail rates? During a HIPAA assessment in...
HIPAA Compliant Remote Access Software
HIPAA compliant remote access software provides HIPAA-covered entities and their busines associates with a secure way of remotely accessing systems containing electronic protected health information (ePHI) and simplifies the management of remote access. Healthcare organizations can have dozens of vendors who require remote access to servers, applications, and healthcare data, and oftentimes several different methods are used to provide access to vendors. Without a single solution, management of remote access is time consuming, complex, and difficult to carefully control. Healthcare employees also need remote access to applications, files, and ePHI and remote access has become even more important in the COVID-19 era. To reduce the risk of infection and help control the spread of COVID-19, there has been a major expansion of telehealth services. Healthcare professionals are now conducting more visits virtually and need to remotely access applications, EHRs, and files to provide those telehealth services. Windows Remote Desktop Protocol can be used for remote access, but RDP is not...
Healthcare Data Breaches Reported in New York, Florida, & Arkansas
Data breaches have recently been reported by Advanced Recovery Equipment & Supplies in New York, We Level Up Treatment in Florida, and Arkansas Blue Cross and Blue Shield. Advanced Recovery Equipment & Supplies, New York Advanced Recovery Equipment & Supplies, a New York-based supplier of medical recovery products, has identified a breach of its network and the theft of files containing customer data. The forensic investigation confirmed that an unauthorized third party accessed its network between June 27, 2023, and July 28, 2023, and removed files from the network. Assisted by third-party specialists, Advanced Recovery Equipment & Supplies conducted a comprehensive review of the affected files, which concluded on September 29, 2024. The files exfiltrated from its network included the protected health information of 56,000 individuals. Data compromised in the incident included names along with one or more of the following: Social Security number, date of birth, driver’s license number/state identification number, credit or debit card information, username and...
Email Incidents Reported by Survival Flight and Jacksonville Children’s Multispecialty Clinics
Survival Flight, Inc., an emergency medical transportation company with bases in Alabama, Arkansas, Florida, Georgia, Illinois, Missouri, Oklahoma, and Tennessee, has identified a breach of its email environment. Suspicious activity was detected within its email system on May 22, 2024. Third-party digital forensics specialists were engaged to investigate the breach and confirmed there had been unauthorized access to several employee email accounts. The affected accounts were reviewed, and it was confirmed on August 19, 2024, that they contained sensitive patient information including names, medical histories, treatment information, health insurance information Social Security numbers, and financial information. The breach was recently reported to the HHS’ Office for Civil Rights as affecting 12,342 individuals. While the accounts were subjected to unauthorized access, no evidence has been found to indicate any misuse of patient data; however, the affected individuals have been advised to monitor their accounts and explanation of benefits statements for suspicious activity....
Henry Schein Confirms 166,000 Individuals Affected By October 2023 Ransomware Attack
Henry Schein, a Melville, NY-based provider of medical and dental supplies and Fortune 500 firm, has continued to investigate a 2023 cyberattack that affected its manufacturing and distribution businesses. The cyber incident was a ransomware attack where files were restored only for them to be encrypted by the ransomware group a second time. Initially, the investigation identified 29,112 individuals who had their data compromised in the attack, and notification letters started to be mailed to those individuals in November 2023. Since then, Henry Schein has been working with an outside expert to review the affected files – a process that has taken a considerable amount of time and resources and continued throughout the first half of the year. In an updated breach notification to the Maine Attorney General, Henry Schein confirmed that 166,432 individuals are now known to have been affected and had their personal and protected health information exposed or stolen. The additional individuals are now being notified and have been offered complimentary credit monitoring and identity...



