Texas Doctor Sues HHS to Prevent Enforcement of Reproductive Health Care Privacy Rule
A lawsuit has been filed against the Department of Health and Human Services (HHS), HHS Secretary Xavier Becerra, the Office for Civil Rights (OCR), and OCR Director Melanie Fontes Rainer over the recent update to the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule to strengthen reproductive health care privacy. The HIPAA Privacy Rule to Support Reproductive Health Care Privacy Final Rule was published in the Federal Register on April 26, 2024, took effect on June 25, 2024, and the compliance date is December 23, 2024. The new rule was introduced to strengthen privacy protections for reproductive healthcare information and prevent HIPAA-regulated entities from disclosing reproductive health care information to law enforcement when that information is sought to investigate or impose liability on individuals or healthcare providers for seeking, obtaining, or providing legal reproductive health care. The lawsuit was filed by attorneys from Alliance Defending Freedom in the United States District Court for the Northern District of Texas, Amarillo Division,...
September 2024 Healthcare Data Breach Report
Apart from a blip in August, the number of healthcare data breaches reported each month has fallen from an annual high of 97 breaches in March 2024. September saw the lowest number of healthcare data breaches since May 2020, with just 34 data breaches of 500 or more records reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR). In the first half of the year it was looking like another new record would be set for healthcare data breaches, but as the year draws to an end, 2024 is now looking like it will be a rare year where the number of healthcare data breaches reduces year-over-year. So far in 2024, 531 data breaches of 500 or more records have been reported to OCR. In the first half of 2024, data breaches were reported at a rate of 67 a month. In the second half of 2024, data breaches have been reported at a rate of 44 a month. Across the 34 reported data breaches, the records of 4,839,018 individuals were exposed or impermissibly disclosed – The third lowest monthly total of the year to date, and well below the average of 7,082,007 records...
Great Expressions Dental Centers Settle Data Breach Lawsuit for $2.7 Million
Great Expressions Dental Centers has agreed to settle a class action lawsuit stemming from a 2023 data breach involving the personal and protected health information of 1,925,397 individuals. Great Expressions Dental Centers, a Bloomfield Hills, MI-based chain of 246 dental practices in 9 U.S. states, experienced a cyberattack in February 2023 that disrupted its IT systems. The hackers had access to its systems for 6 days between February 17 and February 22, 2024, during which time files containing patient data were exfiltrated from its systems. Those files contained information such as names, birth dates, contact information, Social Security numbers, driver’s license numbers, financial account information, credit/debit card numbers, billing records, health insurance information, prescription information, diagnoses, treatment information, x-ray images, and medical and dental histories. Individual notification letters were mailed to the affected individuals in early May 2023. Several lawsuits were filed in response to the data breach that were consolidated into a single action in...
BianLian Threat Group Claims Responsibility for Cyberattack on Boston Children’s Health Physicians
Boston Children’s Health Physicians (BCHP), a Valhalla, NY-based multi-specialty pediatric group serving newborns and children in New York and Connecticut, has confirmed that its IT vendor (ATSG Inc.) fell victim to a cyberattack. The IT vendor notified BCHP on September 6, 2024, that unusual activity had been identified in the IT vendor’s systems. On September 10, 2024, BCHP identified unauthorized activity within its own network and immediately implemented its incident response protocols, which included shutting down systems as a protective measure. Assisted by a third-party digital forensics firm, BCHP learned that on September 10, 2024, an unauthorized third party gained access to certain parts of its network and exfiltrated files that included information related to current and former employees, patients, and guarantors. BCHP has posted a substitute breach notice on its website that confirmed that the information in those files may have included names, Social Security numbers, addresses, dates of birth, driver’s license numbers, medical record numbers, health insurance...
OCR Issues Guidance on Ransomware Prevention and Response
The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) has published a video presentation offering guidance to HIPAA-regulated entities on ransomware prevention and compliance with the HIPAA Security Rule. The video presentation was released in recognition of National Cybersecurity Awareness Month to improve awareness of the threat of ransomware and educate HIPAA-regulated entities on how compliance with the HIPAA Security Rule can help prevent ransomware attacks and limit their impact. OCR investigates all large data breaches (500 or more records) to determine if noncompliance with the HIPAA Rules led to or contributed to the attack. These investigations have allowed OCR to identify ransomware trends, which Nick Heesters, OCR’s senior advisor for cybersecurity, explains in the video presentation. Ransomware attacks on HIPAA-regulated entities increased by 102% between 2019 and 2023 and large numbers of attacks have already been reported this year. It is clear that ransomware is one of the biggest threats to health information privacy. OCR is currently...



