What is Incident Reporting in Healthcare?
The term incident reporting in healthcare refers to the processes developed to report or escalate an incident that affects patients, members of the workforce, and/or the organization at which the incident occurs. Effective incident reporting in healthcare can enhance patient safety, workplace safety, and regulatory compliance, and provide insights into how to mitigate the likelihood of future incidents. There are many types of “incidents” that can occur in healthcare. For example, patients can suffer adverse events due to medication errors, members of the workforce can be injured due to slips, trips, or falls, and organizations can experience cyberattacks that affect their ability to function effectively. When these incidents occur, the processes developed to report or escalate incidents can determine how quickly they are resolved and what the consequences are. What is an Incident Report in Healthcare? In its simplest form, an incident report in healthcare is a report of an error, accident, or other event that occurred in a healthcare facility. Non-emergency reports are usually...
What are the HIPAA Technical Safeguards?
The HIPAA Technical Safeguards consist of five Security Rule standards that are designed to protect ePHI and control who has access to it. All covered entities and business associates are required to comply with the five standards or adopt equally effective measures. However, evidence suggests many covered entities and business associates fail to comply with the HIPAA Technical Safeguards. Despite advances in technology over the past twenty years, the HIPAA Technical Safeguards (45 CFR §164.312) have remained unchanged since their publication in February 2003. This is not due to lax rulemaking by the Department of Health & Human Services (HHS), but rather testament to the work that went into fine-tuning the standards between the publication of the Proposed Security Rule in 1998 and the publication of the Final Security Rule five years later. Consequently, it can be beneficial to go back to the Federal Register entry for the Final Security Rule in order to review the analyses published alongside the standards and implementation specifications. This can help covered entities and...
Thousands of Medical Devices and Data Systems Exposed Over the Public Internet
Censys, a provider of an Internet intelligence platform for threat hunting and attack surface management, has identified thousands of IP addresses that expose medical devices and systems over the Internet, almost half of which (49%) are located in the United States. Censys security researcher Himaja Motheram explained that the research was focused on identifying publicly accessible interfaces and services from the perspective of an external threat actor looking to conduct an attack on a healthcare organization or gain access to healthcare data. The company identified 14,004 unique IPs that publicly exposed healthcare-related devices and applications on the Internet but suggests that their research likely only captured a portion of exposed devices, with many other systems likely exposed but not openly accessible. The findings of the study have been published in the Censys 2024 Global State of Internet of Healthcare Things (IoHT) Exposures on Public-Facing Networks report. The most commonly exposed medical assets were DICOM servers (5,100), which are used for viewing and transferring...
East River Medical Imaging $1.85 Million Settlement Due to Receive Final Approval
A $1.85 million settlement to resolve a class action data breach lawsuit against the New York radiology group, East River Medical Imaging, is due to receive final approval on October 22, 2024. Individuals affected by the breach have until October 22, 2024, 2:30 PM EDT to submit a claim. A security breach was detected by East River Medical Imaging on September 20, 2023. A hacker was determined to have accessed its systems from August 31, 2023, to September 20, 2023, and during that time files were copied from its network. Patient and employee information was compromised including names, contact information, insurance information, exam and/or procedure information, referring physician names, imaging results, financial account information, driver’s license numbers, and Social Security numbers. Notification letters were sent to the affected individuals starting November 22, 2023, and the breach was reported to the HHS’ Office for Civil Rights on November 22, 2024, as affecting 605,809 individuals. The first lawsuit over the data breach was filed by the law firm Shub & Johns...
OCR Announces 50th HIPAA Right of Access Penalty
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 9th financial penalty of the year to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) Rules. A civil monetary penalty of $70,000 has been imposed on the Silver Spring, MD, dental practice Gums Dental Care for failing to provide a patient with timely access to her and her children’s medical records. This is the 50th HIPAA Right of Access enforcement action to result in a financial penalty since OCR launched its HIPAA Right of Access enforcement initiative in the fall of 2019. The complainant sent a written request to Gums Dental Care on or around April 8, 2019, requesting copies of her protected health Information (PHI) and the PHI of her children. She requested the records be sent to her electronically via email and received a reply the same day confirming how many times each of them had visited the dental practice but was not provided with the requested records. She filed a complaint with OCR on May 1, 2019, after no records had...



