Lurie Children’s Hospital Sued Over January 2024 Ransomware Attack
A class action lawsuit has been filed against Ann & Robert H. Lurie Children’s Hospital in Chicago in response to a January 2024 ransomware attack and data breach that exposed the protected health information of 775,860 patients. The cyberattack was detected on January 31, 2024, and the forensic investigation confirmed that hackers had access to the network from January 26, 2024. The data exposed and potentially stolen included names addresses, telephone numbers, email addresses, dates of birth, dates of service, driver’s license numbers, health claims information, health plan beneficiary numbers, medical conditions/diagnoses, medical record numbers, treatment information prescription information, and Social Security numbers. The Rhysida ransomware group claimed responsibility for the attack and claimed to have sold the stolen data. The attack took its electronic health record system offline for months and the investigation and document review were not completed until the summer. Individual notifications were sent to the affected individuals on June 17, 2024. Complimentary...
Risks of HIPAA Compliance Failures with Email
There are many ways that the HIPAA Rules can be violated via email, from simple errors involving protected health information being emailed to incorrect individuals to email security failures that allow hackers to obtain email credentials and gain access to huge amounts of sensitive patient data. Email is relied upon by HIPAA-covered entities but there is considerable potential for HIPAA violations with email. Some of the most common email risks that can result in HIPAA violations are discussed below. Using an Email Vendor That is Not HIPAA-Compliant If ePHI is sent via email, then the email service provider is classed as a business associate and must enter into a business associate agreement (BAA) with a HIPAA-regulated entity. It is not possible to obtain a BAA for a free email service such as Google (Gmail), Yahoo, Hotmail, or AOL. Using a free email service is a HIPAA violation not only due to the lack of a BAA but also because these email services do not generally have sufficiently robust security. Even when HIPAA-compliant email services are used, the email service may not be...
$3.4M Settlement Resolves Claims Against Nationwide Vision/Sightcare Over 2021 Data Breach
A $3.45 million settlement has been settlement has been proposed to resolve a consolidated class action lawsuit over a 2021 data breach at a U.S. Vision subsidiary that affected more than 710,000 individuals, including 637,999 Sightcare members and 73,073 Nationwide Optometry patients. U.S. Vision is a HIPAA business associate that provides administrative services to Nationwide Optometry, Nationwide Vision Center, and Sightcare (Nationwide-Sightcare). On May 12, 2021, suspicious activity was detected within the network of U.S. Vision subsidiary, USV Optical. The investigation confirmed that hackers had access to its email systems and computer network for a month between April 20, 2021, and May 17, 2021, and potentially obtained full names, dates of birth, addresses, Social Security numbers, taxpayer identification numbers, driver’s license numbers, financial account information, medical and/or treatment information, prescription medications, health insurance information, and billing and claims information. Three class action lawsuits were consolidated into a single lawsuit –...
ONC Proposes Rule to Improve Patient Engagement, Information Sharing, and Interoperability
The U.S. Department of Health and Human Services (HHS) Office of the National Coordinator for Health Information Technology (ONC) has published a proposed rule that seeks to improve patient engagement, information sharing, and public health interoperability. The Health Data, Technology, and Interoperability: Patient Engagement, Information Sharing, and Public Health Interoperability (HTI-2) proposed rule implements provisions of the 21st Century Cures Act and aligns with ONC’s goals of advancing interoperability and improving information sharing among patients, providers, payers, and public health authorities. The key proposals in the rule are: The establishment of two sets of new certification criteria that enable health IT for public health and health IT for payers to be certified under the ONC Health IT Certification Program to advance interoperability and support public health reporting and exchange Adoption of United States Core Data for Interoperability (USCDI) version 4 by January 1, 2028. Adjustments to certain exceptions to the information blocking regulations, including a...
Northern Arizona VA Healthcare System Failed to Protect Workers from Patient Violence
A VA medical center in Prescott, AZ, has failed to protect its workers from serious and potentially deadly patient violence. This is the second time that the Occupational Safety and Health Administration (OSHA) has cited the VA medical center for exposing its staff to violence in the past 4 years. The latest OHSA investigation of the Northern Arizona VA Healthcare System’s Bob Stump VA Medical Center was initiated in December 2023 in response to claims that nurses, nursing assistants, and housekeeping staff had been bitten, kicked, struck, punched, slapped, and sexually harassed by unit residents. OSHA’s investigation found the Bob Stump VA Medical Center had failed to protect healthcare workers from violence from unit residents, similar to the findings of a previous investigation in 2019. Executive Order 12196 requires federal agencies to comply with the same safety and health standards as private-sector employers. They must provide safe working conditions and address potential hazards. In contrast to private sector employers, federal agencies are generally exempt from...



