What is a HIPAA Email Disclaimer?
A HIPAA email disclaimer is a section of text located at the end of an email that informs recipients that the email includes Protected Health Information (PHI) and advises them what to do if they receive the email in error. There are circumstances in which the addition of a disclaimer can be beneficial, but it does not absolve the sender of a HIPAA violation. Around 8% of all data breaches notified to HHS’ Office for Civil Rights each year are attributable to misdeliveries. It is not known how many are misdeliveries through the mail and how many are misdeliveries by email, but it is known that in 2022 (the most recent year for which data are available) HHS’ Office for Civil Rights received 64,592 data breach notifications. An equal split of mail/email misdeliveries implies around 2,600 data breach events each year are attributable to emails being sent to the wrong recipients. To clarify, this does not mean 2,600 recipients received emails containing other people’s PHI. Some bulk misdeliveries of email can impact tens of thousands of patients or – in this case – plan members. What...
LivaNova Facing Multiple Class Action Lawsuits Over October 2023 Cyberattack
The Houston, TX-based medical device company, LivaNova, is facing multiple class action lawsuits over an October 2023 cyberattack that exposed the protected health information of 180,000 patients. The attack was detected on November 19, 2023, and the investigation confirmed that unauthorized individuals first accessed its network on October 26, 2023. The data compromised in the incident included names, addresses, phone numbers, Social Security numbers, birth dates, diagnoses, treatment information, prescriptions, physician names, medical record numbers, device serial numbers, and health insurance information. Notifications were issued in May 2024, and complimentary credit monitoring services were offered to the affected individuals. At least two lawsuits have now been filed by patients whose information was exposed in the incident. One of those lawsuits was filed in the U.S. District Court for the Southern District of Texas, Houston Division, on behalf of J.W., by and through her guardian, Angela Johnson. The lawsuit alleges LivaNova maintained sensitive information in a reckless...
SouthCoast Health; Call 4 Health Notify Patients About Cyberattacks
SouthCoast Health and Privia Medical Group in Georgia have notified patients about a cyberattack and HIPAA compliance data breach that occurred in June 2023. Unauthorized activity was identified in South Coast Health’s network on June 18, 2023, and assisted by forensic specialists, it was determined that its network was accessed by an unauthorized third party between June 15 and June 18, 2023. During that time, files on the network were viewed or copied. South Coast Health confirmed that the intrusion was limited to its own network, with Privia Medical Group’s network unaffected; however, some Privia Medical Group patients did have their information exposed. The substitute breach notice provided to the South Carolina Attorney General does not list the types of data compromised in the attack, but that information is detailed in the individual notifications. A substitute notice was posted on its website last year warning patients that they may have been affected, but at the time it was unclear how many patients had been affected or the types of data involved. The review of the...
Patient Data Compromised in Palomar Health Medical Group Cyberattack
Palomar Health Medical Group has warned patients that they may have been affected by an April 2024 cyberattack, and DaVita has learned that tracking tools on its website and mobile app may have sent user data to third-party vendors. Palomar Health Medical Group Announces April 2024 Cyberattack Palomar Health Medical Group, a provider of primary and specialty care to communities in North San Diego County, has informed patients about a recent cyberattack that exposed some of their protected health information. A security breach was detected on or around May 5, 2024, and immediate action was taken to prevent further unauthorized access to its systems. An investigation was launched to determine the nature and scope of the incident, which confirmed that hackers had access to its network from April 23, 2024, to May 5, 2024. Palomar Health Medical Group said the attack “may have caused certain files to files to become unrecoverable,” which suggests that ransomware was used. Palomar Health Medical Group has confirmed that certain files were exfiltrated from its network and the review of...
Pennsylvania’s Updated Breach Notification Law Requires Credit Monitoring Services for Breach Victims
Pennsylvania has updated its data breach notification law, narrowing the definition of personal information, adding the requirement to notify the state Attorney General, and requiring credit monitoring services to be provided to data breach victims in certain circumstances. The Breach of Personal Information Notification Act was amended by Senate Bill 824 and was signed into law by state Governor Josh Shapiro on June 28, 2024. The amended law takes effect on September 26, 2024. The law requires organizations that maintain computerized data that includes personal information to issue notifications to the affected individuals in the event of a breach of their unencrypted and unredacted personal information, or if personal information is reasonably believed to have been accessed or obtained by an unauthorized individual. Notifications must be sent without unreasonable delay, but there is no fixed time frame for issuing those notifications unless the breach occurs at a Pennsylvania state agency or state agency contractor, in which case the notifications must be issued within 7 days of...



