VA Employees Impermissibly Accessed Vice Presidential Candidates’ Medical Records
A criminal investigation is underway following the discovery of unauthorized access to the medical records of vice presidential candidates Sen. JD Vance (R-OH) and Minnesota Governor Tim Walz by employees of the Department of Veteran Affairs (VA). Both vice presidential candidates have served in the military. JD Vance served in the Marine Corps for four years and Governor Walz served in the Army National Guard for 24 years. According to the Washington Post, at least a dozen VA employees accessed the medical records of the vice presidential candidates without authorization in July and August 2024, in violation of the Health Insurance Portability and Accountability Act’s Privacy Rule. The unauthorized access was reportedly discovered by the VA during a routine review of the medical record access logs for high-profile individuals. The campaign teams of both vice presidential candidates have been notified about the unauthorized access and the VA has referred the matter to federal prosecutors. Following the discovery of potential unauthorized access, VA Secretary Denis McDonough sent a...
HHS-OIG: Delayed Background Checks at Gallup Indian Medical Center Put Children at Risk
An audit of the Gallup Indian Medical Center has revealed that the failure to conduct timely and complete background checks on staff members put Indian children at risk of harm and abuse. The Indian Child Protection and Family Violence Act (ICPFVPA) requires federal background checks to be conducted on individuals in contact with Indian children, and for staff members to be supervised pending the completion of background checks. The Department of Health and Human Services Office of Inspector General (HHS-OIG) conducted an audit of the Gallup, New Mexico, Indian Health Service (HIS)-operated health facility to assess compliance with the background check requirements after prior work by HHS-OIG identified noncompliance in that area. Gallup Indian Medical Center is one of four hospitals operated by the IHS through its Navajo Area Office. It has the largest staff and one of the largest workloads of the four hospitals, with 250,000 outpatient encounters and 5,800 admissions a year. HHS-OIG reviewed background investigation documentation for staff members in contact with Indian children...
What Does HIPAA Mean?
HIPAA stands for the Health Insurance Portability and Accountability Act – an Act passed by Congress in 1996 with the primary objectives of reforming the health insurance industry, enabling health insurance portability between jobs, and prohibiting practices that denied or limited access to health care benefits for employees with pre-existing conditions. However, the measures Congress introduced to achieve these objectives incurred costs for the health insurance industry. To avoid insurance companies passing on the costs to employers and group plan members in the form of higher premiums, Congress introduced further measures to tackle health insurance fraud and improve the efficiency of the health insurance industry. The measures to improve the efficiency of the health insurance industry evolved into the Administrative Simplification Regulations (45 CFR Parts 160, 162, and 164). These regulations: Standardize health claims transactions, code sets, and identifiers (the Administrative Requirements), Protect the privacy of individually identifiable health information (the Privacy...
Healthcare Ransomware Attacks Continue to Increase in Number and Severity
Ransomware attacks continue to increase in healthcare despite a fall in attacks in many other sectors, according to the State of Ransomware in Healthcare 2024 report from Sophos. Across all industry sectors, the number of organizations that reported suffering a ransomware attack in the past 12 months fell from 66% in 2023 to 59% in 2024. Sophos surveyed 402 healthcare organizations, and 67% said they had experienced a ransomware attack in the past 12 months, up from 60% the previous year, and on a par with the 66% that experienced ransomware attacks in 2022. Globally, healthcare has the second-highest attack rate, behind central/federal government with a 68% attack rate. Attacks on healthcare were among the most impactful, with an average of 58% of healthcare organizations’ devices affected by a ransomware attack. In 5% of attacks, 20% of fewer devices were impacted and 7% of attacks saw more than 91% of devices affected. Sophos says the reason that so many devices are affected in healthcare is because of the widespread use of legacy technology and infrastructure controls than in...
Updated NIST Password Guidelines Replace Complexity with Password Length
The National Institute of Standards and Technology (NIST) has updated its password security guidelines and now recommends longer passwords rather than enforcing a combination of at least 1 uppercase and lowercase letter, number, and special character. Combining multiple character types in a password increases the complexity and makes it harder to crack passwords; however, the problem with forcing people to use uppercase and lowercase letters, numbers, and special characters in passwords is that in practice, it leads to predictable patterns that weaken password security. Those predictable patterns occur because people need to be able to remember passwords, and remembering a truly random string of numbers and characters is difficult, especially when a unique password should be set for each account. Unless a random password generator is used and passwords are stored in a password manager, people will take shortcuts when creating passwords that will inevitably lead to weak passwords being set. The latest draft version of NIST’s password guidelines eliminates the password requirements...



