Social Media in Healthcare
The use of social media in healthcare can be beneficial or risky depending on how it is used and how compliance with healthcare regulations is monitored. However, the compliant use of social media in healthcare does not necessarily guarantee benefits. Healthcare organizations should take this into account when developing a social media strategy. Before discussing the advantages and disadvantages of social media in healthcare, it is worth mentioning the effectiveness of social media for healthcare organizations. This is because there is some misinformation on the Internet about how social media can be a cost-effective marketing solution for the healthcare industry that builds a positive brand image and drives patient engagement. A reliable source of information about the effectiveness of social media is RivalIQ’s Annual Benchmark Report which breaks down social media effectiveness by industry and explains what works and what doesn’t. For the purposes of the Benchmark Report, the health industry is combined with the beauty industry – making the results appear much better than if the...
OCR: Don’t Neglect Physical Security Controls for ePHI
In its August 2024 cybersecurity newsletter, OCR reminded HIPAA-regulated entities that physical security measures such as facility access controls are essential for HIPAA Security Rule compliance, and should not be thought of as check-the-box items. Physical security measures are important and can prevent data breaches and disruption to patient care. The HIPAA Security Rule operationalizes the protections of the HIPAA Privacy Rule and establishes a set of standards for safeguarding electronic forms of protected health information (ePHI). HIPAA Security Rule compliance involves ensuring the confidentiality, integrity, and availability of ePHI, identifying and protecting against reasonably anticipated threats, protecting against reasonably anticipated uses and disclosures of ePHI, and ensuring compliance by the workforce. Over the past few years, the biggest threats to ePHI have come from cybercriminal groups and nation-state actors, who seek access to healthcare networks to steal ePHI and prevent access to ePHI and essential IT systems. While the majority of large data breaches are...
HHS-OIG: Washington Opioid Treatment Programs Not Fully Compliant with Federal and State Regulations
An audit conducted by the Department of Health and Human Services Office of Inspector General (HHS-OIG) of the opioid treatment programs (OTPs) in Washington state found that 96% of sampled OTPs failed to fully comply with federal and state requirements for providing and documenting opioid treatment services. Those failures potentially put Medicaid enrollees at risk of poor treatment outcomes, including relapses, overdoses, or deaths. OTPs include medication and counseling services for people diagnosed with opioid use disorder. There are federal and state requirements for OTPs, and noncompliance with those requirements can lead to poor patient outcomes. HHS-OIG conducted the audit to assess Washington state’s efforts to combat the opioid crisis and assessed a random sample of 100 enrollee-months at 22 OTPs between January 1, 2019, and July 31, 2020. Out of the sample of 100 enrollee-hours, 96 failed to meet federal and state requirements. If the sample was representative of all OTPs over that period, HHS-OIG estimated that 132,002 enrollee-months did not comply with federal and...
Humana Agrees to Settle Part D Whistleblower Lawsuit for $90 Million
Humana has agreed to settle a lawsuit filed by a whistleblower who accused the health insurer of submitting fraudulent bids to the HHS Centers for Medicare and Medicaid Services (CMS) for Part D contracts between 2011 and 2017. The Medicare Part D program provides prescription drug coverage for more than 54 million Medicare recipients to help them cover the cost of medications, lowering costs and protecting against higher costs. The U.S. government accepts bids from private health insurers to administer Part D benefits and those insurers must cover a minimum required amount of the drug costs. Annual bids are submitted to the CMS by insurers wishing to participate in the Part D program and they are required to report their proposed benefits and confirm that they meet the government’s minimum standards. In 2016, a whistleblower, Steven Scott, filed a lawsuit against Humana that alleged violations of the False Claims Act. Scott, a former actuary for Humana, alleged the health insurer was inflating costs to obtain a higher-paying contract and failed to provide the required level of...
Minnesota Dental Practices Report Email Breach Affecting 277K Patients
Major data breaches have been reported by Park Dental and Dental Specialists of Minnesota, which involved the protected health information of 277,109 individuals. Park Dental, which has dozens of dental clinics in Minneapolis, St. Paul, western Wisconsin, and the greater Minnesota area, reported a breach of the protected health information to the HHS’ Office for Civil Rights (OCR) on August 9, 2024, that affects 238,667 patients. A breach was also reported on the same day by Dental Specialists of Minnesota, which operates as The Dental Specialists, that affects 38,442 patients. Suspicious activity was identified in certain employee email accounts on January 23, 2024. The email accounts were secured, and third-party cybersecurity specialists were engaged to investigate and determine the extent of the breach. The investigation confirmed that multiple email accounts had been accessed by an unauthorized third party between January 11 and January 23, 2024, who may have viewed information in the accounts and related file shares. The review of the accounts was completed on June 10,...



