Court Rules New York Ophthalmologist Violated OSH Act by Retaliating Against Employee for Reporting COVID-19 Safety Concerns
A federal court has found an upstate New York ophthalmologist violated the whistleblower protections of the Occupational Safety and Health (OSH) Act by retaliating against an employee who reported the lack of protections against COVID-19 to the New York State Department of Health (NYSDOH). When the COVID-19 pandemic was raging between March 2020 and December 2020, an employee of Kwiat Eye and Laser Surgery complained on multiple occasions to her supervisor that the practice was not following New York State-mandated health and safety protocols, which included mask-wearing, social distancing, and enhanced hygiene protocols. By December 2020, the state had recorded more than 30,000 deaths related to COVID-19. When the practice refused to update its working practices, the employee filed two complaints with the NYSDOH, one in December 2020 and a second in January 2021. NYSDOH contacted the practice on February 24, 2021, regarding the complaints, and later that morning, practice owner Dr. David Kwiat confronted the employee and fired her on the spot, stating the termination was for...
Medicare Improperly Billed $96 Million for Mechanical Ventilation
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has found that hospitals have been improperly billing Medicare for enrollees who received mechanical ventilation, resulting in Medicare improperly paying out an estimated $79.4 million. HHS-OIG conducted the audit to determine whether Medicare payments to hospitals for inpatient claims for patients with certain Medicare Severity Diagnosis-Related Groups (MS-DRGs) that required more than 96 hours of mechanical ventilation complied with Medicare requirements. Previous OIG audits suggest that hospitals were not complying with Medicare requirements. Inpatient claims include the date that mechanical ventilation commenced, but do not include an end date. The Centers for Medicare and Medicaid Services (CMS) implemented an automated system to identify claims where the start date for ventilation was 4 days or fewer before the discharge date. This audit was conducted on 83,359 inpatient claims between October 2015 and September 2021 that were assigned MS-DRGs 207 or 870 which also included a mechanical...
Two Texas Women File EMTALA Complaints with HHS Over Denial of Emergency Abortion Care
Two complaints have been filed with the Department of Health and Human Services (HHS) alleging regulatory noncompliance at two Texas hospitals. The complainants allege the hospitals violated the federal Emergency Medical Treatment and Labor Act (EMTALA) by failing to provide emergency abortion care to two pregnant women when they presented to the hospital’s emergency departments with a life-threatening condition. EMTALA is a federal law that requires hospitals to provide stabilizing care to patients with emergency medical conditions, regardless of their ability to pay. Patients who present to a hospital emergency department must undergo an appropriate medical screening examination by a physician or qualified medical person to determine whether they have an emergency medical condition, and if they do, stabilizing care must be provided. The patient cannot be refused that care unless providing that care is beyond the capabilities of the facility, in which case, an appropriate transfer is permitted to a facility that has adequate capabilities. EMTALA does not specifically mention...
Vulnerabilities Identified in Azure Health Bot Service
Two vulnerabilities have been identified in the Azure Health Bot Service that can be exploited to access cross-tenant resources including user and customer information, according to Tenable Research. The Azure Health Bot Service is a cloud-based platform that has been developed for use in healthcare. Developers can use Azure Health Bot to build and deploy AI-powered, HIPAA-compliant, conversational AI-powered virtual assistants at scale to improve efficiency and reduce costs. Virtual assistants can be created for specific healthcare purposes and can handle administrative tasks or even triage to reduce the burden on staff. Depending on the configuration of these chatbots, they can have access to sensitive patient information, so if vulnerabilities exist, that information may be at risk. Potentially, vulnerabilities could be exploited to gain access to other resources. Researchers at Tenable conducted an audit of the Azure Health Bot Service to identify potential security issues, and one of the features investigated was the Data Connections feature. Data Connections allows chatbots...
Enzo Biochem Settles HIPAA Violations with State Attorneys General for $4.5 Million
New York Attorney General Letitia James has announced that a settlement has been agreed with the New York-based biotechnology company Enzo Biochem and its subsidiary Enzo Clinical Labs (Enzo) to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule and state law. Under the terms of the settlement, Enzo will pay a $4.5 million civil monetary penalty and has agreed to strengthen its cybersecurity practices. The New York Attorney General, assisted by the New Jersey and Connecticut Attorneys General, launched an investigation of Enzo following a report of an April 2023 data security incident. Hackers gained access to an Enzo database server that was used for analytics and reporting, exfiltrated data relating to testing between October 2012 and April 2023, and then used ransomware to encrypt files. In total, around 2.4 million patients had their data stolen in the attack, including 1,457,843 New York residents. The hackers used the login credentials of two Enzo employees to access the server. The investigation found that those login...



