Is HIPAA a Federal Law?
HIPAA is a Federal law that was passed in 1996 with the objective of reforming the health insurance industry in order to improve the portability of health insurance between jobs and to protect the coverage of employees with preexisting conditions. Due to concerns that the cost of the reforms would be passed onto employers and employees – and that this would negatively affect federal tax revenues – measures were introduced to counter the costs of the reforms. The measures included a “Fraud and Abuse Program” to prevent unscrupulous healthcare providers fraudulently charging for services provided (or not provided) to group plan members, and the “Administrative Simplification Requirements” – which instructed the Secretary of Health and Human Services to: Standardize codes used in electronic healthcare transactions to simplify the administration and improve the efficiency of healthcare transactions, Develop security standards for health information used and disclosed in healthcare transactions, and Make recommendations with respect to the privacy of certain health information....
Atlanta Women’s Health Group Sued Over 2023 Ransomware Attack
Atlanta Women’s Health Group is facing a class action lawsuit over an April 2023 cyberattack that saw an unauthorized third party gain access to its servers and the sensitive data of tens of thousands of its patients. Atlanta Women’s Health Group discovered the attack on April 12, 2023, and its forensic investigation confirmed that patients’ protected health information had been exposed. The types of information involved included names, dates of birth, patient ID numbers, and other information that may be contained in medical records. It was not possible to determine the exact types of information that were accessed or acquired, so notifications were sent to all individuals who had potentially been affected. A lawsuit – M.T., vs. Atlanta Women’s Health Group P.C. – was filed in the U.S. District Court for the Northern District of Georgia Atlanta Division that alleged the OB/GYN healthcare provider had implemented inadequate data security measures and breached its duties imposed by law. As a result of those failures, unauthorized individuals were able to gain access to its...
Seattle Children’s Hospital Website Tracking Technology Lawsuit Dismissed with Prejudice
A class action lawsuit against Seattle Children’s Hospital (SCH) over its use of pixels and other tracking technologies on its website has been dismissed with prejudice by a Washington court. Like many other hospitals, SCH had added pixels to its website which could track user behavior on the site. The tracking technologies were used to gather information on how the website was used to improve the site and patient engagement. Depending on a user’s interactions on the website, the pixels may have captured identifiers and health information, which was transferred to third parties. A lawsuit was filed by parents who had used the site alleging the addition of pixels violated the Washington Privacy Act, Washington Consumer Protection Act, and Washington Uniform Health Care Information Act. They alleged an invasion of privacy, breach of implied contract, conversion, and unjust enrichment. SCH argued that the information gathered by the pixels did not amount to confidential health information and that users had accepted the terms of its privacy policy and by doing so had consented to...
Payers and Providers Plan to Use Generative AI to Improve Patient Engagement
Generative AI (genAI) has tremendous potential in healthcare, with payers enthusiastic about using genAI to enhance the patient experience and improve patient engagement and outcomes. A recent survey of CXOs at 350 U.S. health plans and health systems by HFS Research and Cognizant explored the impact of genAI on consumer experiences and engagement. The U.S. healthcare system is experiencing deteriorating health outcomes, declining life expectancy, an increase in chronic conditions, and opioid and mental health epidemics. At the same time, technological innovation is accelerating, AI systems are being adopted at scale, there has been a resurgence in digital-health-fueled primary care, and the introduction of innovative care models. Together there are significant opportunities for reducing costs, enhancing the experiences, and improving health outcomes. One of the ways that these goals can be realized is through the use of genAI. Surveyed payers were convinced that gen AI was a game changer and would be invaluable in improving the efficiency of administrative functions, especially...
Group Health Cooperative of South Central Wisconsin Ransomware Attack Affects 533K Patients
Group Health Cooperative of South Central Wisconsin (GHC-SCW) has notified 533,809 patients about a January cyberattack. In the early hours of January 25, 2024, an unauthorized third party accessed its network and attempted to use ransomware to encrypt files. GHC-SCW said the file encryption was not successful; however, while containing the attack and securing its systems, some of its systems were temporarily made unavailable. Third-party cybersecurity experts were engaged to investigate the incident, and on February 9, 2024, evidence was uncovered that indicated the attacker had copied certain files from the network before attempting encryption. The attacker also made contact with GHC-SCW and claimed responsibility for the attack and confirmed that data had been exfiltrated from its network. The attacker, a foreign ransomware group, demanded payment to delete the stolen data. GHJC-SCW did not state whether the ransom was paid. The review of the affected files confirmed that they contained the following types of patient information: Member/patient name, address, telephone number,...



