What is PCI Compliance in Healthcare?
PCI compliance in healthcare means securing payment account data in compliance with the Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 when payment account data are maintained separately from Protected Health Information. The failure to comply with PCI DSS can result in the loss of merchant accounts, fines, and civil actions. The PCI DSS (Payment Card Industry Data Security Standard) is an information security standard designed to reduce payment card fraud by increasing security controls around cardholder data and sensitive authentication data. All organizations that process, store, and transmit payment account date are required to comply with PCI DSS unless a federal, state, or industry standard provides greater protection to payment account data than PCI DSS. In the healthcare industry, the HIPAA Administrative Simplification Regulations (“HIPAA”) protect the privacy and security of individually identifiable health information. Any non-health information stored in a designated record set with individually identifiable health information assumes the same protections...
HHS Restructures to Consolidate Technology, Cybersecurity, Data, AI, and HealthIT
The Department of Health and Human Services (HHS) has announced a major restructuring that will allow the department to streamline its operations and more effectively prioritize the use of digital and emerging capabilities such as artificial intelligence. Work related to technology, cybersecurity, and data has historically been distributed across three HHS departments: The Office of the National Coordinator for Health Information Technology (ONC), the Assistant Secretary for Administration (ASA), and the Administration for Strategic Preparedness and Response (ASPR). Opportunities in these areas have grown considerably in recent years, and now is the time to streamline operations and have all tech-centric work handled by a single HHS organization. The ONC will be renamed the Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC), which will be tasked with oversight of technology, data, and artificial intelligence policy and strategy, taking over these oversight roles from the ASA. ASTP/ONC will also be tasked...
Aveanna Healthcare Announces Breach of 11 Employee Email Accounts
The Georgia-based healthcare provider, Aveanna Healthcare, has recently announced that the email accounts of 11 employees have been accessed by an unauthorized third party, who gained access to the protected health information of 10,482 patients. This is the second email breach to be reported by Aveanna Healthcare in recent months. On March 15, 2024, Aveanna Healthcare reported an email breach to the HHS’ Office for Civil Rights that involved the protected health information of 65,482 patients. That incident involved unauthorized access to an employee email account on or around September 22, 2023. The latest breach was detected around a month after OCR was notified about the previous email breach. According to Aveanna Healthcare’s substitute breach notice, unusual activity was detected in the email accounts on April 17, 2024. Immediate action was taken to prevent further unauthorized access to the accounts and an investigation was launched to determine the nature and scope of the breach. On June 12, 2024, it was confirmed that protected health information was present in the...
HealthEquity Confirms Breach Involved PII of 4.3 Million Individuals
In early July, the HIPAA Journal reported on a data breach at the Draper, UT-based financial technology and business services company, HealthEquity. HealthEquity had disclosed in an 8-K filing with the Securities and Exchange Commission (SEC) that it had identified suspicious activity in the device of a business partner. The initial findings of the investigation indicated unauthorized access to the device and member information. HealthEquity has recently notified the Maine Attorney General about the incident and has confirmed that the personal identifying information (PII) of 4,300,000 individuals was exposed and potentially stolen, including the personal information of 13,480 Maine residents. HealthEquity, the parent company of WageWorks Inc. and Further Operations LLC, provides health savings account (HSA) services and other consumer-directed benefits solutions, including health reimbursement arrangements (HRAs). The company manages millions of HSAs, HRAs, and other benefit accounts. In the notification, HealthEquity explains that it was notified about a systems anomaly on March...
Debt Collection Agency Confirms 4.25 Million Individuals Affected by February 2024 Cyberattack
The debt collection agency Financial Business and Consumer Solutions (FBCS) has recently notified the Maine Attorney General that a previously reported breach that was initially reported as affecting 1,955,385 individuals is more than twice as bad. In the fifth report filed with the Maine Attorney General, FBCS has confirmed that 4,050,711 individuals are known to have been affected, including 7, 786 Maine residents. The total continues to increase, as the latest update in late July indicates 4,253,394 individuals have been affected, including 7,841 Maine residents. The data breach occurred on February 14, 2024, and was discovered a couple of weeks later on February 26, 2024. The forensic investigation by third-party cybersecurity specialists confirmed that the breach was confined to FBCS systems, the hackers had access to those systems for almost 2 weeks, and during that time they may have viewed or acquired files containing sensitive information. FBCS first notified the Maine Attorney General about the breach on April 26, 2024; however, the investigation had not concluded. As the...



