Mass General Brigham Terminates Two Employees for Privacy Violations
Mass General Brigham in Boston, MA, has announced that two employees have been terminated over a privacy breach identified on April 4, 2024. An investigation was launched after the health system learned that the two employees allowed a third individual – who was not employed by Mass General Brigham – to perform some of their job duties that may have resulted in patients’ personal information being viewed. The investigation concluded on May 28, 2024, and confirmed that the alleged offenses occurred between February 26, 2024, and April 4, 2024. The Health Insurance Portability and Accountability Act (HIPAA) requires protected health information (PHI) to be safeguarded at all times and prohibits disclosures of PHI to unauthorized individuals unless a valid authorization has been obtained from the individuals concerned in advance. Mass General Brigham had employment and privacy policies in place and said those policies were violated by the employees resulting in the employees’ immediate termination. Mass General Brigham did not disclose the relationship between the...
HHS-OIG and Law Enforcement Partners Tackle $2.75 Billion Healthcare Fraud Schemes
The Department of Health and Human Services Office of Inspector General (HHS-OIG) and its law enforcement partners have tackled nationwide healthcare fraud schemes involving around $2.75 billion in intended losses and $1.6 billion in actual losses. The 2024 National Health Care Fraud Enforcement Action has resulted in criminal charges being filed against 193 defendants, including 76 doctors, nurses, and other licensed medical professionals in 32 federal districts across the country. $231 million in cash, gold, luxury vehicles, and other assets has been seized. One of the actions announced by HHS-OIG Inspector General Christi A. Grimm involved five individuals at a start-up telehealth company that claimed they diagnosed and treated attention deficit hyperactivity disorder (ADHD). The company engaged in deceptive advertising on social media networks to target patients, who were prescribed addictive drugs such as Adderall and other stimulants when they were not medically necessary. Millions of pills were prescribed through the telehealth company, Done Global Inc. and its affiliated...
Health-ISAC Issues Warning Abuse of TeamViewer Remote Connectivity Software
The Health Information Sharing and Analysis Center (Health-ISAC) has issued a warning to the healthcare and public health sector about cyber threat actors exploiting TeamViewer remote connectivity software. TeamViewer provides remote access and remote control of devices and is commonly used for remote IT support and maintenance. Health-ISAC has received intelligence from a trusted source that a threat actor tracked as APT29, aka Cozy Bear/Midnight Blizzard, has compromised TeamViewer, and threat actors associated with APT29 are abusing TeamViewer. APT29 is a threat group that has been in operation since at least 2008 and is a Russian hacking group associated with Russia’s intelligence agencies, the Federal Security Service (FSB) and Foreign Intelligence Service (SVR). The United States believes APT29 is led by the SVR. On Thursday, TeamViewer issued a statement confirming it had detected an irregularity in its internal network on June 26, 2024. According to its security update, “A comprehensive taskforce consisting of TeamViewer’s security team together with globally leading cyber...
January 2024 Cyberattack on Lurie Children’s Hospital Affects 792K Individuals
On January 31, 2024, Ann & Robert H. Lurie Children’s Hospital of Chicago fell victim to a cyberattack that forced IT systems offline, including its Epic electronic health record systems and its MyChart patient portal. Staff were forced to work under downtime procedures and record patient information manually while its EHR was offline. It took until May 20, 2024, to restore access, and then the lengthy process of transferring all manually recorded data to the EHR commenced. Lurie Children’s said it has taken a considerable amount of time to investigate the incident and restore its systems due to the sophistication of the attack and the complexity of its IT infrastructure. The forensic investigation confirmed that an unauthorized, unnamed third party had access to its systems from January 26, 2024, to January 31, 2024. Lurie Children’s confirmed that the hackers were able to access patient data during those 5 days. “Through our ongoing investigation, Lurie Children’s has determined that certain individuals’ personally identifiable and/or protected health information was...
OSHA Offers $12.7M in Grants to Support Employee Safety, Health Training & Education
The Occupational Safety and Health Administration (OSHA) is offering $12.7 million in training grants to help create safer workplaces. The grants are administered under OSHA’s Susan Harwood Training Grant Program to support employee safety, health training, and education. The grants are awarded to provide training and education programs for employers and workers on the recognition, avoidance, and prevention of safety and health hazards in their workplaces, and to ensure that workers are aware of their rights under the Occupational Safety and Health (OSH) Act and the responsibilities of their employers to create a safe workplace. The grants are intended to advance job quality by providing instructor-led training for workers, supervisors, and employers in small businesses, industries with high injury, illness, and fatality rates, and vulnerable, underserved workers, such as seasonal workers who often have limited English proficiency. There are three categories of grants available: Targeted Topic Training: To identify and prevent OSHA-designated workplace safety and health hazards....



