February 14, 2024 Healthcare Data Breach Round-Up
Data breaches have recently been reported by the Hampton-Newport News Community Services Board, Marywood Nursing Care Center, Health Alliance, United Regional Health Care System, Nabholz Construction, and J.D. Gilmour & Co. Hampton-Newport News Community Services Board The Hampton-Newport News Community Services Board, a Virginia-based provider of behavioral health and intellectual and developmental disability services, has notified 44,312 individuals that some of their protected health information was compromised in a recent ransomware attack. Technical disruptions were experienced on November 12, 2023, and it soon became clear that the disruption was due to the use of ransomware. Third-party cybersecurity experts were engaged to assist with the investigation and remediation, and they determined that the attackers gained access to its network on September 26, 2023. A review was conducted of all files that could have been accessed which confirmed that patient data had been exposed. The exposed data varied from patient to patient and may have included names in combination with...
The Benefits of Integrated Healthcare Compliance Management
Integrated healthcare compliance management consists of managing a healthcare organization’s compliance obligations and activities holistically in order to avoid business units duplicating compliance requirements or implementing compliance measures that conflict with other compliance measures. The benefits of integrated healthcare compliance management include a reduction in costs, an improvement in patient safety, and a streamlined approach to regulatory compliance. In a healthcare organization, although every member of the workforce has a responsibility for compliance, there can be multiple team leaders, managers, department heads, and Chief Officers who manage each business line’s compliance program. In many cases, the compliance program in each business line is vertically linear, with minimal crossover between (for example) Nursing, Administration, and Finance – the exception being crossovers with Information Security. The Pros and Cons of Linear Healthcare Compliance Management The linear compliance format has advantages inasmuch as those closer to the top of the chain of...
ONC Expands TEFCA with Two Additional Health Information Networks
The Office of the National Coordinator for Health Information Technology (ONC) at the Department of Health and Human Services (HHS) has announced that two new organizations have been designated as Qualified Health Information Networks (QHINs) and have been added to the nationwide data exchange governed by the Trusted Exchange Framework and Common Agreement (TEFCA). TEFCA was envisioned by the 21st Century Cures Ac to support nationwide interoperability and became operational in December 2023 when the first five QHINs were designated by ONC – eHealth Exchange, Epic Nexus, Health Gorilla, KONZA, and MedAllies. The addition of two new QHINs – CommonWell Health Alliance and Kno2 – brings the total up to seven. ONC has confirmed that CommonWell Health Alliance and Kno2 can immediately begin supporting the exchange of data under TEFCA and can provide shared services and governance to securely route queries, responses, and messages across networks for healthcare stakeholders including patients, providers, hospitals, health systems, payers, and public health agencies....
5 Best Practices for Healthcare Data Breach Incident Response and Reporting
Healthcare data breach incident response and reporting is a key area of regulatory compliance for organizations in the healthcare industry, yet there are many examples in HHS’ Breach Report where the Office of Civil Rights has had to “provide technical assistance regarding [compliance with] the HIPAA Breach Notification Rule”. This implies that covered entities and business associates are failing to respond to and report healthcare data breaches in a timely manner. The Archive section of HHS’ Breach Report is a mine of valuable information about the true causes of HIPAA data breaches. Most of the 5,000+ entries have a dropdown box which reveals the nature of the breach, how it occurred, and the steps taken by the notifying entity to mitigate the consequences of the breach and to prevent it happening again. However, in more than 1,500 cases it is noted the Office for Civil Rights provided technical assistance regarding the HIPAA Breach Notification Rule. Most of the 5,000+ data breaches were avoidable. Had the covered entity or business associate responsible for the breach...
Bipartisan Bill Aims to Ensure the HHS is Implementing Effective Cybersecurity Measures
A bipartisan Senate bill has been introduced that aims to improve healthcare cybersecurity and ensure that the Department of Health and Human Services (HHS) is implementing effective cybersecurity measures to combat evolving cyber threats. In 2023, record numbers of healthcare records were compromised, and more data breaches were reported than in any other year to date. More than 133 million healthcare records were compromised in 2023 across more than 725 reported breaches, the majority of which were hacking incidents. Healthcare organizations must ensure that they are compliant with the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, which sets minimum standards for cybersecurity. The HHS is the main enforcer of compliance with the HIPAA Rules and issues guidance on healthcare cybersecurity. The HHS also manages the health data of approximately 65 million Americans who receive healthcare services through Medicare. As such, it is vital that the cybersecurity measures at the HHS are robust and capable of defending against evolving cyber threats. The...



