Ann & Robert H. Lurie Children’s Hospital Responding to Cyberattack
On February 1, 2024, Ann & Robert H. Lurie Children’s Hospital in Chicago announced on its website and social media channels that it is responding to a cybersecurity incident and has been forced to take its network systems offline. The cyberattack has been reported to law enforcement agencies and Lurie Children’s is working collaboratively with those agencies and third-party cybersecurity experts to investigate the attack and bring network systems back online as soon as it is safe to do so. The 360-bed acute care hospital is a leading provider of pediatric care in Illinois and one of the biggest children’s healthcare providers in the Midwest, serving 239,000 children each year. The cyberattack has disrupted normal operations and caused delays to medical care for certain patients, with ultrasound and CT scan results temporarily unavailable. Some appointments and elective procedures have been canceled to ensure patient safety. The hospital has confirmed that its emergency services are unaffected, and it is operating under a first-come, first-served approach and is...
Paubox Launches HIPAA Compliant Online Forms
Paubox, the market leader in HIPAA-compliant email, has added a new feature to the Paubox Email Suite that allows HIPAA-regulated entities to create secure, HIPAA-compliant online forms for collecting patient data. Healthcare providers need to collect information from patients and the easiest and most efficient way to do so is by using an online form. Patients can be sent a link to a form that they can access on their mobile devices and can quickly and efficiently provide the required information. They can share files and attach images to help their provider better prepare for an appointment, which can shorten appointment times and allow providers to see more patients. Online forms streamline information collection and can be used for getting feedback, arranging telehealth services, collecting insurance information, and obtaining consent. Before any online form can be used by a HIPAA-regulated entity, they must ensure that the forms are HIPAA-compliant and securely collect, store, and transmit patient data. The providers of online forms are classed as business associates and their...
Why a Gap Analysis in Healthcare is Far from Straightforward
In the context of regulatory compliance, a gap analysis in healthcare is an assessment of the required level of regulatory compliance compared to the existing level of regulatory compliance. A gap analysis has the objective of identifying what measures need to be implemented in order to achieve the required level of regulatory compliance. However, a gap analysis in healthcare is far from straightforward. Organizations in the healthcare sector have to comply with multiple federal, state, and industry regulations. They may also be required to comply with voluntary standards to maintain a professional accreditation. Some regulations complement each other. Other regulations conflict with each other. In some cases, regulations can apply to some areas of an organization’s operations – but not others. For example, the Colorado Privacy Act does not apply to “Protected Health Information that is collected, stored, and processed by a covered entity or its business associates”, but it does apply to any other information collected, stored, or maintained by a covered entity or business...
FTC Orders Blackbaud to Improve Security and Enforce Data Retention Policies
The Federal Trade Commission (FTC) has ordered South Carolina-based Blackbaud to implement a raft of security measures and enforce its data retention policies to ensure that customer data is not retained any longer than it is needed. Blackbaud is a customer relationship management software provider, whose software is used by 35,000 fundraising entities, including many nonprofit healthcare organizations to increase philanthropic revenue. In early 2020, a hacker used a Blackbaud customer’s login name and password to access the customer’s Blackbaud-hosted database. Once access was gained, the hacker was able to move laterally by exploiting security vulnerabilities to access multiple Blackbaud-hosted environments and remained undetected in Blackbaud’s environment for 3 months. Over those 3 months, the hacker exfiltrated a vast amount of unencrypted data from tens of thousands of customers, which included the personal and protected health information of millions of individuals. The stolen data included names, contact information, medical information, health insurance information, Social...
Is GoToMeeting HIPAA Compliant?
GoToMeeting is HIPAA compliant and can be used by covered entities and business associates to collect, disclose, and transmit Protected Health Information (PHI) provided the organization enters into a Business Associate Agreement with the software provider. Thereafter, there is very little configuration or training required to use the platform in compliance with HIPAA. GoToMeeting is an online meeting and video conferencing platform offered by LogMeIn. The platform is one of many video conferencing and desktop sharing platforms that can improve communication and collaboration in the healthcare industry; but before any solution of this nature can be used to collect, disclose, or transmit PHI, it is important the solution is HIPAA compliant. Is GoToMeeting HIPAA Compliant? GoToMeeting is HIPAA compliant inasmuch as the platform includes all the capabilities required to support HIPAA compliance regardless of the plan subscribed to. Most capabilities are compliant by default, and system administrators should only have to configure the access controls and disable the feature that could...



