Concentra Confirms Almost 4 Million Patients Affected by PJ&A Data Breach
Concentra, a Texas-based physical and occupational health provider, has confirmed it was affected by a cyberattack at its transcription service provider, PJ&A. PJ&A has already reported the breach to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) as affecting almost 9 million patients; however, some PJ&A clients have chosen to report the breach to OCR themselves, including Concentra. On January 9, 2024, Concentra confirmed that the protected health information of 3,998,162 patients was compromised in the PJ&A cyberattack, bringing the total number of affected individuals up to at least 14 million. That makes it the largest healthcare data breach of 2023. That total is likely to grow further, although by how much is not currently clear as PJ&A has not publicly disclosed which clients have been affected nor the total number of records that were compromised in the attack. The Nevada-based medical transcription company and many of the affected clients are being sued over the data breach. At least 40 lawsuits have already been filed...
How to Become OSHA Compliant
The summarized way to become OSHA compliant is to establish which OSHA standards apply to your business, conduct a risk assessment to identify threats to safety and health, and abate identified threats as necessary. What is OSHA Compliance? OSHA compliance is complying with all applicable workplace standards promulgated by the federal Occupational Safety and Health Administration or an OSHA-approved state plan to promote safe and healthy workplaces. Most businesses are required to comply with “General Industry” standards, but there are separate standards for the agriculture, maritime, and construction industries. The OSHA standards for General Industry cover everything from safe working surfaces and workplace ventilation to exposure limits for hazardous substances and chemicals. There are also standards governing hazard communication, injury and illness recordkeeping, and workforce training. The failure to comply with any applicable safety, health, or administrative standard is a violation of OSHA. What Happens if You Violate OSHA? What happens if you violate OSHA depends on the...
What is Healthcare Compliance Tracking Software?
Healthcare compliance tracking software is a tool that helps healthcare organizations keep compliance programs on schedule by automating the management of activities such as risk assessments, policy and procedure reviews, workforce training, and incident management. When used effectively, healthcare compliance tracking software can help organizations avoid legal risks, better protect the privacy and security of health information, and improve the quality of patient care. Healthcare organizations have a lot of regulations and standards to comply with. Not only are most healthcare organizations required to comply with HIPAA, OSHA, and FDA regulations, but they might also have to meet CMS’ conditions for participation in Medicare, the voluntary standards for Joint Commission accreditation, and industry-specific or role-specific state licensing requirements. In addition, if a healthcare organization operates in a state that has passed a data privacy law that does not exempt HIPAA covered entities and business associates, there may be occasions in which a provision of a state data...
71% of Ransomware Attack Victims Refuse to Pay the Ransom
The latest data from the ransomware remediation firm, Coveware, shows the number of victims of ransomware attacks choosing to pay the ransom has fallen to a record low. At the start of 2019, 85% of victims of ransomware attacks paid a ransom following an attack, by the middle of 2021 the percentage had fallen to 46%, and in Q4, 2023, only 29% of victims paid the ransom. In 2019, ransomware groups started engaging in double extortion tactics, where access is gained to victims’ networks and data is exfiltrated before file encryption. Ransom payments are required to obtain the keys to decrypt files and to prevent stolen data from being leaked or sold. For many victims, the main reason for paying the ransom was to prevent a data leak rather than to obtain the keys to decrypt files. Coveware reports that in ransomware attacks involving data theft, in Q3, 2023, only 26% of victims paid the ransom. There are many reasons behind the steady decline in ransom payments. One of the main factors is better preparedness, such as ensuring that a backup is made of all sensitive data and the backup...
Is Mailchimp HIPAA Compliant?
Mailchimp is not HIPAA compliant because the email service provider is unable to provide the required satisfactory assurances that it will appropriately safeguard Protected Health Information (PHI), which prohibits covered entities and business associates entering into a Business Associate Agreement and disclosing PHI via the Mailchimp platform. Mailchimp is an automated email marketing platform that can be used to send marketing emails, newsletters, and other information emails to mailing lists. It is an effective mass communication solution for covered entities and business associates with large mailing lists who want to keep internal mail servers free for operational purposes. However, the platform cannot be used to collect, maintain, or transmit PHI, as Mailchimp states in its Terms of Use: “You are responsible for determining whether the Service is appropriate for you, in light of your obligations under any regulations, such as the Health Insurance Portability and Accountability Act (HIPAA), […] or other applicable laws. If you are subject to regulations (such as HIPAA) and...



