462,000 Hawai’i Residents Affected by Data Breach at Navvis & Company
Approximately 462,000 individuals who enrolled in health plans through the Hawaii Medical Service Association (HMSA) have been affected by a data breach at the St. Louis, MO-based business services provider Navvis & Company. Navvis & Company detected unauthorized activity within its systems on July 25, 2023, and the forensic investigation confirmed that an unauthorized third party had access to its systems between July 12, 2023, and July 25, 2023, and exfiltrated sensitive information. Navvis & Company mailed notification letters to the affected health plan enrollees last month. The information exposed in the incident included names, dates of birth, health plan information, medical treatment information, medical record numbers, patient account numbers, case identification numbers, provider and doctor information, and health record information. The affected individuals have been offered complimentary credit monitoring and identity theft protection services. Navvis & Company reported the breach to OCR as affecting 917 individuals, with the affected clients mostly...
U.S. Fertility Proposes $5.75 Million Settlement to Resolve Class Action Data Breach Lawsuit
US Fertility LLC, the operator of more than 100 fertility clinics across the United States, has proposed a $5.75 million settlement to resolve a class action lawsuit that was filed in response to a data breach that exposed the data of around 900,000 patients. U.S. Fertility announced in November 2020 that hackers had gained access to its network and installed malware (ransomware) that rendered certain systems inaccessible. The breach was detected on September 14, 2020; however, the hackers first gained access to the network on August 12, 2020. Before encrypting files, the hackers exfiltrated sensitive patient data including names, addresses, dates of birth, MPI numbers, Social Security numbers, medical information, and financial information. A class action lawsuit was filed that alleged U.S. Fertility was negligent by failing to implement reasonable and appropriate cybersecurity measures to protect highly sensitive patient data from unauthorized access. Had those measures been implemented, the breach could have been prevented or its severity would have been severely reduced. U.S....
What is an OIG Corporate Integrity Agreement?
An OIG Corporate Integrity Agreement in healthcare is a contract between the Department of Health and Human Services (HHS) Office of Inspector General (OIG) and an organization that has violated a fraud and abuse law, that outlines the future compliance obligations of the organization. The OIG Corporate Integrity Agreement is often part of a civil settlement for violating a fraud and abuse law that prevents the organization from being added to the HHS OIG Exclusions List. HHS OIG investigates cases of potential fraud and misconduct related to HHS programs, operations, and beneficiaries. When violations of a fraud and abuse law (i.e., the False Claims Act, the Stark Law, the Anti-Kickback Statute, etc.) are identified, the HHS OIG has the authority to pursue a criminal prosecution, a civil prosecution, and/or administrative penalties such as license penalties, revocation of billing privileges, or exclusion from Medicare, Medicaid, and other federal health care programs. When a civil prosecution results in a civil monetary penalty (or settlement) AND exclusion from federal health...
Is Ademero HIPAA Compliant?
Content Central by Ademero is HIPAA compliant and organizations in the healthcare sector can use the cloud-based document management system to streamline document-intensive processes and workflows when documents contain Protected Health Information (PHI). Ademero has told us the company is willing to enter into a Business Associate Agreement with HIPAA covered entities and business associates as necessary. What is Content Central? Content Central is an enterprise document management system that works by capturing documents and files from scanners, network folders, and email accounts, and converting them into searchable PDF files. The PDF files can be grouped together according to administrator-defined values and are stored in a secure cloud server for remote retrieval by authorized users. The process can significantly accelerate workflows by eliminating delays attributable to searching for and retrieving documents. Once retrieved, documents can be shared with or among other authorized users via the Content Central platform without using external solutions. Alternatively, Content...
Memorial Mission Hospital Warned of Imminent Loss of Medicare Funding for Noncompliance
The Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) has warned Memorial Mission Hospital in North Carolina that it is at risk of losing Medicare funding as it is not compliant with the Conditions of Participation in Medicare. The CMS wrote to Memorial Mission Hospital and Asheville Surgery Center CEO, Chad Patrick, explaining that in order to receive Medicare funding, hospitals must be in compliance with the regulatory Conditions of Participation as detailed in 42 C.F.R. Part 482. Section 1864. The North Carolina State Survey Agency concluded a complaint survey on December 9, 2023, at Memorial Mission Hospital and Asheville Surgery Center and identified non-compliance with six Conditions of Participation: 42 C.F.R. § 482.12 Governing Body 42 C.F.R. § 482.13 Patient’s Rights 42 C.F.R. § 482.21 Quality Assessment and Performance Improvement Program 42 C.F.R. § 482.23 Nursing Services 42 C.F.R. § 482.27 Laboratory Services 42 C.F.R. § 482.55 Emergency Services Non-compliance has put Memorial Mission Hospital and Asheville Surgery Center...



