Class Action Lawsuits Filed Against American Vision Partners Over Data Breach
Class action lawsuits are stacking up against Medical Management Resource Group LLC (MMRC), which does business as American Vision Partners, over a major data breach that was announced in early February. MMRC discovered a breach of its systems on November 14, 2023, and the investigation confirmed that the protected health information of 2,350,236 individuals was stored on the compromised parts of its network. The individuals affected by the data breach had their names, contact information, dates of birth, medical information, clinical records, Social Security numbers, and health insurance information exposed. Notification letters were sent to those individuals last month and they were offered complimentary credit monitoring services. Between February 23 and February 28, three class action lawsuits were filed in the US District Court for the District of Arizona by patients whose protected health information was compromised in the breach. The lawsuits allege negligence and claim that MMRC/American Vision Partners failed to implement reasonable and appropriate cybersecurity measures...
Cyberattacks on Eastern Radiologists and UNITE HERE Affect 1,680,000 Individuals
Major data breaches have been reported by Eastern Radiologists, Inc. in North Carolina and the New York-based labor union, UNITE HERE. The protected health information of almost 1,680,000 individuals has been compromised in these two incidents. Eastern Radiologists, Inc. Data Breach Affects Almost 887,000 Individuals Greenville, NC-based Eastern Radiologists, Inc. has recently notified 886,746 individuals that some of their HIPAA protected health information was exposed and potentially obtained by unauthorized individuals in a cyberattack that was detected on November 24, 2023. A third-party cybersecurity firm was engaged to investigate the cause of suspicious network activity and confirmed that there was unauthorized access to its network between November 20, 2023, and November 24, 2023. During that time, documents on the system were accessed and copied, some of which contained patient information. The investigation was completed on January 26, 2024, and confirmed that the exposed information included patients’ names plus one or more of the following: contact information, Social...
Sources for HHS OIG Fraud, Waste, and Abuse Guidelines
The HHS OIG fraud, waste, and abuse guidelines are intended to support healthcare organizations in their efforts to self-monitor compliance with all applicable laws and program requirements. The guidelines can be found in many different sources, including guidance documents, advisory opinions, online training programs, and the HHS OIG YouTube channel. The healthcare industry is one of the most highly regulated industries in the U.S. Federal rules and regulations exist that govern patient safety (i.e., PSQIA), data security (i.e., HIPAA), and the physical environment (i.e., OSHA). In addition, each state has its own requirements for licensing healthcare organizations and healthcare practitioners. Failure to comply with these rules, regulations, and requirements can result in fines, facility closures, and/or loss of license. However, the most substantial penalties for non-compliance are often reserved for offenses against the federal government – particularly offenses that relate to fraud, waste, and abuse against a healthcare program operated by the Department of Health and Human...
CISA, NSA Release Cloud Security Guides
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) have issued five cybersecurity information sheets to help organizations improve the security of their cloud environments. The guides include best practices for securing cloud environments along with recommended mitigations for improving cloud security. The cloud offers a cost-effective and flexible alternative to on-premises infrastructure and has become essential for supporting an increasingly remote workforce; however, cloud environments pose unique security challenges and each year many healthcare data breaches occur as a result of improperly secured cloud environments. Cyber threat actors are actively targeting cloud environments and are exploiting weak security configurations to gain access to sensitive data and after compromising cloud environments, often pivot to internal networks. Managed service providers (MSPs) are frequently targeted as if their environments can be breached, threat actors can abuse their high-privileged access to attack downstream clients, as was the...
HHS-OIG MA Organization Audit Suggests CMS Overpaid $3.7 Million Due to Submission of Incorrect Diagnosis Codes
The Centers for Medicare and Medicaid Services (CMS) makes monthly payments to organizations under the Medicare Advantage (MA) program according to a risk adjustment system that depends on the health status of each enrollee. When MA organizations provide benefits to enrollees who have diagnoses that are associated with more intensive use of health care resources, they are paid more than when benefits are provided to enrollees with diagnoses that typically require fewer health care resources. The CMS bases the payments on the diagnosis codes that are collected by MA organizations from providers and are submitted to CMS. Some diagnoses are at a higher risk of miscoding, which could result in CMS overpaying MA organizations. To assess this, HHS-OIG conducted an audit of one MA organization – MediGold – to determine if the diagnosis codes submitted to CMS for use in the risk adjustment program complied with federal requirements. HHS-OIG found that most of the diagnosis codes submitted by MediGold to CMS did not comply with federal requirements and resulted in CMS overpaying MediGold by...



