What is SOC 2 in Healthcare?
SOC 2 in healthcare is a privacy and security standard that can provide assurances to the C-Suite, to business partners, and to regulators that an organization has implemented appropriate controls to protect data (SOC 2 Type 1) and is using the controls effectively (SOC 2 Type 2). SOC 2 compliance in healthcare is voluntary, but the benefits of being SOC 2 “ready” can be significant. What is SOC 2? SOC 2 stands for System and Organization Controls 2 – one of five sets of standards organizations can use to assess that their privacy, security, and/or administrative processes are adequate to ensure the confidentiality, integrity, and availability of data. In healthcare, SOC 2 is the most relevant of the five sets of standards because SOC 2 controls closely align with the requirements of HIPAA. Healthcare organizations that have implemented policies and procedures to comply with HIPAA should have little difficulty in attesting SOC 2 compliance and passing an SOC 2 audit. The audit report can then be used to demonstrate that the appropriate controls are in place to protect the privacy...
LockBit Ransomware Group Behind Capital Health Cyberattack
Capital Health Systems in New Jersey has recently announced that it fell victim to a cyberattack in late November that temporarily disrupted its IT systems. Capital Health operates two hospitals in New Jersey – Capital Health Regional Medical Center in Trenton and Capital Health Medical Center in Hopewell – and an outpatient facility in Hamilton Township. While the attack caused a network outage, care continued to be provided to patients at its hospitals and their emergency rooms continued to receive patients. Capital Health has confirmed that all systems have now been restored and all services are available at Capital Health facilities; however, the investigation into the cyberattack is ongoing and it has yet to be determined to what extent patient and employee data was involved. Capital Health said law enforcement was immediately notified about the attack and third-party forensic and information technology experts were engaged to assist with the investigation and breach response. Capital Health has yet to confirm the extent of any data breach but the hacking group behind...
Addressing Workplace Violence in Healthcare
The scale of workplace violence in healthcare is unknown due to significant under-reporting; however, data from the Bureau of Labor Statistics indicates healthcare employees are four times more likely to be victims of workplace violence than in any other sector of private industry. Both these issues can be addressed with mobile technology. In 2013, the Wayne State University School of Medicine conducted a survey to examine the difference between reported workplace violence in healthcare and documented workplace violence in healthcare. More than two thousand healthcare professionals from the hospital system responded to the survey – 45% of whom claimed to have reported an incident informally to a supervisor or manager. However, when researchers compared the results of the survey to actual events entered on the hospital system´s database for documenting workplace violence incidents, they found a significant difference. Despite there being a human resource policy mandating the documentation of reported incidents of workplace violence, only 12% of informally-reported incidents...
OSHA Increases Penalties for Workplace Health and Safety Violations
The Occupational Safety and Health Administration (OSHA) has increased the minimum and maximum civil monetary penalties (CMPs) for workplace safety violations, as required by the Federal Civil Penalties Inflation Adjustment Act. To maintain the deterrent effect of CMPs and to promote compliance with the law, the Federal Civil Penalties Inflation Adjustment Act requires an annual adjustment of CMPs to account for inflation. Each year, the Office of Management and Budget (OMB) calculates an inflation multiplier, and all federal agencies are required to apply that multiplier to their CMP structures by January 15. For 2024, the OMB has calculated a multiplier of 1.03241 to reflect the cost-of-living increase over the past 12 months. OSHA confirmed the cost-of-living increase in a final rule published in the Federal Register on January 11, 2023. The final rule is effective on January 15, 2024, and will apply to all citations issued by OSHA on or after January 16, 2024. The new penalty structure also applies to open inspections that commenced before January 16, 2024. The new CMP...
Is Google Hangouts HIPAA Compliant?
The Google services that were formerly known as Google Hangouts are HIPAA compliant, and can be used to collect, transmit, and share Protected Health Information (PHI) provided they are used as part of a Google Workspaces account that supports HIPAA compliance. It is also necessary for HIPAA-covered customers to agree to Google’s Business Associate Addendum before disclosing PHI on a Google Hangouts service. Google Hangouts was launched in 2013 as a cross-platform messaging service that evolved into a popular chat, voice, and video communication tool. Originally offered free of charge to personal customers, and later as part of the G Suite service to enterprise customers, Hangouts came under increasing competition from rival messaging services such as iMessage, WhatsApp, and Facebook Messenger. To give Hangouts a more meaningful identity, the service was divided into two individual services in 2017 which were renamed Hangouts Chat and Hangouts Meet. The two new services underwent a further rebranding in 2020 – to Google Chat and Google Meet – when the enterprise G Suite...



