Is Slack HIPAA Compliant?
Slack is not HIPAA compliant, and although the company provides an enterprise version of the software and supports it with a Business Associate Agreement, there are so many limitations on how the platform can be used in compliance with HIPAA, it is better for healthcare organizations to look elsewhere. There has been considerable confusion about the use of Slack in healthcare and whether Slack is HIPAA compliant. For a long time since the launch, Slack was not a HIPAA compliant communication solution, although steps have been taken to develop a version of the platform that can be used by healthcare organizations. That version is called Slack Enterprise Grid. In 2017, Geoff Belknap, Chief Security Officer at Slack, said “our team has spent over a year investing our time and effort into meeting the rigorous security needs of our customers who work in highly regulated industries.” Slack Enterprise Grid was announced at the start of 2017. It should be noted that Slack Enterprise Grid is not the same as Slack. It has been built on different code, and has been developed specifically for...
How to Handle A HIPAA Privacy Complaint
Privacy complaints should be handled in such a manner to ensure patient concerns are resolved before they might be escalated to HHS Office for Civil Rights, and to ensure that – if a privacy compliant is attributable to a data breach – the consequences of the breach are mitigated quickly and effectively. Healthcare providers need to be prepared to deal with a HIPAA privacy complaint from a patient. In order for an efficient response to be conducted, policies should be developed covering the complaints procedure and staff must be trained to handle HIPAA privacy complaints correctly. Patients must also be clearly informed how they can make a HIPAA privacy complaint if they feel that their privacy has been violated or the HIPAA Privacy Rule has been breached. This should be clearly stated in Notices of Privacy Practices. A HIPAA Privacy Complaint Should be Taken Seriously When a HIPAA privacy complaint is filed, it is important that it is dealt with quickly and efficiently. Fast action will help to reassure patients that that you treat all potential privacy and security...
Is Google Forms HIPAA Compliant?
Google Forms is HIPAA compliant and can be used to create, receive, maintain, or transmit Protected Health Information provided the organization subscribes to an appropriate Google Workspace or Cloud Identity package and signs Google’s Business Associate Addendum. Google Forms is a convenient web-based service used for creating surveys, gaining feedback from customers, and analyzing the results; but, when used by healthcare organizations to collect, store, or share Protected Health Information, it is important healthcare organizations know how to make Google Forms HIPAA compliant. Google Forms does Not Support HIPAA Compliance by Default Google Forms does not, by default, support HIPAA compliance. This is because the service is part of the productivity suite within Google Drive which, unless included in a Google Workspace or Cloud Identity package, does not include the capabilities required to comply with the technical safeguards of the Security Rule. This does not mean Covered Entities and Business Associates cannot use Google Forms outside of a Workspaces or Cloud Identity...
Ransomware Attacks Reported by Foursquare Healthcare and Hi-School Pharmacy
Foursquare Healthcare Ltd, a Rockwall, TX-based operator of short-term rehabilitation, skilled nursing, and long-term nursing care facilities has recently confirmed it experienced a ransomware attack in September. The ransomware attack was detected on September 27, 2023, and the forensic investigation confirmed the attackers accessed its network between September 27, 2023, and September 29, 2023, and acquired certain files that contained employee and patient information. The information in the files varied from individual to individual and included names along with one or more of the following: address, billing information, Social Security number, banking information, and clinical information regarding care received at its clinics. The attack did not cause any material disruption to Foursquare care or services and no evidence has been found to indicate that any of the stolen data has been misused for identity theft or fraud. Foursquare said it has received assurances that all of the stolen data has been deleted. That usually, but not always, means the ransom was paid. Foursquare...
9 Prime Healthcare Hospitals Affected by MOVEit Data Breach
Ontario, CA-based Prime Healthcare has been affected by a data breach at its revenue cycle management vendor, CBIZ KA. The vendor used Progress Software’s MOVEit Transfer solution, a zero-day vulnerability in which was exploited by the Clop hacking group in late May 2023. Prime Healthcare received a copy of the stolen files from CBIZ KA on September 20, 2023, and has confirmed that they contained names in combination with one or more of the following: date of birth, address, medical record number, Social Security Number, admission date, and discharge date. Prime Healthcare operates 45 hospitals, although only 9 were affected: Saint Clare’s Hospital, Saint Michael’s Medical Center, and St. Mary’s General Hospital in New Jersey, Roxborough Memorial Hospital, Lower Bucks Hospital, and Suburban Community Hospital in Pennsylvania, Garden City Hospital and Lake Huron Medical Center in Michigan, and Landmark Medical Center in Rhode Island. Individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity protection...



