How do You Comply with HIPAA Laws in Ohio?
Although the Ohio Personal Privacy Act (HB 376) is still to pass the House, and although no companion bill has yet been introduced into the Senate, the content of this article – originally published in 2022 – is still relevant. It is hoped that HB 376 gets the push it needs in 2024 to better protect the personal information of Ohio residents. Original Article There has been an increased interest in how do you comply with HIPAA laws in Ohio since the introduction of a proposed Ohio Personal Privacy Act. As the proposed Act stands at present, HIPAA Covered Entities and Business Associates will be exempt from complying with any new legislation, while any new privacy standards will not apply to Protected Health Information. In July 2021, Ohio Lieutenant Governor John Husted announced the introduction of the Ohio Personal Privacy Act – a proposed framework of privacy protections similar to those passed in California, Virginia, and Colorado. The Act (HB 376) will – if passed – give consumers in Ohio rights over what information is collected about them, how it is used, and who it is...
State of Maine Reports 450,000-Record Data Breach
The State of Maine has confirmed that the protected health information of 453,894 individuals was stolen in the recent mass hacking of a zero-day vulnerability in Progress Software’s MoveIT Transfer solution. Progress Software released a patch to fix the vulnerability on May 31, 2023; however, the vulnerability had already been exploited. The State of Maine’s investigation confirmed that the vulnerability had been exploited between May 28, 2023, and May 29, 2023, and sensitive data had been stolen by the Clop hacking group. The breach was limited to its MOVEit server, and no other systems were compromised. The Clop hacking group claimed they were only interested in hacking businesses and said they would delete all data stolen from governments; however, the State of Maine is urging all affected individuals to ignore those claims and take steps to protect themselves against fraud. The individuals affected may have been Maine residents, employees, or could have received services from or interacted with a state agency. Maine also participates in data sharing agreements with other...
Texting Patient Information
When Is It Possible to Send Patient Information by Text? Texting patient information has generally been considered to be in violation of the Health Insurance Portability and Accountability Act (HIPAA), but this is not always the case. Text communications between a medical professional and a patient are permissible, provided the medical professional applies the “minimum necessary standard” to reduce the risk of the unauthorized exposure of Protected Health Information (PHI), the patient is warned of the risk that their personal information may be exposed, and a signed consent form is received from the patient. Electronic communications between other healthcare professionals and Business Associates are also allowed, provided that all parties involved adhere to the technical requirements of the HIPAA Security Rule. Unfortunately most “traditional” channels of text communication do not adhere to the technical requirements of the HIPAA Security Rule – exposing healthcare authorities to the risk of civil action and substantial fines if a breach of PHI occurs. What Are the Technical...
Hundreds of Thousands of Blue Shield of California Members Affected by MOVEit Hack
California Physicians’ Service, which does business as Blue Shield of California, has confirmed that it has been affected by the mass exploitation of a vulnerability in Progress Software’s MOVEit Transfer file transfer solution. The breach has been reported to the HHS’ Office for Civil Rights in two separate breach reports, one involving the data of 636,848 Blue Shield of California plan members and another that has affected 26,523 Blue Shield of California or Blue Shield of California Promise Health Plan members. The breach occurred at an unnamed vendor of Blue Shield of California that managed vision benefits. The vendor used the MOVEit Transfer solution to transfer large files as part of its contracted duties. A zero-day vulnerability in the MOVEIt Transfer solution was exploited between May 28, and May 31, 2023, and files were exfiltrated that included members’ names, birthdates, addresses, subscriber ID numbers, subscribers’ names, birthdates, Social Security numbers, group ID numbers, vision providers’ names, patient ID numbers, vision claims numbers, vision-related treatment...
Is Evernote HIPAA Compliant?
Evernote is not HIPAA compliant and cannot be used to save, store, sync, or share documents and images containing Protected Health Information due to the platform lacking the controls to comply with the HIPAA Privacy and Security Rules. Due to the lack of controls, Evernote will not enter into a Business Associate Agreement with customers. Evernote serves as an easily accessible repository for a wide range of information, including documents, audio files, images, and video files. One of the key features of Evernote which makes it so useful is the ability to automatically synch files and notes across multiple devices. Evernote is available as a free app or a paid service for businesses and does incorporate access controls and security features such as single sign-on (SSO) and two-factor authentication to prevent unauthorized use of the applications. Evernote stores data on the Google Cloud platform, which can be HIPAA compliant. Encryption is also supported by Evernote for Mac and Evernote for Windows Desktop. In-note encryption uses an AES 128-bit key. Evernote is designed to make...



