Pan-American Life Insurance Group Data Breach Affects 200,000 Individuals
Pan-American Life Insurance Group MoveIT Data Breach The Pan-American Life Insurance Group in Louisiana has confirmed that it was one of the victims of the mass hacking of a zero-day vulnerability in Progress Software’s MOVEit Transfer solution in late May 2023 by the Clop hacking group. Progress Software released a patch to fix the previously unknown vulnerability on May 31, 2023; however, by that time the Clop hacking group had already mass exploited the flaw to gain access MOVEit servers. More than 2,600 organizations worldwide are now known to have been affected and between 78 and 83 million individuals have had their data stolen in the attacks. The Pan-American Life Insurance Group said it immediately stopped using the MOVEit Transfer tool for file transfers when it was notified about the vulnerability and hired a cybersecurity firm to determine if the flaw had been exploited. The investigation confirmed that files had indeed been stolen. A review of those files was initiated, and on October 5, 2023, it was confirmed that they contained personal and protected health...
HIPAA Compliant VoIP
A HIPAA compliant VoIP service is a service that facilitates voice communications via the Internet which has the necessary safeguards and audit controls to support HIPAA compliance so that covered entities and business associates can exchange protected health information securely. With the increasing use of remote communication technologies and the increasing digitization of healthcare data, it’s more important than ever for healthcare organizations to maintain HIPAA compliance in all operations, including voice communications. This article provides an overview of what HIPAA compliant VOIP is and what steps healthcare providers need to take to make VoIP HIPAA compliant. What is HIPAA Compliance? What is VoIP? The Benefits of VoIP in Healthcare HIPAA and VoIP: Where They Meet Making VoIP HIPAA Compliant Select an appropriate platform Configure the platform Train members of the workforce Conclusion and FAQs What is HIPAA Compliance? HIPAA compliance means complying with the applicable standards, implementation specifications, and requirements of the HIPAA Administrative...
Is Skype HIPAA Compliant?
Skype is HIPAA compliant and can be used for receiving, transmitting, and sharing electronic PHI (ePHI) provided organizations subscribe to a Microsoft 365 or Office 365 plan that supports compliance and provided the service is configured to comply with the Security Rule. It will also be necessary to enter into a Business Associate Agreement with Microsoft before disclosing ePHI via Skype. There is currently some debate surrounding Skype and HIPAA compliance. Skype includes security features to prevent unauthorized access of information transmitted via the platform and messages are encrypted. But does Skype satisfy all requirements of HIPAA Rules? This article will attempt to answer the question, Is Skype HIPAA compliant? Is Skype a Business Associate? Is Skype a HIPAA business associate? That is a matter that has been much debated. Skype could be considered an exception under the Conduit Rule – being merely a conduit through which information flows. If that is the case, a business associate agreement would not be necessary. However, a business associate agreement is necessary if a...
Phishing Training for Employees
Phishing training for employees is important for HIPAA compliance because it prepares employees for the online threats they are most likely to encounter and provides them with the skills to be able to identify phishing emails and prevent this common cause of data breaches. Security Awareness Training is a Requirement for HIPAA Security Rule Compliance The HIPAA Security Rule directly mandates that HIPAA-covered entities and their business associates implement a security awareness training program. The extent to which the healthcare industry is being targeted by cybercriminals – and the number of data breaches that are now occurring – makes security awareness training more important than it ever has been. HIPAA is light on detail when it comes to the topics that should be covered in security awareness training. At the time when the Security Rule was finalized, the threat landscape was very different. Had the HIPAA Security Rule been more specific, it would have been necessary to update the regulation multiple times over the past two decades. The content of security awareness...
Is Text Messaging HIPAA Compliant?
Text messaging is not HIPAA compliant, and unencrypted SMS messages should not be used for communicating ePHI unless a patient has initiated contact by SMS or requested provider-patient communications by text message – in which case healthcare providers can use text messaging provided reasonable safeguards are implemented. Given its ease of use, many healthcare organizations and professionals may wonder is text messaging HIPAA compliant. The answer is generally “no,” but there are exceptions. It is important for members of the workforce to receive HIPAA training on when it is permissible to use and disclose Protected Health Information (PHI) and the ways in which PHI can be used and disclosed – including SMS text messaging as it is likely every workforce member has access to a device with SMS messaging capabilities. Although there are circumstances in which SMS text messaging can be HIPAA compliant, they are few and far between – making it safer for covered entities to prohibit texting electronic Protected Health Information (ePHI) rather than risk a penalty...



