Paubox Launches HIPAA Compliant Online Forms
Paubox, the market leader in HIPAA-compliant email, has added a new feature to the Paubox Email Suite that allows HIPAA-regulated entities to create secure, HIPAA-compliant online forms for collecting patient data. Healthcare providers need to collect information from patients and the easiest and most efficient way to do so is by using an online form. Patients can be sent a link to a form that they can access on their mobile devices and can quickly and efficiently provide the required information. They can share files and attach images to help their provider better prepare for an appointment, which can shorten appointment times and allow providers to see more patients. Online forms streamline information collection and can be used for getting feedback, arranging telehealth services, collecting insurance information, and obtaining consent. Before any online form can be used by a HIPAA-regulated entity, they must ensure that the forms are HIPAA-compliant and securely collect, store, and transmit patient data. The providers of online forms are classed as business associates and their...
Why a Gap Analysis in Healthcare is Far from Straightforward
In the context of regulatory compliance, a gap analysis in healthcare is an assessment of the required level of regulatory compliance compared to the existing level of regulatory compliance. A gap analysis has the objective of identifying what measures need to be implemented in order to achieve the required level of regulatory compliance. However, a gap analysis in healthcare is far from straightforward. Organizations in the healthcare sector have to comply with multiple federal, state, and industry regulations. They may also be required to comply with voluntary standards to maintain a professional accreditation. Some regulations complement each other. Other regulations conflict with each other. In some cases, regulations can apply to some areas of an organization’s operations – but not others. For example, the Colorado Privacy Act does not apply to “Protected Health Information that is collected, stored, and processed by a covered entity or its business associates”, but it does apply to any other information collected, stored, or maintained by a covered entity or business...
FTC Orders Blackbaud to Improve Security and Enforce Data Retention Policies
The Federal Trade Commission (FTC) has ordered South Carolina-based Blackbaud to implement a raft of security measures and enforce its data retention policies to ensure that customer data is not retained any longer than it is needed. Blackbaud is a customer relationship management software provider, whose software is used by 35,000 fundraising entities, including many nonprofit healthcare organizations to increase philanthropic revenue. In early 2020, a hacker used a Blackbaud customer’s login name and password to access the customer’s Blackbaud-hosted database. Once access was gained, the hacker was able to move laterally by exploiting security vulnerabilities to access multiple Blackbaud-hosted environments and remained undetected in Blackbaud’s environment for 3 months. Over those 3 months, the hacker exfiltrated a vast amount of unencrypted data from tens of thousands of customers, which included the personal and protected health information of millions of individuals. The stolen data included names, contact information, medical information, health insurance information, Social...
Is GoToMeeting HIPAA Compliant?
GoToMeeting is HIPAA compliant and can be used by covered entities and business associates to collect, disclose, and transmit Protected Health Information (PHI) provided the organization enters into a Business Associate Agreement with the software provider. Thereafter, there is very little configuration or training required to use the platform in compliance with HIPAA. GoToMeeting is an online meeting and video conferencing platform offered by LogMeIn. The platform is one of many video conferencing and desktop sharing platforms that can improve communication and collaboration in the healthcare industry; but before any solution of this nature can be used to collect, disclose, or transmit PHI, it is important the solution is HIPAA compliant. Is GoToMeeting HIPAA Compliant? GoToMeeting is HIPAA compliant inasmuch as the platform includes all the capabilities required to support HIPAA compliance regardless of the plan subscribed to. Most capabilities are compliant by default, and system administrators should only have to configure the access controls and disable the feature that could...
LockBit Ransomware Gang Claims Responsibility for Attack on Saint Anthony Hospital
The LockBit ransomware gang has added Chicago’s Saint Anthony Hospital to its data leak site and is demanding a ransom payment of almost $900,000 from the nonprofit hospital to prevent the release of the stolen data. Earlier this week, Saint Anthony Hospital confirmed that it was still investigating the attack, which was detected on December 18, 2023. Saint Anthony Hospital took immediate action to secure its network to prevent further unauthorized access and an investigation was launched to determine the nature and scope of the unauthorized activity. The prompt action taken by the hospital in response to the attack allowed care to continue to be provided to patients without disruption. The investigation confirmed on January 7, 2024, that an unknown, unauthorized third party had copied files from its network on December 18, 2023, which contained patient information. Those files are being reviewed to determine the number of patients affected and the types of information involved, and that process is ongoing. At this stage, Saint Anthony Hospital is unable to say how many individuals...



