Daviess Community Hospital Investigating Potential Cyberattack
Daviess Community Hospital, an Ascension St. Vincent affiliated hospital in Washington, IN, has recently announced that it has launched an investigation after being notified by the U.S. Department of Homeland Security (DHS) about a possible security breach. According to the DHS, a security issue was identified during routine monitoring which may have been exploited by cyber actors. Hospital CEO, Tracy Conway, said all internal systems have been shut down while the incident is investigated by a third-party digital forensics firm. Conway said no evidence has been found to date to indicate unauthorized access to its network or patient data, and no ransom demand has been received by the hospital. Disruption has been caused due to IT systems being taken offline, including phone lines to outpatient clinics and email, and the hospital has effectively been temporarily non-computerized. As a result, services have been limited until systems are restored and some appointments have been cancelled and will have to be rescheduled. The biggest impact is on radiology, as it is not possible to send...
Republicans and Democrats Introduce Bills to Improve Consumer Privacy Protections
In the absence of a federal privacy law, it is left to individual states to introduce consumer privacy laws and ensure that companies that collect, process, and sell personal data are adequately protecting that information. While attempts to pass a federal data privacy bill have stalled, Republican and Democratic lawmakers are continuing to push for greater privacy protections for consumers. Congresswoman Anna Paulina Luna Introduces U.S. Data on U.S. Soil Act Congresswoman Anna Paulina Luna (R-FL) recently introduced the U.S. Data on U.S. Soil Act, to protect the data security of Americans and prevent their personal information from being exploited by foreign adversaries. It is no secret that foreign countries are attempting to collect and use the personal data of U.S. citizens. In March 2023, the House Committee on Energy and Commerce explored the role that social media, and specifically TikTok, plays in data collection and how the Chinese Communist Party has access to the data of U.S. citizens that is collected by TikTok, through TikTiok’s parent company, ByteDance. The European...
St. Joseph’s Medical Center Pays $80,000 HIPAA Fine for PHI Disclosure to a Reporter
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 11th HIPAA penalty of 2023. St. Joseph’s Medical Center, a non-profit academic medical center in New York, was investigated over the disclosure of patients’ protected health information (PHI) to a reporter and has paid a $80,000 financial penalty to resolve the alleged HIPAA violations. The Privacy Rule of the Health Insurance Portability and Accountability Act permits disclosures of PHI for the purpose of treatment, payment, and healthcare operations but other disclosures of PHI are generally prohibited unless authorization is obtained from a patient. OCR launched an investigation of St. Joseph’s Medical Center on April 20, 2020, pursuant to the publication of an article in the media by a reporter from the Associated Press (AP). Based on the information in the article it appeared that the reporter had been allowed to observe three patients who were being treated for COVID-19. The article included information about the medical center’s response to the COVID-19 public health...
IT Security Company COO Pleads Guilty to Conducting Cyberattack to Win Business
The Chief Operating Officer (COO) of the Atlanta cybersecurity firm Securolytics has pled guilty to one count of intentional damage to a protected computer after masterminding a series of attacks on Gwinnett Medical Center in Georgia in an attempt to win new business. Vikas Singla was indicted by a federal grand jury on June 8, 2021, for a series of attacks on Gwinnett Medical Center in Duluth and Lawrenceville, GA. The September 2018 attacks disrupted the medical center’s phone and network printer services, data was stolen from a Hologic R2 digitizing device, and the attacks resulted in damage being caused to 10 protected computers. According to the indictment, Singla was aided and abetted by other (unnamed) individuals in attacks that were conducted for financial gain and commercial advantage. Singla was charged with 17 counts of causing damage to a protected computer and one count of information theft and faced a maximum jail term of 10 years for each of the damaging a protected computer counts and a maximum of 5 years in jail for the theft of data count. Singla initially...
Is Square HIPAA Compliant?
Square is HIPAA compliant for some services offered by the company and will enter into a Business Associate Agreement for these services; but, if a covered entity uses Square solely as a payment processor, it is not necessary for Square to be HIPAA compliant or enter into a Business Associate Agreement. Square is a multi-tool business solution that started life as point-of-sale payment processing system. In recent years, it has extended its services to include an ecommerce platform, team management software, payroll services, and much more. In December 2021, the company changed its name to Block, but still provides services under the Square brand. For HIPAA covered entities wishing to use Square´s services, the issue of is Square HIPAA compliant is a little complicated because, when a covered entity only uses Square for its payment processing services, compliance with HIPAA is not required. This is because financial institutions are exempted from HIPAA compliance when processing payments for health plan premiums or health care. This exemption appears in the original 1996 text of...



