Plaza Radiology Data Breach Affects Up to 569,000 Patients
Plaza Radiology, which does business as Chattanooga Imaging across several locations in Tennessee and North Georgia, has suffered a cyberattack and data breach that has affected up to 569,000 patients. Plaza Radiology identified the cyberattack on October 21, 2023, but did not disclose any details about the nature of the attack, other than stating that the initial results of the forensic investigation confirmed there had been unauthorized access to a small number of files on its network that contained patient information. The analysis of the results from the forensic investigation is ongoing and, at this stage, there have been no reports of any actual or attempted misuse of patient data. Plaza Radiology reported the data breach to the HHS’ Office for Civil Rights on December 20, 2023, and said it will be mailing individual notification letters to the affected patients when the specific individuals affected have been identified and the types of data involved have been determined. Legal counsel for Plaza Radiology confirmed that several steps have been taken in response to the...
Florida Bill Seeks Safe Harbor for Organizations with Robust Cybersecurity Programs
Healthcare organizations and businesses in Florida could soon be given protection against data breach lawsuits if they implement and maintain cybersecurity measures that meet government and industry standards. The Florida Cybersecurity Incident Liability Act (H.B 473) has been introduced in the Florida legislature and aims to introduce a “safe harbor” that limits liability for all businesses that implement reasonable and appropriate cybersecurity measures that meet industry standards and cybersecurity frameworks. Businesses can make significant investments in cybersecurity to protect their networks and sensitive data from unauthorized access, but the sophisticated nature of cyber threats means that cyberattacks may still succeed. It is now common for multiple lawsuits to be filed over data breaches that allege a failure to implement appropriate cybersecurity measures, irrespective of the cybersecurity measures that have been implemented. The Florida Cybersecurity Incident Liability Act is intended to provide businesses with a legal defense against tort claims in data breach...
Is Salesforce HIPAA Compliant?
Salesforce can be used in a HIPAA compliant manner provided uses and disclosures of PHI are limited to services covered by Salesforce’s Business Associate Agreement and that the restrictions to each covered service are complied with. It is also important to be aware that Salesforce’s Business Associate Agreement does not apply to third party integrations with access to PHI. Salesforce is a well-known Customer Relationship Management (CRM) service that facilitates communications between businesses and customers. Through the “marketing cloud”, Salesforce offers products for customer service, data analytics, and marketing, and developers can also build apps on the Salesforce platform. By default, there are a number of features in Salesforce that support its use in a HIPAA-compliant manner. Salesforce has a minimum standard security protocol with a 128- bit encryption key and requires an HTTPS connection – both of which are steps towards protecting data in accordance with the HIPAA Security Rule. However, there are some compliance issues with certain products and services. For...
Record Numbers Enroll in Affordable Care Act Individual Marketplace Plans
The Centers for Medicare and Medicaid Services (CMS) has announced record enrollments in Affordable Care Act (ACA) individual marketplace plans for the second year in a row. Last year, a new record was set with 16.3 million individuals signing up for individual market health insurance coverage through the Marketplaces and there was a 30% increase from that record to 21.3 million individuals signing up for 2024. Those figures do not include data from four states and the District of Columbia, which keep enrollment open until January 31, 2024. The total includes 5 million consumers who are new to Marketplaces for 2024 and 16.3 million individuals who had active 2023 coverage and returned to their Marketplaces to renew their plan or select a new one for 2024. There are several factors that have helped drive the increase in people signing up for coverage. Lower premiums and higher tax credits have helped make coverage more affordable for many individuals, the “family glitch” has been fixed, which has made coverage more affordable for families, and investment funding has continued to be...
The Benefits of Outsourced Healthcare Compliance
Outsourced healthcare compliance is when external experts or agencies take responsibility for some of an organization’s compliance obligations – either working inhouse as a separate compliance unit, working inhouse as a consultant to a compliance team, or working remotely via healthcare compliance software. They can also work as outsourced compliance experts for one particular regulation (i.e., HIPAA), or one element of multiple regulations (i.e., workforce training). Outsourced healthcare compliance services can perform a wide range of compliance tasks, including risk assessments, policy development, training programs, audits, and ongoing compliance monitoring. By outsourcing these tasks, healthcare organizations can leverage specialized knowledge and experience not readily available in-house or lacking the resources to keep up to date with changes to federal, state, and industry regulations. The Benefits of Outsourcing Healthcare Compliance Outsourcing healthcare compliance has the primary benefit of enabling organizations to concentrate on core healthcare operations while...



