Refuah Health Center Pays $450K HIPAA Fine; Agrees to $1.2 Million Cybersecurity Investment
New York Attorney General Letitia James has announced that an agreement has been reached with Refuah Health Center Inc. to resolve allegations it failed to maintain reasonable and appropriate cybersecurity controls to protect and limit access to sensitive patient data stored on its network. Under the terms of the agreement, Refuah Health Center has agreed to invest $1.2 million in cybersecurity and will pay $450,000 in penalties and costs. The NY AG launched an investigation of Refuah Health Center after being notified about a May 2021 ransomware attack that compromised the personal and protected health information of 260,740 individuals, including 175,077 New Yorkers. The Lorenz ransomware group gained access to internal systems in late May 2021, initially compromising a system that was used for viewing videos from internal cameras monitoring its facilities. That system was only protected with a four-digit code. The attackers stole administrator credentials that were used by a former IT vendor to remotely access the network. The credentials had not been changed for 11 years and...
HIPAA vs HITRUST
In the context of complying with HIPAA, HITRUST is one of the most commonly adopted Cyber Security Frameworks (CSFs) alongside the likes of NIST SP 800-66r2, ISO/IEC 27001, and AICPA’s System and Organization Controls 2 (SOC 2). In addition to supporting compliance with HIPAA, HITRUST supports compliance with many other federal and state laws, and can be customized to support compliance with some local or industry specific regulations. The HITRUST Alliance is a collaboration between several high profile organizations in the healthcare, technology, and information security industries. In 2007, the Alliance released the first HITRUST Cyber Security Framework (CSF) in response to the increasing number of threats to healthcare data and the increasing number of federal and state compliance requirements (i.e., HIPAA, the Texas Medical Records Privacy Act, etc.). Since 2007, the Alliance has updated the Framework and expanded the control categories and implementation specifications in response to changes to “authoritative sources” (i.e., NIST, ISO, etc.) and new rules and regulations. The...
How to Secure Healthcare Data
HIPAA-regulated entities must ensure that protected health information (PHI) is safeguarded against unauthorized access, but many covered entities and business associates do not know how to secure healthcare data properly and leave sensitive information exposed. The HIPAA Security Rule The HIPAA Security Rule established national standards to protect individuals’ electronic personal health information (ePHI) that is created, received, used, or maintained by HIPAA-covered entities and their business associates. The Security Rule requires appropriate administrative, physical, and technical safeguards to be implemented to ensure the confidentiality, integrity, and availability of ePHI. All regulated entities must assess security risks throughout their organziation and implement a range of different safeguards to protect against unauthorized ePHI access, and ensure all risks are reduced to a low and acceptable level. How to Protect Healthcare Data and Comply with HIPAA The HIPAA Security Rule was developed to be flexible to ensure that it applies to covered entities of all types...
Orrick, Herrington & Sutcliffe Data Breach Affected 637,000 Individuals
The Californian law firm Orrick, Herrington & Sutcliffe has recently confirmed that a cyberattack that was detected in March 2023 has affected more than 637,000 individuals. The Orrick, Herrington & Sutcliffe data breach was reported to the HHS’ Office for Civil Rights on June 30, 2023, as affecting 40,823 individuals, then on July 20, 2023, the law firm notified the Maine Attorney General that the breach had affected 152,818 individuals. An updated notification was sent to the Maine Attorney General on August 18, 2023, with an increased total of 461,100 affected individuals. Another update was issued on December 29, 2023, with an increased total of 637,620 individuals. This appears to be the final total, as the law firm said it does not anticipate providing notifications on behalf of any further affected businesses. The services provided by Orrick, Herrington & Sutcliffe include legal counsel for companies that have suffered security incidents and data breaches, including handling regulatory requirements such as notifications to state authorities and the individuals...
Email Accounts Compromised at The Foleck Center, Mountain Dermatology Specialists
The Foleck Center in Virginia and Mountain Dermatology Specialists in Colorado have discovered unauthorized access to employee email accounts and the exposure of patient data. The Foleck Center Discovers Forwarding Rule on Employee Email Account The Foleck Center, a provider of cosmetic, implant, and general dentistry services in Norfolk, Hampton, and Virginia Beach, has recently notified 6,965 patients that some of their protected health information has been acquired by an unauthorized individual. On October 26, 2023, The Foleck Center was made aware that one of its employees had a forwarding rule on their email account that sent emails to a Gmail account. The Foleck Center contacted its managed IT service provider, which performed a forensic investigation. Rather than this being a HIPAA violation by the employee, the forensic investigation revealed that an unauthorized third party had gained access to the email account and set up the forwarding rule on September 4, 2023. Copies of all emails sent to the employee’s account between September 4, 2023, and October 31, 2023, were...



