CMS Issues Clinical Laboratory Improvement Amendments of 1988 Final Rule
The Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) has issued a final rule that updates the Clinical Laboratory Improvement Amendments of 1988 (CLIA) fees, amends provisions governing alternative sanctions, changes CLIA histocompatibility and personnel requirements, and clarifies CLIA regulations. The purpose of CLIA is to ensure the accuracy and reliability of laboratory testing. All laboratory testing performed on humans – apart from research – in the United States is regulated by the CMS through CLIA. Currently, around 320,000 laboratory entities in the United States are regulated by CLIA, from small labs in physician offices to large independent laboratories. The final rule authorizes new fees to cover administrative costs for surveys, including follow-up, specialties, and complaint surveys, as well as desk reviews and certificate replacements. Current fees have been increased by 18% and the cost of the Certificate of Waiver laboratories certificate fee has been increased by $25. The final rule implements changes to the...
Protect Hospital Computers from Malware
What is Malware? Before explaining how to protect hospital computers from malware, it is advisable to resolve any confusion about what “malware” actually is. Malware is an abbreviation of “malicious software” – a term used to describe any hostile or intrusive software that disrupts computer operations, gains administrator access to computer systems, gathers sensitive information about the computer user or displays unwanted advertising. Legally described as a “computer contaminant”, malware is an umbrella term for computer viruses, adware, spyware, ransomware, worms and trojans – trojans typically being disguised as, or embedded in, non-malicious software. Malware is often detected by security software once it has been installed. However, by the time the computer contaminant is discovered, it is often too late and the consequences of failing to protect hospital computers from malware have already begun to manifest. What Are the Risks to Hospital Computers from Malware? The risks to hospital computers from malware vary according to the type of malware it is and its level...
Healthcare Data Breaches Due to Phishing
Due to way in which breaches of unsecured PHI are notified to HHS’ Office for Civil Rights, it is difficult to ascertain the true scale of healthcare data breaches due to phishing, as an interaction with a phishing email may have been a precursor for the notifiable event. However, there is evidence to suggest healthcare data breaches due to phishing are on the increase. Phishing is a leading cause of healthcare data breaches and attacks appear to be increasing. According to the 2022 IBM X-Force Threat Intelligence Index, phishing is the leading infection vector in cyberattacks. In 2021, four out of 10 attacks started with phishing, which is an increase of 33% from 2021. The Anti-Phishing Working Group (APWG) said phishing attacks have doubled since 2020. Phishing attacks provide cyber threat actors with an easy way to reach their intended targets and the attacks work because a small but significant number of emails attract a click. According to the 2022 Verizon Data Breach Investigations (DBIR) Report, phishing simulation data shows that 2.9% of phishing emails are clicked, on...
Interoperability in Healthcare
Interoperability in healthcare means making sure information technology systems and software solutions work together seamlessly to exchange, interpret, and use data. Interoperability ensures that health data collected in one system can be made available for use in another, which can be achieved through the adoption of standards and use of data exchange models. When there is interoperability in healthcare, data can be shared internally with all people who need access to healthcare information and also externally with other healthcare providers and authorized third parties, irrespective of the systems or software they use. Unfortunately, many software solutions are developed in silos which makes it difficult for data to easily be transferred to other solutions and systems. When data exchange is possible, it often involves come manual processes, data transfer is slow, and communications are often disjointed. Interoperability in healthcare should see healthcare information systems working seamlessly together, within and across organizational boundaries. It should be possible for...
Is Google Slides HIPAA Compliant?
Google Slides is HIPAA compliant and can be used to create slides and presentations containing Protected Health Information provided the service is used as part of a Google Workspace plan covered by a Business Associate Addendum and configured to restrict document sharing. It will also be necessary to include the compliant use of Google Forms in workforce training. Google Slides is a presentation editor that allows users to create slide shows, training materials, and project presentations. Because of its ease of use, Google Slides is an ideal option for users who do not regularly create slide shows or presentations and do not have a software package that offers the same functionality. Google Slides is available free of charge for personal use but personal users cannot use Google Slides in compliance with HIPAA. Using Google Slides in Compliance with HIPAA HIPAA covered entities and business associates that want to take advantage of Google Slides’ functionality can do so without any HIPAA compliance concerns provided Protected Health Information (PHI) is not used or disclosed in the...



