The Chattanooga Heart Institute Doubles 2023 Cyberattack Victim Count
The Chattanooga Heart Institute in Tennessee has confirmed that the protected health information of 411,383 individuals was compromised in a cyberattack that was discovered on April 17, 2023. On July 28, 2023, the Chattanooga Heart Institute notified the HHS’ Office for Civil Rights and the Maine attorney general about the cyberattack, which was thought to have involved the protected health information of 170,450 individuals. A supplemental breach notification has now been sent to the Maine Attorney General, confirming the data breach was more extensive than the initial investigation suggested. The investigation into the attack is ongoing, but it has now been confirmed that an unauthorized third party had access to its network between March 8 and March 16, 2023, and exfiltrated files containing patients’ protected health information. While its electronic medical record system remained secure, files were accessed and exfiltrated that contained information such as names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, driver’s license numbers,...
FBI: Plastic Surgery Offices Targeted by Extortion Groups
U.S. plastic surgery offices are being targeted by cybercriminal groups that gain access to their networks, steal data, and attempt to extort the practices and their patients, according to a recent public service announcement from the U.S. Federal Bureau of Investigation (FBI). There have been several attacks on plastic surgery providers in recent months. While ransomware may be used in these attacks, the primary purpose of the attacks is to steal sensitive patient data, which can include medical records and sensitive pre- and post-surgery photographs. Plastic surgery centers are issued with a ransom demand, payment of which is required to prevent the release of the stolen data. In some cases, sensitive patient data and images have been released online, and the threat actors have attempted to extort the patients directly. One attack on the Hollywood, CA-based plastic surgeon, Gary Motykie, M.D. in May 2023, required payment of a $2.5 million ransom to prevent the release of the stolen data. Some of the practice’s patients were contacted directly and told to pay to have their...
Healthcare Clearinghouse Settles Multi-state HIPAA Investigation for $1.4 Million
Inmediata has agreed to a $1.4 million settlement to resolve a multi-state investigation of potential violations of the Health Insurance Portability and Accountability Act (HIPAA) and state breach notification laws. On January 15, 2019, the Department of Health and Human Services’ Office for Civil Rights (OCR) notified the Puerto Rico-based healthcare clearinghouse that a server containing the protected health information that it maintained had not been properly secured, resulting in files being indexed by search engines that could be found, accessed, and downloaded by anyone with Internet access. The files on the server contained the protected health information of 1,565,338 individuals and some of those files dated as far back as May 2016. The HIPAA Breach Notification Rule requires HIPAA-covered entities to issue notifications to individuals affected by a data breach without undue delay and no later than 60 days from the discovery of a data breach. Despite being notified about the breach by OCR, the primary HIPAA regulator, Inmediata waited three months to mail notification...
What is OSHA Certification?
OSHA certification is a recognition workers obtain for completing courses in OSHA’s Safety and Health Fundamentals Program. Some OSHA certification courses are designed to teach general workplace safety, while others may be geared towards specific hazards or specific roles. Examples include: Job Hazard Analysis Health Hazard Awareness Electrical Standards Industrial Hygiene Machinery and Machine Guarding Standards Permit-Required Confined Space Entry Bloodborne Pathogen Exposure Control Occupational Noise Exposure Hazards Training Guidelines for Safe Patient Handling Fall Hazard Awareness for the Construction Industry How to Obtain OSHA Certification in the Fundamentals Program OSHA’s Safety and Health Fundamentals Program awards certificates to participants who complete a minimum of seven courses. The courses vary in length from 4 hours up to 35 hours, and participants must complete at least 68 contact hours of training for a construction or general industry certificate, or 77 contact hours of training for a maritime certificate. The courses are run at OSHA Training...
Governor Newsom Signs California Delete Act into Law
The California Delete Act enables state residents to request that data brokers delete all personal data maintained about them via a centralized database maintained on the CPPA website rather than having to make a request to each data broker in California. The Act also requires data brokers to visit the database at least once every 45 days to review and process new deletion requests. On October 10, 2023, California Governor Gavin Newsom signed the Delete Act (Senate Bill 362) into law. The bill was introduced in April 2023 by Senator Josh Becker to give California residents greater control over their personal information and how it is used by data brokers. Data brokers sell millions of consumers’ data points to the highest bidder. That information includes purchasing data, which can be accessed by retailers and used to serve targeted ads. More sensitive information may also be collected and sold, such as geolocation information and even reproductive health information. The new law will allow state residents to request that data brokers delete their personal data and/or forbid them...



