ProSmile Holdings Notifies Patients About July 2022 Data Breach
ProSmile Holdings, LLC, a New Jersey dental service organization, started notifying patients on December 22, 2023, about a breach of its email environment. Suspicious activity was detected in July 2022, and a third-party cybersecurity company was engaged to investigate the unauthorized activity and determine if any sensitive data had been exposed or compromised. ProSmile Holdings was notified on December 1, 2022, that numerous email accounts had been compromised and accessed without authorization, and personal and protected health information may have been accessed or acquired. On January 27, 2023, ProSmile Holdings engaged a vendor to conduct a review of the affected files, and the review was completed on November 29, 2023. The compromised information included names, dates of birth, Social Security numbers, driver’s license or other state identification card numbers, financial account numbers, payment card numbers, medical treatment information, diagnosis or clinical information, provider information, prescription information, and health insurance information. ProSmile Holdings...
EHR Interoperability
The transition from paper files and charts to electronic health records (EHRs) promised to transform healthcare, but without full EHR interoperability the full potential of EHRs cannot be achieved. The main benefits of EHRs are to ensure all people who need access to patient information can view patient data when and where they need it. EHRs allow efficient exchange of healthcare data and allow healthcare organizations to improve efficiency and productivity. With a central repository for all patient information, clinicians can always act on up to date information, which reduces the potential for medical errors and improves patient safety. Even though implementing EHRs can cost many millions of dollars, a great deal of money can be saved through improvements in efficiency and productivity over time. Unfortunately, while EHRs have been adopted by most healthcare organizations, the EHRs used by each are often different which makes data exchange problematic. While data is stored in electronic format, transferring that information between two different systems can be far from...
Pan-American Life Insurance Group Reports 105,000-Record Data Breach
Pan-American Life Insurance Group, Inc. (PALIG) has recently confirmed that it was one of the victims of the Clop hacking group, which exploited a zero-day vulnerability in Progress Software’s MOVEit Transfer file transfer solution in late May 2023. PALIG was notified about the vulnerability by Progress Software and immediately disabled to software until the patch could be applied. The patch was applied, and steps were taken to improve the security of its systems. At the same time, an investigation was launched to determine if the vulnerability had been exploited, and that proved to be the case. On October 5, 2023, PALIG determined that files had been removed from the MOVEit server that contained protected health information including names, addresses, Social Security numbers, dates of birth, driver’s license numbers, contact information, medical and medical benefits information, subscriber numbers, certain biometric data, and financial account and credit card information. PALIG has now notified those individuals and has offered complimentary credit monitoring services. PALIG has...
HIPAA Compliant Messaging App
What is a HIPAA Compliant Messaging App? A HIPAA compliant messaging app is an integral part of a secure messaging solution that can help healthcare organizations and other covered entities comply with the technical requirements of the HIPAA Security Rule. Having a similar interface and providing the same functionality as a commercially available messaging app, a HIPAA compliant messaging app has additional safeguards in place to protect the integrity of Protected Health Information (PHI) and prevent unauthorized disclosures. Messaging apps for HIPAA compliant texting can be downloaded onto any desktop computer or mobile device, making them the ideal replacement for unsecure channels of communication such as pagers, SMS and email – particularly in a healthcare environment that encourages a BYOD policy. What´s Different about Messaging Apps for HIPAA Compliant Texting? From a user point of view, there are few differences between messaging apps for HIPAA compliant texting and commercially available messaging apps. Once logged in, users can send text messages, attach images and...
Is Google Cloud Platform HIPAA Compliant?
Google Cloud Platform is HIPAA compliant for “covered products”, provided the products are configured to support HIPAA compliance and organizations accept the terms of Google’s Business Associate Addendum – including those that relate to the Google Cloud Platform Shared Responsibility Model. The Google Cloud Platform is one of the leading cloud service providers for the healthcare industry due its easy integration with other Google Services (i.e., Google Workspace), strong data analytics capabilities, and price competitiveness. The platform also supports more open source integrations than its competitors, which may prove useful as CMS accelerates its drive towards interoperability. When Google Cloud Platform products are used to create, collect, store, or transmit Protected Health Information (PHI), the products used must be capable of protecting the confidentiality, integrity, and availability of PHI. Not all Google Cloud Platform products have adequate capabilities to protect PHI, so Google separates those that do and refers to them as “covered products”. The list of covered...



