HIPAA Compliant SFTP Server
If FTP is required to transfer protected health information, healthcare providers, health plans, healthcare clearinghouses and business associates of HIPAA-covered entities must ensure their service provider uses a HIPAA compliant sFTP server. FTP is a convenient way of sending/receiving medical transcriptions, transmitting electronic medical records and test results, and for transferring files containing ePHI to cloud storage. However, FTP communications are not secure and file transfers can easily be intercepted. Consequently, healthcare organizations and their business associates must avoid sending any protected health information over FTP. Doing so would be a violation of the HIPAA Security Rule. HIPAA Security Standard §164.306 requires covered entities to ensure the confidentiality, integrity, and availability of ePHI is safeguarded at rest and in transit. In order to send ePHI securely, HIPAA-covered entities can use a secure FTP server. A secure FTP server uses the Secure File Transfer Protocol rather than the generic file transfer protocol to send and receive files,...
HIPAA Civil Monetary Penalty Adjustments for 2023
On October 6, 2023, the U.S. Department of Health and Human Services (HHS) published its long-expected annual inflation adjustments in the Federal Register. The inflation adjustments are effective as of October 6, 2023, and will be applied to all penalties assessed by the Office for Civil Rights (OCR) on or after this date, if the HIPAA violations occurred on or after November 2, 2015. Annual increases in inflation are authorized by the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015, which amended the Federal Civil Penalties Inflation Adjustment Act of 1990. Each year, civil monetary penalties (CMPs) are increased in line with inflation to ensure they remain an effective deterrent against non-compliance. The Office of Management and Budget (OMB) published a cost-of-living multiplier of 1.07745 for 2023 in December 2022 and required all federal agencies to update their CMPs using the multiplier by January 15, 2023. The HHS is often slow to apply the adjustments. OBM is expected to publish its 2024 multiplier in a little over two months, but no later than...
Best Practices for Creating an Email Archiving Policy
Applying best practices for creating an email archiving policy enable businesses to create a formal email archiving policy that establishes how long emails should be retained before being permanently and securely deleted to ensure compliance with federal, state, and industry regulations. Emails are considered to be just as important as written documents, and regulators and the courts do not take kindly to poor email retention practices and emails that cannot be produced when requested. Read about email retention requirements in our recent HIPAA compliant email retention solution review. If you are requested to provide emails by regulators such as the HHS’ Office for Civil Rights for an audit or compliance investigation, you receive an eDiscovery request, or there is a legal issue, the consequences of not being able to produce emails can be severe. Financial penalties may be imposed, and your organization’s reputation can be damaged. By formalizing an email archiving policy and automating the policy using an email archiving solution, you will be able to eliminate the potential for...
Blackbaud Settles Multistate Data Breach Investigation for $49.5 Million
A $49.5 million settlement has been reached between Blackbaud and 49 states and the District of Columbia to resolve allegations of insufficient data security practices and an inadequate response to its 2020 ransomware attack. Blackbaud is a Delaware corporation headquartered in Charleston, South Carolina, that provides donor relationship management software to a wide range of organizations, including healthcare providers, educational institutions, and religious and cultural organizations. On May 14, 2020, Blackbaud experienced a ransomware attack that resulted in the exfiltration of sensitive donor information. While data encryption was prevented, more than one million files were stolen in the attack, which included data from around one-quarter of its clients (13,000), including many healthcare organizations. Blackbaud publicly disclosed the ransomware attack on July 16, 2020. The impacted clients then notified their donors about the theft of their information, however, it was not until late September that Blackbaud confirmed that financial information and Social Security numbers...
HPH Sector Warned About Remote Access Software Risks
Healthcare professionals often require remote access to their networks and electronic health records, such as for providing remote patient care. While remote access tools can improve efficiency and allow secure access to data, these solutions also provide a possible entry point into healthcare networks for malicious actors, and attacks exploiting vulnerabilities in remote access solutions are on the rise. Remote access solutions include virtual private networks (VPNs) that encrypt connections between a user’s device and internal networks; remote desktop software such as Remote Desktop Protocol (RDP) and Virtual Network Computing (VNC) that allow computers to be accessed remotely by users and IT support staff; telehealth platforms that support video conferencing; and secure messaging apps, which are used to communicate securely internally and externally. Telehealth platforms and secure messaging solutions may also integrate with EHRs. All of these solutions can improve efficiency and productivity; however, they introduce risks that need to be carefully managed. Vulnerabilities in...



