What to do if Accused of a HIPAA Violation
What you should do if accused of a HIPAA violation can depend on the nature of the violation, whether you work for an organization covered by HIPAA, what your role in the organization is, who is making the accusation, and what their role is. Whatever the circumstances, it is important that you do not ignore the accusation; and, if in any doubt about its validity, seek advice. Individuals and organizations can be accused of a HIPAA violation in multiple circumstances. For example, a trainee nurse could be advised by a senior colleague that something they have unwittingly done is a violation of HIPAA, an IT Department could be alerted to software violating HIPAA by a HIPAA Security Officer, or a covered entity could be accused of a HIPAA violation by a patient who has been unable to obtain a copy of their PHI in a timely manner. Further accusations of HIPAA violations can originate from reliable sources such as HHS´ Office for Civil Rights, or from unreliable sources such as a blog post written by an author who does not understand what HIPAA is or who it applies to. Indeed,...
A Federal Privacy Law is Critical to Effective AI Governance
On October 30, 2023, President Biden announced an executive order that establishes new standards to ensure the safe, secure, and trustworthy development of Artificial Intelligence. The executive order requires developers of AI systems to share their safety test results with the U.S. government to ensure the systems are safe and trustworthy before they are made available to the public. The executive order calls for federal agencies to develop AI safety standards, tools, and tests, including strong new standards for biological synthesis screening to protect against the risks of AI being used to engineer dangerous biological materials. The executive order requires standards and best practices to be established for detecting AI-generated content and authenticating official content and requests the Department of Commerce develop guidance on watermarking products that have AI-generated content. President Biden has also ordered an advanced cybersecurity program to be established to develop AI tools to find and fix vulnerabilities in critical software. President Biden Calls for Federal...
Warren General Hospital Data Breach Affects 169,000 Patients
Data breaches have recently been reported by Warren General Hospital in Pennsylvania, Southwest Behavioral Health Center in Utah, CareTree in Illinois, and the Medical University of South Carolina. Warren General Hospital Data Breach On November 9, 2023, Warren General Hospital (WGH) in Warren, PA, announced it had fallen victim to a cyberattack that potentially affected the confidential information of current and former patients and employees. Suspicious activity was detected within its network on September 24, 2023. Assisted by third-party cybersecurity experts, WGH determined that an unauthorized actor had access to its network between September 15, 2023, and September 23, 2023, and during that time, downloaded files from its network. The review of the files confirmed they contained names, in combination with one or more of the following: address, date of birth, Social Security number, financial account information, payment card information, health insurance claims information, and medical information, which may have included diagnosis, medications, lab results, and other...
HC3 Warns HPH Sector About Critical FortiSIEM Vulnerability and Ongoing Emotet Malware Threat
The Health Sector Cybersecurity Coordination Center (HC3) has warned healthcare organizations that use Fortinet’s FortiSIEM platform to patch a critical vulnerability that is likely to be targeted by malicious actors and has issued a threat brief on Emotet malware. FortiSIEM Command Injection Vulnerability – CVE-2023-36553 A critical vulnerability has been identified by Fortinet in its FortiSIEM platform. The vulnerability has been assigned a CVSS v3.1 severity score of 9.8 out of 10 and can be exploited remotely by malicious actors to execute arbitrary commands. The flaw is related to a bug discovered and patched by Fortinet in October 2023 – CVE-2023-34992. While there have been no known instances of the vulnerability being exploited in attacks, Fortinet vulnerabilities are actively targeted by malicious actors and exploitation of the flaw is likely. “An improper neutralization of special elements used in an OS command vulnerability in FortiSIEM report server may allow a remote unauthenticated attacker to execute unauthorized commands via crafted API requests,”...
Daviess Community Hospital Investigating Potential Cyberattack
Daviess Community Hospital, an Ascension St. Vincent affiliated hospital in Washington, IN, has recently announced that it has launched an investigation after being notified by the U.S. Department of Homeland Security (DHS) about a possible security breach. According to the DHS, a security issue was identified during routine monitoring which may have been exploited by cyber actors. Hospital CEO, Tracy Conway, said all internal systems have been shut down while the incident is investigated by a third-party digital forensics firm. Conway said no evidence has been found to date to indicate unauthorized access to its network or patient data, and no ransom demand has been received by the hospital. Disruption has been caused due to IT systems being taken offline, including phone lines to outpatient clinics and email, and the hospital has effectively been temporarily non-computerized. As a result, services have been limited until systems are restored and some appointments have been cancelled and will have to be rescheduled. The biggest impact is on radiology, as it is not possible to send...



