Is Venmo HIPAA compliant?
Venmo is HIPAA compliant by default for receiving patient-originated payments due to an exemption for payment processors in the HIPAA Act, however, it should not be used for any other purposes due to privacy and security concerns. There are also other reasons why covered entities might want to avoid offering this payment option. There is a common misconception among some sources that Venmo should not be used by covered entities to accept payments from patients because Venmo will not sign a Business Associate Agreement. However, there is nothing in HIPAA that prevents covered entities using any service to receive patient-originate payments and – under section 1179 of the Act – financial institutions are exempt from complying with the Privacy Rule when facilitating a financial transaction. Due to the misconception about payment processors, the Department of Health and Human Services (HHS) clarified the position in the preamble to the 2013 Final Omnibus Rule. HHS stated: “The HIPAA Rules, including the business associate provisions, do not apply to banking and financial institutions...
What are OSHA Whistleblower Rewards?
OSHA whistleblower rewards are payments made to whistleblowers under certain statutes for information that leads to the prosecution of a company in violation of the statute. In no circumstances is OSHA responsible for the payment of a reward, and OSHA’s involvement in such cases is usually limited to addressing retaliation against the whistleblower. The term OSHA whistleblower rewards is a misnomer inasmuch as it implies the Occupational Safety and Health Administration (OSHA) pays whistleblowers for reporting violations of the Occupational Safety and Health Act (OSH Act). This is not the case. The only benefit to employees of reporting an OSH Act violation is to have a safer and healthier environment to work in. In the event an employer retaliates against an employee for an activity protected by §1977 of the OSH Act, the employee can make a whistleblower complaint to OSHA. The employee has to file the whistleblower complaint within 30 days of the retaliatory event if the complaint is being filed with federal OSHA. The time limit for whistleblower complaints under State OSHA Plans...
Sutter Health Confirms 84K Individuals Affected by Cyberattack on Business Associate
Sutter Health, a healthcare provider serving Northern California, has recently confirmed that patient data was compromised in a hacking incident at one of its business associates, Virgin Pulse. Virgin Pulse was contracted to provide important notices and communications to patients and was provided with patient data to fulfill that role. Virgin Pulse used Progress Software’s MOVEit Transfer file transfer tool, which had a vulnerability that was exploited by the Clop Group. Progress Software released a patch to fix the vulnerability on May 31, and Virgin Pulse said it moved quickly to apply the patch and recommended mitigation steps; however, the vulnerability had already been exploited. The vulnerability was exploited in attacks on more than 2,300 organizations and the data of more than 60 million individuals was stolen, including the data of 845,441 Sutter Health patients. Sutter Health was informed by Virgin Pulse on September 22, 2023, that it had been affected by the hack, almost 4 months after the cyberattack occurred, but did not get the final report until October 24, 2023....
Updates on Royal, LockBit 3.0, Hunters International & ALPHV Ransomware Groups
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued an updated cybersecurity advisory about Royal ransomware, which is thought to be about to shut down and rebrand. Royal ransomware first emerged in September 2022 and is thought to have split from the Conti ransomware operation, with a brief spell operating as Quantum in between. Royal ransomware has been a prolific ransomware operation, having conducted more than 350 attacks since September 2022 and has issued ransom demands in excess of $275 million, according to the FBI. Royal ransomware is a private ransomware group that has targeted organizations in healthcare and public health (HPH), education, manufacturing, and communications. The number of attacks on HPH sector organizations prompted an earlier cybersecurity advisory from CISA, the FBI, and the HHS, which shared the latest tactics, techniques, and procedures (TTPs) used by the group and Indicators of Compromise (IoCs). They have been updated in the latest advisory. In May 2023, a new ransomware variant...
Is Hotmail HIPAA Compliant?
Hotmail is not HIPAA compliant and cannot be used to collect, store, or transmit Protected Health Information because the free email service (now known as Outlook) does not support the safeguards necessary for Hotmail users to comply with HIPAA. Many healthcare organizations are unsure whether Hotmail is HIPAA compliant and whether sending protected health information via a Hotmail account can be considered a HIPAA compliant method of communication. In this post we answer the question is Hotmail HIPAA compliant, and whether the webmail service can be used to send PHI. Hotmail is a free webmail service from Microsoft that has been around since 1996. Hotmail has now been replaced with Outlook.com. In this post we will determine if Hotmail is HIPAA-compliant, but the same will apply to Outlook.com. For the purposes of this article, Hotmail and Outlook.com will be considered one and the same. HIPAA, Email and Encryption There is a common misconception that all email is HIPAA compliant. In order for any email service to be HIPAA compliant, it must incorporate security controls to...



