New York AG Settles Data Breach Investigation of U.S. Radiology Specialists for $450,000
New York Attorney General, Letitia James, has announced a $450,000 settlement with U.S. Radiology Specialists Inc. to resolve allegations it failed to protect patients’ personal and health information. U.S. Radiology Specialists is one of the largest private radiology groups in the country and acts as a service provider for healthcare facilities throughout the United States. It also partners with other radiology groups, including the Windsong Radiology Group, which operates 6 facilities in Western New York. Windsong, like other partner companies, relies on U.S. Radiology Specialists for numerous services, including network management and protection. The Office of the Attorney General of the State of New York opened an investigation of U.S. Radiology Specialists into a large data breach that was reported in 2021 to determine whether it was caused by a failure to comply with the Health Insurance Portability and Accountability Act (HIPAA) and state laws. U.S. Radiology Specialists protected the networks of its partners with a SonicWall firewall. On January 22, 2021, SonicWall alerted...
HHS-OIG Issues General Compliance Program Guidance
The Department of Health and Human Services (HHS) Office of Inspector General (OIG) has published new “General Compliance Program Guidance.” In April 2023, HHS-OIG announced that it would be improving and updating its existing voluntary compliance program guidance documents, which were developed and published between 1998 and 2008. Rather than publish them in the Federal Register as it has in the past, the new guides will be added to the HHS-OIG website, the first of which is a 91-page guidance document that provides general compliance guidance, tools, and references. The General Compliance Program Guidance explains relevant Federal laws, the key Federal authorities engaged in healthcare business, and discusses general compliance risks, compliance programs, compliance program infrastructure, compliance program adaptations for small and large entities, and other compliance considerations. The document also includes information on healthcare fraud enforcement by HHS-OIG and other standards. The guidance is voluntary and nonbinding and does not create any new laws or legal...
November 8, 2023, Healthcare Data Breach Round-Up
Mulkay Cardiology Consultants at Holy Name Medical Center has recently confirmed that it fell victim to a ransomware attack. The attack was detected on September 5, 2023, when files on its network were encrypted. According to the breach notice, Mulkay was able to rebuild its systems and recover the encrypted files from backups. Third-party forensics experts were engaged to investigate the breach and determined that its systems were compromised between September 1, 2023, and September 5, 2023, and during that time, files were exfiltrated that contained personal and protected health information. The compromised information included names, addresses, dates of birth, Social Security numbers, driver’s license numbers or state IDs, medical treatment information, and health insurance information. Mulkay said it has enhanced its technical safeguards to prevent similar incidents in the future. Affected individuals have been notified and offered complimentary credit monitoring services. The breach was reported to the Maine Attorney General and HHS’ Office for Civil Rights as involving...
BlackCat Ransomware Group Claims Responsibility for Attack on Henry Schein
The BlackCat (ALPHV) ransomware group has claimed responsibility for an attack on Henry Schein, a Fortune 500 distributor of dental and medical supplies and provider of practice management software and solutions for healthcare providers. Henry Schein confirmed on October 15, 2023, that it had experienced a cybersecurity incident, which was detected on October 14, 2023. The incident affected a portion of its manufacturing and distribution business, which caused temporary disruption to its business operations. More than three weeks on and the company is still experiencing technical difficulties with its website and webshop. Third-party cybersecurity consultants have been engaged to investigate the breach and the data impact, and law enforcement has been notified. The incident is still being investigated; however, it has been determined that users of its client management software were unaffected. In a November 13, 2023, notice to its customers, Henry Schein said “We do not have all the details of what data may have been compromised. Customer and personal (sic) identifiable...
OSHA Violation Cases in Healthcare
Considering the size of the healthcare industry and the potential number of workplace hazards, there are relatively few OSHA violation cases in healthcare. For example, in the year to September 2023, the Occupational Safety and Health Administration issued 626 citations for OSHA violation cases in healthcare. The top ten reasons for citations in the health care and social assistance NAICS category (where indicated) were violations of: The bloodborne pathogen standard The hazard communication standard The respiratory protection standard The control of hazardous energy standard OSHA’s form filling requirements The formaldehyde standard OSHA’s general requirements The asbestos standard The wiring methods, components, and equipment standard. The exit route standard (maintenance, safeguards, and features) OSHA does not publish citation-by-citation information because of the volume of citations issued each year across all industries. Federal OSHA – not including state plans – issued 45,950 citations nationwide in the year to September 2023. Nonetheless, it is possible to tell from...



