OCR Issues Telehealth Guidance for Providers and Patients
The HHS’ Office for Civil Rights has issued new guidance for healthcare providers to help them educate patients about privacy and security risks when using remote communications technologies for telehealth visits and recommendations for patients on how they can protect and secure their health information. During the pandemic, healthcare providers massively expanded their telehealth services to ensure that patients could access the medical services they needed while reducing the risk of contracting COVID-19. OCR issued a Notice of Enforcement Discretion covering the good faith provision of telehealth services to make it easier for healthcare providers to provide telehealth services during the pandemic by using non-public-facing communications platforms that are not fully HIPAA compliant, such as platforms where vendors would not enter into business associate agreements. Now that the COVID-19 public health emergency has been declared over, OCR’s telehealth Notice of Enforcement Discretion has expired; however, OCR continues to support telehealth services, which have proven popular...
236,000 Individuals Affected by Fairfax Oral and Maxillofacial Surgery Ransomware Attack
Fairfax Oral and Maxillofacial Surgery in Virginia has confirmed that the protected health information of up to 235,931 individuals was potentially compromised in a ransomware attack in May 2023. The security incident was detected on May 16, 2023, when files were encrypted on its systems. The forensic investigation determined that an unauthorized third party had access to its network between May 15 and May 16, 2023. According to the breach notification submitted to the Maine Attorney General, the investigation did not find any evidence of data theft, although the possibility that files were stolen could not be ruled out. The review of the files on the affected parts of the network determined they contained information such as names, driver’s license numbers, health insurance information, medical history information, and for some individuals, Social Security numbers. Fairfax Oral and Maxillofacial Surgery said it has taken steps to reduce the risk of this type of incident occurring in the future, including enhancing its technical security measures. A complimentary one-year...
The Chattanooga Heart Institute Doubles 2023 Cyberattack Victim Count
The Chattanooga Heart Institute in Tennessee has confirmed that the protected health information of 411,383 individuals was compromised in a cyberattack that was discovered on April 17, 2023. On July 28, 2023, the Chattanooga Heart Institute notified the HHS’ Office for Civil Rights and the Maine attorney general about the cyberattack, which was thought to have involved the protected health information of 170,450 individuals. A supplemental breach notification has now been sent to the Maine Attorney General, confirming the data breach was more extensive than the initial investigation suggested. The investigation into the attack is ongoing, but it has now been confirmed that an unauthorized third party had access to its network between March 8 and March 16, 2023, and exfiltrated files containing patients’ protected health information. While its electronic medical record system remained secure, files were accessed and exfiltrated that contained information such as names, addresses, email addresses, phone numbers, dates of birth, Social Security numbers, driver’s license numbers,...
FBI: Plastic Surgery Offices Targeted by Extortion Groups
U.S. plastic surgery offices are being targeted by cybercriminal groups that gain access to their networks, steal data, and attempt to extort the practices and their patients, according to a recent public service announcement from the U.S. Federal Bureau of Investigation (FBI). There have been several attacks on plastic surgery providers in recent months. While ransomware may be used in these attacks, the primary purpose of the attacks is to steal sensitive patient data, which can include medical records and sensitive pre- and post-surgery photographs. Plastic surgery centers are issued with a ransom demand, payment of which is required to prevent the release of the stolen data. In some cases, sensitive patient data and images have been released online, and the threat actors have attempted to extort the patients directly. One attack on the Hollywood, CA-based plastic surgeon, Gary Motykie, M.D. in May 2023, required payment of a $2.5 million ransom to prevent the release of the stolen data. Some of the practice’s patients were contacted directly and told to pay to have their...
Healthcare Clearinghouse Settles Multi-state HIPAA Investigation for $1.4 Million
Inmediata has agreed to a $1.4 million settlement to resolve a multi-state investigation of potential violations of the Health Insurance Portability and Accountability Act (HIPAA) and state breach notification laws. On January 15, 2019, the Department of Health and Human Services’ Office for Civil Rights (OCR) notified the Puerto Rico-based healthcare clearinghouse that a server containing the protected health information that it maintained had not been properly secured, resulting in files being indexed by search engines that could be found, accessed, and downloaded by anyone with Internet access. The files on the server contained the protected health information of 1,565,338 individuals and some of those files dated as far back as May 2016. The HIPAA Breach Notification Rule requires HIPAA-covered entities to issue notifications to individuals affected by a data breach without undue delay and no later than 60 days from the discovery of a data breach. Despite being notified about the breach by OCR, the primary HIPAA regulator, Inmediata waited three months to mail notification...



