OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2024
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has submitted its annual reports to Congress on compliance with the Health Insurance Portability and Accountability Act (HIPAA) and breaches of unsecured protected health information for calendar year 2024. The reports are a requirement of the Health Information Technology for Economic and Clinical Health (HITECH) Act and provide a snapshot of the state of compliance in healthcare, the actions taken by OCR in response to potential noncompliance, and the extent to which sensitive health information is being exposed or stolen. The reports to Congress are based on the number of data breaches that occurred in each calendar year, not the year in which the data breach was reported. In calendar year 2024, OCR received 742 reports of data breaches affecting 500 or more individuals; however, only 663 reports related to breaches that occurred in 2024. 2023 was a particularly bad year for large healthcare data breaches. In its previous reports to Congress, OCR reported that 732 large data breaches occurred in...
Mission Community Hospital Pays $1.55M to Settle Data Breach Lawsuit
Deanco Healthcare, LLC, the operator of Mission Community Hospital, an acute care hospital serving patients in the San Fernando Valley in California, has agreed to a settlement to resolve claims stemming from a cyberattack that was discovered by the hospital on May 1, 2023. According to the forensic investigation, the unauthorized access started the same day, and while the attack was quickly identified and contained, the threat actor exfiltrated files containing patient data such as names, addresses, dates of birth, Social Security numbers, driver’s license numbers, and financial account information. The Ransomhouse ransomware group took responsibility for the attack and claimed to have exfiltrated around 2.5 terabytes of data. The data breach was reported to the HHS’ Office for Civil Rights as affecting 269,547 individuals. Two class action lawsuits were filed in response to the data breach in the Superior Court of California for the County of Los Angeles, which were consolidated into a single action – Concepcion et al. v. Deanco Healthcare – as they had overlapping claims....
45 CFR 164.308(a)(5) Security Awareness and Training
45 CFR 164.308(a)(5) is the administrative safeguard provision of the HIPAA Security Rule that mandates security awareness and training for all workforce members of covered entities and business associates, establishing that organizations must “implement a security awareness and training program for all members of its workforce (including management)” and must address protection from malicious software, log-in monitoring, and password management as addressable implementation specifications within that program. The provision sits within the administrative safeguards category of the HIPAA Security Rule, which governs the policies, procedures, and workforce management activities that protect electronic Protected Health Information. Its placement in the administrative safeguards framework means that security awareness training is not a supplementary activity or a compliance courtesy. It is one of the required mechanisms through which an organization demonstrates that it manages its workforce’s relationship with electronic Protected Health Information in a controlled...
Home Healthcare Agency Owner Facing Decades in Jail for $1.6M Medicare Fraud Scheme
The owner and operator of a Michigan home health care company has been convicted of five counts of healthcare fraud and four counts of paying illegal healthcare kickbacks and now faces decades in jail. Ruby Scott, 55, of Farmington Hills, Michigan, the owner and operator of Delta Home Health Care LLC, was alleged to have operated a fraud scheme that caused more than $1.6 million in losses to the Medicare program. From 2018 to 2021, Scott was alleged to have fraudulently billed Medicare for home health services using stolen patient records. Scott bribed a discharge nurse at a Detroit hospital to identify Medicare patients and fax their medical records to Delta Home Health Care. Scott developed a kickback relationship with the nurse, paying approximately $300 for each set of patient records that were successfully used to bill Medicare. The discharge nurse was paid more than $130,000 via PayPal, CashApp, cash, and check for providing the records. Scott used confidential diagnostic and personal information to bill Medicare for home healthcare services for the patients, falsely...
Datavant Group to Pay $900,000 to Settle Class Action Data Breach Lawsuit
A settlement has been agreed to resolve a class action lawsuit against Ciox Health, which does business as Datavant Group, an Arizona-based health IT company, over a May 2024 email-related data breach. Suspicious activity was identified within an employee’s email account on May 9, 2024. The forensic investigation confirmed that an unauthorized individual had access to the account between May 8 and May 9, 2024. Access to the account was gained after an employee responded to a phishing email. The breach was reported to the HHS’ Office for Civil Rights as affecting 320,702 individuals. Data potentially compromised in the incident included names, dates of birth, addresses, contact information, Social Security numbers, financial account information, driver’s license numbers, passport numbers, and health information. A lawsuit was filed in response to the data breach – Jackson v. Ciox Health, LLC d/b/a Datavant Group – in the United States District Court for the District of Arizona. The lawsuit alleged that the defendant failed to implement sufficient security measures to protect...



