Health3PT Shares Best Practices for Improving Third Party Risk Management in Healthcare
The Health 3rd Party Trust Initiative (Health3PT) has published the findings of a recent survey of HIPAA-covered entities and their business associates that explored the current state of third-party cyber risk management in healthcare and identified some of the key challenges faced by HIPAA-regulated entities. Supply chain vendors and service providers introduce risks that need to be identified, managed, and reduced to a low and acceptable level; however, the methods used to manage third-party risks are often burdensome and inadequate. According to the survey, which was conducted on 59 HIPAA-covered entities and 128 business associates, significant resources and money are committed to managing third-party risk but 68% of covered entities and 79% of business associates say third-party risk management (TPRM) processes are inefficient and 60% of HIPAA-covered entities and 72% of business associates think TPRM is not effective at preventing data breaches. 55% of healthcare organizations have experienced a data breach in the past year through a third party, and 90% of the most...
98,000 UT Southwestern Medical Center Patients Affected by MOVEit Cyberattack
UT Southwestern Medical Center (UTSW) has recently confirmed that the protected health information of 98,437 patients was stolen in a cyberattack on May 28, 2023. The Clop ransomware group exploited a zero-day vulnerability in Progress Software’s MOVEit file transfer solution, gained access to UTSW’s MOVEit server, and exfiltrated files that contained names, medical record numbers, dates of birth, medication names, medication dosages, prescribing provider names. A subset of the affected individuals also had their Social Security numbers stolen. UTSW was notified about the attack by Progress Software on May 30, 2023, and the exploited vulnerability was immediately patched. The German cybersecurity firm KonBriefing has recently announced that its data shows at least 455 organizations were attacked in this campaign, and at least 23 million individuals were affected. The Clop group has recently started posting victim data on its clear web data leak site. Family Vision of Anderson Suffers Ransomware Attack Family Vision of Anderson in South Carolina was the victim of a May 2023...
Norton Healthcare Facing Class Action Lawsuit Over BlackCat Cyberattack
Norton Healthcare, a Kentucky-based operator of more than 140 clinics and hospitals in Kentucky and Southern Indiana, is facing a class action lawsuit over a May 2023 cyberattack and data breach. Norton Healthcare has only disclosed limited information about the attack; however, the BlackCat ransomware group announced that it was behind the cyberattack and leaked some of the data stolen from Norton Healthcare on its data leak site. The stolen information included names, addresses, email addresses, dates of birth, Social Security numbers, government identification ID numbers, driver’s license numbers, payment/financial institution information, health insurance providers, medical treatment information, medical diagnoses, medications, medical images, and lab test results. The HIPAA breach was reported to the HHS’ Office for Civil Rights as affecting 501 individuals, and was later updated to 2,500,000 individuals. On July 21, 2023, a class action lawsuit was filed in U.S. District Court on behalf of plaintiff Lanisha Malone and similarly situated individuals who had their sensitive...
Majority of Americans Mistakenly Believe Health App Data is Covered by HIPAA
There is a common misconception that the Health Insurance Portability and Accountability Act (HIPAA) applies to health apps; however, the majority of health apps are not covered by HIPAA nor is the health information collected, stored, or transmitted by the apps. HIPAA applies to HIPAA-covered entities – healthcare providers, health plans, and healthcare clearinghouses – and vendors used by those entities, which are classed as business associates. While health apps may collect some of the exact same health data that is maintained by HIPAA-covered entities, the information collected by health apps is not subject to the same privacy and security standards. As such, health information collected by health apps may be transmitted to third parties, sold, or used for purposes that are not permitted under HIPAA. According to a recent ClearDATA Harris Poll survey of 2,000 U.S. adults, 68% of respondents said they were very or somewhat familiar with HIPAA, yet 81% of respondents believed that the health data collected by digital health apps is covered by HIPAA and subject to its...
What does OSHA Regulate?
The Occupational Safety and Health Administration (OSHA) is responsible for the regulation and enforcement of safety and health standards in most private and public workplaces in the United States. Key areas that OSHA regulates include: Safety Standards Hazard Communications Recordkeeping and Reporting Training and Education Inspections and Enforcement Emergency Preparedness and Response Whistleblower Protections Overview of OSHA Regulation OSHA is best known for setting and enforcing workplace safety and health standards. These standards include rules and regulations concerning the use of personal protective equipment (PPE), fall protection, and the safe handling of hazardous materials. The agency requires employers to inform and train employees about hazards in the workplace, safe handling procedures, and emergency protocols. This includes the use of Safety Data Sheets (SDSs) and the proper labeling of hazardous substances. With regard to recordkeeping and reporting, employers must maintain records of work-related injuries and illnesses, submit annual summaries of the injuries...



