OSHA Issues Citations to Florida and Wisconsin Hospitals for Health and Safety Failures
The Occupational Safety and Health Administration (OSHA) has issued citations to two hospitals over health and safety failures, resulting in almost $24,000 in fines. Florida Behavioral Health Facility Fined for Failing to Protect Workers from Workplace Violence OSHA conducted an investigation of UHS of Delaware Inc.- Wekiva Springs Center LLC, which does business as Wekiva Springs Hospital in Jacksonville, Florida, in response to an alarming number of incidents involving workplace violence. Wekiva Springs provides treatment for individuals suffering from behavioral health and substance abuse issues. OSHA visited the facility in November 2022 following reports of multiple instances where employees had been bitten, punched, kicked, scratched, and sexually assaulted. Several employees had suffered broken bones, concussions, and wounds, and had to endure regular, and often intense, incidents of workplace violence. According to OSHA, in 2022 there were 182 reports of alleged incidents of workplace violence at the hospital, and over a 6-month period, 70% of the incidents of workplace...
HSCC Publishes Coordinated Healthcare Incident Response Plan Template
The Healthcare and Public Health Sector Coordinating Council (HSCC) Cybersecurity Working Group (CWG) has published a Coordinated Healthcare Incident Response Plan (CHIRP) that can be used as a template by healthcare organizations to develop a coordinated cybersecurity incident response plan. Given the frequency of cyberattacks on the healthcare sector and the harm that these incidents can cause, it is vital for healthcare organizations to develop, implement, maintain, and test an incident response plan. In the event of a cyberattack, the incident response plan can be initiated immediately to limit the harm caused and help ensure a rapid recovery. There are several resources available on the technical response process to a cybersecurity incident, and while these resources provide guidance on the technical aspects of the response, such as detection, containment, response, and recovery, they do not deal with the impact of an attack on patient care and patient safety. Healthcare organizations have emergency plans to ensure business continuity and patient care in the event of IT...
11.27 Million HCA Healthcare Patients Affected by Recent Cyberattack
Nashville, TN-based HCA Healthcare, the largest health system in the United States with more than 180 hospitals and 2,300 healthcare sites, has announced that an unauthorized individual had obtained the protected health information of patients. The initial report from HCA Healthcare indicated more than 11 million records were involved. The breach has now been reported to the HHS’ Office for Civil Rights as affecting 11,270,000 individuals, which makes this the third-largest healthcare data breach to be reported by a HIPAA-regulated entity. Largest Healthcare Data Breaches Name of Covered Entity Year Covered Entity Type Individuals Affected Type of Breach Anthem Inc. 2015 Health Plan 78,800,000 Hacking/IT Incident American Medical Collection Agency 2019 Business Associate 26,059,725 Hacking/IT Incident HCA Healthcare 2023 Healthcare Provider 11,000,000+ Hacking/IT Incident Premera Blue Cross 2015 Health Plan 11,000,000 Hacking/IT Incident Excellus Health Plan, Inc. 2015 Health Plan 9,358,891 Hacking/IT Incident On July 10, 2023, HCA Healthcare announced that hackers had gained...
Comprehensive Data Privacy Law Passed by the Delaware Legislature
A comprehensive new data privacy law has been passed by the Delaware legislature and now awaits Delaware Governor John Charles Carney Jr.’s signature. Governor Carney is expected to sign the Personal Data Privacy Act into law and make Delaware the 12th state to introduce a comprehensive data privacy law. In contrast to the data privacy laws introduced in several other states, the Delaware Personal Data Privacy Act does not include exceptions for HIPAA-covered entities and their business associates, although the Act does have an information-level exception and does not apply to protected health information. HIPAA-regulated entities will need to ensure that they are fully compliant with the new law, although many of the requirements should not prove too challenging for organizations that are fully compliant with the HIPAA Privacy and Security Rules. The Personal Data Privacy Act gives state residents new rights over their personal data and allows them to find out about the information that is being collected about them, inspect that information, correct errors, and request the...
EU Health Sector Cyber Study Confirms Ransomware is the Leading Threat
The European Union Agency for Cybersecurity (ENISA) has published the results of its first-ever analysis of the cyber threat landscape of the health sector in the European Union (EU). ENISA mapped healthcare cyber incidents between January 2021 and March 2023 and identified the key targets of attacks, the threat actors behind them, attack trends, and the impact that cyberattacks have on the health sector. A range of healthcare entities experienced cyberattacks over the two-year study period, including health authorities, bodies and agencies, and pharma firms; however, the majority of attacks targeted healthcare providers (53%), especially hospitals (42%). Over the two years, ENISA analyzed 215 publicly reported cyber incidents in the EU and neighboring countries, 208 of which were cyberattacks on the health sector, and the analysis included 5 reports of identified vulnerabilities (not necessarily exploited), and two warnings of potential cyber activity affecting the health sector. ENISA notes that cyber incidents have remained stable but there appears to have been an increase in...



