Is WhatsApp HIPAA Compliant?
WhatsApp is not HIPAA compliant and should not be used for receiving, storing, or sending Protected Health Information unless a patient initiates a contact via WhatsApp or exercises their right to request confidential communication via a specific channel or platform. In such cases, healthcare providers must document the initial contact or request and implement reasonable safeguards to protect the privacy of health information. WhatsApp is used in a variety of healthcare settings for a variety of purposes. In a 2019 survey, the most common uses of WhatsApp for healthcare professionals included sharing scientific information with colleagues, managing agendas with colleagues, and communicating with colleagues about clinical situations without mentioning patient-specific information. The same survey identified a number of WhatsApp interactions between healthcare professionals and patients which were most often initiated by patients. Common interactions included patients sending images and videos prior to a consultation, asking healthcare-related questions, and providing updates on...
Schneck Medical Center Settles HIPAA Lawsuit with Indiana AG
Seymour, IN-based Schneck Medical Center has settled a lawsuit with the Indiana attorney general, Todd Rokita, over a 2021 ransomware attack and data breach that affected 89,707 Indiana residents. Schneck Medical Center has agreed to pay a penalty of $250,000 to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) and state laws and will implement additional safeguards to prevent further data breaches. According to the lawsuit, Schneck Medical Center conducted a risk analysis in December 2020 which revealed many critical security issues, but Schneck Medical Center failed to address them. 9 months later, on or around September 29, 2021, security flaws were exploited by a malicious actor who gained access to the network, exfiltrated sensitive patient data, and then deployed ransomware to encrypt files. The information stolen in the attack included names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account information, payment card information, diagnoses, and health insurance information. Schneck...
L.A. Care Health Plan Settles Multiple HIPAA Violations for $1.3 Million
The Local Initiative Health Authority for Los Angeles County, operating as L.A. Care Health Plan, has settled multiple violations of the HIPAA Privacy and Security Rules with the HHS’ Office for Civil Rights (OCR) and will pay a $1,300,000 penalty and adopt a robust corrective action plan. L.A. Care Health Plan is the largest publicly operated health plan in the United States and has more than 2.7 million members. OCR said it launched two separate investigations of L.A. Care Health Plan to assess the state of HIPAA compliance, the first of which was in response to a media report about impermissible disclosures of protected health information (PHI) via its member portal and the second was in response to a breach that was reported to OCR involving the PHI of 1,498 members. In March 2014, an online media source reported that members of the health plan were able to access the protected health information (PHI) of other members via the online member portal between January 22 and January 24, 2014. The breach was due to a manual processing error that allowed members to view other...
How Can You Report a Company to OSHA?
You can report a company to OSHA by phone, mail, email, fax, visiting an OSHA office, or via an online report form. Some channels of communication are more appropriate than others for reporting urgent issues, and these are the things you should consider before you report a company to OSHA: Are you reporting a violation of an OSHA standard? Have you evidence to support your report? Do you have all the detail you need to report a company to OSHA? Which is the most appropriate reporting method? Reporting a Violation of an OSHA Standard When you report a company to OSHA for violating a safety and health standard, your report will be dealt with quicker if you are able to indicate which specific standard(s) your report relates to. OSHA’s website provides a full list of Occupational Safety and Health Standards and the option exists to search the Standards by keyword. If you are uncertain about which standards apply to your report, the website can also be searched by most reported topics (i.e., heat, PPE, hazard communication, etc.) or by most reported industry sector (i.e., agriculture,...
Kaiser Pays $49 Million to Settle Improper Disposal Investigation
California Attorney General Rob Bonta has announced a $49 million settlement has been reached with Kaiser Foundation Health Plan Foundation Inc. and Kaiser Foundation Hospitals to resolve allegations of improper disposal of hazardous waste, medical waste, and protected health information. Oakland, CA-based Kaiser is the largest healthcare provider in California with more than 700 healthcare facilities in the state, serving more than 8.8 million patients. An investigation was launched by 6 district attorneys from Alameda, San Bernardino, San Francisco, San Joaquin, San Mateo, and Yolo counties into the unlawful dumping of dangerous items. Undercover staff from the district attorneys’ offices inspected dumpsters at 16 different Kaiser facilities. The dumpsters were not secured and the contents were destined for disposal in landfill sites. The inspectors found hundreds of items of hazardous and medical waste, including aerosols, cleansers, sanitizers, batteries, syringes, medical tubing containing body fluids, pharmaceuticals, and electronic wastes. The dumpsters also contained...



