Ohio Hospital Exposed Nurses and Other Staff to Workplace Violence
The Occupational Safety and Health Administration (OSHA) has determined a children’s hospital in Columbus, Ohio failed to adequately protect healthcare employees from workplace violence. Patients attacked nurses and other healthcare professionals and their bites, kicks, punches, and other assaults resulted in staff members sustaining serious injuries. An investigation was launched by OSHA in November 2022 following complaints from nurses and mental health staff at the Big Lots Behavioral Health Pavilion at Nationwide Children’s Hospital who had suffered serious injuries due to violent patient incidents, including lacerations, concussions, and sprains. Nationwide Children’s Hospital is the second-largest pediatric hospital in the United States and operates 68 facilities throughout Ohio and accepted over 1.5 million patient visits a year. The Big Lots Behavioral Health Pavilion provides acute behavioral healthcare services through intensive outpatient programs. OSHA determined that employees at the facility were exposed to the hazard of workplace violence due to insufficient safety...
Managed Care of North America Hacking Incident Impacts 8.9 Million Individuals
Managed Care of North America, Inc. (MCNA), which also does business as MCNA Dental – a provider of dental benefits and services for state Medicaid and Children’s Health Insurance Programs – has recently reported a major HIPAA compliance data breach to the Maine Attorney General and HHS Office for Civil Rights that has affected 8,923,662 individuals. This is the largest healthcare data breach to be reported by a single covered entity so far this year, and the second 5 million record+ healthcare data breach to be reported this month. On March 6, 2023, MCNA discovered an unauthorized third party was able to access certain systems within its IT network. The threat was immediately contained and a third-party cybersecurity firm was engaged to investigate the intrusion and determine the nature and scope of the incident. The forensic investigation determined that the network had been compromised and infected with malicious code and that the attackers removed some copies of personal and protected health information from its systems between February 26, 2023, and March 7, 2023....
Ransomware Gangs Claim Three Healthcare Victims
There has been a growing breach notification trend where the exact nature of a cyberattack is not disclosed in breach notification letters, including whether there has been confirmed theft of patient data. The failure to provide this information makes it difficult for victims of data breaches to assess the level of risk they face. That appears to be the case with two recent cyberattacks, neither of which mention ransomware or confirm that data theft occurred. Albany ENT & Allergy Services Earlier this month, two ransomware groups – BianLian and RansomHouse – added Albany ENT & Allergy Services (AENT) to their data leak sites, along with claims that 1TB of data was stolen from its network before files were encrypted. Evidence of data theft was published on the RansomHouse data leak site. Albany ENT & Allergy Services has now confirmed in a notification to the Maine Attorney General that unauthorized individuals gained access to its network, which contained the protected health information of 224,486 individuals, including 61 Maine residents. AENT explained in the...
CISA & Partners Release Updated StopRansomware Guide
An updated version of the StopRansomware Guide has been published that includes further recommendations on actions that can be taken to reduce the risk of ransomware attacks. The StopRansomware Guide is a one-stop resource developed by the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), and Multi-State Information Sharing and Analysis Center (MS-ISAC) that details best practices for detecting, preventing, responding to, and recovering from ransomware attacks and provides step-by-step approaches for addressing potential attacks. The updated guide was produced through the Joint Ransomware Task Force (JRTF), which was set up by Congress in 2022 to deal with the growing threat of ransomware attacks. The StopRansomware Guide can be used by government agencies and organizations and businesses of all sizes to ensure appropriate defenses are in place to block attacks and can help with the development, implementation, and maintenance of incident response plans to ensure the fastest possible recovery in the event...
Doctor Fined for Privacy Violations Following Abortion on 10-Year-Old Rape Victim
Dr. Caitlin Bernard, an Indianapolis, IN-based obstetrician-gynecologist has been fined $3,000 by the Medical Licensing Board of Indiana and issued with a letter of reprimand for violating HIPAA and state privacy law after talking to the media about an abortion she provided to a 10-year-old rape victim on July 1, 2022. Within hours of the Supreme Court’s decision that overturned Roe v Wade and removed the federal right to an abortion, Ohio banned abortions after 6 weeks of pregnancy. Three days later, on June 27, 2022, Dr. Bernard received a call from a child abuse doctor in Ohio about a 10-year-old patient who could not legally have an abortion in Ohio as she was three days past the legal cutoff. The victim then traveled from her home state of Ohio to Indiana to have the procedure performed by Dr. Bernard. A reporter for the IndyStar overheard a conversation between Dr. Bernard and another doctor at an anti-abortion rally and approached Dr. Bernard and asked for comment. The IndyStar ran a story about the girl and the reduction of access to abortions following the Supreme Court’s...



