CentroMed Facing 2 Class Action Lawsuits Over 350,000-Record Data Breach
El Centro Del Barrio, dba CentroMed in San Antonio, TX, is facing at least two class action lawsuits over a June 2023 cyberattack in which hackers gained access to the personal and protected health information (PHI) of 350,000 patients. The attack was detected on June 12, 2023, and the forensic investigation confirmed unauthorized access to IT systems first occurred on June 9, 2023. The information accessed in the attack included names, addresses, dates of birth, Social Security numbers, financial account information, medical record numbers, health insurance plan member IDs, and claims data. The affected individuals were notified by mail on August 11, 2023. CentroMed patients Jasmine Grace and Dawn Leal have each taken legal action against CentroMed over the impermissible disclosure of their personal information and allege CentroMed was negligent for failing to properly secure and safeguard their personally identifiable information, which is now in the hands of cybercriminals. They both claim they face an imminent, ongoing, and substantial risk of identity theft and fraud and have...
Allwell Behavioral Health Settles Data Breach Class Action for $650,000
Allwell Behavioral Health has proposed a $650,000 settlement to resolve a class action lawsuit that was filed on behalf of victims of a March 2022 data breach that affected 29,972 patients. The breach was detected on March 5, 2022, and sensitive data was found to have been accessed by unauthorized individuals on March 3, 2022. The compromised data included names, dates of birth, Social Security numbers, phone numbers, treatment activity, treatment provider, treatment date, treatment location, and payer information. The lawsuit alleged Allwell Behavioral Health was negligent for failing to adequately secure patient data. Allwell Behavioral Health admitted no wrongdoing; however, chose to settle the lawsuit to prevent further legal costs and to avoid the uncertainty of trial. Under the terms of the settlement class members are entitled to receive a $50 payment, which may be increased depending on the number of claims received. Claims of up to $4,000 may be submitted to cover extraordinary, unreimbursed monetary losses, which can include up to 5 hours of lost time at $25 per hour....
When Did HIPAA Take Effect?
HIPAA took effect in various stages following the passage of the Health Insurance Portability and Accountability Act in 1996, with some changes enacted by HIPAA taking effect immediately, most taking effected 90 days after the passage of HIPAA, and those relating to the privacy and security of healthcare data taking up to ten years to take effect. Even then, HIPAA was not effectively enforced until after the HIPAA Omnibus Final Rule took effect in September 2013. When Did HIPAA Take Effect? HIPAA was signed into law by President Clinton on August 21, 1996, although HIPAA has been updated several times over the past 27 years and many new provisions have been incorporated to improve privacy protections and security to ensure health information remains confidential. The main updates to HIPAA are summarized below. The HIPAA Privacy Rule The HIPAA Privacy Rule was a major update to HIPAA and introduced many of the aspects for which HIPAA is known today. The HIPAA Privacy Rule defined ‘Protected Health Information (PHI), patients were given the right to obtain copies of their protected...
78% of Healthcare Organizations Suffered a Cyberattack in the Past Year
A recent survey of healthcare professionals indicates 78% of healthcare organizations have experienced at least one cybersecurity incident in the past 12 months. 60% of those incidents had a moderate or significant impact on the delivery of care, 15% had a severe impact, and 30% involved sensitive data. Protected Health Information (PHI) was exposed or stolen in 34% of incidents in North America. The survey was conducted by Pollfish on behalf of the cybersecurity firm Claroty on 1,100 individuals in North and South America, APAC, and Europe. Respondents worked full-time in the health sector in cybersecurity, engineering, IT, or networking. The survey indicates 26% of organizations that experienced a cyberattack paid a ransom to either prevent the release of stolen data or to decrypt encrypted files. The costs of these attacks typically fell in the range of $100,000 to $1 million; however, more than one-third of respondents who experienced a cyberattack said the recovery costs were greater than $1 million. The biggest cost from the attacks in all but the APAC region was operational...
DoL Issues NPRM Clarifying Third Parties Can Participate in Physical Workplace Inspections
The U.S. Department of Labor (DOL) has published a Notice of Proposed Rulemaking (NPRM) that revises the current Occupational Safety and Health Administration (OSHA) regulations concerning representatives of employees that can accompany the OSHA Compliance Safety and Health Officer (CSHO) during workplace inspections. The proposed rule makes it clear that the representatives authorized by employees may be employees of the employer or a third party. If a non-employee(s) is chosen, the OSHA compliance officer will determine whether the third party is reasonably necessary to conduct an effective and thorough inspection. The current regulations provide two examples of third-party representatives that could be present during inspections – industrial hygienists and safety engineers. The proposed update makes it clear that third-party representatives need not be limited to these individuals. The proposed change would permit union representatives and interest groups to be present during walkarounds, provided the CSHO conducting the inspections deems their presence to be reasonably...



