Value in Health Care Act Seeks to Extend Medicare Payment Incentives for APMs
On July 27, 2023, the bipartisan Value in Health Care Act was introduced and seeks to extend the 5% Medicare payment incentives for advanced Alternative Payment Models (APMs) under the Medicare Access and CHIP Reauthorization Act (MACRA), which are due to expire at the end of the year. The Value in Health Care Act was introduced by Reps. Darin LaHood, (R-IL); Suzan DelBene, (D-WA).; Brad Wenstrup, (R-OH); Earl Blumenauer, (D-OR); and Kim Schrier, (D-WA) to ensure that APMs continue to produce high-quality care for the Medicare program and its beneficiaries. The sponsors of the bill explained that value-based care programs have a successful track record of improving outcomes and reducing costs. Some APMs have helped to provide billions of dollars in savings for taxpayers in the past decade and accountable care organizations (ACOs) alone have saved Medicare more than $17 billion while improving quality. One of the problems, however, is that rules implemented to the ACO programs have limited the number of participating providers. While the aim of MACRA was to speed up the transition...
Health3PT Shares Best Practices for Improving Third Party Risk Management in Healthcare
The Health 3rd Party Trust Initiative (Health3PT) has published the findings of a recent survey of HIPAA-covered entities and their business associates that explored the current state of third-party cyber risk management in healthcare and identified some of the key challenges faced by HIPAA-regulated entities. Supply chain vendors and service providers introduce risks that need to be identified, managed, and reduced to a low and acceptable level; however, the methods used to manage third-party risks are often burdensome and inadequate. According to the survey, which was conducted on 59 HIPAA-covered entities and 128 business associates, significant resources and money are committed to managing third-party risk but 68% of covered entities and 79% of business associates say third-party risk management (TPRM) processes are inefficient and 60% of HIPAA-covered entities and 72% of business associates think TPRM is not effective at preventing data breaches. 55% of healthcare organizations have experienced a data breach in the past year through a third party, and 90% of the most...
98,000 UT Southwestern Medical Center Patients Affected by MOVEit Cyberattack
UT Southwestern Medical Center (UTSW) has recently confirmed that the protected health information of 98,437 patients was stolen in a cyberattack on May 28, 2023. The Clop ransomware group exploited a zero-day vulnerability in Progress Software’s MOVEit file transfer solution, gained access to UTSW’s MOVEit server, and exfiltrated files that contained names, medical record numbers, dates of birth, medication names, medication dosages, prescribing provider names. A subset of the affected individuals also had their Social Security numbers stolen. UTSW was notified about the attack by Progress Software on May 30, 2023, and the exploited vulnerability was immediately patched. The German cybersecurity firm KonBriefing has recently announced that its data shows at least 455 organizations were attacked in this campaign, and at least 23 million individuals were affected. The Clop group has recently started posting victim data on its clear web data leak site. Family Vision of Anderson Suffers Ransomware Attack Family Vision of Anderson in South Carolina was the victim of a May 2023...
Norton Healthcare Facing Class Action Lawsuit Over BlackCat Cyberattack
Norton Healthcare, a Kentucky-based operator of more than 140 clinics and hospitals in Kentucky and Southern Indiana, is facing a class action lawsuit over a May 2023 cyberattack and data breach. Norton Healthcare has only disclosed limited information about the attack; however, the BlackCat ransomware group announced that it was behind the cyberattack and leaked some of the data stolen from Norton Healthcare on its data leak site. The stolen information included names, addresses, email addresses, dates of birth, Social Security numbers, government identification ID numbers, driver’s license numbers, payment/financial institution information, health insurance providers, medical treatment information, medical diagnoses, medications, medical images, and lab test results. The HIPAA breach was reported to the HHS’ Office for Civil Rights as affecting 501 individuals, and was later updated to 2,500,000 individuals. On July 21, 2023, a class action lawsuit was filed in U.S. District Court on behalf of plaintiff Lanisha Malone and similarly situated individuals who had their sensitive...
Majority of Americans Mistakenly Believe Health App Data is Covered by HIPAA
There is a common misconception that the Health Insurance Portability and Accountability Act (HIPAA) applies to health apps; however, the majority of health apps are not covered by HIPAA nor is the health information collected, stored, or transmitted by the apps. HIPAA applies to HIPAA-covered entities – healthcare providers, health plans, and healthcare clearinghouses – and vendors used by those entities, which are classed as business associates. While health apps may collect some of the exact same health data that is maintained by HIPAA-covered entities, the information collected by health apps is not subject to the same privacy and security standards. As such, health information collected by health apps may be transmitted to third parties, sold, or used for purposes that are not permitted under HIPAA. According to a recent ClearDATA Harris Poll survey of 2,000 U.S. adults, 68% of respondents said they were very or somewhat familiar with HIPAA, yet 81% of respondents believed that the health data collected by digital health apps is covered by HIPAA and subject to its...



