Settlement Reached in Preferred Home Care Data Breach Lawsuit
AssistCare Home Health Services has agreed to settle a class action lawsuit, filed on behalf of individuals affected by a cyberattack and HIPAA data breach in January 2021. In March 2021, AssistCare Home Health Services, which does business as Preferred Home Care of New York, notified more than 92,000 patients that their protected health information had been exposed in a cyberattack. Unauthorized individuals gained access to its network between January 8 and January 10, 2021, and exfiltrated files containing patient data. The attack was conducted by the Sodinokibi ransomware group, which published some of the stolen data on its data leak site. The compromised data included names, personal information, health information, and Social Security numbers. A class action lawsuit – Simmons v. AssistCare Home Health Services LLC, was filed in the New York Superior Court for Kings County covering the 92,283 individuals that were notified about the data breach. The lawsuit alleged negligence for failing to implement reasonable cybersecurity measures to protect against a known risk of...
BetterHelp Settlement Agreed with FTC to Resolve Health Data Privacy Violations
The Federal Trade Commission (FTC) has announced a settlement has been reached with the California-based online counseling service provider, BetterHelp Inc., to resolve allegations of violations of the FTC Act. The proposed BetterHelp settlement requires $7.8 million to be paid to consumers as refunds due to deceptive trading practices. This is the first such FTC settlement to require refunds to be paid to consumers whose health information was compromised. FTC Cracks Down on Deceptive Privacy Practices by Online Healthcare Service Providers This is the second such settlement to be announced by the FTC in the past month and is part of its current crackdown on deceptive trading practices by online providers of healthcare services. The announcement was made just a few days after a $1.5 million settlement with GoodRx was signed off by a judge to resolve alleged FTC Act and Health Breach Notification Rule violations. These settlements are intended to send a message to providers of online health services – which are often not bound by the protections of HIPAA – that they must ensure...
Amazon Completes Acquisition of OneMedical Amid Concern About Uses of Patient Data
Amazon has completed its $3.9 billion acquisition of the primary care provider One Medical as the retail behemoth continues its move into the healthcare ecosystem. One Medical has over 220 medical offices, a subscription-based telehealth service, and an electronic health record system, and contracts with more than 9,000 employers across the country. When Amazon announced its intention to acquire One Medical, consumer groups and privacy advocates expressed concern about the potential for misuse of patient data, with many analysts believing that data acquisition was a driving factor behind the deal. The consumer rights advocacy group, Public Citizen, voiced concern about the merger and has been urging the Federal Trade Commission to step in and block the deal due to fears that Amazon could gain an unfair advantage in the healthcare market, by leveraging the retail side of its business. For instance, Amazon could add One Medical services to its Prime membership package or use the retail side of the business for advertising products related to customers’ medical conditions. Of even...
Lawmakers Continue Push for Federal Data Privacy Law
In 2022, the bipartisan, bicameral American Data Privacy and Protection Act (ADPPA) was proposed to introduce a new federal data privacy law to replace the current patchwork of privacy laws that exist at the state level. The legislation progressed further than any previous attempt to introduce a federal data privacy law, advancing past the House Energy and Commerce Committee with a vote of 53-2 to the verge of a House vote. While the ADPPA has strong bipartisan support, it is currently not strong enough for the ADPPA to survive a House vote, with California one of the most vocal states opposing the ADPPA in its current form. Ahead of a second House Energy and Commerce Committee hearing on March 1, California Governor Gavin Newsom, Attorney General Rob Bonta, and the California Privacy Protection Agency (CPPA) wrote to Congress confirming their opposition to the ADPPA, although they welcomed the need for stronger federal action to protect the privacy of Americans. The major sticking point for California is the preemption language of the ADPPA, which sets a ceiling rather than a...
Evergreen Treatment Services Hacking Incident Affects 21K Patients
Evergreen Treatment Services, a Washington-based provider of addiction treatment services, announced on February 13, 2023, that unauthorized individuals gained access to its IT systems and potentially accessed patient information, including names, addresses, birth dates, Social Security numbers, and treatment information. A third-party cybersecurity firm assisted with the investigation but found no instances of fraud or identity theft; however, as a precaution, the 21,325 affected patients have been offered complimentary credit monitoring and identity theft protection services. Evergreen Treatment Services did not state in its breach notice when the incident was detected, for how long the hackers had access to its network, or any information about the nature of the attack. Data security policies have been enhanced in response to the breach to prevent similar incidents in the future. Data Stolen in Cyberattack on Texas Orthopaedics and Sports Medicine Tomball, TX-based Texas Orthopaedics and Sports Medicine (TOSM) has confirmed that an unauthorized third party gained access to its...



