Survey Reveals a Majority of Americans Are Uncomfortable with AI in Healthcare
A recent survey conducted by the Pew Research Center found a majority of Americans are uncomfortable with their healthcare providers using artificial intelligence tools to aid the diagnosis and treatment, indicating a need to improve education on the benefits of AI in healthcare. 60% of respondents expressed discomfort with the use of AI in care settings, with 39% of respondents saying they are comfortable with their care providers relying on AI for medical care. 38% of respondents believe AI will lead to better health outcomes, such as faster diagnosis and treatment, with 33% of respondents believing AI would result in worse health outcomes. 27% of respondents said they didn’t think AI would make much difference to patient outcomes. When probed about the potential benefits of AI in healthcare, 40% of respondents believe AI will reduce the number of mistakes by healthcare providers, such as misdiagnosis or the failure to diagnose a disease, compared to 27% who thought medical mistakes would increase. Out of the respondents who believe there is a problem with racial and ethnic bias...
True Health New Mexico Proposes Settlement to Resolve Class Action Data Breach Lawsuit
The Albuquerque, NM-based health insurance provider, True Health New Mexico, has proposed a settlement to resolve claims related to a 2021 HIPAA data breach that affected 62,983 members of its health plans. True Health New Mexico identified a security breach on October 5, 2021, with the investigation confirming that an unauthorized third party had gained access to its network and used ransomware to encrypt files. During the period of access, files were potentially viewed and exfiltrated that contained plan member data such as names, dates of birth, ages, home addresses, email addresses, insurance information, medical information, Social Security numbers, health account member IDs, provider information, and date(s) of service. No evidence of misuse of plan member data was identified at the time of issuing notification letters; however, as a precaution against identity theft and fraud, complimentary credit monitoring and identity theft protection services were offered to affected individuals. Several lawsuits were filed soon after notifications were sent alleging the health plan...
Alvaria Inc. Confirms Hive Ransomware Attack
Alvaria Inc. (formerly Aspect Software, Inc.), a provider of call center and customer experience software technology to large enterprises, has recently confirmed that it fell victim to a ransomware attack on a limited portion of its network. There is a trend for breach notification letters to only contain the bare minimum information to meet regulatory requirements; however, Alvaria breach notifications include comprehensive details about the attack including the name of the ransomware group responsible. The company has also confirmed that sensitive information was stolen, some of which was released on the Hive group’s dark web data leak site, which helps victims of the breach accurately assess the level of risk they face. Alvaria explained that the ransomware attack occurred on November 28, 2022, and steps were immediately taken to contain the attack and prevent further unauthorized access to its network. An investigation was launched and a third-party digital forensics company was engaged to investigate the scope of the attack and determine if protected health information had...
Judge Approves FTC’s $1.5 Million Settlement with GoodRx to Resolve FTC Act and Health Breach Notification Rule Violations
The GoodRx settlement with the FTC to resolve allegations that the FTC Act and Health Breach Notification Rule have been violated has been approved by a judge and is now in effect. The GoodRx FTC settlement involves a $1.5 million penalty and requires GoodRx to cease the alleged deceptive trading practices. On February 1, 2023, the Department of Justice filed a proposed order on behalf of the Federal Trade Commission prohibiting GoodRx from sharing the health information of its users with third parties for advertising purposes, following an FTC investigation that identified potential violations of the FTC Act and the FTC Health Breach Notification Rule. The FTC alleged that GoodRx – doing business as GoodRx Gold, GoodRx Care, and Hey Doctor (GoodRx) – violated the FTC Act by engaging in unfair and deceptive trade practices by sharing the data of millions of users without their consent and knowledge and violated the FTC Health Breach Notification Rule by failing to notify users about the privacy violation. The information shared with third parties included personally...
HHS Announces Restructuring Effort to Trim Backlog of HIPAA and Civil Rights Complaints
The U.S. Department of Health and Human Services (HHS) has restructured its Office for Civil Rights (OCR) and has created new divisions that will help improve the enforcement of HIPAA and civil rights laws and clear the current backlog of complaints and investigations. OCR is the main law enforcement agency of the HHS and is responsible for enforcing 55 civil rights, conscience, and privacy statutes, including the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act. In a recent report to Congress, OCR explained that its caseload has increased significantly in recent years, yet appropriations have not risen, which has placed the department under great strain. Reported data breaches increased by 58% between 2017 and 2021, and complaints about potential HIPAA have also been soaring, rising 25% year-over-year to 34,077 complaints in 2021. Complaints about civil rights violations have also increased, rising by 69% between 2017 and 2022. In 2022, 51,000 complaints were received by OCR, 66% for...



