Hacking and Data Theft Incident Reported by CentraState Healthcare System
Freehold Township, NJ-based CentraState Healthcare System has recently confirmed that its network was compromised by unauthorized individuals in December 2022. Unusual activity was detected within its computer systems on December 29, and immediate action was taken to isolate the network and block unauthorized access. CentraState has been working with the Federal Bureau of Investigation and independent cybersecurity experts to investigate the breach and has determined that the unauthorized party exfiltrated a copy of an archived database that contained the protected health information of patients. The database included the following information: names, addresses, dates of birth, Social Security numbers, health insurance information, medical record numbers, and patient account numbers. Additionally, some information related to care received at CentraState, such as date(s) of service, physician names and departments, treatment plans, diagnoses, visit notes, and prescription information. CentraState said it continually enhances the security of its electronic systems and will continue...
Lehigh Valley Health Network and MKS Instruments Recovering from Ransomware Attacks
Lehigh Valley Health Network (LVHN) in Pennsylvania has confirmed that it is dealing with a ransomware attack that was detected on February 6, 2023. An announcement was made on Monday confirming the Russian-speaking ransomware gang, BlackCat, was behind the attack and demanded a ransom, but no payment was made. Brian A. Nester, LVHN President and CEO, said the attack has not affected its operations and care continues to be provided to patients. While the attack is still being investigated, Nester has confirmed that the attack was conducted on a network supporting an unnamed physician practice in Lackawanna County and that the network housed a system that was used to store “clinically appropriate patient images for radiation oncology treatment,” and other sensitive information. That practice appears to be Delta Medix in Scranton, PA. It is currently unclear if other physician practices have been affected. The LVHN technology team launched an investigation when suspicious network activity was detected, its network was immediately secured, and third-party cybersecurity experts were...
March 1, 2023: HIPAA Breach Notification Rule Deadline for Reporting Small Data Breaches
The deadline for reporting healthcare data breaches of fewer than 500 records is fast approaching. HIPAA-regulated entities must ensure these data breaches are reported to the HHS’ Office for Civil Rights (OCR) no later than March 1, 2023. Late reporting of data breaches is a HIPAA violation and can result in a financial penalty. The HIPAA Breach Notification Rule requires HIPAA-regulated entities to issue notifications to all individuals whose protected health information has been exposed or impermissibly disclosed without unnecessary delay, and no later than 60 days from the discovery of a data breach. HIPAA-regulated entities are also required to report data breaches to the Secretary of the HHS via the OCR breach reporting portal. The HIPAA Breach Notification Rule requires large data breaches – affecting 500 or more individuals – to be reported to OCR within the same time frame – No later than 60 days from the discovery of the data breach. There is greater flexibility for reporting data breaches affecting fewer than 500 individuals. HIPAA-regulated entities must also report...
Lack of Funding Hampering OCR’s Ability to Enforce HIPAA
The HHS’ Office for Civil Rights (OCR) has published a report it sent to Congress that details its HIPAA enforcement activities in 2021, which provides insights into the state of compliance with the HIPAA Privacy, Security, and Breach Notification Rules. The report makes it clear that OCR’s resources are under considerable strain, and without an increase in funding from Congress, OCR will struggle to fulfill its mission to enforce HIPAA compliance, especially considering the large increase in reported data breaches and HIPAA complaints. OCR reports significant increases in reported data breaches and HIPAA complaints, with large data breaches – 500 or more records – increasing by more than 58% between 2017 and 2021, and HIPAA complaints increasing by 25% between 2020 and 2021, yet between 2017 and 2021, OCR has not had any increases in appropriations, with Congress only increasing funding in line with inflation. If Congress is unable to increase funding for OCR, the financial strain could be eased through enforcement actions; however, OCR has seen funding through enforcement decline...
OCR: HIPAA-Regulated Entities Need to Continue to Improve HIPAA Security Rule Compliance
The Department of Health and Human Services’ Office for Civil Rights (OCR) has publicly released two reports that were submitted to Congress that provide insights into data breaches, HIPAA enforcement activity, and the state of HIPAA Privacy and Security Rule compliance for calendar year 2021. According to OCR, in calendar year 2021, OCR received 609 reports of large data breaches – data breaches affecting 500 or more individuals – with those incidents affecting 37,182,558 individuals. OCR also received 63,571 reports of data breaches affecting fewer than 500 individuals – which are not publicly reported. 319,215 individuals were affected by those smaller data breaches. That’s 64,180 data breaches in total in 2021 affecting 37,501,772 individuals. If you follow the breach reports and healthcare data breach statistics reported in the HIPAA Journal, you will notice a discrepancy with OCR’s official figures. That is because the statistics are based on the data breaches reported to OCR via the OCR HIPAA Breach Web Portal, which lists 714 data breaches for calendar year 2021. OCR...



