Interview: J. Veronica Xu, Chief Compliance Officer, Saber Healthcare Group
HIPAA Journal is conducting interviews with healthcare professionals and vendors to get their points of view on HIPAA, how the legislation relates to their roles, and the successes and challenges they face with HIPAA compliance. This week, J. Veronica Xu, Chief Compliance Officer, Saber Healthcare Group, shared her thoughts. Tell the readers about your career in the healthcare industry I currently serve as the Chief Compliance Officer for Saber Healthcare Group – one of the largest long-term care providers in the nation. As a long-term care provider with more than 120 facilities in the nation (including skilled nursing facilities and assisted living facilities), we provide individualized care to patients and residents in seven states. What was your first position? I worked as an attorney at a law firm. When did you first get involved in HIPAA compliance? When I was practicing law and advising corporate and individual clients on various legal matters, HIPAA compliance issues would come up from time to time. When I first assumed the current role, HIPAA compliance was part of...
98% of Organizations Use a Vendor That Had a Data Breach in the Past 2 Years
Healthcare organizations have been investing in cybersecurity to improve their defenses against increasingly numerous and sophisticated cyberattacks; however, while an organization’s security posture can be improved, it can only be as good as the weakest link. Cybercriminals are increasingly targeting the supply chain in their attacks, as these are usually the weakest links in the security chain. Healthcare organizations typically contract with many different vendors which are often provided with sensitive data or privileged access to healthcare networks. In 2022, data breaches at business associates increased to the point where reported data breaches with business associate involvement outnumbered the data breaches at healthcare providers. Many of the data breaches at business associates affected dozens of healthcare clients. Assessing and managing supply chain risk is now one of the biggest cybersecurity challenges in healthcare. A recent study conducted by SecurityScorecard and the Cyentia Institute explored the reasons why data breaches at third parties and fourth parties are...
Cedars-Sinai Medical Center Sued for Website Tracking Technology Privacy Violations
A lawsuit has been filed against Cedars-Sinai Medical Center alleging impermissible disclosures of patient data to Google, Meta, and other third parties due to the use of website tracking technologies without either a business associate agreement with the code providers or authorizations from patients. In the summer of 2022, an investigation into the use of these technologies revealed almost one-third of the top 100 hospitals in the United States had used pixels and other tracking code on their websites that were capable of collecting and transmitting sensitive data to the providers of that code. The Cedars-Sinai lawsuit is one of dozens filed against healthcare providers and other health-related companies in the past year over the use of tracking technologies on websites and mobile apps without user consent. The widespread use of tracking technologies prompted the HHS’ Office for Civil Rights to issue guidance in December 2022 on the use of these technologies to ensure a HIPAA compliant website. The guidance confirmed that any tracking technologies that are capable of touching...
Hackers Compromised Sharp HealthCare Web Server and Stole Patient Data
Sharp HealthCare in San Diego has recently notified almost 63,000 patients that some of their personal and protected health information has potentially been stolen in a recent cyberattack on its web server. Sharp HealthCare detected the cyberattack on January 12, 2023, and immediately shut down the web server while the incident was investigated. A third-party digital forensics company was engaged to investigate and determine the nature and scope of the incident and confirmed that an unauthorized third party successfully compromised the web server that powered the sharp.com website for a few hours on January 12. During that time the third party downloaded a file that contained patient data. Sharp HealthCare stressed that the FollowMyHealth patient portal was not accessed, and no highly sensitive information was exposed or stolen. Financial information, contact information, dates of birth, Social Security numbers, health insurance information, or medical information were not accessed or stolen in the attack. The affected individuals had previously visited the website and paid medical...
Lawsuit Seeks Damages for GoodRx Users for Invasion of Privacy
Last week, the Federal Trade Commission (FTC) announced its first-ever financial penalty for a violation of the FTC Health Breach Notification Rule. GoodRx was alleged to have failed to issue notification letters to customers whose PHI was disclosed to third parties such as Google and Facebook via tracking technologies on its website and mobile app. GoodRx said it decided to settle the case and pay a $1.5 million financial penalty to avoid the time and expense of protracted litigation, and that proactive steps were taken to address the issue prior to the FTC investigation. The settlement has yet to be approved by a federal judge. Several healthcare data breaches have been reported over the past few months that involved impermissible disclosures of protected health information to third parties such as Google, Meta, and others due to the use of tracking technologies on websites and mobile apps. Multiple lawsuits have been filed over those impermissible disclosures, and the GoodRx data breach is no exception. A lawsuit was filed in the U.S. District Court of the Northern District of...



