Mystic Valley Elder Services Agrees to Settle Class Action Data Breach Lawsuit for $520,000
The Malden, Massachusetts-based Mystic Valley Elder Services has agreed to pay $520,000 to settle a consolidated class action lawsuit stemming from an April 5, 2024, data breach. Unauthorized individuals gained access to the network of Mystic Valley Elder Services and potentially obtained the names, dates of birth, passport numbers, financial account numbers, payment card numbers, online credentials, taxpayer identification numbers, Social Security numbers, driver’s license numbers, health insurance information, and medical information of more than 89,600 individuals. Five class action complaints were filed in response to the data breach, which were consolidated in the Middlesex County Superior Court in Massachusetts. The consolidated class action lawsuit – In re Mystic Valley Elder Services Inc. – alleged that the data breach occurred as a result of cybersecurity failures, Mystic Valley Elder Services failed to detect the unauthorized activity in a timely manner, and did not send timely notifications to the affected individuals, who did not learn about the data breach until 6...
HIPAA Compliance for Nurses
HIPAA compliance for nurses is considered to mean adhering to policies and procedures developed by an organization’s HIPAA Privacy Officer and applying the best practices of security awareness training provided by an organization’s HIPAA Security Officer. However, sometimes it is necessary to do more than provide basic training to help nurses work compliantly. Under the Administrative Requirements of the HIPAA Privacy Rule, covered entities are required to implement policies and procedures with respect to Protected Health Information that are designed to meet the requirements, standards, and implementation specifications of the HIPAA Privacy and Breach Notification Rules. Covered entities are required to train all members of the workforce on the policies and procedures “as necessary and appropriate for the members of the workforce to carry out their functions with the Covered Entity”. The training should include details of the sanctions that apply when a nurse violates any HIPAA standard. Under the Administrative Safeguards of the HIPAA Security Rule, all members of the...
HIPAA Training for Students
HIPAA training for healthcare students ensures that they understand and adhere to HIPAA guidelines regarding the handling and protection of Protected Health Information (PHI), preparing them for responsible and compliant professional practices in their future healthcare careers. Because most undergraduate medical education is hospital-based, and because medical students in hospital environments have access to PHI, HIPAA training for students is important to ensure PHI is not disclosed due to a lack of knowledge. HIPAA training for students is not just a preventative measure, it is a requirement of the HIPAA Privacy Rule. This is because, although medical students might not be paid members of a Covered Entity’s workforce, §160.103 of the Privacy Rule defines a covered entity’s workforce as: “Employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity or business associate, is under the direct control of such covered entity or business associate, whether or not they are paid by the covered entity or business...
What are the HIPAA Training Requirements for New Hires?
The HIPAA training requirements for new hires are that “a covered entity must provide training […] to each new member of the workforce within a reasonable period of time after the person joins the covered entity’s workforce” (45 CFR 164.530(b)(2)). What a “reasonable period of time” is may depend on the new hire’s role and their existing HIPAA knowledge. Because HIPAA applies to many different types of organizations, it is important the HIPAA training requirements for new hires are put into context rather than taken in isolation. This is because HIPAA requires covered entities and business associates to identify risks to the privacy of Protected Health Information (PHI) and mitigate the risks to a reasonably acceptable level. If a covered entity conducts a risk assessment, and identifies a risk to the privacy of PHI by allowing an untrained new hire access to PHI, the new hire must be trained before being allowed access to PHI. It may also be the case that the new hire requires security awareness training in addition to HIPAA training if the new hire demonstrates a lack of online...
Is Gmail HIPAA Compliant?
Gmail is HIPAA compliant, and can be used to receive, store, or send Protected Health Information (PHI) when Google’s email service is used as part of an Enterprise Workspace Plan supported by a Business Associate Addendum to the Workspace Terms of Service. To ensure Gmail is used compliantly, it is necessary to configure Workspace controls correctly, apply user policies, and train members of the workforce on how to use Gmail in compliance with HIPAA. In small medical practices without a dedicated HIPAA compliance officer to determine the appropriate procedures for using Gmail and an IT manager to configure Gmail in a HIPAA compliant way, the best option is to use a HIPAA-compliant email provider like Paubox. Gmail is the most popular personal email service in the world; and, because most employees are accustomed to how Gmail works, Google’s email service is widely used in business behind customized domain names (i.e., [email protected], rather than [email protected]). Although several methods exist to operate a Gmail account behind a customized domain name, the simplest method for...



