HHS Announces Restructuring Effort to Trim Backlog of HIPAA and Civil Rights Complaints
The U.S. Department of Health and Human Services (HHS) has restructured its Office for Civil Rights (OCR) and has created new divisions that will help improve the enforcement of HIPAA and civil rights laws and clear the current backlog of complaints and investigations. OCR is the main law enforcement agency of the HHS and is responsible for enforcing 55 civil rights, conscience, and privacy statutes, including the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act. In a recent report to Congress, OCR explained that its caseload has increased significantly in recent years, yet appropriations have not risen, which has placed the department under great strain. Reported data breaches increased by 58% between 2017 and 2021, and complaints about potential HIPAA have also been soaring, rising 25% year-over-year to 34,077 complaints in 2021. Complaints about civil rights violations have also increased, rising by 69% between 2017 and 2022. In 2022, 51,000 complaints were received by OCR, 66% for...
On-the-Spot Intervention 95% Effective at Preventing Further Unauthorized Medical Record Access
Defenses need to be put in place to detect and block attempts by cybercriminals to access healthcare networks, but not all threats are external. Each year, many data breaches are reported by hospitals and medical practices that involve unauthorized access to medical records by employees. These data breaches include non-malicious snooping on the medical records of colleagues, friends, family members, and high-profile patients, and insider wrongdoing incidents where patient data is stolen for identity theft and fraud or to take to a new employer. The healthcare industry has historically had a far bigger problem with insider data breaches than other industry sectors. The study, recently published in the JAMA Open Network, was conducted at a large academic medical center and explored the effectiveness of email warnings in preventing repeated unauthorized access to protected health information by employees. Over a 7-month period in July 2018, the medical center’s PHI access monitoring system flagged 444 instances where employees accessed the medical records of patients when they were...
Healthcare Organizations Warned About MedusaLocker Ransomware Attacks
The healthcare and public health (HPH) sector has been warned about cyberattacks involving MedusaLocker ransomware – one of the lesser-known ransomware variants used in cyberattacks on the sector. The HPH sector has been extensively targeted by prolific ransomware groups using ransomware variants such as Clop, Royal, and BlackCat, but attacks involving these lesser-known variants can be just as damaging. The threat actor behind MedusaLocker is believed to run a ransomware-a-service operation, where affiliates are recruited by the group to conduct attacks for a cut of any profits they generate, which is believed to be around 55%-60% of the ransom payment for MedusaLocker ransomware affiliates. The ransomware variant was first detected in September 2019 and the group is thought to primarily target the HPH sector. Since 2019, the majority of attacks have used phishing and spam emails with malicious attachments as the initial access vector. When the attachments are opened, a connection is made to the command-and-control server, and a script and the ransomware payload are...
Data Breaches Reported by The Hutchinson Clinic & 90 Degree Benefits
The Hutchinson Clinic Reports December 2022 Hacking Incident The Hutchinson, KS-based healthcare provider, The Hutchinson Clinic, has recently announced that hackers accessed its network between December 19, 2022, and December 22, 2022, and during that time, files containing patient data may have been accessed and stolen. According to the clinic’s website data breach notice, the impacted information included names, contact information, birth dates, Social Security numbers, driver’s license numbers, health insurance information, medical record numbers (MRN), medical histories, diagnoses, treatment information, and physician names. The exposed files are currently being reviewed and notifications will be mailed to affected individuals when that process is completed. The Hutchinson Clinic said it has conducted a review of its policies and procedures and will be implementing additional administrative and technical safeguards to better secure its systems and prevent further incidents of this nature. The HHS’ Office for Civil Right website indicates up to 100,000 patients have been...
Time to Stop Blocking a National Patient Identifier System
In 1996, the Health Insurance Portability and Accountability Act (HIPAA) was signed into law and one of its requirements was for the Department of Health and Human Services (HHS) to develop a national patient identifier system. Under such a system, every person in the United States would be provided with a unique permanent ID number that would allow them to be tracked across the entire U.S. health system, not for any form of control, government interference in healthcare, or any other nefarious purpose, but to address a pressing public health and safety issue: To ensure patients can be reliably and accurately connected with their health information. 27 years later and we are no closer to a national patient identifier than we were in 1996. The reason for the lack of action goes back to 1998, when Representative Ron Paul (R-TX) introduced a ban on the HHS developing a national patient identifier system by ensuring no funding was provided by Congress for that purpose. Language has been included in every appropriation bill since then that prevents any funding from being given to the...



