CHIME Urges FTC to Stringently Enforce Health Breach Notification Rule
The College of Healthcare Information Management Executives (CHIME) has recently provided feedback to the Federal Trade Commission (FTC) on its Advance Notice of Proposed Rulemaking (ANPR) on the Trade Regulation Rule on Commercial Surveillance and Data Security and has urged the FTC to hold health apps and data brokers accountable for illegal disclosures of health data and unfair or deceptive data practices. The ANPR was published in the Federal Register on August 22, 2022, with comment sought from healthcare industry stakeholders, specifically “on whether [the Commission] should implement new trade regulation rules or other regulatory alternatives concerning the ways in which companies collect, aggregate, protect, use, analyze, and retain consumer data, as well as transfer, share, sell, or otherwise monetize that data in ways that are unfair or deceptive.” CHIME expressed broad support for the measures proposed by the FTC in response to the prevalence of commercial surveillance and data practices that are harming consumers, especially with respect to health data due to the extent...
OCR Issues Reminder About the HIPAA Security Rule Security Incident Requirements
In its October 2022 cybersecurity newsletter, OCR has reminded HIPAA-regulated entities of their obligations with respect to security incidents, including clarifying the breach reporting timeframe and confirming when the clock starts ticking. The number of healthcare data breaches being reported continues to increase. There was an almost 8% increase in reported data breaches of 500 or more records between 2020 and 2021, and a recent Check Point report suggests healthcare data breaches have increased by 69% between 2021 and 2022 – the highest percentage observed in any sector. Given the sharp rise in data breaches, OCR has chosen to raise awareness of the security incident requirements of the HIPAA Security Rule in its October Cybersecurity Newsletter. October is Cybersecurity Awareness Month – a month dedicated to raising awareness of the importance of cybersecurity and sharing best practices to help individuals and organizations ensure the privacy and security of confidential information. While the focus of this year’s Cybersecurity Awareness Month is the steps that everyone...
RIPTA, UnitedHealthcare of New England Sued Over 2021 Data Breach
The American Civil Liberties Union of Rhode Island (ACLU of RI) is taking legal action against the Rhode Island Public Transit Authority (RIPTA) and UnitedHealthcare New England (UHC) over an August 2021 data breach that affected more than 22,000 individuals. According to RIPTA, a cyberattack on its systems was detected and blocked on August 5, 2021. The breach was investigated, and it was determined that hackers gained access to its network two days previously, on August 3. The review of the files on the accessible parts of its system revealed they contained the data of 5,015 members of its group health plan, including names, dates of birth, Social Security numbers, and health plan ID numbers. The breach was reported to the HHS’ Office for Civil Rights as affecting 5,015 individuals; however, the information of a further 17,378 individuals who were not RIPTA employees was also compromised. Notification letters were sent to all affected individuals four months after the discovery of the data breach, which saw multiple complaints filed with the Rhode Island Attorney General by...
CISA Director Encourages All Organizations to Adopt FIDO Authentication
In a recent blog post, Jen Easterly, the Director of the Cybersecurity and Infrastructure Security Agency (CISA) explained that for Cybersecurity Awareness Month she has been traveling the country promoting cybersecurity best practices, explaining the steps that everyone can take to stay safe online, and stressing the importance of enabling multi-factor authentication on email accounts, bank accounts, social media accounts, and any other accounts that contain sensitive data. “Enabling multi-factor authentication is the single most important thing Americans can do to stay safe online,” said Easterly. When multi-factor authentication is enabled, a username and password are no longer sufficient to gain access to an account. An additional factor must be provided before access to the account is granted. This security measure is important, as passwords may be guessed or stolen, and phishing and brute force attacks are increasing. Despite MFA being an important security feature that can prevent unauthorized account access, MFA has still not been widely adopted. Many vendors make...
Hacking, Database Misconfigurations, and Improper Disposal Incidents Reported
A round-up of healthcare data breaches that have recently been reported to the HHS’ Office for Civil Rights and State Attorneys General. Delaware Department of Health and Social Services – Database Misconfiguration The Delaware Department of Health and Social Services, Division of Developmental Disabilities Services (DDDS) has recently discovered a misconfiguration occurred when creating new user accounts for the division’s client database. As a result of the misconfiguration, access was granted to the records of 7,074 individuals. The misconfiguration was discovered on August 23, 2022, with the investigation confirming 159 new user accounts had been created that provided access to service recipients’ personal, identifiable information and protected health information, as well as some more detailed information. 12 cases were identified where records were actively accessed by the users, but many more records may have been passively accessed. It was not possible to determine how many records were passively accessed. As such, the decision was taken to notify all 7,074 individuals, who...



