Microsoft Business Associate Agreement
If your organization is a HIPAA Covered Entity, Business Associate, or subcontractor to either, and it creates, receives, maintains, or transmits electronic Protected Health Information (ePHI) via a covered Office 365, Dynamics 365, or Azure service, it will be necessary to enter into a Microsoft Business Associate Agreement. Back in 2016, the Department of Health and Human Services (HHS) published an FAQ about whether a Cloud Service Provider could be considered a “conduit” for ePHI and thereby not qualify as a Business Associate. In the answer to the FAQ, HHS replied that Cloud Service Providers qualify as Business Associates because they have “persistent” access to ePHI (rather than “transient” access), even if ePHI is encrypted and the Cloud Service Provider does not have access to the decryption key. Therefore, before an organization subject to HIPAA uses any cloud service (or any on-premises service that synchronizes via the cloud) to create, receive, maintain, or transmit ePHI, it is necessary to conduct due diligence on the vendor. If the vendor has appropriate measures in...
St. Luke’s Health Reports Third Party Data Breach
St. Luke’s Health has recently notified 16,906 patients that some of their protected health information has been exposed in a security incident at a vendor that provides consulting services. On November 5, 2021, the email accounts of two employees of Adelanto Healthcare Ventures (AHCV) were accessed by an unauthorized individual. An investigation was launched into the incident, which initially determined no patient information had been exposed; however, a subsequent review determined the information of certain St. Luke’s Health patients was present in the email accounts and could potentially have been accessed or acquired by the attackers. The exposed information included names, addresses, dates of birth, Social Security numbers, dates of service, medical record numbers, Medicaid numbers, and some limited clinical information, such as treatment and diagnosis codes. St. Luke’s Health was notified about the breach on September 1, 2022 St. Luke’s Health explained in its breach notification letters that no reports have been received that suggest there has been any misuse of patient...
Lawsuits Filed Against OakBend Medical Center and Keystone Health Over Data Breaches
Oakbend Medical Center in Richmond, TX, and Keystone Health in Chambersburg, PA, are facing class action lawsuits over recent hacking incidents that resulted in the exposure and theft of the protected health information of hundreds of thousands of patients. OakBend Medical Center On September 1, 2022, OakBend Medical Center discovered its systems had been compromised and files had been encrypted. The breach was contained and access to its network was terminated, and a forensic investigation was conducted to determine the nature and scope of the attack. The forensic investigation confirmed that the attackers had exfiltrated files containing patient data. OakBend Medical Center said entire medical records do not appear to have been stolen. The stolen data included names, contact information, dates of birth, and Social Security numbers. The threat actors behind the attack – Daixin Team – claim the data they stole included 1 million patient records, although Oakbend Medical Center reported the breach to the HHS Office for Civil Rights as affecting up to 500,000 patients. On October 28,...
What is OSHA Certified?
The term OSHA certified has several meanings. It can mean the certificate an individual receives for completing an OSHA-authorized training course, the “card” required by some employers, industries, or states to demonstrate a knowledge of workplace safety, a document proving a trainer is qualified, or a point-in-time record an employer complies with OSHA standards. Getting a straightforward answer to the question what is OSHA certified can be confusing – mostly due to contradictions in OSHA´s literature. For example, in OSHA´s booklet “Training Requirements in OSHA Standards” (PDF), the section relating to OSHA Training Institute Educations Centers states “none of the courses within the Outreach Program is considered a certification”. Yet, within the same section there is a link to a directory of Education Centers offering OSHA-authorized training courses – most of which award a certificate at the completion of the course. Indeed, according to some certificate programs, it is necessary for students to be OSHA certified in one course before they can take a more advanced course in...
Cybersecurity is Now a Patient Safety Issue, Suggests Sen. Warner In Congressional Report
Senator Mark Warner (D-VA), Chairman of the Senate Select Committee on Intelligence, has recently published a white paper – Cybersecurity is Patient Safety – that highlights the current cybersecurity challenges facing the healthcare industry and suggests several potential policy changes that could help to improve healthcare cybersecurity and better protect all health information, including health data not currently protected under the HIPAA Rules. Sen. Warner suggests the only way to improve healthcare cybersecurity rapidly is through a collaborative effort involving the public and private sectors, with the federal government providing overall leadership. While further regulation may be necessary, the overall consensus of healthcare industry stakeholders is the best approach is to introduce incentives for improving cybersecurity, rather than mandating cybersecurity improvements with a threat of financial penalties for noncompliance. The healthcare industry is under attack from cybercriminals and nation-state threat actors and cyberattacks and data breaches are increasing at...



