235,000 Keystone Health Patients Affected by August 2022 Cyberattack
Chambersburg, PA-based Keystone Health has recently announced that it fell victim to a cyberattack on August 19, 2022, which caused temporary disruption to its computer systems. Steps were immediately taken to restore the security of its systems and prevent further unauthorized access, and a third-party cybersecurity firm was engaged to investigate the breach and determine how the hackers gained access to its systems and the scope of the breach. The forensic investigation revealed the hackers first gained access to its systems on July 28, 2022, with access terminated on August 19. During that time, files were accessed that contained patients’ protected health information, including names, Social Security numbers, and clinical information. A comprehensive review of those files confirmed they contained the information of 235,237 patients. Law enforcement was notified about the cyberattack and all affected individuals have been notified by mail. Credit monitoring services are being offered to eligible patients. Keystone Health said it is implementing additional security measures to...
VisionWeb Data Breach Affects Up to 35,900 Individuals
Austin, TX-based VisionWeb Holdings, a provider of Internet-delivered software solutions for the eye care industry for improving practice efficiency, has recently reported a data breach to the HHS’ Office for Civil Rights that has affected up to 35,900 patients. According to the breach report sent to the HHS on October 3, 2022, unauthorized individuals gained access to its email environment which contained patient information. The breach was also reported to the Texas Attorney General, with that report stating that names, Social Security numbers, government-issued identification numbers, medical information, and health insurance information had potentially been compromised. Individual notifications started to be sent to affected individuals on October 3, 2022, along with information on the steps they can take to protect against identity theft and fraud. This post will be updated when further information about the breach becomes available. Eventus WholeHealth Announces Email Account Breach Durham, NC-based Eventus WholeHealth has recently confirmed that the email account of an...
Radiology Associates of Albuquerque Notifies Patients About Security Breach That Started in December 2020
Radiology Associates of Albuquerque (aka RAA Imaging/Advanced Imaging, LLC) has recently notified patients that some of their protected health information was stolen in a cyberattack that was detected more than 12 months previously. RAA said suspicious activity was detected within its environment in August 2021. Prompt action was taken to secure its systems and prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the incident. The forensic investigation confirmed that unauthorized individuals had access to certain systems between July 22, 2021, and August 3, 2021, and copied files from its network that contained patient data. The investigation also uncovered unauthorized access to email accounts, with the email accounts accessed by unauthorized individuals at various points over the preceding 8 months, between December 22, 2020, and July 15, 2021. RAA explained in a substitute breach notice on its website that the delay in issuing notifications was due to the time taken to investigate the incident. RAA said the review and...
70,000 Valle del Sol Community Health Patients Affected by Cyberattack
Phoenix, AZ-based Valle del Sol Community Health has notified 70,268 patients that some of their protected health information has been exposed. Valle de Sol did not state in its notification letters when hackers gained access to its network, or for how long they had access, but did confirm that the unauthorized activity was detected on January 25, 2022. Valle del Sol immediately took steps to secure its network and prevent further unauthorized access and engaged an independent cybersecurity firm to investigate the breach to determine if patient data had been accessed. Valle de Sol said the investigation indicated unauthorized individuals had access to files containing sensitive patient data and that patient information may have been acquired. A comprehensive review was conducted of all files that may have been accessed, which was completed on July 18, 2022. The delay in sending notification letters was due to the length of the investigation, then having to verify up-to-date contact information. The verification of addresses concluded on September 1, 2022. Valle de Sol explained in...
What Federal Department Regulates HIPAA?
Healthcare providers, health plans, healthcare clearinghouses, and business associates of those organizations must comply with the Health Insurance Portability and Accountability Act (HIPAA), but what federal department regulates HIPAA and takes action against organizations that fail to comply with HIPAA Rules? What Federal Department Regulates HIPAA? HIPAA is regulated by the Department of Health and Human Services’ Office for Civil Rights (OCR). Since the introduction of the HIPAA Enforcement Rule in March 2006, OCR was given the power to investigate complaints about HIPAA violations. OCR was also given the right to issue civil monetary penalties if HIPAA-covered entities were found to have violated HIPAA Rules. While OCR had the power to issue financial penalties, it is relatively rare for HIPAA violations to result in financial penalties. Over the years since the Enforcement Rule was passed, OCR has steadily increased enforcement of HIPAA Rules, although it has only been in the past four years that financial penalties for HIPAA violations have become more common. Since the...



