California Governor Signs Package of Bills to Improve Protections for Individuals Seeking Abortion Care
California has taken further steps to improve protections for individuals seeking abortion care and birth control. A package of bills has recently been signed into law by state governor Gavin Newsom, including new data privacy legislation that prohibits healthcare providers from releasing individuals’ medical information in response to subpoenas and requests from out-of-state. The bill (AB 2091) was introduced by Assemblymember Mia Bonta (D-Oakland) in response to the Supreme Court Decisions in Dobbs v. Jackson Women’s Health Organization which removed the federal right to an abortion and put abortion rights in the hands of individual states. Following the decision, several states implemented bans or restrictions on abortions and there are mounting fears that criminal investigations will be launched into women who seek abortions in other states. HIPAA permits healthcare providers to provide PHI to law enforcement to support criminal investigations in limited circumstances. The HHS recently issued guidance to health care providers that stressed that HIPAA does not require regulated...
Data Breaches Reported by Neurology and Fertility Centers in Nevada and California
Neurology Center of Nevada Cyberattack Impacts 11,700 Patients The Neurology Center of Nevada (NCNV), in Henderson, NV, has confirmed a data security event was detected on July 17, 2022, which rendered certain computer systems inaccessible. Prompt action was taken to secure its systems and an investigation was launched to determine the nature and scope of the security breach, with assistance provided by third-party cybersecurity experts. The investigation confirmed that the threat actors behind the attack had access to its systems for more than a month between June 12, 2022, and July 17, 2022, and during that time, files on its systems were subjected to unauthorized access. The compromised files contained full names, addresses, dates of birth, gender, driver’s license numbers, Social Security numbers, health insurance information, and medical information, such as diagnosis/treatment information, lab results, and medications. Affected individuals have been notified by mail and advised to monitor their accounts, credit reports, and explanation of benefits statements for unusual...
HHS Urged to Extend Deadline for Compliance with Cures Act Information Blocking Requirements
The deadline for compliance with the information blocking requirements of the 21st Century Cures Act is October 6, 2022, after which the HHS can impose financial penalties and healthcare providers will be subject to appropriate disincentives if they are determined to have failed to facilitate the easy digital sharing of patient data. Information blocking is defined as any practice by an entity that is likely to interfere with the access, exchange, or use of electronic health information that is not covered by eight exceptions. These new requirements were introduced pursuant to the 21st Century Cures Act to improve patient access to their medical records. From October 6, 2022, healthcare providers are required to start sharing the data of patients contained in a designated record set, as defined under HIPAA. Previously the data sharing mandates only required information to be shared that is contained in the USCDI. Last week, 10 healthcare groups wrote to HHS Secretary, Xavier Becerra, to express their concern about the fast-approaching deadline. They explain that despite the best...
Cybersecurity Awareness Month Focuses on 4 Key Behaviors
October is Cybersecurity Awareness Month – a 19-year collaborative effort between the government and industry to improve awareness of cybersecurity in the United States, led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance (NCA). 2022 Cybersecurity Awareness Month – See Yourself in Cyber The theme of this year’s Cybersecurity Awareness Month is See Yourself in Cyber, where the focus is on the actions that everyone should take to improve cybersecurity. In previous years, the month of October has been divided into four weeks, each of which has a different theme. This year, rather than have a different weekly theme, the focus each week will be on one of four key behaviors that everyone should adopt. Simply practicing these basics of cybersecurity will greatly improve an individual’s and an organization’s security posture. Enabling multifactor authentication – Improve access controls by adding additional authentication requirements in addition to a password. MFA can prevent access from being granted to accounts using stolen...
Zero Day Microsoft Exchange Server Vulnerabilities Being Actively Exploited
Microsoft was warned that two zero-day vulnerabilities in Microsoft Exchange Server are being actively exploited in the wild and has shared mitigations ahead of the vulnerabilities being patched. The two flaws are being chained together and are being exploited by a Chinese threat actor. The attacks have been limited so far, but the healthcare and public health sector in the United States could potentially be a target. The flaws affect Microsoft Exchange Server 2013, 2016, and 2019. CVE-2022-41040 is a Server-Side Request Forgery (SSRF) vulnerability that can be exploited for initial access, after which the second vulnerability can be exploited – A Remote Code Execution vulnerability thacked as CVE-2022-41082. The second vulnerability can only be exploited if PowerShell is available to the attacker. Microsoft has confirmed that the flaws cannot be exploited by an unauthenticated attacker. Both vulnerabilities require authenticated access to a vulnerable Microsoft Exchange Server to be exploited, such as if an attacker had valid stolen credentials. The first vulnerability has been...



