San Diego Family Care Agrees to $1 Million Settlement to Resolve Class Action Data Breach Lawsuit
San Diego Family Care, a Californian provider of medical, dental, & mental health services, has agreed to settle a class action lawsuit filed by patients affected by a data breach in 2020. The data breach that sparked the lawsuit was announced by the healthcare provider in May 2021 and was reported to the HHS’ Office for Civil Rights (OCR) as affecting 125,500 patients, although the total was later revised to 154,513 patients. The compromised data included names, Social Security numbers, government identification numbers, financial account numbers, dates of birth, medical diagnosis or treatment information, health insurance information, and client identification numbers. The security breach occurred in December 2020 at a technology provider and business associate, Netgain Technologies, and involved ransomware. Netgain Technologies reportedly paid a $2.3 million ransom for the keys to decrypt data and prevent any further disclosures of data. San Diego Family Care was one of several healthcare providers to have data compromised in the attack. After notifying the affected...
Data Theft Incidents Reported at MCG Health, Choice Health, & Goodman Campbell Brain and Spine
MCG Health Announces Data Theft Incident Affecting 1.1 Million Individuals MCG Health in Seattle, WA, a provider of patient care guidelines to healthcare providers and health plans, started notifying patients and members of MCG customers that an unauthorized party has obtained some of their protected health information. According to the breach notice on the MCG website, MCG determined on March 25, 2022, that an unauthorized individual had obtained data that matched data on its systems, including names, Social Security numbers, medical codes, postal addresses, telephone numbers, email addresses, dates of birth, and gender. MCG Health has advised affected individuals to review their account statements and monitor their free credit reports for signs of misuse of their information. The substitute breach notice on the MCG Health website does not explain the nature of the attack, how much data was stolen, how MCG Health learned that data had been stolen, or when the data theft incident occurred. A lawsuit filed against MCG Health alleges hackers first gained access to its systems in...
Class Action Lawsuit Filed Against Shields Health Care Group Over 2 Million-Record Data Breach
A class action lawsuit has been filed against Shields Health Care Group over its recently announced 2 million-record data breach – the largest healthcare data breach to be reported so far this year by a single HIPAA-regulated entity. Shields Health Care Group is the largest provider of MRI imaging services in New England and operates more than 40 facilities in the region. On May 27, 2022, the Massachusetts-based medical imaging service provider reported the data breach to the HHS’ Office for Civil Rights and confirmed that an unauthorized actor had access to some of its IT systems from March 7 to March 21, 2022. During that time, files were exfiltrated from its systems that included protected patient information (PHI) such as names, addresses, birth dates, Social Security numbers, diagnoses, billing information, insurance numbers and medical or treatment information. A HIPAA data breach of this scale is likely to see several lawsuits filed, with Keller Postman LLC and co-counsel Sweeney Merrigan Law LLP, and Finkelstein, Blankinship, Frei-Pearson, & Garber LLC the first to...
Kaiser Permanente Reports Email System Breach and Exposure of 70,000 Individuals’ PHI
Kaiser Permanente, one of the largest nonprofit health plan and healthcare providers in the United States, has reported a breach of its email system. Kaiser Permanente provides healthcare services to more than 12.5 million patients in 8 states and D.C. but said this breach only affected around 70,000 members of the Kaiser Foundation Health Plan of Washington. Kaiser Permanente said it was alerted to a security incident involving its email system on April 5, 2022. The email account of an employee was confirmed as being accessed by an unauthorized party, and immediate action was taken to secure the account to prevent further unauthorized access. Kaiser Permanente said the account shut down and was secured within hours. An investigation was launched to determine the nature and scope of the security breach and it was confirmed that the incident was limited to a single account; however, that account contained emails and attachments that included the protected health information of certain health plan members. The types of information exposed in the breach included patients’ first and...
OCR Issues Guidance on Audio-Only Telehealth for When the COVID Public Health Emergency Ends
Start preparing now and get your telehealth services HIPAA compliant as when the COVID-19 Public Health Emergency (PHE) ends, the telehealth HIPAA flexibilities stop. That is the advice of the Department of Health and Human Services’ Office for Civil Rights, which released new guidance this week on HIPAA and audio-only telehealth services. The Period of Enforcement Discretion Will End In March 2020, the HHS’ Office for Civil Rights issued a Telehealth Notification and said it would be exercising enforcement discretion and would not be imposing sanctions and penalties for HIPAA violations with respect to the good faith provision of telehealth services. The move was intended to make it easier for healthcare organizations to offer telehealth services to patients to help prevent the spread of COVID-19. OCR permitted healthcare organizations to use remote communication tools for telehealth, which included apps and platforms that would not normally be considered ‘HIPAA-compliant,’ and did not require HIPAA-covered entities to enter into a business associate agreement with the...



