Phishing Attacks Announced by Comprehensive Sleep Care Center, McLaren Health Plan, and Ivy Rehab Physical Therapy
Loudoun Medical Group, dba Comprehensive Sleep Care Center (CSCC), has been affected by a phishing attack that occurred on or around June 19, 2019. The IT department was alerted to a potential email security breach when suspicious activity was detected in an employee’s email account. The password was immediately changed to prevent further unauthorized access and the incident was investigated. Forensic investigators confirmed the breach was confined to a single email account that was accessed by an unauthorized individual between June 15, 2019 and June 19, 2019. On October 17, 2019, the investigators confirmed which patient information had been accessed. The information in the email account varied for each patient and may have included the patient’s name along with one or more of the following data elements: Date of birth, Social Security number, passport number, driver’s license number, medical record number, payment card information, patient account number, financial account information, medical history, health insurance information, treatment information and/or date(s) of...
New Alexa Healthcare Skill Helps Patients Manage Their Medications
Amazon has announced that Alexa has a new healthcare skill that patients can use to manage their medications and order prescription refills. Earlier this year, Amazon announced that it has developed a HIPAA-eligible environment for skill developers that incorporates the necessary safeguards to comply with the requirements of the HIPAA Privacy and Security Rules. Amazon set up an invite-only program for a select group of skill developers to create new skills that could benefit patients. The new skill is the result of a collaboration between Amazon and the medication management firm Omnicell. Amazon contacted Omnicell and offered the company the chance to create the new skill after it was noticed that many Alexa users were using their devices to set medication reminders. Amazon had received feedback from several users who requested improvements be made to the reminders feature to allow them to set multiple reminders a day to take their medications. Initially, the new Alexa capabilities will be available to customers of the Giant Eagle pharmacy chain, which operates over 200...
Consumer Online Privacy Rights Act Offers CCPA-Style Privacy Protections for All U.S. Citizens
A federal law giving U.S. citizens new rights over their personal data has been introduced by U.S. Sen. Maria Cantwell (D-Washington). The Consumer Online Privacy Rights Act (COPRA) proposes California Consumer Privacy Act (CCPA) style protections at a national level to better protect the privacy of consumers and give them greater control over how their personal data is used. CCPA will take effect on January 1, 2020, but only applies to California residents. While there are laws in most states covering privacy and data security, there is no federal law covering all states. If such a law is introduced, it would make the rights of all U.S. citizens crystal clear and all Americans would have the same rights over how their personal data is used, irrespective of where they live. The bill, co-sponsored by Sens, Amy Klobuchar (D-Minnesota.), Ed Markey (D-Massachusetts), and Brian Schatz (D-Hawaii), is not the first of its type to be introduced. Several other bills have been introduced but they have failed to receive the required support. This bill may gather more support than others as it...
Great Plains Health Ransomware Attack Prevents Access to Patient Medical Records
North Platte, NE-based Great Plains Health has experienced a ransomware attack that has resulted in the encryption of patient medical records. The attack was detected at around 7pm on Tuesday, November 26. Prompt action was taken to minimize the impact on patients, and staff switched to pen and paper while computer systems were offline. IT staff have been working round the clock dealing with the attack. With access to medical records prevented, the decision was taken to cancel non-emergency patient appointments and some medical procedures, although surgeries and certain imaging procedures are continuing to be provided as normal. The hospital has not switched to emergency operations and is not diverting patients. The attack also impacted its phone and email system, although voicemail is unaffected. Staff have been checking voicemail messages regularly and have been calling patients back who have not been able to get through on the telephone. It is currently unclear whether the ransom demand was paid or if medical records and other encrypted files are being restored from backups....
$2.175 HIPAA Settlement Agreed with Sentara Hospitals for Breach Notification Rule and BAA Failures
The Department of Health and Human Services’ Office for Civil Rights (OCR) has announced its 8th HIPAA financial penalty of 2019. Sentara Hospitals has agreed to settle potential violations of the HIPAA Privacy and Breach Notification Rules and will pay a penalty of $2.175 million and will adopt a corrective action plan to address areas of noncompliance. Sentara operates 12 acute care hospitals in Virginia and North Carolina and has more than 300 care facilities in both states. OCR launched a compliance investigation in response to a complaint from a patient on April 17, 2017. The patient had reported receiving a bill from Sentara containing another patient’s protected health information. Sentara did report the breach to OCR, but the breach report stated that only 8 individuals had been affected, when the mailing had been misdirected and 577 individuals had had some of their PHI impermissibly disclosed. OCR determined that those 577 patients had their information merged with 16,342 different guarantor’s mailing labels. OCR advised Sentara that under the HIPAA Breach Notification...



