Minnesota DHS Notifies 21,000 Patients That Their PHI Has Potentially Been Compromised
The Minnesota Department of Human Services has mailed letters to approximately 21,000 individuals on medical assistance to alert them to a possible breach of their protected health information (PHI) due to two recent phishing attacks. Two DHS employees’ email accounts have been confirmed as having been compromised as a result of the employees clicking on links in phishing emails. The investigation into the breach determined that the attackers accessed both email accounts although it was not possible to determine which, if any, emails in the account had been accessed or copied by the attackers. Minnesota DHS has reason to believe that other employees may also have been targeted and could also have clicked on links in phishing emails, but it has not yet been confirmed whether their accounts have been breached. The investigation into the phishing attacks is ongoing. The two email account breaches occurred on June 28 and July 9, 2018, although the IT department only determined that the accounts had been breached in August. Upon discovery of the phishing attack, both accounts were...
HSS Secretary Issues Limited Waiver of HIPAA Penalties Following Declaration of Public Health Emergency in Florida and Georgia
Following the presidential declaration of public health emergencies in the states of Florida and Georgia in the wake of Hurricane Michael, secretary of the Department of Health and Human Services (HHS) Alex Azar has followed suit in both states and has exercised his authority to waive HIPAA sanctions and penalties for certain provisions of the HIPAA Privacy Rule in the disaster areas. The HHS announced the public health emergency in Florida on October 9, and Georgia on October 11. The HIPAA Privacy Rule does permit healthcare providers to share protected health information during disasters to assist patients and ensure they receive the care they need, including sharing information with friends, family members and other individuals directly involved in a patient’s care. The HIPAA Privacy Rule allows the sharing of PHI for public health activities and to prevent or reduce a serious and imminent threat to health or safety. HIPAA-covered entities are also permitted to share information with disaster relief organizations that have been authorized by law to assist with disaster relief...
HHS OIG Raises Awareness of Its Cybersecurity-Related Activities on New Web Page
The Department of Health and Human Services’ Office of Inspector General (HHS OIG) has recently created a new web page detailing some of the actions that have been taken to improve cybersecurity within the HSS as part of its efforts to improve transparency of its cybersecurity activities. The new cybersecurity-focused web page will be regularly updated to include details of cybersecurity activities that have positively affected HHS programs and have helped strengthen the cybersecurity defenses, including reports of its audits, evaluations, and inspections of its offices and agencies that HHS OIG oversees. On the new web page, HHS OIG explains that it currently uses a three-pronged approach to safeguard data and the systems on which those data are stored. They are IT security controls, risk management, and resiliency. IT security controls are technological and procedural controls that protect against vulnerabilities to the confidentiality, integrity, and availability of data and systems. Risk management is proactively identifying risks and threats and taking action to reduce those...
Vulnerabilities Identified in PeerVue Web Server, Carestream Vue RIS and Siemens Healthcare Products
The Department of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) has issued five advisories in the past week about vulnerabilities discovered in equipment used by healthcare organizations in the United States. Change Healthcare PeerVue Web Server A vulnerability (CVE-2018-10624) has been identified in the Change Healthcare PeerVue Web Server which could allow an attacker to gain information about the web server that would enable it to be targeted in a cyberattack. The vulnerability only requires a low level of skill to exploit by an attacker on an adjacent network. The vulnerability exposes information through an error message. The flaw was discovered by security researcher Dan Regalado of Zingbox and has been assigned a CVSS v3 base score of 4.3. Change Healthcare took rapid action to address the vulnerability and a patch has now been issued. Users should contact Change Healthcare if they are running PeerVue Web Server 7.6.2 or earlier for information about installing the patch. Carestream Vue RIS A remotely exploitable vulnerability...
Hospitals Failing to Fully Comply with HIPAA Requirement for Providing Patients with Copies of Medical Records
The HIPAA Privacy Rule gave patients the right to obtain a copy of their medical records from their healthcare providers. Under HIPAA, copies of medical records should be provided to patients as soon as possible, but no later than 30 days from when the request is made. Even though compliance with the HIPAA Privacy Rule has been mandatory since April 14, 2003, there have been several cases of hospitals failing to provide patients with copies of their medical records. In 2011, the Department of Health and Human Services’ Office for Civil Rights (OCR) sent a message to healthcare providers about this aspect of HIPAA compliance when it issued a $4,300,000 civil monetary penalty to Cignet Health of Prince George’s County. Even though it has now been 15 years since compliance with the HIPAA Privacy Rule became mandatory, there is still widespread noncompliance when it comes to providing patients with copies of their medical records. According to a new study published in JAMA Network Open, healthcare providers are not providing patients with copies of their full medical records,...



