- All
- Backup & Disaster Recovery
- Business Associates
- Client News
- Healthcare Industry
- HIPAA
- HIPAA Audits
- HIPAA Violations
- HSN News
- Legal
- MACRA
- Policies and Procedures
- Press Release
- Remote Workforce
- Risk Assessment
- Scams
- Security
- Security Reminders
- Security Training
- Telehealth
- Website
Annual Business Checkup
It’s standard practice to remind your patients to schedule an annual checkup. As a healthcare provider, you should do the same for your business. Don’t worry or feel overwhelmed at the thought of it! Many of the questions will be the same: what’s working, what isn’t, and what would you do better in the new […]
The Future of Healthcare Cybersecurity: Trends to Watch
Introduction As technology booms, healthcare has become increasingly reliant for patient care, record-keeping, and communication. While this digital transformation has brought many benefits, it has also made the healthcare sector a prime target for cyberattacks. Protecting patient data and ensuring the integrity of healthcare systems is of paramount importance. To stay ahead of cyber threats, […]
How to Handle a Breach
Introduction: “You’ve been breached”: three words that no business owner ever wants to hear, but for which they should be prepared. Data breaches have become an unfortunate reality for many organizations, especially those in the healthcare industry. Protecting sensitive patient information is not just a matter of compliance; it’s a crucial component of maintaining trust […]
A Dynamic Duo: Cybersecurity and Compliance
Introduction In a world where health records are considered 50 times more valuable than credit card information on the dark web, the OCR’s basic requirements are no longer sufficient on their own. Covered entities and business associates need comprehensive solutions and cybersecurity training to avoid data breaches and safeguard their patient data. Like pediatrics and […]
Elements of a Comprehensive HIPAA Annual Training
Introduction Navigating HIPAA can be an intimidating process, from finding information to documenting completed requirements. According to the training page of the OCR’s website: “The HIPAA Rules are flexible and scalable to accommodate the enormous range in types and sizes of entities that must comply with them. This means that there is no single standardized […]
Maintaining HIPAA-Compliant Communication Amongst Colleagues
Maintaining HIPAA-Compliant Communication Amongst Colleagues Let’s Talk About Oral Privacy In such an intense and impactful field, it’s completely understandable that healthcare professionals often find themselves wanting to share experiences or seek support from colleagues. However, they must navigate a delicate balance due to the stringent regulations imposed by HIPAA. While the spotlight often shines […]
Safeguarding Patient Privacy through Proper Record Disposal
Common Mistakes & Best Practice Recommendations In the fast-paced world of healthcare, safeguarding patient privacy remains paramount. Yet, despite the diligence exercised in patient care, one area where vulnerabilities persist is record disposal. From the cluttered file rooms to the maze of electronic data, mistakes are made that can jeopardize sensitive patient information. In this […]
Why Your SMB Needs SAT
A Comprehensive Guide Welcome to 2023, where cybersecurity is not just an IT concern, but a vital aspect of business continuity. For small and medium healthcare organizations (SMBs), the stakes are high when it comes to data breaches and ransomware attacks. The consequences can be devastating, with costs exceeding $250,000 for recovery, investigations, customer notifications, […]
Non-Cloud Backups: A Lifeline for Healthcare
IT Experts Fall Victim to Cyberattack Last week, CloudNordic, a prominent Danish cloud provider, became the victim of a devastating ransomware attack. This malevolent intrusion sent shockwaves through the IT company as cybercriminals encrypted their servers, grinding all operations to a halt and endangering the integrity of both company and customer data. Remaining Calm and […]
The Year-Round Commitment to SRA Recommendations
The Year-Round Commitment to SRA Recommendations A Pillar of HIPAA Compliance As a covered entity or business associate, protecting sensitive patient information is not just a priority—it’s a legal and ethical obligation. HIPAA stands as the guardian of patient data, ensuring its security, privacy, and confidentiality. One of the cornerstones of HIPAA compliance is the […]
Ensuring Robust Data Security
5 Vital Plans Every Covered Entity and Business Associate Should Have in Place With cyberattacks and data breaches on the rise in healthcare, safeguarding sensitive information has become paramount for organizations. For covered entities and business associates, proactivity is key to maintaining the integrity and confidentiality of data. Here are five essential plans that every […]
The Rising Threat of Social Engineering Attacks in Healthcare
Social engineering attacks involve manipulating individuals into divulging confidential information, providing unauthorized access, or executing actions that compromise the security of systems or data. Attackers exploit psychological and emotional factors to exploit employees’ trust and manipulate them into performing actions that put the organization’s sensitive information at risk. Small healthcare businesses are under a heightened […]
NIST Guidelines for Strong Passwords
The healthcare industry relies heavily on technology to store, manage, and access patient information. And one fundamental aspect of protecting patient information is using strong passwords or passphrases in line with the National Institute of Standards and Technology (NIST) guidelines. The Significance of Strong Passwords Passwords act as the first defense against unauthorized access to […]
Online Tracking Technologies: Warning Issued for Healthcare
In response to the growing use of online tracking technologies in healthcare, the HHS Office for Civil Rights (OCR) and the Federal Trade Commission (FTC) have issued a joint warning to hospital systems and telehealth providers about the potential threats these tracking technologies pose to patient data security. The Importance of Compliance HIPAA was enacted […]
Amazon Clinic and HIPAA
The healthcare industry has witnessed the integration of technology into many different aspects of patient care and management. The Amazon online community has stepped into this domain with the introduction of Amazon Clinic. While an innovative healthcare solution, it raises questions about its adherence to HIPAA (Health Insurance Portability and Accountability Act) compliance, a crucial […]
Cybersafe Tips for Finding Steals while Avoiding Scams
It’s finally here! After months of racking up your cart with all the therapy materials, prize reinforcements, and other office odds and ends, it’s time to check out. What you may not have considered is that cybercriminals have also been waiting in anticipation of Prime Day. The increased online activity and sense of urgency are […]
Healthcare Security Violation
A recent investigation by the Office of Civil Rights (OCR) alleges that several security guards from Yakima Valley Memorial Hospital impermissibly accessed the medical records of 419 individuals. This incident highlights the importance of maintaining strict protocols and vigilant oversight when it comes to safeguarding sensitive patient information. The details involving the hospital security guards […]
The Importance of a Security Risk Assessment
What is a security risk assessment (SRA) and how can it help your healthcare business? The protection of sensitive patient information and the integrity of critical systems is of paramount importance to any business. With the increase in cybersecurity threats, taking a proactive approach to security measures is far more ideal than being reactive to […]
Enhancing Ransomware Defense
Recent research conducted by Arete and Cyentia Institute sheds light on the ransomware landscape within the healthcare sector. The study reveals that healthcare organizations are more likely to pay ransoms than other industries. Additionally, the report highlights the low adoption of multi-factor authentication (MFA) and emphasizes the need for improved cybersecurity measures in the healthcare […]
HIPAA Secure Now: Helping Healthcare Businesses
Simplifying HIPAA compliance for Covered Entities with HIPAA regulations can be complex and challenging for covered entities. Failure to meet the requirements can lead to severe penalties and reputation damage. This is where we come in. Here are some of the ways that HIPAA Secure Now can help healthcare businesses: Annual Risk Assessment: We […]
Enhancing Healthcare With Increased Language Access
HHS Releases Report to Increase Language Access for Persons with Limited English Proficiency Language barriers can pose significant challenges when it comes to delivering quality healthcare to individuals with limited English proficiency (LEP). Recognizing the importance of language access in healthcare settings, the U.S. Department of Health and Human Services (HHS) has recently released a […]
Understanding the OCR 90-Day Transition Period
The Office for Civil Rights (OCR) 90-day transition period commenced on May 12, 2023. As a HIPAA compliance company, we understand the importance of staying up-to-date with regulatory changes. Let’s delve into the transition period and its significance, and provide guidance on how your organization can ensure seamless compliance in this evolving landscape. Understanding the […]
Business Associates HIPAA Compliance
A recent incident involving Arkansas-based MedEvolve serves as a reminder of the consequences that arise from the mishandling of PHI and the importance of healthcare businesses ensuring that they and their business associates are HIPAA compliant. The HIPAA Violation On May 16, 2023, the HHS Office for Civil Rights announced the resolution of a HIPAA investigation […]
End of COVID-19 Public Health Emergency
As a healthcare provider, you are familiar with the Public Health Emergency (PHE) declaration that has been in place since the beginning of the COVID-19 pandemic. This declaration has provided a number of flexibilities and protections for healthcare providers, including increased telehealth access and relaxed HIPAA requirements. Approaching Deadline On May 11, 2023, the PHE […]
How to Communicate with Dental Patients via Text-Messaging
As technology continues to evolve, so do the ways in which dental practices communicate with their patients. Text messaging has become a popular method of communication, providing convenience and efficiency for both patients and dental staff. However, it is crucial that any communication is done in a secure and HIPAA-compliant manner. Our team of HIPAA […]
Privacy vs. Security Rule
When it comes to HIPAA compliance, it’s easy to feel as if you’re being pulled in a million different directions at once. In part, this could be due to the fact that there are 4 different rules that go into HIPAA: the Privacy Rule, the Security Rule, the Breach Notification Rule, and the Omnibus Rule. […]
Physical Safeguards for HIPAA Compliance
While it’s easy to get caught up in the many, many words of policies and procedures, how your space physically looks and functions are just as important. Physical safeguards play a vital role in achieving HIPAA compliance and keeping sensitive data out of the wrong hands. Let’s look at six physical safeguards that every healthcare […]
HIPAA Compliant Waiting Room
Let’s discuss the most bustling room in your healthcare practice- the waiting room. Whether it’s parents waiting for their children to finish their sessions, patients who arrive super early, or you’re having one of those running-behind days, having a HIPAA-compliant space is crucial to maintain patient privacy and security. So, what can you do to […]
Be Alert: Phishing Attacks
Healthcare businesses are increasingly reliant on technology to manage patient information, conduct financial transactions, and communicate with staff and patients. While technology has many benefits, it also presents significant risks, including the threat of cyberattacks. One of the most common types of cyberattacks is phishing when an attacker impersonates a trusted individual or entity and […]
HIPAA Legal Reminder
As a HIPAA-covered entity, it is crucial to understand the importance of protecting the privacy and security of patient personal health information (PHI). And a recent surge in litigation serves as a reminder that healthcare organizations must take adequate measures to safeguard PHI. Recent Cases In one recent case, a healthcare provider was sued for […]
HIPAA Security Policies
. In healthcare, it is crucial to ensure the security and privacy of electronic health records and all patient data with security policies. HIPAA provides guidelines for healthcare organizations and covered entities to follow in order to maintain the confidentiality, integrity, and availability of patient health information PHI, or ePHI. What are some of the […]
Restructuring the OCR
The Health and Human Services (HHS) Office for Civil Rights (OCR) is responsible for enforcing and protecting civil rights and privacy rights in the healthcare industry. With the increasing number of complaints and reviews regarding the Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health (HITECH) Act, the […]
HIPAA: P for Portability
Undoubtedly, and whether you’re in healthcare or not, you’ve paused when writing or typing ‘HIPAA’. Is it HIPPAA? HIPPA? What does it stand for? We find that the P trips most people up more often than the rest. It’s something about ‘patient’ right? Not exactly, so let’s learn more about that P and what it […]
OCR Healthcare Report Released
The Office of Civil Rights (OCR) within the U.S. Department of Health and Human Services is responsible for enforcing compliance with the Health Insurance Portability and Accountability Act (HIPAA). As part of its mandate, the OCR annually releases a report on data breaches in the healthcare industry. The most recent report, which covers the year […]
HIPAA Compliance & Cybersecurity: How They Differ
Data privacy and cybersecurity are paramount concerns for individuals and organizations alike. The Health Insurance Portability and Accountability Act (HIPAA) and cybersecurity standards are in place for both. It’s common to confuse the two critical healthcare business components as the same thing – yet they are very different. While both HIPAA compliance and cybersecurity address […]
A Different Kind of Heart Health
Valentine’s Day is here. Romance and love are in the air. It’s also a good time to remind your patients to protect their hearts in a different way. It’s the time of year when we express our love and affection for one another. That may often be with gifts, cards, and romantic gestures. However, this […]
The Benefits of Artificial Intelligence in Healthcare
Artificial intelligence (AI) is rapidly transforming many industries and healthcare is no exception. With the advent of AI, healthcare businesses may face different threats to their cybersecurity. As a result, they could find their business in possible violation of HIPAA rules and regulations. There are also important ethical and privacy concerns associated with the use of […]
HIPAA’s Role in Software Support
The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that was enacted in 1996 to protect the privacy and security of individuals’ health information. It established requirements for covered entities, such as healthcare providers, insurance companies, and healthcare clearinghouses, to implement reasonable and appropriate administrative, physical, and technical safeguards to protect electronic […]
Data Privacy Week
This week is Data Privacy Week. This international effort to encourage respect for privacy is encouraged for all industries, but in healthcare, it’s essential. Data privacy in healthcare is a critical issue that affects not only patients, but also healthcare providers, insurers, and researchers. The sensitive nature of personal health information (PHI) and the potential […]
HIPAA: Text Messaging and Chat Services
Necessary Technology As technology advances, more healthcare providers adopt digital technologies. Therefore, HIPAA compliance in regard to text messages and chat services becomes increasingly important. The HIPAA Privacy Rule was created to protect the privacy of personal health information (PHI). And that includes PHI that is transmitted via text message or other electronic messaging services. […]
Cybersecurity is Vital for Healthcare Organizations
In today’s digital world, it has become increasingly important to protect healthcare organizations from cyber threats. With the rise of medical data breaches and ransomware attacks, there has never been a more pressing need for healthcare organizations to take their cybersecurity measures seriously. Let’s take a look at why cybersecurity is so critical in the […]
Social Security Scam
Social Security Scam Alert The beginning of the year provides a new opportunity to scam people. Scams that center around the annual updates and renewals of programs and policies like Social Security are one of the most reported to the government. Be sure to advise your patients that if they are in receipt of Social […]
Healthcare Industry End of Year Checklist
Let’s wrap up 2022 with some end-of-year tasks you’ll want to check off of your list if you’re in the business of healthcare! Training Program HIPAA compliance requires a training program. This means ensuring that your existing staff has completed their training annually and making sure that any new hires have been trained as well. […]
Artificial Intelligence in Healthcare
AI in Healthcare Artificial Intelligence, or AI, is increasingly used in healthcare. This can be seen in the form of machine learning which assists in detecting patterns, diseases, learning technologies, and more options to assist with patient care. Though not a failsafe, it can offset the risk of medical errors and allow for treatment that […]
HIPAA & Tracking Technologies
HIPAA & Tracking Technologies Tracking technologies such as Google Analytics and Meta Pixel are designed to collect and analyze user data for online activity. The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) recently issued a notification regarding these and the obligation to HIPAA from the covered entities […]
End of Year SRA
A security risk assessment must be conducted to maintain HIPAA compliance per the Security Rule. A security risk assessment is also referred to as an SRA. It is a requirement for government plans such as Medicare, Obamacare, and Medicaid. It is also required for individual health care plans and employer-sponsored plans. Where to Start Identify […]
Health Insurance Scams
The annual open enrollment period for healthcare insurance provides another opportunity for scammers to take advantage of. From gathering personal information to receiving payments for non-existent plans, criminals will try nearly anything to score. The signs of a scam aren’t always easy to spot. Here are some of the tactics that consumers should be on […]
Amazon In Healthcare
Amazon has launched its latest venture in healthcare with Amazon Clinic. This virtual care platform will provide services and support for nonurgent health and lifestyle needs. This was created with the goal of providing users with easy access to care that allows them to “skip the waiting room.” Treatments This virtual healthcare service will provide […]
Administrative Simplification Provisions of HIPAA
The HIPAA Administrative Simplification provisions are in place to provide consistency in electronic communications within healthcare for Protected Health Information (PHI). These mandate the usage of standard transactions, code sets, and identifiers for the United States healthcare system. Who Must Comply? The most common organizations which must comply are healthcare clearinghouses, healthcare providers, and health […]
Asset Management Program
Having an asset management plan is essential to your healthcare business. Similar to how you’d want a list of your household items for insurance coverage in the event of theft or loss, you need to know the details and access them quickly. Especially if an item goes missing or breaks. It is likely that your […]
Security Incident Guideline Reminder
The HIPAA Security Rule includes requirements for a security incident response plan that are important to know especially as the number of reported data breaches continues to rise. The Data Check Point Research provided a mid-year report on cyber attack trends that indicated a 69% increase in targeted healthcare data breaches between 2021 and 2022. […]
Cybersecurity: Physical Devices
As we wrap up National Cybersecurity Awareness Month, we’re going to take a look at the importance of protecting your physical devices. The panic that sets in when you misplace your phone or laptop is overwhelming. But that feeling is amplified if that device contains patient information or access to it. When we mention your […]
Cybersecurity: Social Media
As we continue into National Cybersecurity Awareness Month, this week we focus on social media. Why does what you do in your personal life matter in your professional world? Aside from the possible personal implications, the risk to your cybersecurity also exists. How Hackers Work A cybercriminal knows how to gain access to your trust. […]
Cybersecurity: What is Phishing?
Phishing is one of the biggest threats to any business or individual. With October being National Cybersecurity Awareness Month, we thought we’d explain what it is, why it is dangerous, and how to avoid falling for it, which are all critical to staying safe. What is Phishing? Officially, phishing is defined as the practice of […]
Security Risk Assessment
The HIPAA Security Rule mandates that covered entities must conduct a security risk assessment or SRA. This includes health care plans for individuals, government plans (Medicare, Medicaid, Obamacare), and employer-sponsored plans. Providers that conduct electronic health care transactions must comply with the Security Rule. This means conducting an SRA. It is recommended that this occurs […]
HIPAA Fines for Three Dental Offices
The HHS Office for Civil Rights (OCR) has announced resolutions regarding three HIPAA violation investigations. These settlements result from a years-long emphasis on enforcing this regulation by the OCR. There were three dental practices that were given fines with regard to the potential violation of the HIPAA Privacy Rule’s patient right of access. Recently appointed […]
Common Healthcare Breaches
What Are the Most Common Healthcare Breaches? When it comes to protecting your business, the approach needs to extend beyond the locks on the doors. Cyber threats are the highest risk to your patient and data security. So what are the most common healthcare breaches that you should be on the lookout for regularly? Ransomware […]
Is There a HIPAA Violation in Your Trash?
Is Your Trash a HIPAA Violation? In the case of the New England Dermatology and Laser Center (NEDLC), their trash was a violation. And a costly one with a $300,640 fee attached. A security guard found a container with identifying information on the attached label. As a result, an investigation by the Department of Health […]
HIPAA & Cybersecurity Insurance
Healthcare businesses need to be aware of the requirements that come with a cybersecurity insurance policy. In a world of online profiles, splashy websites, and great social media campaigns, businesses can misrepresent themselves in more ways than one. A great photo of your team or a full biography may help create patient trust, but it […]
HIPAA Compliant Chat
HIPAA Compliant Chat Being available to your patients 24/7 isn’t practical for most healthcare practices. Chat services can provide a response option or even resolution until normal business hours resume. Additionally, chats can offer initial patient care or registration services. As a HIPAA-covered entity or business associate, you must consider compliance when offering this service. […]
NHS Cyber Attack
An Indirect Hit The NHS, or National Health Service, is the publicly funded healthcare system for the United Kingdom. They are supported by Advanced who is a managed service provider (MSP). Healthcare companies may outsource their IT departments to other companies to manage the cybersecurity and technical aspects of the business. This allows them to […]
Portability in HIPAA
Portability in HIPAA There are many aspects of HIPAA. And sometimes there isn’t a clear understanding of what it covers. We also find that it is the “P” that often trips people up. Because of the strong emphasis on confidentiality, security, and safe handling of information, there is an assumption that the word Privacy is […]
NIST and HIPAA
Health Care Cybersecurity Update on Guidance The National Institute of Standards and Technology (NIST) has provided updated guidance for the health care industry. Designed to help with electronically protected health information (ePHI), they have created a new draft titled Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide (NIST Special […]
ADA: Americans with Disabilities Act
This year marks the 32nd anniversary of the signing of the Americans with Disabilities Act, known as ADA. This Act is in place to prohibit discrimination against any qualified individual. As outlined on the ADA National Network site, it ‘is a civil rights law that prohibits discrimination against individuals with disabilities in all areas of […]
What Is GDPR?
Are you familiar with the European Union (EU) regulation of GDPR? There may be some confusion over this policy and those who believe it to be the counterpart to the United States’ HIPAA regulation. While there may be some overlap, they are not the same. As a US-based business that is a covered entity or […]
HIPAA Right to Access Enforcement
The Office for Civil Rights (OCR) isn’t offering leniency just because you’re a small business. Action will be taken, despite the impact that a HIPAA fine can have on this sector of healthcare. And as eleven recent investigations prove the point, many of those were small practices. This brings the total to 38 enforcement actions […]
Certificate of Need
What is a Certificate of Need? A certificate of need, or CON, is a legal document that is required for the construction of a new healthcare facility. It regulates the healthcare system by requiring approval from regional governments. However, there are variations within the 35 states and Washington D.C. that need them. What Do They […]
API Adoption and Healthcare
API Adoption and Healthcare Healthcare faces threats from cybercriminal activity at rates that continue to rise. The patient data that they access and maintain is valuable on the dark web in more ways than one. It can be an access point for a greater breach and then used to manipulate or steal identities and attack […]
Healthcare Breaches on the Rise
Healthcare Breaches on the Rise Don’t shy away from this headline, healthcare businesses cannot put their head in the sand or look the other way when it comes to establishing a strong cybersecurity program. For many, the focus has been on HIPAA compliance. This consumes resources both in the workforce and funding. It has also […]
HIPAA and Audio-Only Telehealth
HIPAA and Audio-Only Telehealth The Department of Health and Human Services (HHS) put clarity recently on how the HIPAA Security Rule applies to telephone technologies. In the case of telephone lines that are traditional landlines, the rule does not apply. But it does apply to mobile technologies that utilize electronic media such as WIFI. What […]
Exceptions to a HIPAA Breach
Exceptions in a HIPAA Breach In 2007 the Guide to Medical Privacy Law was published. It indicated that on multiple occasions hospitals, EMT services, schools, and other public agencies were incorrectly withholding news out of a fear of violating HIPAA policy. Often, there isn’t a clear understanding as to what constitutes exceptions to HIPAA and […]
What is the Digital Front Door?
The traditional way to see your healthcare practitioner was to call the office, schedule an appointment and when the time came, go to the office for your visit. You’d get there and then open the front door to attend your appointment. Like nearly everything, time, and our increased electronic footprint have brought change to that […]
Remote Workforce and HIPAA
Whether a change in your business structure came about from the pandemic, or it just makes more sense for your team, remote work is the norm for many more professionals today than it was in years past. If you’re in healthcare, this means that you need to factor in the HIPAA component as well as […]
What’s the HIPAA Omnibus Rule?
The HIPAA Omnibus Rule was established to identify and further outline accountability within the entities of healthcare regarding patient data. To understand the HIPAA Omnibus Rule and how it affects these entities, we need to understand who and what are the “moving parts” that make up the operation. Once we recap these key components, we’ll […]
The 18 PHI (Protected Health Information) Identifiers
18 HIPAA PHI Identifiers HIPAA regulations are in place to ensure that you protect and secure the patient data that as a healthcare business, you have access to and collect. The Department of Health and Human Services (HHS) has identified 18 patient identifier categories as it pertains to their guidance on satisfying the safe harbor […]
Your New HIPAA + Cybersecurity News Source
Good Intentions Your workday in your healthcare business may start out with a clear plan of what you have ahead – you have your task list and work items to get through. But when it comes to cybersecurity, we need to be made aware of things in a timely and efficient manner. It may be […]
HIPAA Compliance Audit: What to Expect
“We’re being audited!” Those words strike fear and uncertainty in most of us – especially if you are in healthcare. But what actually happens in a HIPAA audit? Will a government official show up unannounced with a briefcase and ask for you to produce every bit of your business’s HIPAA documentation while sequestering your team […]
Business Websites: Do They Need to Be HIPAA Compliant?
The process of assessing your business when it comes to HIPAA Compliance will likely present you with the opportunity to review all the components that contribute to your professional structure and setup. This will likely include a website. Does a Website Fall Under HIPAA Regulations? If a website is used to collect and process protected […]
High Alert: Healthcare Ransomware Threat!
The Cybersecurity Program within the Department of Health and Human Services (HHS) came out this week with a strong warning for healthcare organizations about an “exceptionally aggressive” ransomware group that is targeting them. The Hive ransomware group is financially motivated and uses various methods to target organizations including phishing and attacking remote access/VPNs. They encrypt and steal data […]
HIPAA Security Officer
Recently we went over the role of the HIPAA Privacy Officer and what responsibilities that individual would oversee, as well as what qualifications an ideal candidate would bring to the position. Additionally, HIPAA Regulations require that you formally identify a Security Officer in addition to a Privacy Officer, but they can be the same person. […]
HIPAA Privacy Officer – Who’s in Charge Here?
Under the HIPAA Privacy Rule, there must be one individual who is identified as the Privacy Officer. What does that mean? Is it a paid job? What are the requirements? Are they the ones who will be accountable in the case of a violation or if a data breach should occur? Every covered entity and […]
Regardless of Your Business Size, You’re a Target
Many people in healthcare make the incorrect assumption that their business won’t be a target for cybercriminals because they are “just a one-man show” or “aren’t part of a big network”. Neither way of thinking is wise, because when a cybercriminal is trying to compromise data or an entire network, every organization is valuable, and […]
IoMT: What is the Internet of Medical Things?
Are you familiar with the IoT or the Internet of Things? This is the term that is applied to objects that are connected via the internet to collect and transfer data without any human interaction or intervention. This includes items like your smart television or even a refrigerator that is connected to an app on […]
Fraud Alert: Beware of Tax Related Scams
Healthcare professionals are gatekeepers to a variety of confidential information about their patients and the businesses that they work for, and for this reason, they are a highly coveted target by cybercriminals. Being on guard and alert all year is critical when you are overseeing the Protected Health Information (PHI) of your patients. Be aware, […]
Protected Health Information: How Long Do You Need to Keep Records?
In your home, it is likely that you have at minimum a pile of paperwork and records that you’ve held onto “just in case you need it” for a possible tax audit, warranty, to make a return, or several other random reasons you’ll need to reference it in the future. No one ever seems to […]
What Is MFA….and Do I Need It?
What Is MFA? Multi-Factor Authentication, or as it has become commonly known, MFA, is the practice of “doubling down” on your login security. You are using Multiple (more than one) Factors (ways or methods) to Authenticate (verify) your identity when you access an account. When you hear the term 2FA, this means that you need […]
You Can Leave a Message – But Make Sure It Is HIPAA Compliant
Even though telephone conversations and answering machines are considered outdated or passe to some people, it remains necessary to sometimes leave a message for the intended call recipient. In healthcare, voice messages are often necessary for appointment reminders, follow-up calls, and communication to patients. Within the realm of HIPAA, what are you allowed to say? […]
Reporting a HIPAA Breach – Details You’ll Want to Know
The Health Insurance Portability and Accountability Act, or as it is commonly known as HIPAA, was created to set standards nationally. These are in place to protect the personal health information and medical records of individuals as well as give them access easily. As the March 1st deadline for reporting a breach draws closer, knowing […]
Annual Deadline for HIPAA Small Breach Reporting is Approaching
March 1st, 2022 is the deadline for breach reporting for HIPAA-covered entities and their business associates – and the date is fast approaching! The HIPAA Breach Notification Rule requirement means that HIPAA-covered entities, as well as any of their business associates, notify the appropriate parties, including the Office for Civil Rights (OCR) Secretary of Health […]
Healthcare Breach Statistics Continue Rising
An astronomical increase of 450% would be a wonderful thing if we are talking about revenues or productivity. But when it comes to COVID-19 related phishing attacks, that percentage in the jump of attacks from 2019 to 2020 is staggering – and a serious issue that needs to be addressed. According to the ForgeRock 2021 […]
How to Handle HIPAA and Email
It’s fast and easy, and you can often work more efficiently with an email exchange than if you must make phone calls or schedule appointments to discuss patient care. But where does that exchange fall when it comes to HIPAA compliance? The HIPAA Security Rule introduced several requirements to consider before an email can be […]
What is a Business Associate Agreement in HIPAA?
In simple summary, a Business Associate Agreement (BAA) is a legal contract that exists between a Covered Entity and a Business Associate who comes into contact with Protected Health Information (PHI). Sometimes called a Business Associate Contract, it is critical and required to maintain HIPAA compliance. With the main bulk of PHI being stored electronically, […]
Phishing Attacks on the Healthcare Industry
What is Phishing? Phishing is the practice of tricking users by imitating reputable companies in order to reveal personal or confidential information which can then be used in a more illicit manner. This is done via a deceptive email or website, and often in a combination of both. Spear phishing takes the manipulation one step […]
Looking Ahead: Healthcare Cybersecurity Predictions for 2022
The pandemic pivot that seemed as if it would be temporary a few years ago, those behaviors that redirected how we work and live, is now a seemingly permanent modification. Remote work, telehealth, and the increasing use of products that are part of the IoT, or the internet of things, have provided us with increased […]
Your HIPAA Breach Notification Questions Answered
The HIPAA Breach Notification Rule is a requirement put in place that requires HIPAA-covered entities and their business associates to “provide notification following a breach of unsecured protected health information.” The details provide an outline for how healthcare providers, hospitals, and physicians must notify the affected individuals, the Secretary of the U.S. Department of Health […]
HIPAA Privacy Rule Update: Extreme Risk Protection Orders
Recently the Department of Health and Human Services (HHS) along with the Office for Civil Rights (OCR) issued an announcement regarding extreme risk protection order (ERPO) laws and the disclosure of protected health information (PHI). This published model was created as a way to provide each state with a framework to consider as they implement […]
End of Year Checklist for Healthcare
As we wrap up another calendar year, getting ready for holiday break means wrapping up more than presents. Take a moment to go over a few items that you should review to make sure they are done for 2021 or ready to go in the new year. Security Risk Assessment A Security Risk Assessment, or […]
HIPAA Right of Access
HIPAA Right to Access Initiative is Alive & Well In 2019 we witnessed the Office for Civil Rights (OCR) make it public that they were going to up their efforts when it came to enforcing the rights of an individual to access their health records. This is known as the HIPAA Right of Access initiative. […]
Is That Video Rated HC?
No, there isn’t such a rating system, but it might be something to consider. There are many different communication platforms that healthcare providers can use to communicate with each other, such as email, instant messenger systems, and even through social media sites. While these platforms can be very useful for communicating quickly and easily, they […]
Oops, Was That A HIPAA Violation?!
Working in healthcare means that you are certainly aware of HIPAA’s existence, but it doesn’t necessarily mean you are the resident expert on what constitutes compliance. You know what you can or can’t do – generally speaking. Most likely, you follow the rules as they are explained to you, and don’t deviate much from that. […]
‘Tis the Season for Yams…and Scams
Seasonal Scams in Healthcare We’re entering the time of year that we pause and reflect on what we have to be thankful for, especially this year, as more of us are able to gather in person. We can stop, slow down, and appreciate what we have. But this doesn’t necessarily mean a break for those […]
Administrative Safeguards of the Security Rule: What Are They?
The HIPAA Security Rule requires healthcare providers and their business associates to implement physical, technical, and administrative safeguards to protect the electronic Protected Health Information (PHI) that they utilize. It establishes national standards to protect that information. These standards apply not just to covered entities, but any organization that handles PHI – including subcontractors and business associates. Administrative safeguards (also called […]
Is Your Head or Your Business in the Cloud?
Cloud Hosting & HIPAA Compliance When you think of trends in healthcare, what comes to mind? Maybe it’s a particular EMR system, new machines in the office, ways in which you communicate with patients… the list goes on. One thing is for sure when we think about all the ways that healthcare has changed over […]
What’s So Important About Security Risk Assessments for HIPAA Compliance?
Before you buy a home, an inspection is completed as a way of exposing any potential issues to you as a buyer. This can give you leverage when it comes to purchasing price negotiation since these liabilities can often present risks to you as a resident. Those risks can come in the form of cost […]
Human (t)Error
October. That time of year when we have pumpkin spice everything and when tricks, treats, and terrors are given front-page billing. And for some people, it is the ideal time to binge-watch scary movies on repeat. We stare at the screen with one eye open, begging the main characters not to go into the woods, […]
Why Celebrate Cybersecurity Awareness Month?
The History A trip into any card store or venture onto social media will alert or remind you that there is a holiday for nearly everything. Who got to decide that April 23rd was National Talk Like Shakespeare Day? Or that Squirrel Appreciation Day would fall on January 21st? Some of them might make you […]
Health Apps & HIPAA
The Federal Trade Commission (FTC) recently released a new policy statement that requires health apps and connected device companies that collect health information to comply with the Health Breach Notification Rule. Yes, that means those very apps that so many of us use to collect our heart rate, weight, sleep, fertility, height, or any other sensitive […]
PHI or PII – What’s the Difference?
The terms protected health information (PHI) and personally identifiable information (PII) are often used interchangeably. But while they may sound like the same thing, there are differences that set them apart, and that is especially true when it comes to HIPAA. What’s the difference? PII is any information that can be traced to a person’s […]
Cybersecurity Resources for Healthcare
Recently The HHS Office for Civil Rights (OCR) shared a comprehensive list of resources for any HIPAA-regulated entity to assist them in the prevention, detection, and mitigation of data breaches of protected health information that occurs because of hacking or ransomware. As a covered entity or business associate under HIPAA compliance, an attack on your […]
Long Term Effects
Accessibility is Here to Stay Health Information Technology (Health IT) is an always evolving realm, with new tools coming to market as fast as we can master the old ones. With the advancement of technology comes a need for new software and security to maintain these systems. This past year has been one example of […]
Remember When
There was a time when you would walk into any doctor’s office and the sliding walls or file cabinets of patient folders seemed endless. Guarded like vaults, all the information safely under lock and key. And in addition to patient data, there is employee data, which likely contained personal and banking records. The “really” important […]
What Is a HIPAA Entity?
It’s easy to find a news story with someone misappropriating what HIPAA is, what it means, and what it does. Most people incorrectly assume how it protects their health records and information from ‘the world at large’. It does protect private health information, and it was created to allow for easy access to one’s health […]
Cyberattack Cost to Healthcare
Bigger business, bigger problems, right? Not necessarily true when it comes to the cost of a cyberattack within the healthcare industry. A recently published survey brings unexpected results when it comes to comparing large and medium-sized businesses. Surprisingly, medium-sized businesses are hit with cyberattack costs that are nearly 4x that of their larger counterparts at […]
Electronic Health Records & The Security Rule
Patient care in a digital age means that most information is stored electronically. These records, known as electronic Protected Health Information (ePHI), are collected as electronic health records (EHR) and then stored in a variety of systems. With the Health Insurance Portability and Accountability Act (HIPAA) in mind, how do you maintain security around the […]
Challenges in Healthcare Cybersecurity
The healthcare industry is always a top target for cybercriminals, but cybersecurity doesn’t always take the top spot when it comes to business concerns or plans in this sector. While we hear about breaches happening on a regular basis, we don’t seem to act at the same rate. What are the challenges that healthcare faces […]
Healthcare & Ransomware
As healthcare continues to be a prime target for cybercriminals, understanding what is happening as an employee is equally, if not more, important than just being aware of the risk. Having insight into how the attack can play out will help you understand the threat and the outcome if a hack occurs. Ransomware is one […]
Why Do Hackers Love Healthcare?
Cybercrime. It has become a regular part of the conversation around healthcare. We are regularly presented with the stats, and we know that the risk is greater for our businesses when it comes to cybercriminal activity. WHY is that the case? While some factors may seem obvious, let’s look at some of the other issues […]
No Vacation for HIPAA
This summer many of us are taking long overdue vacations that were put on hold or delayed because of the pandemic. As healthcare workers, you are certainly due time off – especially after the brunt of COVID-19 was dealt with by your industry. While you’re checking out and hoping that you won’t have to check […]
HIPAA & 18-Year-Old Patients
As a parent, you might recall the first time that the doctor asked you to leave the room because your “baby is now a teenager” (ugh, cry, sigh…. joy?) and they have a few questions for them that they would like to conduct one-on-one and in private. Suddenly your brain races, ‘what do they […]
HIPAA Turns 25
As the Health Insurance Portability and Accountability Act of 1996 (HIPAA), approaches the 25th anniversary of its enactment, we thought we’d look into the history of this game-changer in the healthcare industry. Signed into law by President Clinton on August 21, 1996, this federal statute was enacted to modernize the flow of healthcare information as […]
Common HIPAA Mistakes
As a person who works within the healthcare industry, understanding HIPAA is a necessity, even if it is knowing just the basic rules. These rules and regulations are complex and ever-changing so that they can keep up with the fluid landscape of healthcare, so unless you are an expert, it is unlikely that you know […]
Wait, a Breach is HOW Much?
The Background Wolfe Eye Clinic is a healthcare provider located in Iowa. In business since 1919, they specialize in medical eye care and have 11 main eye care clinics across the state, and various other locations that offer treatments. According to their website, they treat approximately 700,000 patients. This seems to be a solid and […]
Executive Order
This month a memo went out from the White House and Cybersecurity and Infrastructure Agency (CISA) to industry leaders that emphasized the threat posed by ransomware within their businesses as well as emphasizing just how important it was to the current administration to prioritize the awareness. The memo also is putting the responsibility on the […]
Vaccine Required
June 21st is fast approaching, and to most of us, that means the official start of summer. But to a group of 178 healthcare workers in Houston, it could mean the end of their employment. We’ve been discussing the various mandates and situations concerning getting the COVID-19 vaccine. The more public of these scenarios include […]
It Isn’t Always Obvious
Far too often, and in just about every industry, those of us who are “in it” assumes that certain aspects of what we know are obvious to the general public. For example, in healthcare, we know the basics of HIPAA and what information can and cannot be shared. This thought came to me again while […]
Vaccination Nation
Whether you choose to get a vaccine for COVID-19, it is your decision. We aren’t here to provide personal medical guidance or tell you what is right for you. But with regard to informing you about the healthcare landscape, well, that’s part of our program here at HIPAA Secure Now. And we would be remiss […]
Rising Danger
Meticulous Research released a market research report “Healthcare Cybersecurity Market”, that indicated a number that anyone in healthcare would want to be aware of. They expect that by 2027 – which sounds far off but is NOT – the cybersecurity market within healthcare will reach $26.1billion with a compound annual growth rate (CAGR) of 19.8% […]
Pipeline Problems & Healthcare
The recent attack on the Colonial Pipeline has (hopefully) reawakened any slumbering notion that cybersecurity isn’t everyone’s problem. Not sure what we mean? To recap at a high level, a cybercrime group identified as DarkSide hacked Colonial Pipeline’s infrastructure. As a result, the company acknowledged that they were the “victim of a cybersecurity attack” that […]
Document Storage
While the world is moving to electronic storage as a standard, there are still physical documents within healthcare that need to be protected and fall under HIPAA regulations. Let’s take a look at how that should be handled. As paper can pile up, how long do you have to store HIPAA documents? And what do […]
Your Prescription for Healthcare
Your patients arrive in your office with injuries and ailments that threaten their health. You review the situation and prescribe a plan of action and perhaps medication that will remedy the situation at best and alleviate pain or risk as well. You give them a prescription for health. Because that’s what you do. When […]
Vaccination Passports
Many people are getting their vaccines for their own safety, for the general well-being of the public, for their jobs, and some are getting it so that they can safely travel again. In fact, many people are doing this because they know that they won’t be able to leave their home base if they don’t […]
It’s Not for Everyone
Telehealth Is Not Everyone’s First Choice With regard to telehealth statistics, we saw a great rise in the number of participants during the past year with COVID-19. It was a perfect solution for many people, especially if leaving their homes meant putting them in danger due to their high-risk factors linked to the virus. Equally […]
Oversharing
Last week we covered the different ways that social media is playing a role in deploying healthcare messages. From patient experience to alerting the public about the pandemic, individuals and corporations are taking to the ‘digital airwaves’ of TikTok, Facebook, Instagram, and other platforms to spread awareness and messaging. This sounds like a great idea. […]
Socially Distanced Messaging
The social media platform TikTok has become a mainstream method of learning dance moves. And some recipes. And maybe a silly dog video here and there. But what we didn’t expect it to become was a healthcare platform. No, surgeries aren’t being performed via the application – although we won’t be surprised if and when […]
Fake Supplements
Fake Supplements Buying a knockoff purse or jersey is one thing, and we can take you down a rabbit hole of “why you shouldn’t do that” that would occupy you for hours. But when it comes to items you ingest and don’t simply wear, you need to pay attention. Supplementing your healthcare regime with vitamins, […]
More Time for Comments
Last week, the Office for Civil Rights (OCR) at the US Department of Health and Human Services (HHS) announced that there would be a 45-day extension of the comment period for the public with regard to the Notice of Proposed Rulemaking (NPRM) on modifying the HIPAA Privacy Rule that was originally posted in December of […]
A Different Kind of Health Hero
A Year of Heroic Feats The healthcare industry has been called to task this year in ways that make them heroic in the eyes of the world. As a global community, words can’t accurately convey the gratitude they deserve from all of us. Today we’re going to talk about another way, one that is less […]
Dark Web Dangers
With healthcare being a top target in the world of cybercrime, it never hurts to do a review every so often of the landscape and of the players in the game. We’ll also take a look at how you might be compromised without even knowing it or suspecting it could happen. A Lay of the […]
Humans of Healthcare
With healthcare being a huge target of cybercrime, the immediate concern is likely with regard to how it will coincide with any HIPAA regulation – or revealing any failure to comply. First thoughts usually go to the business side of a situation. How much will this cost? Will we be fined? Will we have to […]
HIPAA Stats & Facts
We couldn’t call them fun facts, because there’s really not a lot that one could label “fun” when it comes to HIPAA, but we thought we’d take a look at some of the statistics and facts in a summary fashion. HIPAA, often misspelled HIPPA, stands for the Health Insurance Portability & Accountability Act. This federal […]
Heart Healthy
With romance in the air for the upcoming Valentine’s Day holiday, we thought we’d shine a light on the ways that HIPAA can be affected by love in the workplace and what rules are in place to address it. Are there ethical repercussions to dating your doctor? Can my significant other access my medical records? […]
Remote Working & Healthcare
We have seen the healthcare industry rise to the occasion this past year. Stepping up in more ways than can be counted and doing so under extraordinary conditions. Telehealth does offer a viable solution for many people who cannot travel outside of their homes, and at the same time, it offers a safe solution to […]
As the Rules Apply
This week in HIPAA news we are shining a light on two rules that display the spectrum of ‘bending’ from the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). The first, showing flexibility, announced that penalties with regard to HIPAA, as it pertains to the COVID-19 vaccination, will not be […]
What if Employees Refuse the Vaccine
In healthcare, we want to assume that we are collectively working to advance medicine and whatever the latest developments are, well we want “in”. What if that development is the COVID-19 vaccine and as it turns out, someone on your team isn’t interested? According to a survey done by the Pew Research Center, not all […]
Learn From Others
The office for Civil Rights gathered information at the end of 2020 that is important for any covered entity or business associate that operates under HIPAA guidelines. Summarized in the U.S. Health and Human Service (HHS) HIPAA Audits Industry Report, this data should be regarded as a useful tool for any business that deals with […]
Year-End Health Report
Ideally, we have a health physical once a year. We assess what we are doing right, what we are doing wrong, and make modifications to our overall wellness plan as needed. Hopefully, nothing is wrong, and we can proceed with the usual cautions and goals of maintaining a long and productive life. The same could […]
Safe Harbor Act
In our blog earlier this year that provided an overview of 2009’s Health Information Technology for Economic and Clinical Health (HITECH Act) we discussed how this was designed to promote the use of electronic health records (EHR) within the healthcare system and its providers. As is with most things, time goes on and often reveals […]
Vaccination Scams
It hasn’t even been available for a minute and we’re already being warned about scams surrounding the COVID-19 vaccination. With healthcare being a huge target for cybercrime already, this isn’t surprising. Consumers should be aware of phone calls, text messages, social media links and posts, emails, and even in-person tactics that will be used to […]
Potential Changes Ahead
The Health and Human Services Office for Civil Rights has proposed changes to the HIPAA Privacy Rule that could be substantial. The Notice of Proposed Rulemaking (NPRM) proposal stated it was to “remove barriers to, coordinated care and individual engagement” and was issued last week. Addressing standards of the rule may limit and/or discourage care […]
Threat to Healthcare
We have had quite a year so far in 2020, and if you are in healthcare, you were hit especially hard with something that you likely didn’t adequately prepare to deal with. However, according to a recent report from Black Book Market Research LLC, the healthcare industry has no idea what could hit them in […]
HIPAA & the Media
Can a journalist reveal an individual’s COVID-19 diagnosis or are they in violation of HIPAA laws by doing so? Healthcare and the diagnosis of a person’s well-being are private information in general, but when it comes to reporting, and doing so in a pandemic, suddenly ‘who has what and where are they?’ becomes a matter […]
HITECH Act
This week we’re taking a look at the HITECH Act and an overview of what it is and how it relates to HIPAA. Formed in 2009, the Health Information Technology for Economic and Clinical Health (HITECH) Act was introduced as part of an economic stimulus package to promote and expand the awareness and adoption of […]
HIPAA & Medical Devices
The human factor is something of huge consideration within the HIPAA and healthcare landscape. With that industry being a huge target already within the world of cybercrime, where do medical devices as well as their manufacturing companies, fall within HIPAA regulations? When the Department of Health and Human Services (HHS) created HIPAA guidelines, there were […]
No Business Is Too Small
It Happens Everywhere While the world might still be in varying states of chaos with regard to a multitude of topics, when it comes to HIPAA fines and enforcement of regulations, things are getting back on track. As the global pandemic settled into our daily lives and it became clear that the sharing of information […]
Notification Rule
Timing is Everything A data breach within your business. You think it won’t happen, you hope it doesn’t happen, but what if it does happen? What are your next steps? Like most things in healthcare, timing is essential. You need to think quickly and act swiftly during a time when your head might not be […]
Wearable Technology
The saying goes that you’re never fully dressed without a smile, but the reality for many people today is that you’re never fully dressed until you put on your smartwatch. Or your phone in your pocket. Or your health and fitness monitor at the gym. These component pieces are now standard in our attire and […]
Cybersecurity Awareness Month
We’re halfway through this year’s Cybersecurity Awareness Month and never has it been more important to make sure that you are informed and making smart cyber choices in both your personal and professional life. With the pandemic providing cybercriminals ample opportunity to take advantage of our uncertainties in many aspects, and with online activity through […]
Systemic NonCompliance
The story narrative varies slightly from episode to episode, but the outcome is generally the same. Pay a fine, make a plan, regret not doing this all in the first place. This isn’t some soap opera or Netflix binge-worthy series; this is real life and the characters are the healthcare industry and Office for Civil […]
Second Largest Fine
Coming in second can sometimes be a good thing. But not when you’re on the receiving end of a HIPAA fine and have to pay out $6.9 million like Premera Blue Cross. The insurer is the largest health plan in the Pacific Northwest, serving more than 2 million people. This fine is the second-largest payment […]
Right to Access Enforcement Initiative
In 2019, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) announced an initiative that they would make it a priority to enforce an individual’s right to access their health records in a timely manner and at a reasonable cost. This falls under the HIPAA Privacy Rule. While […]
Hover Hover Hover
At times, it feels as if we could start every week with this sentence: “There’s a new tactic being used by cybercriminals to trick unsuspecting victims.” And the sophistication level of the new tactics is off the charts. So, what are we dealing with as of late? Well, where should we start… Hidden text is […]
Please Complete This Form
You walk into your healthcare provider’s office and are usually handed a clipboard with papers that need to be filled out, updated, and wrapped up with your signature. We mindlessly take our task to the nearest seat and complete, sign, initial, and update whatever we’ve been given. This information goes into our file and continues […]
COVID-19, Cybercrime, & HIPAA: Prepare Your Practice
Is your practice prepared to securely operate during the COVID-19 crisis? Are you facing new challenges with telehealth, your remote workforce, or with the growing cybersecurity threat to healthcare? Watch this webinar to get instant insight into how your practice can prepare and prevent losing time, money, and your good reputation because of a HIPAA […]
Statistically Speaking
Three universities recently conducted a joint study of participants that aimed to explore their likelihood of being monetarily incentivized to violate HIPAA regulations. The pilot study involved medical residents or individuals in an executive MBA program, with some of those participants already in health care executive roles. Of the 64 medical students and 32 executive […]
Caught Off Guard
The term “new normal” is something I think we would all enjoy hearing less of at this point. We’re at a point where this is how we are going to be operating and we need to pause, assess what happened, where we are, and how we move forward. As we reflect back, we know first […]
Physical Theft of PHI
How many unexpected and unforeseen circumstances can 2020 present us with? Each month we think that we’ve likely seen it all, considered it all, and readied ourselves for whatever comes our way. This year has provided us with plenty to panic over, and many things that we never thought we’d face. Take for example the […]
Wish You Were Here!
It’s always nice to get a postcard from friends or family who are away on vacation. But this week we learned of a new kind of postcard being sent out with not-so-well wishes. The Department of Health & Human Services’ (HHS) Office for Civil Rights (OCR) sent out a warning that fraudulent postcards are being […]
Million Dollar Laptop
Was it made of gold? Encrusted in diamonds? No. Read on to learn how one laptop ended up being worth a massive one million dollars. The U.S. Department of Health and Human Services (HHS) recently closed an investigation into Lifespan Health System Affiliated Covered Entity for a stolen laptop incident reported back in 2017. That […]
Caught off Guard: What the Pandemic Taught Healthcare Organizations About Being Prepared for a Business Interruption
COVID-19 has had a profound impact on the healthcare industry. Many day-to-day operations have changed, like how organizations provide care to patients and handle business functions behind the scenes. While these changes were required to be made quickly, some organizations found themselves far less prepared than others. – Was your organization prepared for the quick […]
COVID-19 Crime
For every moment in time, there is an opportunity to create good from it, and likewise, to create bad or negative reactions. COVID-19 has given us both. While of course, we wouldn’t wish it to happen again, we have seen people come together, new businesses arise, and an overall re-evaluation of our priorities. Then there’s […]
Smart Telehealth Practices
COVID-19 has ushered in the mass acceptance of telehealth, with so much optimism and excitement around the technology. But like many new technologies, the initial use is rushed and not well thought out with many providers trying to figure out the right technology, best practices, and optimal patient experience. We have seen temporary waivers to […]
Mask Mandate
Mask Mandate Whatever your opinion is of wearing, or not wearing a mask, there are in increasing number of mandates being put in place by governments or independent establishments in an effort to mitigate the spread of COVID-19. This mask mandate means that most people over a certain age need to have their face covered, […]
Limitless Liability
A year of credit monitoring along with identity theft monitoring services. That’s what most of us settle for when we find out that our personal data has been compromised. We are alerted, we change our password, we read the letter that offers these services and may or may not sign up for them. Some individuals […]
Employee Errors
We all know (or should know) that human error accounts for the majority of breaches. Phishing gives hackers entry to a business’s front door by manipulating the employees who work there. Phishing is when a cyberattack is disguised and delivered using email as the carrier or weapon. Through very convincing and cleverly designed messages, the […]
Employee Coverage
As businesses like shops, restaurants, and others that were previously closed as a result of COVID-19 begin to open, precautions of various kinds are now in place. As the state or perhaps local government encourages and sometimes requires protective gear, employers must take into consideration how it will affect their workforce. One outward-facing and immediate […]
Employee Privacy In a Pandemic
Employee Privacy in a Pandemic COVID-19 has presented businesses with a new challenge in keeping their company safe and it starts with employee health. As they re-open in the wake of the pandemic, they must keep track of individual health with regard to who is sick and how it might affect the company as a […]
Is COVID-19 Unraveling HIPAA?
Let’s Recap The Health Insurance Portability & Accountability Act (HIPAA) was created in 1996 to protect patients and their privacy, and if you are in healthcare, you already know this and are familiar with what it means. With a goal to ensure that people could maintain health insurance between jobs, thus the “Portability” part of […]
Delaying Treatment
The Patients Are Not Equal As COVID-19 took over in the headlines, it also took over at many hospitals around the country. We saw a rise in the number of patients that were taken in and diagnosed with the virus, but there was an unexpected result as well. The rate of decline in-patient activity didn’t […]
Lenient Doesn’t Mean Lazy
In mid-March, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced that they would use “enforcement discretion” in regard to HIPAA compliance with telehealth. And, the healthcare community gave out a collective sigh of relief. Not because the rules and regulations were unfair, but in a time of […]
Free Download: Cyber-Attack Quick Response Resources
Cyber-attacks against healthcare organizations are on the rise, as cybercriminals target covered entities and business associates alike. The uptick in attacks on healthcare has proven the need for organizations to invest in their preventive cybersecurity efforts and ensure they are prepared to handle the aftermath of a successful attack or security incident. Download our free […]
Changes Ahead
While we have all had to adjust in obvious ways to the pandemic, the reality is that after the panic subsides, and after the immediate emergency vibe in the air passes, we will never return to the way things once were. We are in a new reality, or as many keep saying, a new normal. […]
Healthcare Trendsetters
COVID-19 has given us a type of Fashion Week within healthcare, where new trends and rising stars emerge unexpectedly, and all at an alarmingly fast pace down the virtual runway. We are seeing work from home take on a whole new significance, which leads to new software platforms rising in popularity, existing applications modified to […]
Mental Health Assessments
We find ourselves months into the trenches of the COVID-19 crisis, and with each new day comes not only a different set of problems but new solutions as well. As first responders, public safety officers, and the medical community continue to show the need to increase hires within their fields, the process to make those […]
COVID-19 Long Term Effects
We’ve all had to make adjustments to how we work, how we live, and how we interact overall with humanity during the COVID-19 pandemic. This means that we’ve been stricter in some regard, and more relaxed in others (limiting screen time, who can be bothered?). The government is no exception to this. We’ve seen some […]
Resource Guide for HIPAA Compliance & Telehealth Guidelines During COVID-19
Is your healthcare organization using telehealth to communicate with patients during this pandemic? Not sure how HIPAA comes into play with these remote communications? Our free Resource Guide for HIPAA Compliance & Telehealth Guidelines During COVID-19 will provide you with the information you need regarding telehealth and the Office for Civil Right’s enforcement discretion during […]
Redefining Identifiable Data
HIPAA provides guidelines to establish the permissible use of an individual’s personal health information (PHI). Seems pretty straightforward for the most part. And it was – for the most part. Until we start to dig a little deeper and look at the resources that are now in play (which were not 20+ years ago when […]
Resource Guide for Securely Operating During the COVID-19 Crisis
Is your healthcare organization operating during the global pandemic, whether in the office or working remotely? Not sure of how to handle HIPAA compliance when using technology to communicate with patients? Worried about the rise in COVID-19 scams and data breaches? We’re here to help! Our free Resource Guide for Securely Operating During the COVID-19 […]
Free Security Training: Introduction to Working Remotely
According to a survey by OpenVPN, 36% of organizations experienced a security incident caused by the actions of a remote employee. Watch this easy-to-understand video and learn how you can take steps to protect yourself, your business, and your loved ones. Watch the Free Training Video
Community-Based Testing Sites
Community-Based Testing & HIPAA Community-Based Testing Sites (CBTS) are the latest entity to be excluded from HIPAA enforcement penalties by the Office for Civil Rights (OCR) for their participation in regard to COVID-19 specimen collection and testing. This “exercise of enforcement discretion is effective immediately (April 9, 2020), but has a retroactive effect to March […]
COVID-19 Scams Continue
Whether it involves faces masks, hand sanitizer, hospital and medical supplies, or a stimulus check, scams against healthcare organizations and individuals are booming with COVID-19 as the starting point. Hackers and cybercriminals are looking at the pandemic as a great opportunity to take advantage of unsuspecting businesses and consumers in a variety of ways. The […]
COVID-19 & First Responders
As we continue to make our way through new territory with the COVID-19 crisis, we are having to adjust the rules and regulations that previously stood in place. HIPAA is no exception to that. The U.S. Department of Health and Human Services Office for Civil Rights (OCR) has continued to update the guidelines under these […]
Telehealth & COVID-19
In recent years there has been an increase in the use of telehealth and remote management tools as options for maintaining patient well-being. If you’re not familiar with these, the HHS’ Health Resource & Services Administration (HRSA) defines telehealth as “the use of electronic information and telecommunications technologies to support and promote long-distance clinical health […]
Safely Working Remotely
Effective Immediately As the Novel Coronavirus pandemic continues to greatly impact our nation, working from home is no longer an occasional benefit for many Americans, but is now a requirement for many businesses to continue operating safely and effectively. While working from home does come with its perks, there are many new cybersecurity risks created […]
Interoperability & Information Sharing
Recently, the U.S. Department of Health and Human Services put the final approval on two rules that will be transformative in the way that patients can access their health data. This unprecedented approval will provide safe and secure access to that data via interoperability and information sharing. These rules identify the most extensive healthcare data […]
HIPAA Right of Access Myths
A patient’s right to access their healthcare data so that they can make informed decisions regarding their own health and wellbeing is the component of HIPAA known as the HIPAA Right of Access. Recently, the American Medical Association (AMA) published a new HIPAA playbook for physicians and their practices to better understand this component. With […]
Greatest Cybersecurity Threats to Healthcare
20/20 Vision in 2020 What lies ahead for the healthcare industry in 2020? Like patient health, we can’t predict the future accurately, but we know that preventative care can go a long way when we know the risk factors. If you’re in the business of patient care, whether that is through treatment or within a […]
One Virus, Two Ways
How Scammers Are Using the Coronavirus to Trick Their Victims As if the fear of the Coronavirus outbreak weren’t enough to have the world on edge, there’s a new way that the virus is impacting humans: through email cyber-attacks. The method of contamination takes a trusted name, the World Health Organization, and uses it to […]
Sharing Safely During an Emergency
When an emergency situation occurs, like that of the recent Novel Coronavirus (2019-nCoV) outbreak that is said to have originated in mainland China, the healthcare industry is affected worldwide. From the individual patients all the way up to the largest facilities for patient care, it’s imperative to share knowledge and information, but it MUST be […]
Healthcare Data Breaches Affected 40 Million Americans in 2019
40 Million The US state with the highest population is California. At the end of 2019, it was 39.56 million. That’s A LOT of people, right? Yes. However, according to the recent study published by Fortified Health Security, 40 MILLION Americans were affected by a healthcare data breach in 2019 alone. That represents an increase […]
Windows 7 End of Life Creates New Opportunities for Scammers
End of Windows 7 They say when one door closes another one opens, but in this case, it’s a window. On January 14th, 2020, Microsoft ended its support for Windows 7. Since Microsoft is no longer offering patches or security updates for vulnerabilities identified in Windows 7, hackers have a new way of gaining access […]
2019 HIPAA Breach Reporting Deadline Approaching
2019 HIPAA Breach Reporting Deadline If in 2019 you had a HIPAA breach that affected fewer than 500 individuals, you must report that to the US Department of Health and Human Services (HHS) by Saturday, February 29, 2020. Not sure if you’ve had an incident that requires reporting? Start by knowing that every breach must […]
Cybercriminals Now Demanding Ransoms from Patients
Imagine this: One day, out of the blue, you receive an unusual communication from an unknown individual warning YOU that they have photos and personal information about you that they are prepared to release if you don’t pay them a ransom. At first, you might chuckle thinking, there is no way this is true. But […]
Protecting Patients – More Than Meets the Eye
Don’t Overlook It When you consider a healthcare organization’s role in protecting patients, it’s easy to look at things from a high-level and miss out on some of the most critical protections an individual needs, expects and is owed. For example, when I think about protecting patients, my mind goes directly to the reason behind […]
Lost Laptop Leads to New Kind of Accident
Fender Bender In Carroll County, Georgia, there was a vehicle accident of an unusual kind recently. It resulted in the Department of Health & Human Services’ Office for Civil Rights (OCR) slapping a $65,000 fine on West Georgia Ambulance when they were found to have multiple violations of HIPAA rules. It started in February of […]
Healthcare’s Annual Physical
Annual Physical We’ve conducted our end of year physical on the healthcare industry, and while the humans that are cared for have a variety of health issues, there is one that is plaguing the healthcare industry as a whole: cybersecurity. This was not a good year for hospitals and healthcare businesses when it came to […]
OCR Issues Guidance on Targeted Ransomware
We Are All Affected by Bad Cyber Health Pay attention, the health of your business depends on it. Wherever you fall in the food chain of the healthcare industry, cybersecurity needs to be at the forefront of your mind. That might mean you are a small doctor’s office with a few patients, a large hospital, […]
Alexa, Increase Time with My Patients
Amazon isn’t a company that lets an opportunity go by. With the awareness of cybersecurity rising every single day, opportunity presents itself in a variety of ways. Not only do they have a captive consumer audience, but familiarity and reputation allow them to venture into the enterprise field with credibility as well. With that being said, recently they announced the […]
Sentara Hospitals Agrees to $2.175 Million Settlement for HIPAA Violations
Crazy Eight If only we were talking about a card game. Unfortunately, for Sentara Hospital, we aren’t. Instead, we are referring to them receiving the unwanted title of being the eighth recipient of a HIPAA financial penalty in 2019. This $2.175 million fine is given in conjunction with the requirement to create a corrective action […]
Ransomware Attack Impacts 100+ Nursing Homes
“Doctor, How Bad Is It?” “I’m not sure, I can’t access your medical records to tell you exactly what the prognosis is.” Recently, this is what Virtual Care Provider had to tell its clients; that the technology services that they were providing were on hacker hiatus. In other words, they were hit by a […]
Now Will You Listen?
It is likely that we can all recall a moment when we “knew about” something before anyone else. A band, a trend, a fad. Then it goes mainstream and you realize the word is out, and when a big name gets on board with promoting the person, place or cause, you find yourself part of […]
Conducting a Risk Analysis – What You Need to Know
You’ve likely heard of a risk analysis. Hopefully, you’ve also performed one for your organization. Whether you’ve been helping your organization work on its HIPAA compliance for years, or you’re new to the world of HIPAA, performing a risk analysis should be a high-priority item on your business’s to-do list. Let’s start with the basics. […]
Healthcare to Go
Isn’t it wonderful how technology has made medical care more accessible? Not only can medical professionals be mobile and go TO their patients, but patients can now take ownership via apps and devices that allow them to monitor their own well-being. Apps and devices are now available that give us so much information and access; […]
Data Breach Costs Texas Health and Human Services Commission $1.6 Million
When DADS Don’t Know Best No, we aren’t talking about Father Knows Best here. We are referencing the Department of Aging and Disability Services (DADS). In 2017 it was added to the Texas Health and Human Services Commission (HHSC), which is comprised of childcare and nursing facilities, operations of supported living centers, providing mental health […]
American Cancer Society’s Online Store Hit with Skimming Malware
Sick on the Inside The American Cancer Society deals with illness of the human sort, but recently they had to deal with another kind of toxic plague silently taking over. On the outside, things looked fine. But on the inside, there was a silent plague. Hidden as analytical code, security experts discovered malware embedded in […]
OCR Issues $2.15 Million Fine to Jackson Health System
HIPAA compliance doesn’t care if you’re a small business or a non-profit. This isn’t said in a disrespectful manner to the laws that govern the policies, but to make you aware that your business status, or identifying structure won’t allow you to be overlooked. Hefty Fine Imposed Recently the Office for Civil Rights (OCR) at […]
Importance of a Risk Assessment
HIPAA Requirement While it is required within HIPAA rules and regulations to complete a risk assessment regularly, the question may still be in your mind regarding WHY you have to do this. The legal ramifications are obvious. If audited, you’ll have to show a risk assessment as part of your HIPAA compliance program. And remember, […]
$85,000 Settlement in OCR’s First HIPAA Right to Access Case
HIPAA Enforcement is Happening Enforcement is in action. That’s what Bayfront Health-St. Petersburg recently learned when they agreed to pay $85,000 in penalties to the Department of Health & Human Services (HHS) Office of Civil Rights for a potential violation of the HIPAA right to access provision. This is the first enforcement by the OCR […]
Dental Practice’s Response to Yelp Review Leads to $10,000 Fine
When it’s YOU in the Review Making dinner plans? Check online for reviews before you spend your money dining out. Ready to book a vacation? You’re definitely making sure the pool is as big as they say it is. How about when it comes to personal care? Do you check online to see if a […]
HIPAA Secure Now Joins Far-Reaching Initiative to Promote the Awareness of Online Safety and Privacy for National Cybersecurity Awareness Month
October 1, 2019 — HIPAA Secure Now! today announced its commitment to National Cybersecurity Awareness Month (NCSAM), held annually in October, by signing up as a Champion and joining a growing global effort to promote the awareness of online safety and privacy. NCSAM is a collaborative effort among businesses, government agencies, colleges and universities, associations, nonprofit […]
HIPAA Secure Now Joins Far-Reaching Initiative to Promote the Awareness of Online Safety and Privacy for National Cybersecurity Awareness Month
October 1, 2019 — HIPAA Secure Now! today announced its commitment to National Cybersecurity Awareness Month (NCSAM), held annually in October, by signing up as a Champion and joining a growing global effort to promote the awareness of online safety and privacy. NCSAM is a collaborative effort among businesses, government agencies, colleges and universities, associations, nonprofit […]
Ransomware Chaos in Campbell County
Campbell County Chaos Hopefully, you didn’t have a doctor appointment in Campbell County Wyoming recently. And if you had an emergency situation, perhaps you were not getting the immediate care that you may have hoped for when you showed up at the ER. It wasn’t the long wait from an overcrowded hospital waiting room, or […]
Right to Access was Implemented to Protect Patients but is Hurting Patients & Providers Alike (Part 2)
We previously published Part 1 of this article on abuses of Patient Right to Access for medical records and how these abuses can overburden healthcare providers and put patient health information at risk. This Part 2 focuses on what healthcare organization can do about the growing problem. The following blog was written for the HIPAA […]
Right to Access was Implemented to Protect Patients but is Hurting Patients & Providers Alike (Part 1)
The following blog was written for the HIPAA Secure Now community by DataFile Technologies, a leading provider of health data management including fast records release services with a 24-hour turn-around time, and an industry-leading accuracy rate over 99.9%. You may have seen an uptick in medical records requests labeled with “HITECH Request” or experienced requestors […]
Compliance & Cybersecurity Go Hand-In-Hand
Humans or HIPAA? When it comes to healthcare organizations addressing the HIPAA compliance of their business, many feel prepared and comfortable, readily checking that “compliant” box. But addressing the human part of security falls by the wayside too often. Compliance and cybersecurity, which includes human security, both need to be a part of your overall […]
Does Your Breach Response Plan Include Notification?
Remain Calm, Remain Honest – and Remain in Business Avoiding the inevitable does not make it go away. Healthcare patients choose a provider based on the quality of care. In addition to that, the public will generally assume that their private information is safeguarded and not something that they need to verify or investigate before […]
Ransomware Hits Hundreds of Dental Offices
A Toothache Beyond Repair Hackers have used the very software that hundreds of dentists relied on to run their business, to bring it to their knees. A ransomware attack is responsible for shutting down computers at roughly 400 dental offices all over the U.S. The Digital Dental Record and Wisconsin-based cloud services provider, PerCSoft collaborated […]
Repeat Offender
It’s a Fact When you search for cyberattacks by vertical, always in the top categories is healthcare. It can be filtered from there by the size of the business, whether it is enterprise or small to medium-sized establishments, but the information targeted is patient data. Why? Because who knows more personal information about you than […]
Why We Need to Go Beyond HIPAA
HIPAA – Then & Now The Health Insurance Portability and Accountability Act, better known as HIPAA, has been around since 1996, with the intent to protect patients by properly handling their protected health information (PHI). With good intentions, HIPAA set forth to provide both security provisions and data privacy. The legislation was passed in the […]
Allscripts to Pay $145 Million for Practice Fusion EHR Investigation
As many of you know, an Electronic Health Record (EHR) is a digital record of a patient’s paper charts, updated in real-time. This is an incredible option to have in the world of medicine, where information can be exchanged between doctors as well as business associates. It also provides an incredible benefit to the patient, […]
Halfway Health Check
We’re just passed the midway point of the year and if this were our own health report, we’d be failing miserably when it comes to data breach prevention. According to a recent report from Protenus and Databreaches.net, over 31 million healthcare records were breached in the first six months of 2019. That is double the […]
Scrolling Through the Breaches
Every day in my newsfeed I’m alerted to yet another compromise to patient information. The headline isn’t always the attention-grabbing ones that we see when major credit companies or big-box retailers are exposed. These are just listed, one after the other, identifying locations of healthcare businesses, whether it be hospitals or private practice, that have […]
Make Time for Cybersecurity
This isn’t something you can pencil in and get to when you have time, cyber maintenance has to be something you commit to. We all have those moments when we realize that we had the best intentions to stick with something, but its priority fell by the wayside. We start off strong, then taper off […]
25,000 Patients’ Data Exposed in Email Hack
Approximately 25,000 patients are being notified by Adirondack Health that their protected health information (PHI) may have been obtained by a hacker. Vermont-based Adirondack Health is part of the Adirondacks Accountable Care Organization (ACO). Adirondacks ACO analyses health data for the entire region and is made up of all the Adirondack region’s hospitals. The Breach […]
An Analysis of Cybersecurity Practices in Healthcare
A recent report by KLAS and CHIME looked at the cybersecurity practices of healthcare providers based on recent guidance issued on the subject. The results? Although some best practices seem to be on the radars of organizations of all sizes, overall findings suggest that small practices have some work to do. In their white paper, […]
Hackers Using Social Profiles
Facebook Status: Away on Vacation Social media is great for a lot of things. Sharing photos, reconnecting with old friends, finding like-minded people and groups to share ideas and hobbies. But when does sharing become oversharing? Hackers gain access to your personal data via your profile and the information you share there – and you […]
Lawsuit Filed Against the University of Chicago Medical Center and Google over Data Sharing
A potential class action lawsuit has been filed against the University of Chicago Medical Center (UChicago Medicine) by a former patient, claiming his and thousands of other patients’ medical records were shared with Google without authorization and without removing identifying information. The suit was filed in the United States District Court for the Northern District […]
NEO Urology Suffers Ransomware Attack, Pays $75,000 Ransom
Cybercriminals continue to flex their muscles on the healthcare industry with ransomware hitting an Ohio medical practice earlier this month. NEO Urology in Boardman, Ohio, suffered a complex ransomware attack, with hackers encrypting the organization’s entire computer system. According to a report from local news agency WFMJ, the attack on NEO Urology occurred on June […]
Preventing Medical Identity Theft
Earlier this month, a data breach affecting Quest Diagnostics, LabCorp, and Opko was announced, stemming from an incident caused by the collections vendor, American Medical Collection Agency (AMCA). Now, the number of individuals who had their medical and personal information compromised by the incident has exceeded 20 million, bringing up major concerns of medical identity […]
10 Cybersecurity Tips for Small Businesses
In 2018, 71% of ransomware attacks targeted small businesses, according to a report by Beazley Breach Response Services. It’s clear that small businesses are a cybercriminals favorite target, yet many remain unprepared to handle a cyber-attack. Is it that small businesses don’t care about cybersecurity? It wouldn’t be fair to make that assumption; however, small […]
Quest Diagnostics Data Breach Could Impact Nearly 12 Million Patients
Quest Diagnostics, one of the country’s largest blood testing providers announced on Monday that nearly 12 million patients may have had their sensitive information compromised in a data breach. The breach occurred at one of Quest’s billing collections vendors, American Medical Collection Agency (AMCA). Quest was notified on May 14, that between August 1, 2018, […]
$100,000 Settlement Reached for 2015 HIPAA Breach
Medical Informatics Engineering, Inc. (MIE), a software and electronic medical records service provider has paid the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services $100,000 to settle a HIPAA breach from 2015. The Indiana-based company reported the data breach to OCR on July 23, 2015, following the discovery that […]
Ransomware: The Trend That Never Goes out of Style
Ransomware is not a new type of cyber-attack. In fact, it’s been around for years, but don’t let its age fool you; ransomware is not “yesterday’s news”. Ransomware is just as alive as ever before, continuing to dominate industries across the globe, and healthcare is not immune from its threat. You may be familiar with […]
HIPAA Audits 101: Your Compliance State Under Review
Hello, HIPAA The Health Insurance Portability and Accountability Act, better know as HIPAA, was passed by Congress in 1996 and called for the protection and confidential handling of protected health information (PHI). HIPAA still exists today, aiming to protect patients and their information, but it’s important to think about how far we’ve come in the […]
$3 Million Fine Issued for PHI Breach of Over 300,000 Patients
The Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) has announced a settlement with Touchstone Medical Imaging (“Touchstone”) for their potential violations of HIPAA Security and Breach Notification Rules. Touchstone has agreed to pay $3,000,000 and adopt a corrective action plan. Touchstone is a diagnostic medical imaging services company based in […]
Misconfigured Webpage Exposed Patient Data
Patient data exposed Inmediata Health Group, Corp., a provider of clearinghouse services, software, and business processing solutions to health plans, hospitals, IPAs, and independent physicians recently announced a security incident affecting some customer data. The incident was discovered in January 2019 when Inmediata found a misconfigured webpage was allowing some electronic health information to be […]
Metrocare Services Discloses Second PHI Breach in 5 Months
Metrocare Services, a mental health service provider in North Texas, has notified the Department of Health & Human Services (HHS) of a data breach affecting 5,290 patients. The Breach Discovery The breach was the result of a phishing attack and was discovered on February 6, 2019, when Metrocare found that an unauthorized third-party accessed some […]
Business Email Compromise Incidents up 133%
Business email compromises (BEC) scams made a big statement in 2018, seeing a 133% increase over 2017, according to a recent report by Beazley Breach Response Services. The Beazley Breach Briefing looked at information gathered from investigations into more than 3,300 data incidents that were reported to Beazley in 2018. The investigations revealed that nearly […]
Lost Files: The Beginning of the Problems
We previously wrote an article about the ransomware attack striking a Michigan doctor’s office, leaving their patients with no medical records and leading the practice to closure. This article is intended to provide professional insight into the liability of the practice despite its decision to close its doors. The following blog was written by Matthew […]
Ransomware Attack Shuts down Michigan Practice – Deletes All Patient Files
A doctor’s office in Battle Creek, Michigan is closing its doors following a ransomware attack that left them with no other option – besides pay up. The Demand and the Decision Dr. William Scalf told a local news outlet, WWMT West Michigan, that hackers locked the files at Brookside ENT and Hearing Center, demanding […]
Tax Refund Scams – Know What to Look For
Tis the season! You’re making mental plans with what is hopefully a generous tax refund and deciding what to do with the surplus of cash you’ll soon have on hand. Along the way from starting to submitting the paperwork, there are quite a few roadblocks to be aware of. Even if you aren’t getting a […]
Ransomware Dominated Healthcare and Small Businesses in 2018
Ransomware wreaked havoc on businesses across the globe throughout 2018 with no signs of slowing down. Which sector was hit the hardest? A recent report from Beazley Breach Response Services found that the healthcare industry suffered from the most ransomware attacks last year. Why was healthcare the hardest hit? Healthcare data is valuable, and hackers […]
Study Finds Healthcare Sector Uniquely Susceptible to Phishing Attacks
Is the healthcare sector uniquely vulnerable to phishing attacks? A recent report published in the Journal of the American Medical Association says yes, with research to back that claim. A team of researchers led by William Gordon, MD of Harvard Medical School and Boston’s Brigham and Women’s Hospital set out to answer the question, “Are […]
How to Create an Incident Response Plan
Data breaches are extremely common as technology continues to advance. Of those breaches, small and medium-sized businesses (SMBs) are a favored target for cybercriminals. In fact, more than 70% of attacks target small businesses, according to the National Cyber Security Alliance, and as many as 60% of hacked SMBs go out of business following a […]
7,038 Patients of Pawnee County Memorial Hospital Notified of Phishing Attack
Pawnee County Memorial Hospital (PCMH) in Pawnee City, Nebraska has notified 7,038 patients that a hacker may have accessed some of their protected health information. The incident was discovered on November 29, 2018, when PCMH learned that their business e-mail system was compromised by a malware virus. A forensic computer investigator was hired immediately following […]
Fake Check Scam
Being scammed can happen so easily today, but when you make it about a topic that many people can let their guard down with, the scam can happen much easier. What topic is that? We’re talking about money. Fake check scams have been around for quite some time, however, with the increase in online sales […]
Third-Party Vendor Causes Breach Impacting 45,000 Patients
Rush University Medical Center is feeling the impact of a breach they themselves did not cause. A third-party vendor is responsible for compromised personal information of 45,000 patients of Rush Medical. The breach was caused by an employee of the claims processing vendor when they inappropriately shared a patient file with an unauthorized individual. Rush […]
Nearly 974,000 UW Medicine Patients’ Medical Records Exposed
The University of Washington Medicine is notifying approximately 974,000 patients of a data breach that occurred in December, which left some of the patients’ information exposed on the Internet. The breach occurred over a 3-week period and was determined to be the result of a misconfigured server. The database was used to track the sharing […]
When a Healthcare Breach Lands You on the Wall of Shame
Healthcare breaches are incredibly difficult for organizations to deal with. Repercussions of a data breach vary greatly depending on what caused the breach to begin with. For example, there’s the struggle of getting your organization back up and running, determining the cause of the breach, notifying patients, taking corrective action, reporting the breach, potentially finding […]
Research Suggests Employees Remain the Weak Links in Security
We’ve known that employees are the weak link in security. In fact, we have been cautioning organizations for quite some time regarding the risks their employees pose when not properly trained. Despite heightened awareness of these risks, recent research from Microsoft suggests that employees remain the weak link, posing huge risks to their organizations. A […]
Sextortion Scam
You get an email or text from what seems to be a legitimate email or phone number. Then you read the message: “Send bitcoin right away or else I am sending compromising photos or information to your friends and family.” If you’ve received this type of email, you’ve likely been a victim to a new […]
Performing a Security Risk Assessment Offers Value Beyond Compliance
As the digital ecosystem continues to thrive and advance, so too must the regulations and practices for safely caring for sensitive data. That is especially true for the healthcare industry, which continues to be a prime target for cybercriminals. Healthcare practices need to appropriately safeguard electronic protected health information in compliance with the Health Insurance […]
Mystery Shopper Scams
Today, many people are working more than one job, and with the flexible options of contractor work, or work as needed opportunities, you can likely find something that fits your schedule and financial needs. Maybe you are looking for a little bit of extra work to make ends meet, or a way to save up […]
Ransomware Attack on CT Optometry Office Raises Tax Fraud Concerns
Ransomware Attack on CT Optometry Office Raises Tax Fraud Concerns Cybercriminals target businesses of all industries and sizes, however, it seems as though their sights are set more on small and medium-sized businesses than large corporations. While there are many factors that may influence the shift of attention to small businesses, one explanation stands out, […]
HHS Cybersecurity Guidelines: The 6 Simple Steps That Will Mitigate The Top 5 Threats To Healthcare
Every day it seems there’s another ransomware attack in the healthcare sector. What’s worse is that these types of cyber-attacks are expected to continue to increase. Why do cybercriminals target this industry so heavily? – Their victims pay the ransom because healthcare practices can’t afford a business interruption – Large numbers of outdated systems make […]
Email Hack Leads to Valley Hope Association Breach of Patient Data
Valley Hope Association (VHA), a Kansas-based addiction treatment organization with 16 facilities in seven Midwest states has started notifying patients that their information may have been compromised in a data breach. After officials found suspicious activity on an employee’s email account in October, an investigation was launched. VHA hired a forensics team to uncover details […]
Ransomware Is Alive and Well – Here Are 10 Tips to Help Protect Your Organization
Remember ransomware, the malicious software that blocks computer access until a ransom demand is paid? The threat was huge and dominated headlines in the past but seems to have slowed down in recent months. Could the decline in publications citing ransomware as the cause of a data breach or loss of data indicate that […]
5 Tips for Protecting Your Electronic Health Records
As the value of healthcare data remains high, there is no denying that healthcare organizations make prime targets for cybercriminals. To wreak havoc and make a profit from compromised patient data, cybercriminals exploit weak spots in healthcare organizations, whether that be a loophole in the security of the server, poorly trained employees, or a variety […]
VUMC Uses Multi-Factor Authentication to Combat Phishing Attacks
Educating employees on security awareness and the dangers posed by cybercriminals is critical to any organization. While you can train employees on what to look for and how to best protect your practice, cybercriminals will continue to find unique and more sophisticated ways to trick individuals and gain access to the sensitive data they’re trying […]
Why Physicians Need Improved Cybersecurity Education
A recent survey conducted by the American Medical Association (AMA) and the consulting firm Accenture surveyed 1,300 U.S. physicians to find out about their experiences and attitudes towards cybersecurity. Unsettling findings in the survey revealed a lack of cybersecurity education among physicians. The five key findings of the survey as reported by the AMA and […]
Why Your Employees Break the Rules
It’s no secret that employees violate security policies. Whether we’d like to admit it or not, there’s a good chance we have all violated a security policy once upon a time. Sometimes, employees violate policies to save time or make their job easier, and sometimes, they don’t even know they’re doing it. How do you […]
Phishing Attack Leaves 37K Gold Coast Health Plan Members’ PHI at Risk
On October 5, California-based Gold Coast Health Plan (GCHP) informed the Office for Civil Rights (OCR) that a phishing attack may have exposed the protected health information of 37,005 plan members. The attack occurred when hackers successfully tricked a GCHP employee with a phishing email, which allowed the hackers access to that employee’s email account […]
Why Hackers Target Healthcare
Cybercriminals have been targeting the healthcare industry for years. As healthcare has become the second largest sector of the U.S. economy, it should come as no surprise that the industry receives special attention from hackers. Aside from its size, what else accounts for the indisputable interest cybercriminals have in exploiting healthcare? Hackers Set Sights on […]
Business Email Compromise Scams – Here to Stay
Business email compromise (BEC) scams remain one of the most widely used attack vectors among cybercriminals to date. In fact, cybercriminals are finding so much success in exploiting human vulnerabilities through BEC scams that their frequencies have been dramatically increasing. What is a BEC scam? In a BEC scam, the attacker gains access to an […]
HIPAA Violations During ‘Boston Med’ Filming Leave Three Boston Hospitals with $999,000 in Fines
On September 20, the Department of Health and Human Services’ Office for Civil Rights announced a fine of $999,000 for three Boston hospitals, all of which violated HIPAA while allowing ABC’s TV series “Boston Med” to film the show in their facilities. Boston Medical Center (BMC), Brigham and Women’s Hospital (BWH), and Massachusetts General Hospital […]
Breached Records to Skyrocket with SMBs as the Biggest Targets
A lot can happen in 5 years, and unfortunately, not always for the better. According to a recent report by Juniper Research, Cybercrime & the Internet of Threats 2018, data breaches are expected to reach 146 billion records over the next five years. For cybercriminals to successfully compromise such an extreme number of records, significant […]
51% of SMB Leaders Think Their Business Isn’t a Target for Cybercriminals
Small businesses are often thought to be a forgotten entity when it comes to cybercrime. On the surface, it seems like a fair assumption that hackers wouldn’t target small businesses when there are large enterprises with much greater assets. Unfortunately, many small business leaders fall for this “I’m not a target” mentality, when in fact, […]
HIPAA and MACRA/MIPS 2018 – What You Need to Know
As we move into the second half of the year, many practices and physicians are starting to consider the data they will need to submit under the MACRA/MIPS program. The MACRA/MIPS rules change slightly every year, and this year is no exception. Even though the rules have been adjusted, a basic requirement remains in place: […]
Missouri-Based Practice Suffers Breach of Nearly 45,000 Patient Records
Despite reports that the healthcare sector is seeing fewer ransomware attacks this year than years prior, that doesn’t mean they don’t still exist. Unfortunately, for Missouri-based Blue Springs Family Care, that lesson was learned the hard way after suffering a breach of 44,979 patient records resulting from a ransomware attack. Cass-Regional Medical Center, also based […]
Healthcare Data Breaches Rise Along with Consumer Concerns of Privacy and Data Security
A recent survey conducted by the health insurance company Aetna revealed some significant results as to what consumers consider to be their most important concern in terms of healthcare. According to the survey of 1,000 consumers, concerns of patient privacy and data security are more important than the cost of care. 80% of survey respondents […]
The Psychology of Falling for a Phishing Email
Phishing is a cybercrime that has been around for many years, where targets are sent malicious emails claiming to be from a legitimate individual or organization to trick them into disclosing their sensitive information. Phishing emails remain a major threat today, however despite increased awareness of the cybercrime, cybercriminals continue to fool their targets into […]
Healthcare Data Security: Less of a Concern for U.S. Adults than Threats to Financial Information
Our healthcare data holds a multitude of sensitive information regarding our personal lives. That information could include our full name, date of birth, home address, health history, diagnoses, and test results to name a few pieces of information. While we know the data contained in our healthcare records is quite extensive, less than half of […]
$150K Proposed Settlement for Victims of 2014 Flowers Hospital Data Breach
The end may now be in sight for a four-year-long legal battle for individuals affected by a 2014 healthcare data breach. While the settlement has not yet received final court approval, the tentative settlement of the class-action lawsuit could provide more than 1,200 affected individuals of the 2014 Flowers Hospital data breach up to $150,000 […]
Exactis Database Leaks 340 Million Records of Personal Data
There is a good chance you’ve never heard of the major marketing and data aggregation company Exactis, but that doesn’t mean they don’t know you. In fact, Exactis may know a great deal of your personal information, including your email address, your home address, your habits and hobbies, your children’s ages and genders if you […]
Password Reuse: A Common Practice for 25% of Employees
Risky cyber behavior among employees is nothing new, in fact, despite organizations becoming more aware of the state of cybersecurity, employees continue to cause data breaches in unacceptable numbers. TechRepublic looks at a recent OpenVPN survey, which dissects poor cyber hygiene among employees. Despite an increased focus on security training, 25% of the 500 […]
HIPAA Security Tips and Reminders – Phishing Sites
Security Tips: Phishing Sites Click on above to view in fullscreen mode!
Security Awareness Training – Time to Jump on the Bandwagon
Human-error; we talk about it all the time, but what exactly do we mean? Human-error occurs when an individual performs a task or does something with an unintended outcome. It’s easy to point the finger at employee’s as being an organization’s weakest link, but without appropriate security awareness training provided by the employer, how can […]
SMS Phishing Scam for Email Accounts
[tvideo type=”youtube” clip_id=”_dj_90TnVbo” rel=”false” showinfo=”false”]
HHS’ OCR proposes HIPAA change to share settlements of data breaches with victims
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) is planning to issue an advance notice of proposed rulemaking this November that could be a major game changer for HIPAA breach settlements. According to the Data Protection Report, the OCR plans to get the public’s input on a policy change […]
Insiders to Blame for Poor Cybersecurity in Healthcare
It comes as no surprise that the healthcare industry is a prime target for cybercriminals. Since it’s easy to recognize the potential profit in stealing Protected Health Information (PHI), it is crucial to know and understand the potential security threats that exist, including threats from the inside. Verizon found in their 2018 Protected Health Information […]
FTC: Five Ways to Help Protect Your Identity
[tvideo type=”youtube” clip_id=”lp_8cvNm_vE”]
Two San Francisco Hospitals Suffer Breach of Patient Data
According to the San Francisco Public Health Department, nearly 900 patients at two San Francisco hospitals had their personal information breached. On Friday, the Department stated that the breach occurred at San Francisco General and Laguna Honda hospitals when a former employee of one of the hospitals’ vendors gained unauthorized accessed the patient data. An […]
Learn more about the impact of ransomware
[tvideo type=”youtube” clip_id=”X08wgodFgXw” width=”600″ rel=”false”]
HIPAA Security Tips and Reminders – Public WiFi Networks
Security Tips: Public WiFi Networks The FTC has some good tips on securing confidential information, including patient information, when using Public WiFi Networks.
OCR Cyber Security Newsletter: Risk Analyses vs. Gap Analyses – What is the difference?
April 2018 OCR Cyber Security Newsletter Risk Analyses vs. Gap Analyses – What is the difference? The Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security and Breach Notification Rules require covered entities and their business associates to safeguard electronic protected health information (ePHI) through reasonable and appropriate security measures. One of these measures required […]
Mitigating Insider Threats in Healthcare
It is no secret that healthcare data breaches are on the rise. While we often hear about hackers targeting the healthcare industry, you may be surprised to learn that more healthcare data breaches are caused by insiders than hackers! In their recent Protected Health Information Data Breach Report, Verizon has found that 58% of all […]
Why SMEs and SMBs Fail After A Cyberattack
Malicious cyberattacks are increasing every day around the globe. In fact, cyber-incidents nearly doubled from 82,000 incidents in 2016, to 159,700 in 2017. While the media often depicts large corporations as the primary target for cyberattacks, small business are just as likely – if not more likely to be targeted. An article on CSO looks […]
Effective Security Training Requires Change in Employee Behavior
Many organizations spend countless hours and resources on training their employees, only to find that their business has suffered a data breach caused by human error. Despite the quality and frequency of a security awareness training program, if employees are not engaged in training or feeling a sense of motivation to protect their organization, […]
You Received a Letter from OCR, Now What?
This article was written by Matt Fisher and originally appeared on the Mirick O’Connell Health Law Blog. It is published here with permission. At some point in time most group practices, hospitals or other provider organizations will receive a letter from the Office for Civil Rights (“OCR”). The letter will state that OCR received a […]
Federal Trade Commission Warns of Fake Invoice Phishing Scams
Phishing has become a common threat faced by organizations in today’s digital era. While cybercriminals are enhancing their tactics to make their attempts seem more legitimate, they continue to recycle old scams, making only minor changes to trick their victims. An old phishing attempt has recently started resurfacing where scammers pose as a well-known tech […]
FBI Warns Small Businesses to Beware of Cybercriminals
It is no secret that the Internet has become a key component of our daily lives for personal and business use alike. Unfortunately, the dependency of the Internet in today’s culture has become quite clear to cybercriminals, making security an incredibly important concern, especially for small businesses. An article on Homeland Security Today explores the […]
OCR February 2018 Cybersecurity Newsletter: Phishing
In the February OCR Cybersecurity Newsletter, they give very good information on Phishing and how to avoid being a victim. The newsletter is reprinted below: February 2018 Cybersecurity Newsletter Phishing Phishing is a type of cyber-attack used to trick individuals into divulging sensitive information via electronic communication by impersonating a trustworthy source. For example, […]
How Does the Dark Web Impact Small Businesses?
Identity theft is an unfortunate occurrence that is all too familiar with most business owners, but do those individuals know where the compromised data will end up? Often, these business owners are unaware of the virtual marketplace where stolen data is purchased and sold by cybercriminals; a place known as the “Dark Web”. An article […]
The Human Factor – The Weakest Link In Data Protection
Click for full image
How Will Your Employees Get You Hacked?
Breaches are becoming increasingly common as cybercriminals continue to advance their skills and tactics to trick their victims into falling for their scams. While cybercriminals are remaining diligent in their efforts to carry out their attacks, small business owners continue to underspend on cybersecurity. An article on Entrepreneur looks at 5 things your employees are […]
Affiliated Covered Entities
Matthew Fisher, ESQ and Jonathan Krasner Healthcare represents a very large segment of our economy – approaching 20% by some estimates. As such, healthcare organizations come in many sizes and flavors. We are all, hopefully, familiar with the basics that HIPAA compliance requirements apply Covered Entities, Business Associates and subcontractors. A CE and a BA […]
What is Your Personal Information Worth on the Dark Web?
The dark web is often known for the illegal activities conducted there, and while not everything on the dark web is illegal, it’s most appealing factor is its anonymity. The dark web is often a place where stolen data and personal information is bought and sold following a data breach or hacking incident. An article […]
Mapping Base-EHR to MIPS ACI-Base-Score: 5 Things You Need to Know
This is a guest post by Pawan Jindal of MyMIPSScore and originally appeared at the MyMIPSScore Blog Under MACRA, Advancing Care Information(ACI) category of MIPS replaced Meaningful Use. As we discussed briefly in the 10 step overview of MIPS, ACI scoring under MIPS is determined based on the provider’s performance for a set of base […]
Ransomware Wreaks Havoc in 2017
Ransomware dominated the healthcare industry in 2017, with six of the top ten breaches reported to the U.S. Department of Health and Human Services a direct result of the malicious software. An article on Security Current looks at some ransomware attacks from 2017 as well as steps you can take to help avoid becoming a […]
Allscripts Suffers Ransomware Attack: Recovery Underway
Billion-dollar electronic health record (EHR) company Allscripts has fallen victim to a ransomware attack, which began on Thursday, January 18 around 2:00 a.m. EST. By 6:00 a.m. EST, the ransomware attack was full-blown requiring Microsoft and Cisco’s incident response teams to be called upon for assistance. An article on CSO explores the attack which […]
Analysis of 2017 Health Data Breaches
While you might expect that the number of mega-breaches in 2017 would surpass all previous years, the numbers may take you by surprise. In fact, 2017 saw a drop in the number of individuals affected by healthcare breaches. An article on Bank Info Security provides an analysis on 2017’s health data breaches and the outlook […]
Employee training crucial this holiday season
Employee training crucial this holiday season American small businesses know the holiday shopping season is a vital time to make one final push to meet sales goals for the year. With an increase in retail sales, it is crucial that businesses, especially startups, have a robust cybersecurity plan in place to protect themselves and their […]
Make sure to make available patient records on a timely basis
HIPAA is often described as dealing with CIA – the Confidentiality, Integrity and Access to patient records. In the past, access to patient records often required a written request, accompanied by a response in the mail that could take several weeks. However, in today’s world where electronic systems can provide almost instant action to data, […]
HIPAA Secure Now! Chosen as Preferred Vendor for 2,700 YMCAs Across the United States
MORRISTOWN, N.J. (PRWEB) DECEMBER 04, 2017 YMCA of the USA (Y-USA), the national resource office for 2,700 YMCAs (“Ys”), has selected HIPAA Secure Now! (HSN) as a preferred provider of HIPAA compliance and cyber security services to local Ys nationwide. HSN will help ensure that protected health information (PHI) for thousands of participants in the […]
HIPAA Secure Now! Joins Forces with MyMipsScore to Aid Physicians in Raising MIPS Scores and Medicare Reimbursements
MORRISTOWN, NJ (PRWEB) NOVEMBER 27, 2017 HIPAA Secure Now! (HSN) and MyMipsScore™ (MMS) are joining forces in a new partnership designed to give healthcare providers a competitive advantage as they adapt to the requirements of MIPS – the Merit-based Incentive Payment System – which determines Medicare reimbursements using value-based care criteria rather than the traditional fee-for-service […]
Tips for securing ePHI on mobile devices
While mobile devices play a major role in how we stay connected to the world in our personal lives, they are also becoming increasingly popular in our work environments. Not only are mobile devices such as smartphones, tablets and laptops convenient in the workplace, but they can also help increase productivity. In its October cybersecurity […]
Avoiding MIPS Penalty: There’s an App for That!
This is a guest post by Pawan Jindal of MyMIPSScore and originally appeared at the MyMIPSScore Blog In our last blog we discussed an overview of MIPS submission process. As promised, we are very excited today to announce the availability of a new feature of MyMipsScore that will allow you to avoid the MIPS penalty for free. […]
The weakest link in cybersecurity
By now I’m sure you’ve heard that when it comes to information security, employees are the weakest link. Organizations often emphasize that despite any security measures they put in place to protect their infrastructure, all it takes is one employee who is not following the rules to undo all of that. An article on TechRepubic […]
MIPS Submissions: It’s NOT Complicated
This is a guest post by Pawan Jindal of MyMIPSScore and originally appeared at the MyMIPSScore Blog It is hard to believe that we are already in the last quarter of 2017. Even as the first year of MIPS winds down, complaints about how complicated MIPS is, continue to dominate the news. Over the past nine […]
Security risks can be a MIPS score killer
Prolonging the process of figuring out quality measures under the Medicare Access and CHIP Reauthorization Act of 2015 (MACRA) and increasing scores for the Merit-Based Incentive Payment System (MIPS) could put medical practices at a competitive disadvantage. Healthcare providers will earn a MIPS score each year, starting in 2019 (based on 2017 performance). According to Jim Tate, president […]
Fall prevention strategies apply to anti-phishing efforts
Patient falls have been a serious problem in hospitals and other healthcare facilities for years. In fact, in January 2013 the Agency for Healthcare Research and Quality set out to help reduce the number of falls in healthcare facilities by commissioning a RAND Corporation/ Boston University School of Public Health Report. The report, titled “Preventing […]
Study finds cybercriminals favor small businesses
As ransomware continues to grow, so do the millions of dollars businesses are dishing out to cybercriminals in hopes of regaining control of their sensitive data. An article on Fox Business looks at a study released by data security solutions firm Datto to see how ransomware is affecting small-to-mid-sized businesses. According to the study, in […]
5 ways a hacker may target your small business
Cyberattacks only happen to large corporations because they hold the most personal and sensitive data, right? Wrong. While the media often leads us to believe cyberattacks are only occurring on high-profile organizations holding a lot of data, the statistics show us otherwise. An article on Information Security Buzz takes a look at 5 ways hackers […]
Engage Users in Cybersecurity Training
As you may know, successful cyberattacks often come as a result of human error, but did you know those errors are often made by employees who have already been through training? An article on Healthcare IT News takes a look at what methods help cybersecurity training stick. Cybercriminals direct their attacks on untrained employees or […]
“Human Factor” to Blame for Increase in Ransomware Attacks
Cybersecurity company Malwarebytes recently released findings from their Second Annual State of Ransomware Report, which provides us with some important insight on today’s state of digital security. An article on CNET highlights findings from the report. According to the report, one-third of SMBs (small-to-medium-sized businesses) were hit by ransomware in the last year. For the […]
Study finds that 30% of SMEs lack an incident response plan
Cybersecurity issues have become very prevalent in the modern era, making headlines with their disasters and fines associated with them. While it may seem obvious that businesses should take precautions to protect themselves against these potential attacks, they have been slow to move forward with improving their security measures – especially small and medium-sized enterprises […]
OCR deputy discusses common mistakes that often lead to compliance reviews
Have you ever wondered what exactly triggers a breach case investigated by Health and Human Services? While a number of things may attribute to an investigation, according to Deven McGraw, deputy director for health information privacy at the HHS Office for Civil Rights, nearly every breach case investigated by the department stems from a […]
Article: What Happens When Your Small Business Is Hacked
As cyber-attacks continue to sweep across the globe, the pressure is also increasing for IT providers and security professionals to keep security measures a top priority. An article on Entrepreneur explores the consequences of falling victim to a data breach and ways to prepare for one in the event it were to occur. While you […]
56% of healthcare organizations see employees as their greatest threat to IT security
A recent survey conducted by Netwrix found that although healthcare organizations understand the importance of protecting patient information, they often fall short on improving their security measures. An article on PR Newswire explores the findings of the Netwrix survey. The survey included responses from IT professionals across various industries, including healthcare. Where are healthcare organizations […]
Cyberattack Costs New York Hospital Nearly $10 million
Erie County Medical Center in New York fell victim to a ransomware attack in April, leaving the hospital with the decision to pay the ransom and potentially recover their data or lose their encrypted files to a cybercriminal. The cyberattack, which took down over 6,000 computers had a ransom demand of $30,000 dollars (24 bitcoins […]
New Strain of Ransomware Hits Michigan Hospital
A hospital in Michigan is feeling the pressure after suffering a ransomware attack earlier this month. On July 5th, Caro Community Hospital, Caro Medical Clinic and Caro Quick Care lost access to their phones, email services and patient records as a result of the ransomware attack. According to CEO Marc Augsburger, the ransom note accompanying […]
Data breaches happen to both small and large businesses
It is no secret that despite increased awareness of data breaches around the globe, businesses continue to fall victim to cybercriminals exploiting their weak security measures. An article on Small Business Computing explores data breaches and how the size of the business doesn’t matter to criminals seeking confidential information. Large corporations are often thought to […]
Cyberattack Forces West Virginia Hospital to Scrap Its Computer Systems
As another detrimental cyberattack, coined NotPetya, wreaks havoc across the globe, organizations are hoping their security measures are enough to keep them from falling victim. Unfortunately for Princeton Community Hospital in West Virginia, their security measures were not enough, resulting in NotPetya destroying their entire computer network. An article on Fox Business explains the […]
Should healthcare organizations be incentivized to adopt cybersecurity?
It is no secret that healthcare organizations underfund their defense efforts when it comes to protecting patient data. Even though personal health information is very valuable to cybercriminals and can even generate more revenue on the black market than financial information, healthcare organizations continue to take a lax approach in their cybersecurity practices. Last week […]
Article: Former Durango Family Medicine patients warned of security breach
While convenient, portable devices come with a great deal of risk. No organization wants to imagine their portable devices getting lost or stolen, however it happens. If appropriate safeguards are not in place to protect those devices, a serious breach could occur. Unfortunately for Durango Family Medicine, this nightmare came true when a portable external […]
Google to remove ePHI from its Search Results
HIPAA data breaches can occur if ePHI (electronic protected health information) is posted on an open web site. In that situation, not only is the ePHI available for viewing, it also can be indexed by an Internet search engine such as Google. Many data breaches have been uncovered by finding the unauthorized ePHI via […]
Healthcare Seen Highly Vulnerable to Cyberattack
In a recent report conducted by the American International Group (AIG), experts were asked a broad, but valid question; “is cyber risk systematic?” Looking at recent events, AIG indicated that cyber risk is in fact systemic, predicting an event much like the global ransomware attack, “WannaCry” that took the world by storm earlier this month. […]
Global Ransomware Attacks Target Healthcare Organizations
As you may be aware, a global ransomware attack, called WannaCry, started on Friday May 12, 2017 and is continuing as of today. The attack has affected 200,000 Microsoft Windows based machines in over 150 countries. The cybercriminals have focused on healthcare and financial services but have affected many other industries and individuals as well. […]
75% of health organizations fall below cybersecurity poverty line
George DeCesare, Chief Technology Risk Officer for Kaiser Permanente, met with the Health and Human Services Department as well as other security experts and came away with some shocking truth. An article on Healthcare IT News provides some great insight on why falling below the cybersecurity poverty line could be detrimental to health organizations. Seventy-five […]
$31,000 fine for not having a Business Associate Agreement
The Center for Children’s Digestive Health (CCDH) a small, for-profit practice has agreed to implement a corrective action plan for their potential violations of the Health Insurance Portability Accountability Act of 1996 (HIPAA) Privacy Rule. According to the U.S. Department of Health and Human Services (HHS), the settlement includes a hefty payment of $31,000 for […]
Article: 68 percent of healthcare organizations have compromised email credentials
A study from the cloud services provider, Evolve IP suggests that over two-thirds of all healthcare organizations have employees using compromised email credentials. An article over on Healthcare IT News explains how Evolve IP determined these findings. The study found that 55 to 80 percent of organizations have email accounts that have been compromised. Looking […]
Article: How healthcare organizations should prepare for a HIPAA audit
Preparing for a HIPAA audit is vital for healthcare organizations. Sure, these organizations understand that they may face a HIPAA audit, but often let preparation for such an event fall to the bottom of their priority list. It is important to ensure your organization is prepared prior to receiving notification of a forthcoming audit. An […]
Even Non-Profits can get HIPAA Fines
Federally Qualified Health Centers (FQHCs), Community Health Centers (CHCs) and related entities are non-profit organizations that run on shoestring budgets. These organizations are constantly in search of revenue, grants and donations to keep their operations running. Therefore, any type of adverse financial event will be devastating. However, these organizations also must comply with relevant regulations, […]
Ransomware Attack Hits Pediatric Practice
ABCD Pediatrics, a Texas based pediatric practice has recently reported a major data breach, which came as the result of a ransomware attack occurring in early February. An article on Gov Info Security explores the attack, looking closely at what made it a reportable incident. According to the practice, an employee discovered a virus had […]
Large data breaches happening at U.S. Hospitals
When you think of being a patient in the hospital, the last thing you may think about is the safety of your personal data. According to research findings by Michigan State University, the security of your personal information in U.S. hospitals is something to be concerned over. An article on UPI explores the study, showing […]
Ransomware ‘Philadelphia’ Discovered Targeting Healthcare Industry
According to researchers, a new variant of ransomware has stepped onto the scene, choosing the healthcare industry as its target. Researchers from the security firm Forcepoint have discovered the ransomware, which has been name Philadelphia. An article over on Healthcare IT News explores how the newly discovered virus works. Philadelphia can be purchased by amateur […]
Americans receive mixed results in cybersecurity IQ
While it is true that Americans are becoming more aware of the need to protect their information online through methods such as utilizing strong passwords or being conscious of how they’re using public Wi-Fi, many still lack in key areas which could cause significant data breaches. Things like recognizing “phishing” emails or determining if a […]
TV Show – Chicago Med a Ransomware Victim
You know ransomware is a real threat when it starts showing up on TV shows. Chicago Med is a victim of a ransomware attack on the hospital. It is time to be concerned in real life! [tvideo type=”youtube” clip_id=”LOQfWaKOSnU”]
5 Tips for Staying #HIPAA Compliant on Social Media
Social media has become an incredibly valuable tool, whether for personal or business use, the need and desire to use social media has increased dramatically since it first stepped on the scene. Historically, medical professionals have steered clear from social media in fear that they may violate HIPAA guidelines. Today, medical professionals cannot deny the […]
Article: Computer Virus Potentially Exposes PHI of 2.5K at Oregon Clinic
Lane Community College (LLC) health clinic located in Oregon may be dealing with a serious breach. An article over on Health IT Security discusses the computer virus a technician at the hospital discovered, which may have led to exposure of some patients PHI. The Oregon college health clinic stated the virus may have been […]
Ransomware Attack on Urology Austin
A total of 279,663 patients are being notified by Urology Austin that their protected health information (PHI) may have been compromised in a ransomware attack. Information that may have been compromised in the attack includes patient names, addresses, dates of birth, medical records and social security numbers. An article over on HIPAA Journal provides insight […]
Article – FBI: Attackers Targeting Anonymous FTP Servers in Healthcare
A warning issued by the FBI cautions healthcare providers to beware of threat actors, who are now targeting anonymous File Transfer Protocol Servers (FTP), associated with both medical and dental organizations. An article on Dark Reading goes into great detail about the trouble with anonymous FTP servers and why it is important to turn yours […]
The Latest Details on HIPAA Compliance Audits
Deven McGraw, deputy director of the Department of Health and Human Services’ Office for Civil Rights has announced that the department’s plans for initiating onsite audits is currently on hold and will remain so until more than 200 desk audits have been completed. An article over on Data Breach Today gives us great detail on […]
Office for Civil Rights Issues Second Largest HIPAA Fine to Date – $5.5 Million
According to an article over on tripwire, a covered entity is facing serious penalties after the Office for Civil Rights issued them a hefty fine for their failure to comply with audit procedures including review, modification and termination of users’ access. In the scope of the investigation, it was discovered that more than 100,000 individuals […]
Article: Snooping St. Charles Health System Employee Accessed Almost 2,500 Patient Records
According to an article on HIPAA Journal, over a 27 month period an employee of St. Charles Health System in Oregon accessed nearly 2,500 patient records without authorization. All it took to discover the unnamed employee had been inappropriately accessing patient records was one incident that sparked further review, occurring on January 16, 2017. The […]
Healthcare firms to increase security spending
With the dramatic number of security breaches over the last few years, it should come as no surprise that the healthcare industry has plans to increase spending on IT security. An article over at CIO talks about just how necessary the increase in IT security spending really is. According to a survey released this Tuesday, […]
Ransomware: could smaller practices be the next victims?
As you may know, ransomware has become a top concern for organizations across the globe as cybercriminals continue to flex their muscles and show just how easily they can take down an organization through a simple e-mail. An article over at SC Magazine takes a look at the threat of ransomware to smaller practices. What is […]
Want to Score with MACRA? Perform a HIPAA Risk Assessment.
Congress may be poised to roll back the Affordable Care Act, but HIPAA and MACRA, the Center for Medicare & Medicaid’s (CMS) new model for reimbursements, are as certain to remain as death and taxes. Moreover, MACRA and HIPAA go hand in hand. Physicians cannot participate in MACRA, which went into effect on January 1, […]
Want to Score with MACRA? Perform a HIPAA Risk Assessment.
Congress may be poised to roll back the Affordable Care Act, but HIPAA and MACRA, the Center for Medicare & Medicaid’s (CMS) new model for reimbursements, are as certain to remain as death and taxes. Moreover, MACRA and HIPAA go hand in hand. Physicians cannot participate in MACRA, which went into effect on January 1, […]
CMS extends Meaningful Use deadline to March 13, 2017
The Centers for Medicare & Medicaid Services extended the deadline for Meaningful Use requirements for providers participating in the Medicare EHR Incentive program. The new deadline is March 13, 2017, a two-week extension from the previous Feb. 28 deadline, according to a CMS spokesperson. Eligible providers, hospitals, and critical access hospitals must attest to the […]
Updated 2017 HIPAA Training
We are excited to announce that the HIPAA training classes have been updated for 2017. The update includes the HIPAA Security and Privacy classes for both HIPAA Covered Entities and Business Associates. [tvideo type=”youtube” clip_id=”6Ogt7YBqh6k” autoplay=”true” controls=”false” loop=”false” rel=”false” showinfo=”false” modestbranding=”false”] More engaging The training now utilizes more multimedia, video and engaging content. In fact, […]
OCR’s guidance to audit controls
In the January, 2017 edition of the OCR Cyber Newsletter (PDF), OCR gives guidance to what is required from Covered Entities and Business Associate regarding auditing / monitoring of access to PHI. Covered Entities and Business Associates should make sure that they appropriately review and secure audit trails, and they use the proper tools to […]
Still time to do a SRA for Meaningful Use
We frequently get asked about the timing of when a Security Risk Assessment (SRA) needs to be performed for Meaningful Use. So here is some guidance: SRA for Meaningful Use A SRA needs to be performed before a provider attests for Meaningful Use. According to CMS – https://www.cms.gov/Regulations-and-Guidance/Legislation/EHRIncentivePrograms/Downloads/2016_SecurityRiskAnalysis.pdf Conducting a security risk analysis is required […]
Data breaches at smaller companies can be devastating
According to a Verizon study, data breaches at Small and Midsize Businesses (SMBs) occur more frequently than at larger companies. Another study found that the impact of a SMB breach could be devastating to the business. Find out more about the leading cause of SMB data breaches and what you can do to prevent a […]
MACRA regulation commences January 1, 2017
MACRA regulation (Medicare Access and CHIP Reauthorization Act) commences January 1, 2017. MACRA significantly changes the way physicians are paid and overall Medicare reimbursements. Learn more in our 80 second video [tvideo type=”youtube” clip_id=”3Qe2bVJK05s” rel=”false”]
Peachtree Orthopedics breach hits 531,000 patients
Peachtree Orthopedics has experienced a huge data breach that affects over 500,000 patients. It seems that Peachtree was a victim of a hacker who stole the information and went a step further by issuing a press release: It all began many months ago when we acquired 543k patient records which contain both PII and PHI […]
MACRA Requires a HIPAA Security Risk Assessment
MACRA starts in January, 2017 and requires a HIPAA Security Risk Assessment [tvideo type=”youtube” clip_id=”Bo-ZdAd1sFk” width=”500″]
New CMS MACRA Rule Kicks In, Factors HIPAA Compliance into New Payment Structure
MORRISTOWN, NJ (PRWEB) NOVEMBER 21, 2016 HIPAA Secure Now! is set to handle security risk assessments that will be required of medical practices, under the new MACRA regulation (Medicare Access and CHIP Reauthorization Act), which commences January 1, 2017. HIPAA Secure Now! helps medical practices comply with HIPAA, and protect their most valuable asset – […]
New CMS MACRA Rule Kicks In, Factors HIPAA Compliance into New Payment Structure
MORRISTOWN, NJ (PRWEB) NOVEMBER 21, 2016 HIPAA Secure Now! is set to handle security risk assessments that will be required of medical practices, under the new MACRA regulation (Medicare Access and CHIP Reauthorization Act), which commences January 1, 2017. HIPAA Secure Now! helps medical practices comply with HIPAA, and protect their most valuable asset – […]
WARNING: BE ON THE LOOKOUT FOR OCR PHISHING EMAIL
In a cruel twist of fate, health care entities are being phished using an OCR (HHS Office of Civil Rights) email as the bait. Here is the context: HHS/OCR is the governmental entity in charge of enforcing the HIPAA statutes. Back in May, we reported that OCR had started sending emails to Covered Entities […]
OCR ‘Laser Focused’ on HIPAA Violation Complaints, Enforcement
HealthIT Security has a very good article on OCR HIPAA activities. A key message is that not all OCR complaints result in HIPAA violations OCR will continue to focus “its enforcement efforts and its resources” in areas of alleged non-compliance and “where corrective action under HIPAA may be the only remedy.” In terms of OCR […]
OCR’s Guidance to HIPAA & Cloud Computing
We have previously posted about HHS/OCR’s Guidance on HIPAA & Cloud Computing. The guidance is presented in question and answer form. To see the full guidance, you can go to the OCR page. Below are the 11 questions with partial answers to keep this brief but provide a good overview: Questions 1. May a […]
HIPAA Gets a Little Cloudy
Pun intended. We all use cloud computing resources every day. All you have to do is go on the Internet, and chances are the website you are accessing uses cloud services. Our website, www.healthsecurenow.com, uses the Amazon cloud. There are many definitions of cloud services, but at a high level it is the use of […]
Hospital fined $400,000 for obsolete Business Associate Agreements
In a clear message to healthcare organizations, The U.S. Department of Health and Human Services Office of Civil Rights (OCR), fined Women & Infants Hospital of Rhode Island (WIH) for not having updated HIPAA Business Associate Agreements. WIH provided OCR with a business associate agreement with Care New England Health System effective March 15, 2005, […]
Dropbox Data Breach and Phishing Scams
Dropbox, the popular file sharing service, has experienced a data breach that could affect up to 60 million users. Dropbox is urging their users to change their passwords immediately. In addition, we are seeing an increase in Dropbox related phishing emails. In this security tip video, we show you real examples of Dropbox related phishing […]
Athens Orthopedic won’t pay for credit monitoring in data breach
Data breaches are happening on a frequent basis. You can’t read the news or watch TV without hearing about another data breach. While a company may give out some details of a data breach, the financial details of what the data breach will cost a company usually are not disclosed. This is especially true with […]
Healthcare software bugs have big consequences
Almost all software programs have bugs in their code. The bugs may be security holes, problems displaying pages on mobile devices or inaccurately displaying results in reports to name a few. So it should be no shock that electronic health record (EHR) systems would have bugs as well. EHRs are complex software programs and are […]
IRS Imposter Scams
[tvideo type=”youtube” clip_id=”i4nCy6Xs6R8″ rel=”false” showinfo=”false”]
HHS Office for Civil Rights releases ransomware guidance
There has been a lot of articles written lately about the threat of ransomware to healthcare organizations. Hollywood Presbyterian Medical Center paid a $17,000 ransom to regain access to their systems after they were infected with ransomware. Several other hospitals have been ransomware victims and countless other medical practices have fallen victim as well. There […]
Phase 2 HIPAA Audits – You Can Get Selected
Back in March, we reported that OCR had announced its Phase 2 Audit Program. When we last heard from OCR about Phase 2 HIPAA Audits, we saw that emails were being sent to Covered Entities and Business Associates. The purpose of the emails was to verify and expand the OCR HIPAA audit pool. We wrote […]
Don’t Let HIPAA Audits, Ransomware Sink Your Practice
HIPAA Secure Now! President and CEO writes an article for Physicians Practice called: Don’t Let HIPAA Audits, Ransomware Sink Your Practice At the same time medical practices are faced with the increased likelihood of a HIPAA audit, hackers hover around waiting to steal patients’ personal data and/or hold it hostage through ransomware scams. These practices […]
Becker’s: 8 HIPAA compliance best practices
A recent article over at Becker’s Spine Review, discusses some of the “low hanging fruit of HIPAA compliance”. They give 8 best practices for being HIPAA compliant. For the article they interviewed David Holtzman, JD, CIPP, vice president of compliance strategies, Cynergistek and Aaron Tantleff, partner and intellectual property lawyer with Foley & Lardner LLP. Encrypt health information. The […]
Secure Now! Discusses Data Security on Worldwide Business with kathy ireland®
Tune in to Fox Business Network as sponsored programming and Bloomberg International on Sunday, June 26, 2016. See market-by-market listings below. Los Angeles, CA – June 23, 2016 — Secure Now! President/CEO Art Gross will soon appear on the award-winning, global TV show, Worldwide Business with kathy ireland®. Gross will share his expertise in the small and mid-sized business […]
Secure Now! Discusses Data Security on Worldwide Business with kathy ireland®
Tune in to Fox Business Network as sponsored programming and Bloomberg International on Sunday, June 26, 2016. See market-by-market listings below. Los Angeles, CA – June 23, 2016 — Secure Now! President/CEO Art Gross will soon appear on the award-winning, global TV show, Worldwide Business with kathy ireland®. Gross will share his expertise in the small and mid-sized business […]
Lack of HIPAA Education causes problems in Orlando
By now we are all aware of the horrible event that took place in Orlando over the weekend. Mass casualties caused local hospitals and ERs to respond heroically. One of the tasks required during these operations was the necessity to communicate patient status with family and loved ones. Unfortunately, this was not handled very well. […]
MedSafe and HIPAA Secure Now! Announce Partnership to Offer Enhanced Healthcare Compliance Solutions
We are excited to partner with Medsafe to add OSHA services to our suite of HIPAA services. We are also looking forward to helping their clients with HIPAA Security Risk Assessments. WELLESLEY, MA–(Marketwired – May 24, 2016) – MedSafe, the leader in total healthcare compliance solutions, is pleased to announce its partnership with HIPAA Secure […]
Physicians: Don’t skip your security risk assessment
Publication: Medical Economics Until you’ve opened a letter from the U.S. Department of Health and Human Services’ Office of Civil Rights (OCR) notifying you that your practice is being audited for Health Insurance Portability and Accountability Act (HIPAA) compliance, you won’t realize the gravity of the situation.
Phase 2 HIPAA Audits – The OCR Emails Have Begun
Back in March, we reported that OCR had announced its Phase 2 Audit Program. OCR stated that they would compile a database of both Covered Entities and Business Associates to form the basis of the pool of organizations potentially targeted for audit. They have followed up on their intentions and in the last week organizations […]
Holy MACRA! – Being HIPAA Compliant is Part of How Physicians get Paid
On April 27, CMS came out with a proposed rule on how physicians will get paid under MACRA (the Medicare Access and CHIP Reauthorization Act). If you want to read the whole 962 page snoozefest, you can find it here (PDF). But sleep or not, this regulation changes the fundamental Fee-For-Service (FFS) system that CMS […]
New ransomware is bad news for healthcare organizations
Well that didn’t take long. In a recent article I made the case that newer variations of ransomware could result in a reportable HIPAA breach. I argued that if ransomware not only encrypted the victim’s files but also copied the files off of a computer or allowed access to the files, then the result could […]
Updated HIPAA Training
If you go back in time, to 2004, and look at Facebook it looks a lot different than it does today. The same can be said for applications like Microsoft Word or Excel. As these services or products mature they evolve – offering improved functionality, performance, stability and features. New HSN HIPAA Training Like Facebook […]
Is Ransomware Considered A HIPAA Breach?
The topic of ransomware, especially ransomware hitting healthcare organizations, is making headlines daily. Dan Munro has a very good article over at Forbes that asks an important question: Is Ransomware Considered A Health Data Breach Under HIPAA? David Harlow, Principal – The Harlow Group, LLC, whose insight into HIPAA law I respect greatly, states: Ransomware […]
HSN CEO on NJTV discussing the next phase of the HIPAA audits
Watch HSN CEO discuss the next round of HIPAA Audits
OCR HIPAA Audits – It’s real this time
Background Although HIPAA is an important set of laws passed to protect the sensitive medical information handled by millions of covered entities and business associates, Health and Human Services Office for Civil Rights (OCR) has never established a permanent compliance audit program. Auditing activity to date by OCR has consisted of a pilot program of […]
NBC NY Reports on Medical Records Found in Trash
NBC news in New York is reporting that medical records from Mount Sinai Beth Israel Senior Health Center were found un-shredded in a public trash container. The documents were apparently discarded from the Mount Sinai Beth Israel Senior Health Center in Chelsea. NBC 4 New York viewer Chris Caeser contacted the I-Team when he discovered […]
Six Ways to Improve Data Security at Your Practice
A married couple — both doctors who shared a medical practice — almost divorced over a HIPAA breach that blindsided them when a patient called to say that her medical records appeared in a Google search and she was filing a lawsuit. The orthopedist of a small practice didn’t want to fund the cost of […]
Another healthcare ransomware attack
First it was Hollywood Presbyterian Medical Center that made headlines when ransomware disabled the hospital’s computer network. Now another California healthcare organization has become a victim. Los Angeles County Department of Health Services is the latest large healthcare organization to experience the pain of ransomware. According to the Los Angeles Times: Los Angeles County Department […]
Free Wi-Fi is hard to resist for most people
In this “always connected” society being without Wi-Fi and Internet access makes a lot of people uncomfortable. Many people have heard about the dangers of free Wi-Fi but still that doesn’t stop a majority of people from connecting when it is available. According to an article over at ZDNet, the security company Avast setup open […]
Texas Print Shop Hit by Ransomware
Ransomware that crippled Hollywood Presbyterian Hospital made national headlines but ransomware continues to be a major menace for small to midsize businesses. A print shop in Lubbock, Texas was shut down last week due to ransomware. An employee opened an infected file and ransomware took control of the network. Click below to watch the video […]
HSN President and CEO contributes to NJTV story on ransomware
Art Gross, the President and CEO of HIPAA Secure Now!, contributes to the NJTV News story on the dangers or ransomware. Watch the full story below (Click on image to start video)
How to avoid ransomware called “Locky”
[embedyt]https://www.youtube.com/watch?v=zPTOcjWtJ5E&width=600[/embedyt]
Paper-based PHI and Business Associate Cause HIPAA Breach
A story over at Gov Info Security details a recent HIPAA breach involving paper-based records that were dumped on a city street on the way to be disposed. “During transport, a small quantity of records were released on Fowler Street in Fort Myers, Florida,” the statement says. “This incident resulted from the condition of […]
The Aftermath of a HIPAA Data Breach
Quite often we hear about data breaches, but we don’t always hear about the consequences. On February 17, Memphis, TN media sources ran articles about a man who was indicted on felony fraud charges. According to a Commercial Appeal newspaper article: “Jeremy Jones is charged in a scheme to steal the identities of more than […]
Hollywood hospital becomes ransomware victim
A hospital in Hollywood, CA has been a victim of a ransomware attack that has left computers unusable for over a week. According to a ZDNet article: the Southern California hospital has been left unable to practice its usual day-to-day operations. The hospital’s president and CEO Allen Stefanek said “significant IT issues” were discovered last […]
NBC Special Report: 1 in 3 American’s Info Compromised in 2015
NBC News had a special report on medical record theft. Medical record fraud is up over 11,000% last year and 1 in 3 Americans have been a victim. When your clients see this, be prepared to answer the question: What are you doing to protect my medical records? Watch the report below:
CMS Administrator Announces the End of Meaningful Use – NOT
Last week, Andy Slavitt, Acting Administrator, Centers for Medicare & Medicaid Services (CMS), spoke at a health care conference. The text of his speech can be found here. His remarks touched on many subjects including Meaningful Use. The MU program is controversial because many providers feel, and with good reason, that portions of MU are […]
HHS offers guidance regarding HIPAA and individual access
The Department of Health and Human Services (HHS) has issued guidance regarding an Individual’s Right under HIPAA to Access their Health Information. The link should be bookmarked by all organizations as a reference for future guidance, questions and answers: http://www.hhs.gov/hipaa/for-professionals/privacy/guidance/access/index.html Here is the introduction text from the guidance: Providing individuals with easy access to their […]
HHS modifies HIPAA to strengthen the firearm background check system
CMS announced in a blog post that HHS has modified HIPAA to strengthen the firearm background check system. Today the Department of Health and Human Services (HHS) moved forward on commitments made by President Obama to curb gun violence across the nation. Specifically, we have modified the Health Insurance Portability and Accountability Act (HIPAA) Privacy […]
IBM Says that 2015 is the “Year of the Healthcare Breach”
At the end of the year all kinds of publications and organizations publish yearly summaries to review the events of the past 12 months. Much of the time this can be positive publicity for a celebrity, firm, organization or industry. In this case, for healthcare, it is decidedly negative. Why has IBM made this proclamation? […]
Why is HIPAA compliance and security so weak?
Computerworld has an excellent article called Healthcare security and HIPAA: Why compliance and security are still lacking. The author does a very good job of trying to figure out why there are so many healthcare related data breaches. Here are some highlights: The author takes a look at a previous article and cites some reasons: […]
Healthcare Data Breaches Cost $6 Billion A Year (Infographic)
Royal Jay has developed an interesting infographic on healthcare breaches Highlights: 19 out of 20 organizations had at least one breach in the last 2 years The cost of a healthcare related breach is $398 per record In 2014, around 1.6 million patients had their medical information stolen from healthcare providers Medical identity theft victims […]
What You Should Know About the HIPAA Privacy Rule
Publication: AAOS Headlines about data breaches draw attention to the Health Insurance Portability and Accountability Act’s (HIPAA) Security Rule. However, its companion—the HIPAA Privacy Rule—is just as important. Although the two rules work hand-in-hand, they are based on different concepts. The Security Rule oversees the mechanisms used to protect the privacy of electronic patient health […]
Don’t skimp on your HIPAA risk assessment
Publication: Medical Economics Until you’ve opened a letter from the U.S. Department of Health and Human Services’ Office of Civil Rights (OCR) notifying you that your practice is being audited for Health Insurance Portability and Accountability Act (HIPAA) compliance, you won’t realize the gravity of the situation.
Dropbox Business will now sign a HIPAA BAA
Dropbox announced at the Dropbox Open event that their business product is now HIPAA compliant. Dropbox Business is a business version of the consumer file sync product. Dropbox announced that they will sign a HIPAA Business Associate Agreement (BAA) for the Dropbox Business product. Dropbox now supports HIPAA-regulated businesses Big news for companies that handle […]
Computer Fraud and Abuse Act may help companies against employee cyber theft
The Computer Fraud and Abuse Act CFAA is not a very widely known piece of federal legislation but could help companies that have been victims of employee or ex-employee theft of digital information. According to an article over at Fox Rothschild LLP the CFAA can be used to help companies that have had employees or […]
Average cost per lost health care record is $363
A recent study by the Ponemon Institute calculated the cost of a healthcare related data breach to be $363 per record. This was the highest amount across all industries. A financial data breach cost $215 per record and a retail data breach cost $165 per record Targeting Protected Health Information According to an article by […]
HIPAA compliance is a business risk
Medicine is Risky The practice of medicine is a risky business. There is always the risk that a certain treatment will fail to help a patient. There is a risk of being accused of malpractice. There is a risk of being accused of incorrectly billing a patient, insurance company or government agency. There is a […]
Revised Meaningful Use: SRA #1 Objective
There is a lot of confusion about the requirements for Meaningful Use. The program has been around for 5 years and has seen many changes. We talk to potential clients and have recently heard the following quote many times: I heard the Security Risk Analysis is no longer a requirement for Meaningful Use I heard […]
OCR squeezed between OIG and funding restraints
The Department of Health and Human Services Office of Inspector General (“OIG”) has issued a report that is critical of the Office for Civil Rights (“OCR”). OIG concluded that OCR is not fulfilling its responsibility to enforce HIPAA regulations that safeguard protected health information (PHI) and to ensure that organizations protect patient’s privacy. Here are some […]
Excellus Blue Cross Blue Shield Breach Yet Another Sign To Step Up Health-Care Security Investment
Publication: CRN The challenge, Gross said, is that many health-care organizations are still taking the “it can’t happen to me” attitude toward security. On a smaller scale relative to many of the health-care breaches so far this year, Gross said that he hopes the Excellus incident will alert smaller insurance and medical companies that hackers […]
$750,000 HIPAA fine offers valuable lessons
On September 2, 2015 The HHS Office of Civil Rights (OCR) issued a press release announcing a $750,000 HIPAA settlement with Cancer Care Group, P.C. This large fine offers some very important lessons. Let’s take a closer look: Cancer Care Group is a mid-size practice. They have 18 physicians. It is important to note the […]
It’s Not Just Large Data Breaches That Matter
We are all well aware of the epidemic of large data breaches that have been occurring recently. Anthem, Blue Cross, UCLA, the list goes on and on. Over 143 million records breached to date – an astounding figure! Since 2009, when the Office of Civil Rights “Wall of Shame” came into existence, there have been […]
Wall of Shame now at 143 million breached individuals
Hacking and breaches of healthcare data continue to happen. The scale of the breaches are increasing as well. According to an article over at Data Breach Today, 143 million individuals have had their healthcare related information breached. 70% of the 143 million breached records have occurred just in 2015. Healthcare organizations are not making security […]
Six Potential HIPAA Threats for PHOs and Super Groups
Publication: Physicans Practice But just like a negative restaurant review on Yelp can hurt customer patronage and the restaurant’s reputation, one practice that commits a HIPAA violation can affect the entire group, and result in an expensive fine, cause distrust among patients, and in extreme cases, the data breach can lead to medical identity theft.
Recorded Webinar: How to Avoid HIPAA-Related Breaches
Art Gross, President and CEO of HIPAA Secure Now!, participated in an American Osteopathic Association (AOA) webinar on 2015 HIPAA Audits and How to Avoid HIPAA Related Breaches. The recorded webinar is below.
AOA Webinar: Protect Your Practice: How to Avoid HIPAA-Related Breaches
Publication: American Osteopathic Association Join Art Gross, president and CEO at HIPAA Secure Now!, to learn how to prepare for the recent Office of Civil Rights (OCR) HIPAA audits. Understand the need for a Security Risk Assessment, HIPAA Security and Privacy Policies, and Employee Training.
Patients Demand the Best Care … for Their Data
Publication: EMR & HIPAA Prep for natural disasters, teach staff to spot threats, and review activity in your electronic medical record system, DOs and security experts say.
The Security Risks of Medical Devices
There are a large number of potential attack vectors on any network. Medical devices on a healthcare network is certainly one of them. While medical devices represent a potential threat, it is important to keep in mind that the threat level posed by any given medical device should be determined by a Security Risk Assessment […]
Audits are only one way of coming under the HIPAA microscope
Now that the 2015 HIPAA Audits have begun, organizations are reevaluating their HIPAA compliance posture. This is a good thing being that an organization will have very little time to respond to pre-audit and audit inquiries from the Office of Civil Rights (OCR). On the other hand, some organizations are evaluating the risk of being […]
Ounce of prevention: 5 steps to boosting your practice’s data security
Publication: The DO Prep for natural disasters, teach staff to spot threats, and review activity in your electronic medical record system, DOs and security experts say.
HIPAA Secure Now! Appoints Jonathan Krasner to Head Business Development, Grow MSP Partner Base, Help Partners Succeed
Krasner brings 25 years of IT and seven years of Healthcare IT, HIPAA and Meaningful Use experience to HIPAA Secure Now! Morristown, NJ (PRWEB) June 04, 2015
HIPAA Secure Now! Appoints Jonathan Krasner to Head Business Development, Grow MSP Partner Base, Help Partners Succeed
Krasner brings 25 years of IT and seven years of Healthcare IT, HIPAA and Meaningful Use experience to HIPAA Secure Now! Morristown, NJ (PRWEB) June 04, 2015 HIPAA Secure Now!, a HIPAA compliance service provider, has named Jonathan Krasner to the position of Director of Business Development. Krasner was hired to expand the company’s MSP […]
Horizon-scanning around HIPAA, HITECH
Publication: Health Management Technology How far will they protect healthcare data from insiders, outsiders?
Safety first: How to perform a security risk assessment
Publication: The DO The patient information in your practice is one of your most valuable assets, so protecting it is a smart business move.
Top Day 1 Quotes From ASCII Chicago
Publication: Business Solutions Magazine A crowd of nearly 100 channel executives enjoyed Day 1 of Wednesday’s ASCII Success Summit at the Hyatt Regency O’Hare in Chicago. I wanted to share with you some the best quips and quotes from the day.
Health care in the time of data breaches: 3 things to know
Publication: Business Solutions Magazine A HIPAA expert outlines what physicians need to understand about preparation, fines and retaining patients.
2015 HIPAA Audits – A Step Closer
There has been a lot of talk about the next round of HIPAA Audits. While the rollout of the audits have been delayed a few times, it now looks like they are about to start. The clear sign is that a the pre-audit survey has been approved by the Office of Management and Budget (OMB). […]
Starbucks data breach shows the real damage of a breach
Starbucks has a big problem. Don’t worry, they will still sell you their $5 cup of coffee. The problem they are dealing with is the repercussions of a data breach. The breach is connected with Starbucks’ mobile app. The Starbucks’ mobile app makes it incredible easy to buy a cup of coffee. Customers love the […]
The Hidden Epidemic of Medical Identity Theft Now Claiming Millions of Victims
Publication: Business Solutions Magazine NEW YORK (MainStreet) — Credit card related data breaches get all the headlines – but there is a bigger, more worrisome threat to your safety and privacy, multiple experts insisted to Mainstreet, and they pointed to medical identity theft.
HIPAA lacks guidance on BYOD policies
If you look around you will see the overwhelming amount of mobile devices that are in use today including laptops, smartphones and tablets. Many organizations allow employees to use their own smartphones or laptops to access the organization’s email, network and data. Clients are starting to understand the risk of these devices and many have asked […]
How to Teach Your Employees to Recognize Hacker Scams
Publication: American Express OPEN forum Cyber criminals are on the prowl for business data. Every company, no matter the size, has valuable data that’s as enticing as cracking a safe–but with far less risk, because cyber attackers are virtually untraceable. Here’s how your employees can learn to recognize hacker scams.
HIPAA Security Tips and Reminders – How to Create a Strong Password
Security firm Sophos has a good video on how to create a strong password.
ONC releases guide to Privacy and Security of Electronic Health Information
The Office of the National Coordinator for Health Information Technology has just released a valuable resource called: Guide to Privacy and Security of Electronic Health Information Here is a look at the information included in the guide: [framed_box bgColor=”#ffd390″] Understand a HIPAA / Meaningful Use Risk Assessment Organizations need to perform a Risk Assessment […]
OIG increases the pressure of Meaningful Use audits
The U.S. Health and Human Services Department’s Office of Inspector General (OIG) will begin auditing individual providers to determine if they met Meaningful Use requirements. Currently the Centers for Medicare & Medicaid Service (CMS) is auditing providers through contractor Figliozzi & Co. The CMS audits look to see if providers met the Meaningful Use measures […]
HIPAA Secure Now! Helps Covered Entities Comply with HIPAA Privacy Rule
HIPAA Secure Now’s New Privacy Tools Augment the Company’s HIPAA Security Compliance Services Morristown, NJ (PRWEB) April 08, 2015
I Won I Won the Audit!
Today started like every other day until I opened an email from a client. Below is a excerpt of the email: I Won I Won I Won I won the audit. Many thanks to you. I have been giving out your website and phone # to everyone I know. I cannot thank you enough. We […]
Infographic: HIPAA, We Have a Problem
Interesting Infographic on healthcare professionals’ knowledge of HIPAA regulations from NueMD [framed_box bgColor=”#ffd390″] Free HIPAA Security Training! All Covered Entities and Business Associates need to train their employees on HIPAA security. We now offer free online HIPAA security training for Covered Entities and Business Associates. Find out more about our free training and send […]
CIO: Health records are the new credit cards
An article over at CIO compares health records to credit cards and unfortunately they come to a gloomy conclusion: Health records are worth more and easier to get The value of health records “Cyber criminals are now going after health care records because they hold up to ten times more value on the black market […]
HIPAA Security Tips and Reminders – Protecting Portable Devices
Security Tips: Protecting Portable Devices Click on above to view in fullscreen mode!
Top 10 ridiculous overheard HIPAA statements
After performing over 1,000 HIPAA Security Risk Assessments, you can imagine that we have heard some ridiculous statements concerning HIPAA. There is a LOT of misinformation about HIPAA. Here are the Top 10 ridiculous overheard HIPAA statements: 10) My IT company won’t sign the Business Associate Agreement because they said it is not valid unless […]
Even Dear Abby knows about HIPAA
The column Dear Abby gives advice to a wife who illegally accessed her husband’s medical records. Read the whole article here. DEAR CONCERNED: Unless you claim to be clairvoyant, I don’t see how you can discuss this without admitting you accessed his medical records, which is against the law. Be prepared for him to be […]
Health Informatics and HIPAA
The following is a guest post by James Hinton In 1854 John Snow had a moment. At the time it hadn’t seemed like that significant an event, but Dr. Snow’s use of collected data and maps to pinpoint the source of a cholera outbreak in London started something. Though it started small, Big Data and Geographic […]
The problem with patient portals
Publication: Medical Practice Insider Patient portals seem like the logical next step for a healthcare system that’s becoming increasingly more reliant on electronic health records and other various digital constructs.
Are you a sitting duck for data breaches?
The below infographic gives some frightening facts about healthcare related breaches. Click on the image to see the whole infographic Source: Datamotion [framed_box bgColor=”#ffd390″] Free HIPAA Security Training! All Covered Entities and Business Associates need to train their employees on HIPAA security. We now offer free online HIPAA security training for Covered Entities and […]
OCR 2016 budget includes increase for HIPAA audits
The total budget request (PDF) for the Department of Health & Human Services (HHS) is $83 billion. This includes $43 million for the Office for Civil Rights (OCR) which is a $4 million increase over the 2015 budget. The increase will help support the permanent HIPAA audit process. OCR conducted a pilot program to ensure […]
MSP Differentiates His Business With HIPAA, SMB Security, Expands Partner Program
Publication: Business Solutions Magazine “Security is the place to focus on now and in the future,” advises Art Gross, president and CEO of HIPAA Secure Now! “It’s not going away.”
Why is healthcare data so valuable?
Security experts have been predicting that large healthcare related data breaches will continue into 2015. With the Anthem Inc., breach of 80 million records this prediction is now a reality. An article over at Forbes explores why healthcare data is so valuable. Here are some of the reasons: Quantity of information—Think of the 15 pages […]
CMS to shorten the MU EHR reporting period in 2015 to 90 days
On a blog post over at the CMS website, it has been announced that CMS will shorten the Meaningful Use 2015 reporting period to 90 day. Currently the 2015 reporting period is 365 days. Today, we at the Centers for Medicare & Medicaid Services (CMS) are pleased to announce our intent to engage in rulemaking […]
Tips for avoiding HIPAA fines in 2015
An article over at Physicians Practice gives some useful tips to avoid HIPAA fines. 1) Conduct or update your security risk assessment required by the security rules – A security risk assessment is the core of the HIPAA security rule 2) Implement the administrative, technical, and physical safeguards required by the HIPAA security rule – […]
HIPAA Security Tips and Reminders – Privacy Screens
Security Tips: Privacy Screens Click on above to view in fullscreen mode!
The business of selling patient records
Publication: Dermatology Times Criminals are after your patients’ medical records, plain and simple. The number of criminal cyberattacks reported by healthcare organizations jumped to 40% in 2013 from 20% in 2009, according to an annual survey by the Ponemon Institute. Whether it’s an ex-employee with a grudge, a crime ring defrauding the government, or a […]
10 quotes that defined the medical practice realm in 2014
Publication: Medical Practice Insider Small and midsize physician practices confronted challenges seemingly from every direction during 2014. Doctors and industry observers voiced their views on the realities of contemporary practice in these memorable quotes from Medical Practice Insider’s coverage of the year just concluded.
2015 HIPAA Audits
With the start of a new year, many organizations take a second look at their business and make necessary changes. 2015 is looking like a challenging year in terms of data security. The New Year brings back the Office of Civil Rights (OCR) HIPAA audits. Both HIPAA Covered Entities (CEs) and Business Associates (BAs) will […]
Nurse steals patients’ credit cards for personal use
According to the Herald-Tribune, a registered nurse working in the Lakewood Ranch Medical Center’s emergency room was fired and arrest for using patients’ credit card information. While investigating separate fraudulent credit card cases, detectives determined the victims’ information had been stolen while receiving treatment at the Lakewood Ranch Medical Center’s emergency room, according to the […]
HIPAA Secure Now! is the ASCII 2014 Esteemed Noble Partner #10
HIPAA Secure Now! is the ASCII 2014 Esteemed Noble Partner #10. We are honored to be included with industry heavyweights Datto, HP, AVG, StorageCraft, Lenovo, and GFI Max/Maxfocus! Click to watch the video on Vimeo
What happens if your business associate has a patient data breach?
This article written by HIPAA Secure Now! President and CEO, Art Gross, was published over at Dermatology Times. What happens if your business associate has a patient data breach? Here’s a cautionary tale: A medical practice comes to us in a panic. It turns out the physician had received a letter from the Office of […]
What happens if your business associate has a patient data breach?
Publication: Dermatology Times Here’s a cautionary tale: A medical practice comes to us in a panic. It turns out the physician had received a letter from the Office of Civil Rights (OCR) ordering an investigation related to a patient data breach – not his own.
Promoting Data Security in the Workplace (Infographic)
Source: University of Alabama at Birmingham’s Online Business Program
Hey Small Business: You ARE a cyber-target!
The security firm, FireEye, has a very eye opening report titled “Big Threats for Small Businesses Five Reasons Your Small or Midsize Business is a Prime Target for Cybercriminals” The report addresses a common misconception that small businesses have: I’m too small to be a target “The ‘I’m too small to be a target’ argument […]
How to avoid a HIPAA related breach
HIPAA Secure Now! President and CEO, Art Gross, offers some tips to avoid HIPAA related breaches in an article over at Dermatology Times Back in 2013 Adult & Pediatric Dermatology of Concord, Massachusetts, was hit with a $150,000 HIPAA fine for an unencrypted thumb drive that stored more than 2,200 patient records and was stolen […]
The ASCII Group Names HIPAA Secure Now! Esteemed Noble Partner at ASCII Success Summit 2014
Members of ASCII Group, longstanding IT channel organization voted HIPAA Secure Now! for award, signifying company’s commitment to peers and helping them grow their businesses. Morristown, NJ (PRWEB) November 17, 2014 HIPAA Secure Now! was voted one of the top 10 Esteemed Noble Partners by members of the ASCII Group, a membership-based community of independent […]
The ASCII Group Names HIPAA Secure Now! Esteemed Noble Partner at ASCII Success Summit 2014
Members of ASCII Group, longstanding IT channel organization, voted HIPAA Secure Now! for award, signifying company’s commitment to peers and helping them grow their businesses. Morristown, NJ (PRWEB) November 17, 2014
Hackers love small businesses – Infographic
A infographic by the National Cyber Security Alliance (NCSA) reported that 71 percent of security breaches target small businesses, and nearly half of all small businesses have been victims of cyberattacks.
How to avoid the HHS ‘Wall of Shame’
Publication: Dermatology Times Back in 2013 Adult & Pediatric Dermatology of Concord, Massachusetts, was hit with a $150,000 HIPAA fine for an unencrypted thumb drive that stored more than 2,200 patient records and was stolen from a staff member’s car. Not only did the dermatology group owe the hefty sum, it joined the ranks of […]
Cost to a HIPAA breach victim is $19,000
We talk about the cost of HIPAA related breaches for organizations but have you ever wondered how much it costs a victim of a HIPAA related breach? According to Becker’s Hospital Review, the average cost of a HIPAA related breach to an individual is about $19,000. According to a report by the Ponemon Institute, the […]
Not encrypting PHI is negligent
With over 30 million patient records breached since 2009 (and that only includes the breaches that have been reported. The actual number is probably much higher) there is a real crisis with protecting patient information. We keep hearing about healthcare organizations having breaches due to lost or stolen laptops and portable media (USB drives, CD/DVDs, […]
Weak 2014 Meaningful Use Attestation Numbers
According to FireceEMR, as of Nov 1, 2014 only 43,898 eligible professionals (EPs) have attested from Meaningful Use (MU). There are over 500,000 active registrants signed up to participate in the MU program. Furthermore, only 11,478 EPs have attested for MU Stage 2 as of Nov 1, 2014. The number of providers attesting to Meaningful […]
How Hackers Attack: Inside a Business Data Breach
Good video on how hackers gain access to valuable data. Steps on how to protect your organization are discussed as well. Share with employees and colleagues [divider] [framed_box bgColor=”#ffd390″] Free HIPAA Security Training! All Covered Entities and Business Associates need to train their employees on HIPAA security. We now offer free online HIPAA security training […]
CMS changes timing for Meaningful Use Security Risk Assessment
The Centers for Medicare & Medicaid Services (CMS) has made a change to the timing of a Meaningful Use (MU) Security Risk Assessment. Previously, providers were required to perform a Security Risk Assessment either before or during the MU reporting period. The change gives more flexibility to providers on when they can perform the Security […]
There’s a blind spot in every meaningful use attestation
Publication: Dermatology Times The Centers for Medicare and Medicaid Services (CMS) pulls no punches when it warns healthcare providers that meaningful use audits are happening, at random, and consequences for failing the audit are costly. If a provider cannot produce documentation that fully supports its electronic health record (EHR) attestation, the CMS could recoup incentive […]
HIPAA Secure Now! Signs Agreement with the American Osteopathic Association (AOA), Provides Full Array of HIPAA Compliance Services to 100,000-Plus Members
HIPAA Secure Now! Signs Agreement with the American Osteopathic Association, Provides Full Array of HIPAA Compliance Services to 100,000-Plus Members (PRWEB) October 21, 2014 HIPAA Secure Now! has forged a partnership with the American Osteopathic Association (AOA) to help members become fully compliant with HIPAA rules for protecting electronic protected health information (ePHI). Members will […]
HIPAA Secure Now! Signs Agreement with the American Osteopathic Association, Provides Full Array of HIPAA Compliance Services to 100,000-Plus Members
HIPAA Secure Now! Offers HIPAA risk assessment and other compliance services to American Osteopathic Association. (PRWEB) October 21, 2014
Prevent business associates from putting your practice at risk
Publication: Medical Practice Insider So you’ve taken all the steps to align your practice with HIPAA mandates — you’ve conducted a risk assessment, you keep regular tabs on your encryption functionality and you’ve memorized your breach disaster plan by heart.You’re ready; the problem is, your business associates may not be.
InformationWeek: Inside A HIPAA Breach
The following article, written by Alison Diana, appeared over at InformationWeek on 10/7/2014. The article interviews one of HIPAA Secure Now’s clients that utilized our service after one of their Business Associates had a HIPAA related breach. The client asked to remain anonymous but wanted to share the information so other HIPAA Covered Entities and […]
Inside A HIPAA Breach
Publication: InformationWeek A Saturday night phone call gave no indication it heralded months of bureaucracy, finger pointing, expense — and the dismal realization that even the smallest healthcare provider is liable and harmed when a business associate suffers a HIPAA breach.
HIPAA Security Tips and Reminders – Securing Your iPhone
Security Tips: Securing Your iPhone
OCR Fines Are the Least of Your Worries in a HIPAA Related Breach
Publication: EMR & HIPAA Ask any medical professional about their biggest concern for protecting patient information and they will probably tell you about the threat of a random audit conducted by the Office of Civil Rights (OCR). OCR is tasked with enforcing HIPAA regulations and has the ability to hand out fines up to $1.5 […]
eWEEK: CHS Breach a Sign of Health Care’s Security Illness
An article over at eWEEK takes a look at the Community Health Systems’ (CHS) 4.5 million patient record breach. The message of the article is that the healthcare industry spends the least on protecting data and is the most susceptible to data breaches. Some highlights of the article include: The health care industry has given […]
This actual OCR audit letter should terrify everyone!
A prospective client asked for our help after receiving a HIPAA audit letter from the Office of Civil Rights (OCR). OCR sent the client the letter after one of the client’s business associates experienced a HIPAA related breach. I won’t give any additional information on the client, the business associate or details of the security […]
HIPAA Secure Now! Ramps up EHR Partner Program, Helps Healthcare Providers Achieve Meaningful Use under Revised CMS Deadlines
HIPAA Secure Now! Ramps up EHR Partner Program, Helps Healthcare Providers Achieve Meaningful Use under Revised CMS Deadlines Medical practices applying for Meaningful Use can now get a HIPAA security risk assessment through their EHR provider. The risk assessment is a key requirement for Meaningful Use, Stages 1 and 2. Morristown, NJ (PRWEB) August 21, […]
HIPAA Secure Now! Ramps up EHR Partner Program, Helps Healthcare Providers Achieve Meaningful Use under Revised CMS Deadlines
Morristown, NJw (PRWEB) August 21, 2014 HIPAA Secure Now! rolled out its EHR (electronic health records) partnership program, making it possible for EHR vendors to now offer their customers a HIPAA security risk assessment, a vital requirement for achieving meaningful use. HIPAA Secure Now! provides risk analysis services, policies, procedures and training to medical practices […]
Hacker’s advice: How to create stronger passwords
There is an insightful article over at WonderHowTo written by an IT security professional and forensic investigator. The article looks at ways to prevent hackers from accessing important information online. Specifically the article focuses on how to create strong passwords that will reduce the likeliness that your account will be hacked. All passwords can be […]
HIPAA and the Cloud: How to Securely Store and Share Patient Files with Dropbox
The following is a guest post by Asaf Cidon, CEO and co-founder of Sookasa Healthcare providers across the country are quickly learning how useful cloud-based file-sharing services like Dropbox, Box, and Google Drive can be. These services allow practitioners to store documents in the cloud, share them with other users, and automatically synchronize the latest […]
Legal Pitfalls of Electronic Patient Communication
This article originally appeared in the July/August 2014 issue of Physicians Practice. July 28, 2014 | Law & Malpractice, Mobile, Patient Relations, Risk Management By Shelly K. Schwartz Patients prefer it. Medicare’s meaningful use program requires it. And within a few years, health information technology analysts predict that electronic communication will be par for the […]
How to approach your next risk assessment
Publication: Medical Practice Insider Try as they may, small practices are having a hard time running HIPAA’s gamut between compliance and security.Of course, when the source material is so dense and with technical support hard to come by, who could blame them? Certainly not Art Gross.
OCR: shred, burn or pulverize PHI before disposing!
The Department of Health and Human Service (HHS) Office of Civil Rights (OCR) has a frequently asked questions document (PDF) on the disposal of protected health information (PHI). Below are some of the highlights of the guidance: What do the HIPAA Privacy and Security Rules require of covered entities when they dispose of protected health […]
Legal Pitfalls of Electronic Patient Communication
Publication: Physicians Practice Patients prefer it. Medicare’s meaningful use program requires it. And within a few years, health information technology analysts predict that electronic communication will be par for the course in delivering patient care. Indeed, mobile devices and Web-based technology have provided new platforms to market your practice, transmit medical records, consult with other […]
AMA advises members to perform a security risk assessment
Hot off the American Medical Association (AMA) Wire, a service that provides news and information to AMA members, is a reminder that the HIPAA audits will resume this year. The AMA Wire reminds members that the HIPAA audits will start as early as this summer If you haven’t conducted a privacy and security risk assessment […]
Good infographic on the need to implement secure communications to protect patient information
Good infographic on the need to implement secure communications to protect patient information Original infographic can be found at TheConnectedClinician.com [divider_line] [divider_line]
Beware of racketeers making big money on patient records
Publication: Cardiovascular Business Armed robbery and drug trafficking are no longer the only crimes of choice for gangs. Instead of a gun, their newest weapon of choice is a mobile phone with Internet access. Now more sophisticated gang members are targeting medical practices and using their smart phones to steal patient records.
Case study: Breach of PHI by a Business Associate
One of our medical practice clients contacted us regarding a breach of Protected Health Information (PHI) by their billing company. The client received a letter from the billing company’s attorney stating that 60 of the client’s patients had their information breached when the billing company’s file server was compromised. The PHI included treatment reports, name, […]
HIPAA Complaints Vex Healthcare Organizations
Publication: InformationWeek Since 2013, complaints to the Department of Health and Human Services have risen regarding Health Insurance Portability and Accountability Act violations.
Criminals Have Their Eyes on Your Patients’ Records
The post appeared on June 26, 2014 in EMR & HIPAA It’s one thing to have a laptop stolen with 8,000 patient records or for a disgruntled doctor to grab his patients’ records and start his own practice. It’s another when the Cosa Nostra steals that information, siphons money from the patient’s bank account and […]
Criminals Have Their Eyes on Your Patients’ Records
Publication: EMR & HIPAA It’s one thing to have a laptop stolen with 8,000 patient records or for a disgruntled doctor to grab his patients’ records and start his own practice. It’s another when the Cosa Nostra steals that information, siphons money from the patient’s bank account and turns it into a patient trafficking crime […]
Don’t comply with HIPAA!
Here is a quote from one of our IT partners: My client got physically upset at me when I brought up the topic of HIPAA. They didn’t want to discuss it and said it was just another government regulation and they just want to practice medicine. While I was shocked to hear someone actually say […]
Text messages are part of a patient’s medical record
Medical Economics has a very interesting and thought provoking article on sending patients text messages. The article is definitely worth reading in its entirety. Here are a few highlights: Any text message that involves the transmission of information that would be considered PHI, including information relating to the treatment of your patients, should be considered […]
HIPAA Secure Now! Offers Annual HIPAA Security Training Subscriptions for Employees of Covered Entities and Business Associates
HIPAA Secure Now!’s Training Program Ensures Employees Understand and Maintain HIPAA Compliance and Security Morristown, NJ (PRWEB) June 23, 2014
Another HIPAA breach caused by unencrypted flash drive
Another day, another HIPAA breach of 34,000 patient records on an unencrypted USB drive. The drive was stolen from an employee’s locker at Redwood Regional Medical Group imaging center. According to a report: The drive was stolen June 2 from an unlocked employee locker at the former Redwood Regional Medical Group imaging center at 121 […]
Interesting look at paper referrals and HIPAA violations
referralMD has a very interesting article and infographic on paper based referrals. They take a look at HIPAA violations as well. Courtesy of: referralMD
Dropbox links spreading malware
A phishing scam that uses Dropbox links to spread malware is being sent to unsuspecting users. The malware makes it seem like the user has received an electronic fax and provides a link to access the file. The file contains a screen saver that encrypts the user’s hard drive and all of its contents. The […]
Healthcare Organizations Prep For Increased Audits
Publication: InformationWeek As office manager of the Fertility Institute of Virginia, Pattie Carson needed to ensure the practice was compliant with laws related to mobile usage, emails, and security. But keeping up with changing laws while running the busy reproductive endocrinology practice was impractical, if not impossible.
A HIPAA violation that every organization should read about
Our job at HIPAA Secure Now! is to help our clients comply with HIPAA regulations. As part of that process we try to educate our clients and their employees on the importance of protecting patient privacy. We use examples of HIPAA violations to help clients understand some of the concepts of HIPAA such as; what […]
CMS 2014 MU Changes – Risk Assessment Impact
Centers for Medicare & Medicaid Services (CMS) has proposed extending the use of 2011 certified EHR technology (CEHRT) into 2014. Previously all eligible providers (EPs) were required to use 2014 CEHRT to attest for Meaningful Use in 2014. The table below explains what version and what Meaningful Use objectives EPs can use in 2014 […]
HIPAA – Looking Forward
We are at an inflection point regarding HIPAA enforcement. For years we have talked about HIPAA regulations including the HIPAA Security Rule, HITECH Act, small scale HIPAA audits and the HIPAA Omnibus Rule but true HIPAA enforcement has eluded us. Are we at a fork in the road where HIPAA enforcement and compliance with HIPAA […]
Is Meaningful Use Helping or Hurting EHR Adoption? [INFOGRAPHIC]
Very interesting Infographic from NueMD [divider_line] [divider_line]
6 things organizations are doing that are not HIPAA compliant
Here is a list of common HIPAA violations that we find while performing a HIPAA Risk Assessment: Using Dropbox to store PHI Everyone loves Dropbox! Dropbox is simple, easy to use and convenient. It makes backing up and sharing data very easy. Unfortunately Dropbox is NOT HIPAA compliant. So use Dropbox for personal use but […]
Physicians Find Security In The Cloud
Publication: InformationWeek Healthcare practices are increasingly partnering with trusted cloud service providers to provide enhanced data security along with improved efficiency of IT operations.
Fine of $1,689 per lost unencrypted record!
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) levied $1,975,220 in fines on two entities for HIPAA violations. Both entities had breaches related to lost laptops that were not encrypted to protect the patient information. Concentra Health Services (Concentra) was handed down a $1,725,220 for a stolen laptop that […]
Infographic – How to create the perfect password
Click on the image to see the full infographic
Good insight into new HHS Security Risk Assessment Tool
There is an article over at HealthIT Security that discusses the new Department of Health and Human Services – HHS security risk assessment tool. The article interviews Alisa Chestler a shareholder in the Washington, D.C. office of Baker Donelson. Alisa shares many of the same thoughts I had when I reviewed the tool for the […]
Colleagues In Cuffs: When Employees Steal Patient Records
Publication: InformationWeek The Queens County DA recently arrested two Jamaica Hospital employees for stealing patient data, a lucrative crime occurring at hospitals across the nation.
One Guy’s Opinion: MSPs and HIPAA Compliance
Publication: Recovery Zone It’s important for MSPs to understand what HIPAA compliance is, what they can do to be HIPAA compliant, and what might happen if they try to service clients in the medical field without being HIPAA compliant. Luckily, our friend Guy Baroan, expert MSP and owner of IT solutions provider Baroan Technologies, knows […]
Fear OCR like you do the IRS
Have you ever received a letter from the Internal Revenue Service (IRS)? The letter might be due to a discrepancy on your tax return, a notice of interest due or that your tax return is being audited. Remember the fear that overwhelms you just seeing the letter from the IRS. Even if you have done […]
ONC provides insight on protecting mobile devices
The Office of the National Coordinator for Health Information Technology (ONC) has updated their website with with very useful information on protecting patient information on mobile devices. Click on image below to access the ONC Mobile Device Security Page ONC has also published a Mobile Device Fact Sheet
Your clients aren’t worried about HIPAA
Publication: MAX IQ The hard reality is that a lot of organizations including HIPAA Covered Entities (physicians, dentists, chiropractors) and their Business Associates (IT, medical billing, transcriptionists, and lawyers) aren’t overly worried about complying with HIPAA.
HIPAA Secure Now Voted Best Vendor at ASCII IT SMB Success Summit in Austin, TX
Austin, TX — (SBWIRE) — 03/25/2014 — HIPAA Secure Now! (HSN) was voted best vendor at the ASCII IT SMB Success Summit held in Austin, TX. The ASCII event was well attended by Managed Service Providers (MSPs). HSN was represented by Art Gross HSN President and CEO and Patrick Felicetta HSN National Partner Relations. Gross […]
Step by step approach to HIPAA security
When it comes to complying with the HIPAA Security and Omnibus Rules, there is a lot of confusion as to what needs to be done. And if you look at the amount of work it can be overwhelming; security risk assessment, employee training, policies and procedures, business associates, breach notification, encryption, disaster recovery to name […]
The reality of Meaningful Use audits
If anyone doubts that Meaningful Use (MU) audits are occurring, I would like a chance to change their mind. Yesterday 2 potential new clients contacted us with similar stories. Both had received letters from the Centers for Medicare & Medicaid Services (CMS) letting them know that they have been audited for Meaningful Use. One client […]
HIPAA audits: 800 covered entities and 400 business associates
Susan McAndrew, OCR deputy director for health information privacy, said in an interview with Information Security Media Group that the Office of Civil Rights (OCR) will resume its HIPAA compliance audit program. The audit program should resume in the coming months. Hopefully in coming months you’ll see actual activity that will start up on the […]
OCR HIPAA audit program to start with pre-audit survey
We have been writing about the permanent HIPAA audit program that will be put in place in 2014. Details of the program are starting to be released. The full text can be access by going to: Agency Information Collection Activities; Proposed Collection; Public Comment Request Here are some of the highlights: Number of Organizations A […]
Photocopiers are a danger to patient information – must watch video!
Almost every business uses a multi-function copy machine that copies, scans, prints and possibly faxes information. What most people don’t realize is that many of these machines have hard drives that store all information that the machine has access to. Think of these machines as computers that store a digital record of every copy it […]
Admit it, you don’t know where to start with HIPAA security
Like many other people, you keep hearing about increased HIPAA enforcement and the increase in patient data breaches. And naturally you are starting to worry. But here is the problem, you are not sure what to do about HIPAA security or where to start. Privacy is much easier HIPAA privacy is much more intuitive. Only […]
Basic rule to determine cloud provider’s HIPAA compliance
The HIPAA Omnibus Rule made major changes to how Business Associates are regulated under HIPAA. How can I tell if my cloud vendor is HIPAA compliant? One of the most frequent questions that we get asked by clients: How can I tell if my cloud vendor is HIPAA compliant? A lot goes into being HIPAA […]
HIPAA Security Tips and Reminders – Social Networks
Security Tips: Social Networks Click on above to view in fullscreen mode!
More employees fired over posting a patient picture on Facebook
WZZM13 is reporting that several employees of Spectrum Health in Grand Rapids, MI have been fired over a picture of a patient posted on Facebook. A source tells WZZM 13 News that an off-duty employee was in the emergency room when he saw an attractive female. He took a picture of her back side and […]
Meaningful Use Risk Assessment for 2014
As we previously mentioned, we were busy in December, 2013 with practices rushing to get their Meaningful Use (MU) Risk Assessments completed by 12/31/2013. So here we are in 2014 and organizations need to be concerned about attesting for MU again. We are hoping to shed some more light onto MU Risk Assessments, ongoing MU […]
OCR gives more insight into 2014 plans
HealthITSecurity.com has a very good article called What the HIPAA Omnibus Rule meant for healthcare in 2013 They give a good overview of the HIPAA Omnibus Rule and its impact. What I found even more interesting is some of the comments by OCR regarding their plans for 2014. It gives clear insight into the permanent […]
Dermatology practice agrees to pay $150,000 HIPAA fine
This post is updated with an official company statement below Adult & Pediatric Dermatology of Concord, MA has agreed to pay a $150,000 HIPAA fine as a result of a HHS Office of Civil Rights (OCR) investigation. The 12 physician practice was investigated by OCR after they reported a loss of an unencrypted thumb drive […]
Tis the season of meaningful use risk assessments!
Usually you think of the last 2 weeks in December as a slow period in terms of work. Many people schedule vacations during these 2 weeks. But if you are performing Meaningful Use Risk Assessments it is anything but slow. As organizations rush to ensure their 2013 Meaningful Use Risk Assessment is completed, our HIPAA […]
Microsoft’s site helps with preventing weak passwords
Microsoft recently released a research website that will help prevent the use of weak passwords. Weak passwords can be easily guessed and can put sensitive information including patient information at risk. The new site is called Telepathwords According to Microsoft: How does Telepathwords work: Telepathwords tries to predict the next character of your passwords by […]
HIPAA Secure Now! Announces a Low Cost $399 HIPAA Security Service Aimed at Small Organizations
Morristown, NJ — (SBWIRE) — 12/10/2013 — HIPAA Secure Now! (HSN) announced today a low cost HIPAA security service aimed at organizations with 10 or fewer employees. The new service called the HIPAA Basic Service includes a thorough HIPAA / Meaningful Use risk assessment, HIPAA security training / compliance testing for all employees and 1 […]
OCR’s Clear Message: Protect Patient Information
U.S. Department of Health & Human Services’ (HHS) Office of Civil Rights (OCR) has produced a series of videos. The videos are targeted at both providers and patients. The message is clear, providers have the responsibility to protect patient information. Patients are educated on their rights and told to file a complaint if they feel […]
ONC’s 10 Myths of Security Risk Analysis
The Office of the National Coordinator for Health Information Technology (ONC) has published a list of the top 10 Myths of Security Risk Analysis. The complete list can be found here: http://www.healthit.gov/providers-professionals/top-10-myths-security-risk-analysis The first myth is one we get asked about all the time. 1.) The security risk analysis is optional for small providers. False. […]
HIPAA Security Tips and Reminders – Protecting Mobile Devices
ONC has launched a mobile device guidance page to help protect mobile devices. The page offers some good advice and tips to protect mobile devices including (go to the ONC page for more details on each): Use a password or other user authentication Install and enable encryption Install and activate remote wiping and/or remote disabling […]
3 things you can do for HIPAA compliance
Nobody thinks complying with the HIPAA Security and Omnibus Rules are easy. Both HIPAA regulations are hundreds of pages long, require a lot of understanding, planning, policies and technology to be in full compliance. It should be noted that there is a huge difference between not complying, trying to comply and being in full compliance […]
Google will sign a BAA but it will cost you
Microsoft used to be one of the only large cloud providers that was willing to sign a HIPAA Business Associate Agreement (BAA). That has changed now that Google has announced that they will sign a BAA for customers that use their Google Apps platform. Google Apps includes: Gmail, Google Calendar, Google Drive, and Google Apps […]
HIPAA Security Tips and Reminders – Protecting Your Laptop
Security Tips: Protecting your laptop Click on above to view in fullscreen mode!
OCR gives more insight into increased HIPAA enforcement
Leon Rodriguez, director of the U.S. Department of Health & Human Services’ (HHS) Office for Civil Rights (OCR), spoke this week at the HIMSS Privacy and Security Forum in Boston. Rodriquez gave some interesting insight into where HIPAA enforcement is going. The permanent audit program is scheduled to be in place the beginning of 2014. […]
Won’t make the Omnibus deadline? It is never too late to be compliant
September 23, 2013, the official date that HIPAA Omnibus regulations are enforced. One of the results of the new HIPAA Omnibus Rule is that it has raised awareness of HIPAA regulations. Existing covered entities (hospitals, physicians, dentists, chiropractors) and business associates (IT companies, medical billing, law firms, etc.) are scurrying around in efforts to be […]
The AMA releases toolkit to help organizations comply with HIPAA Omnibus Rule
The American Medical Association (AMA) released a toolkit that helps organizations understand and comply with the HIPAA Omnibus Rule changes. Below is the table of contents from the toolkit (click on image to access the PDF toolkit). The toolkit gives a very good overview of the HIPAA Omnibus Rule changes. In addition to the overview […]
HIPAA Compliance: Will you have a good story?
Here is a secret that compliance experts have known for a long time: It is very difficult to be 100% compliant with HIPAA regulations Of course, you have probably seen claims like these: Buy our product and we will make you HIPAA compliant Compliance in a box! Be HIPAA compliant in 30 days! Snake oil […]
960,000,000 Reasons to Encrypt Patient Information
Chicago based Advocate Medical Group announced that a burglary at their administrative office has resulted in a breach of 4 million patient records. Immediately after discovering that four computers were stolen, that same day, the Park Ridge Police Department was notified. AMG then launched an investigation and discovered that while the computers did not contain […]
Trendjacking the latest threat to patient information
Steve Thom wrote an interesting article called Trendjacking threats are a growing concern. Trendjacking is a refined phishing scam. Thom defines the term Trendjacking as: The term is “Trendjacking”, and it refers to spammers and malware authors using current trends to trick you into opening malicious email messages. Trendjacking scams are emails that come from […]
Your employees will cause your next HIPAA breach
When people think of HIPAA breaches a lot of times they think of hackers breaking into a network and stealing patient information. While that is a real concern, another cause of breaches should not be ignored. What is the other cause of breaches you should be concern with? Your employees. Employees cause HIPAA breaches. In […]
HIPAA Omnibus Rule Enforcement Countdown
HIPAA Omnibus Rule Enforcement Countdown [framed_box bgColor=”#d5d5d5″ textColor=”#BC1310″ rounded=”true”] HIPAA Omnibus Final Rule enforcement begins on September 23, 2013 [fergcorp_cdt_single date=”09/23/2013″] Eastern Standard Time [/framed_box] Are you ready? (Click on the links below for more information) Covered Entities Business Associates Now is the time to get ready for the HIPAA Omnibus Final Rule enforcement!
The threat of thumb drives to patient data
In the past you would need a truck to steal 10,000 patient’s charts. Now you can download a report out of an EHR and copy it to a thumb drive and stick it in your pocket. In an interesting article over at Business Insider called: The Biggest Threat To National Security Is The Thumb Drive, […]
We are a small practice do I need to worry about HIPAA security?
We had a discussion with a potential client today. We were explaining the requirements of the HIPAA Security Rule. The client stopped us and said: I am a small provider practice. I never heard of HIPAA security. Are you sure I need to do this? No one ever mentioned this to me. Not my lawyer, […]
HIPAA Secure Now! includes $100,000 financial protection from HIPAA breach and violation expenses
Morristown, NJ (SBWIRE) – July 23, 2013 –HIPAA Secure Now! announced today that the HIPAA Secure Now! annual HIPAA compliance subscription will include $100,000 of financial protection from HIPAA breach and violation expenses. The financial protection will be included in the HIPAA Secure Now! annual compliance subscription for 50 employees or less. The financial protection […]
ONC Privacy & Security Training Games
The Office of the National Coordinator for Health Information Technology (ONC) has some great resources to help healthcare organizations ensure privacy and security of health information. Privacy & Security Training Games ONC has a very good privacy and security training game. The game gives real life scenarios and has the player make privacy and security […]
Don’t think We are too small a fish to worry about the HIPAA net
Big HIPAA penalties and fines make great news headlines. Recently the managed care company WellPoint Inc. agreed to pay a $1.7 million fine to settle potential HIPAA violations. False sense of security Large fines make headlines and show that violating HIPAA regulations can be very expensive. Unfortunately it can have an opposite effect as well. […]
Another business associate breach affects 277,000 patients
We have previously written about the risk of business associates (BAs) to patient information here and here. Now we have another large data breach caused by a hospital’s business associate. An article over at the Star Telegram goes into the details. A contractor for Texas Health Harris Methodist Hospital Fort Worth failed to destroy hundreds […]
HIPAA dangers of mobile devices
Mobile devices including laptops, tablets and smartphones are a growing threat to patient information. We wrote about how many organizations fail to realize how much protected health information (PHI) is on mobile devices. Ponemon Study In a very insightful study called The Risk of Regulated Data on Mobile Devices & in the Cloud, the risks […]
HHS video explains the HIPAA Security Rule
HHS released a short video (under 2 minutes) in 2012 that briefly explains the HIPAA Security Rule. With the upcoming HIPAA Omnibus Rule enforcement and the expanded regulation to Business Associates, we thought we would post the video again. Note the push to implement encryption to protect patient records! HHS OCR – HIPAA Security Rule […]
Evidence mounts that illegally selling PHI is big business
Recently we wrote about gang members stealing patient information and filing false tax returns and we wrote about meth dealers stealing patient information to obtain the materials to manufacture methamphetamine. Once again a there is a case where a hospital employee is accused of stealing patient information and selling it in exchange for crack cocaine. […]
Stanford HIPAA breach shows value of destroying PHI
The one thing you can say is that there are no 3 strikes and you are out when it comes to HIPAA breaches. Stanford Hospital in Palo Alto, Calif. recently suffered its 5th HIPAA breach since 2009. The most recent breach involved a stolen unencrypted laptop that contained 13,000 patient records. What makes this even […]
HIPAA breach exposes woman’s secret adoption
We have written about various HIPAA breaches but this breach is much easier to identify with. An article over at The Tampa Bay Times explains how a patient’s secret was exposed by a relative that was snooping in an EHR. Not only did the relative access her family member’s records inappropriately but she breached her […]
Employees quit practice and steal EHR data
The news on patient information breaches gets stranger every day. In an article over at Pensacola News Journal (pnj.com), 2 ex-employees are being sued for stealing patient information. Sight and Sun Eyeworks Gulf Breeze are suing a former physician and office manager for stealing patient information and trying to switch patients to the new practice […]
First gang members, now meth dealers want your health records
Back in April we wrote about gang members who are getting their girlfriends hired at medical practices. The gang member’s girlfriends are stealing medical records and giving it to their boyfriends to file false tax returns. Detective Craig Catlin of the North Miami Beach Police Department Gang Unit goes so far as to call it an […]
Ensure your Business Associates know how to protect patient information
We wrote about the risks of Business Associates (BAs) to patient information. The reality is many Business Associates have no idea of the requirements of HIPAA or the real risks to patient information. And even though all Business Associates will be responsible for complying with the HIPAA Security and Omnibus rules come September that may […]
Free HIPAA Security Training!
Click below to watch a short video on our free HIPAA security training! Clients love our HIPAA security training! We keep hearing that their employees find the training to be valuable and some even say it is fun (or as fun as HIPAA security training can be). We keep working to make the training engaging […]
Your smartphone will cause your next data breach
You may have read the headline and said to yourself “How can my smartphone cause a data breach if I don’t have any patient information on it?” While it may be true that you do not access your EMR on your phone, you should still be concerned. Smartphones are amazing devices. They have the power […]
Do you know what is going on in your EHR?
One of the requirements of the HIPAA Security Rule is to audit access to Protected Health Information (PHI). Auditing is the recording of access to PHI. It usually includes: who accessed PHI, when was PHI accessed and what PHI was accessed? Many EHRs and all certified EHRs for Meaningful Use have the ability to audit […]
Guilty until proven innocent regarding HIPAA breaches
The HIPAA Omnibus Final Rule brings a significant change to the HIPAA/HITECH Breach Notification Rule. Prior to the HIPAA Omnibus Rule, organizations were required to perform a risk assessment to determine if there was likely harm to a patient resulting from a privacy breach. Determining if the breach resulted in harm was referred to as […]
The calm before the HIPAA enforcement storm
Pilot Program Last year the Department of Health and Human Services’ Office for Civil Rights (OCR), which enforces HIPAA, conducted 115 HIPAA compliance audits. The program is being looked at as a pilot project that will eventually be used to put in place a permanent audit program. According to a HealthcareInfoSecurity interview with OCR’s Susan […]
What sets us apart?
A potential client asked us on a conference call: What sets HIPAA Secure Now! apart from your competition? A lot of companies offer similar services. I thought about the question for a second before responding. The client was right. There are a lot of companies that offer similar services. I responded: What sets HIPAA Secure […]
A closer look at the $400,000 Idaho State University HIPAA fine
The HHS Office for Civil Rights (OCR) announced that it has fined Idaho State University (ISU) $400,000 for failing to protect patient information. The HHS Office for Civil Rights (OCR) opened an investigation after ISU notified HHS of the breach in which the ePHI of approximately 17,500 patients was unsecured for at least 10 months, […]
HIPAA Secure Now! and BUMI Partner to Provide a HIPAA Compliant Data Backup Service
Introduces New HIPAA Compliant Data Backup Service, HIPAA Secure Backup Powered by BUMI Morristown, NJ (PRWEB) May 21, 2013 HIPAA Secure Now! and BUMI (Backup My Info!) announced today a new HIPAA compliant data backup service called HIPAA Secure Backup Powered by BUMI. BUMI is the premium provider of managed online backup and recovery solutions […]
The risk of having patient information is similar to the risk of owning a car
Risk of owning a car If you take a step back and think of the risks of owning a car I think you would be shocked. Cars have associated risks that could significantly impact you and your family. Some of the risks include: The risk of being hurt or killed in a car accident The […]
5 Common Myths About HIPAA Compliance – Infographic
The below infographic provides good insight into common myths of HIPAA compliance for medical practices. Embedded from HIPPOmsg.com Thanks goes out to HIPPOmsg for putting the infographic together! [framed_box bgColor=”#ffd390″] We put together a free guide to help your compliance effort called: 5 simple and inexpensive tips to protect patient information [/framed_box]
Microsoft updates BAA to address HIPAA Omnibus Rule
Microsoft has announced that they have updated their Business Associate Agreement (BAA) for Microsoft Office 365. The new BAA addresses the requirements in the HIPAA Omnibus Rule that went into effect on March 26, 2013. Addressing HIPAA is embedded in the DNA of Microsoft’s cloud solutions, and Microsoft updated its BAA to help healthcare organizations […]
HIPAA Book of Evidence when OCR Audits Your Organization
There is a very good article over at HealthData Management called Want to Impress OCR During a HIPAA Audit? Write a Book The author discusses the benefits of creating a “Book of Evidence” that your organization is in HIPAA compliance if you were to get audited by the HHS Office of Civil Rights (OCR). Creating […]
Emergency operations plans under HIPAA – Boston metro lockdown scenario
The Harvard Business Review has an excellent article on how some Boston companies handled the Boston metro lockdown situation. The article points out that proper planning for emergencies is the best way to prepare in the event of a real emergency. The Cambridge-based company, HubSpot, had an emergency operations plan in place and executed the […]
Here is why you haven’t addressed HIPAA security yet
We know you know about HIPAA security. HIPAA breaches are in the news on a weekly basis. The new HIPAA Omnibus Rule has been finalized and there is a lot of buzz about it. So the question is why haven’t you gotten serious about HIPAA security? We think we know some of the reasons. […]
Farzad Mostashari, MD gives good insight into healthcare IT
Dr. Farzad Mostashari, the National Coordinator for Health Information Technology at the U.S. Department of Health and Human Services, participated in an excellent interview. He gave insight into: EHR technologies Where the Meaningful Use program is headed EHR interoperability The future of Regional Extension Centers It was a very good interview and I urge everyone to read […]
Additional insight into: Why Gang Members Want Your Identity
In a very interesting article titled Why Gang Members Want Your Identity Fox Business News reporter Kate Rogers examines a disturbing trend of stealing electronic patient records and using them to commit crimes. Gang members are stealing patient records and using them to file false tax returns. Detective Craig Catlin of the North Miami Beach […]
A valuable look into cybercrime and cyber / HIPAA insurance
Two recent articles shed some needed light on the risk of Cybercrime to small businesses including medical practices. Most Small Businesses Don’t Recover From Cybercrime The first article from the Wall Street Journal titled Most Small Businesses Don’t Recover From Cybercrime examines how many small businesses suffer from cyberattacks and the consequences of those attacks. […]
Information security director talks of increased HIPAA enforcement
An article over at Healthcare IT News titled Get set: New HIPAA has teeth gives insight into the increased HIPAA enforcement that is looming. Diana Manos interviewed Jorge Rey, an associate principal and the director of information security and compliance for Kaufman, Rossin for the article. Rey provides some insight into some of the changes […]
Microsoft Office 365 for Healthcare
We have put together some useful information on Microsoft’s HIPAA compliant cloud based Office 365 service. The Office 365 suite of products enables communication and collaboration while providing the required HIPAA security to protect patient information. Microsoft is the only leading cloud provider that will sign a HIPAA Business Associate Agreement. Our Microsoft Office 365 […]
Entegration’s move to Microsoft Office 365
This is a guest post from C. Patrick Felicetta. Patrick is the Entegration, Inc. Chief Operating Officer (COO). He gives some good insight into some of the advantages of Microsoft’s cloud based Office 365 service. For the past 13 years Entegration, Inc., a computer networking company, has specialized in meeting the IT needs of healthcare […]
Incredibly detailed analysis of a HIPAA security breach
I came across an article on HIStalk Practice that describes exactly what happens when a laptop containing patient information is stolen from an employee’s car. The stolen laptop cost the company around $300,000. An analysis and breakdown of the costs are provided in the article. A few things to note about the article: The article […]
A closer look at a real-life HIPAA breach notification
The Gloucester, MA Fire Department Ambulance Service experienced a HIPAA security breach when one of its billing company’s employees improperly accessed and disclosed patient account information. The employee was involved in a scheme to file false federal tax return. The Gloucester Fire Department Ambulance Service posted a substitute data breach notice on the Gloucester government […]
ONC video explains Health IT to patients
The Office of the National Coordinator for Health Information Technology (ONC) has released a very good video that explains the push towards Electronic Health Records (EHR). The video is aimed at patients so they understand Health IT and the push to upgrade technology. From the ONC website: Health Information Technology, or Health IT for short, […]
Most common BA question regarding HIPAA Omnibus
We have received a lot of questions from our clients regarding the changes to HIPAA from the HIPAA Omnibus Rule. The most common question to date has been around Business Associate Agreements (BAAs). The questions come from covered entities as well as business associates. The question is basically the same for a different perspective. We […]
More Phishing Scams – LinkedIn
My inbox had a lot of emails from LinkedIn today. I sent several requests to connect last night and I received notifications that these people accepted the invitation. But a few of the notifications were about people I didn’t even know. My first reaction was to click on the link to go to LinkedIn and […]
Make HIPAA easy
Make HIPAA easy When we started to build the HIPAA Secure Now! service, we had 2 goals. Those goals were to help clients with protecting patient information and to “make HIPAA easy”. We realize most organizations hate HIPAA. We thought if we could build a service with the following characteristics, clients may not love HIPAA […]
OCR Director talks about breaches and encryption
Office for Civil Rights Director Leon Rodriguez presented at the HIMSS13 conference Monday morning. His message was very clear. Organizations that make an effort to protect patient information by the use of encryption and organizations that respond and learn from breaches will be much better off. Organization’s “willful neglect” of the HIPAA regulations and failure […]
Make no mistake, HIPAA enforcement to increase!
The Federal government is not being shy or covert about the increase in HIPAA enforcement that is about to occur. Covered Entities (Physician Practices and Hospitals) as well as Business Associates (Contractors and Subcontractors of Covered Entities) should have no doubt that compliance with HIPAA is no longer an optional activity. There is no way […]
HIPAA Omnibus and Microsoft Office 365
As we mentioned here and here, the HIPAA Omnibus Rule has a significant impact on HIPAA Business Associates. There is some debate over exactly who is a Business Associate regarding Cloud Providers. One thing that seems clear is, if you are storing protected health information (PHI) unencrypted at a Cloud Provider, the Cloud Provider most […]
CEs responsibilities for BAs under the HIPAA Omnibus Rule
In a previous blog we discussed the new HIPAA Omnibus regulations as they related to Business Associates (BA). Let’s take a look at the HIPAA Omnibus regulations for Business Associates as they relate to Covered Entities (CE). Business Associates Agreements CEs have been required to have Business Associate Agreements (BAAs) with BAs for quite a […]
Business Associates under the HIPAA Omnibus
There is lots of buzz about the changes to Business Associates under the new HIPAA Omnibus Rule. Let’s take a look at some of the items that both Covered Entities (CE) and Business Associates (BA) should know about the new HIPAA changes. Who are Business Associates? The definition of Business Associates for the most part […]
Not encrypting laptops is negligent
If you work in a healthcare organization and you have a laptop it should be encrypted. We have heard many discussions about why a laptop does not need to be encrypted. Some of the reasons include; it doesn’t contain patient information or it never leaves the office or it never leaves our employee’s possession. Laptops […]
DHS advises disabling Java in Browsers
The Department of Homeland Security (DHS) is advising people to disable Java in their browsers (Internet Explorer, Chrome, Safari, etc.). According to a CBS News report: The recommendation came in an advisory issued late Thursday, following up on concerns raised by computer security experts. Experts believe hackers have found a flaw in Java’s coding that […]
2012 strangest data breaches
Gienna Shaw over at FierceHealthIT has an entertaining article on some to the strangest security breaches in 2012. Here are her “highlights” of 2012. 1.) EMR held ransom (We also discussed another EMR ransom case here) In the Lake County case, an unauthorized remote user posted a message on the practice’s server stating that its […]
HIPAA fine for breach under 500 patients
The HHS Office for Civil Rights (OCR) has fined the Hospice of North Idaho (HONI) $50,000 for a breach resulting from a stolen laptop. What makes this unique is it represents the first time an organization has been fined for a breach of less than 500 patients. We will take a look at the details […]
Lawyer warns against ignoring HIPAA
In an article over at Healthcare IT News, Philadelphia attorney Christopher Ezold gives some very good insight that organizations should not ignore HIPAA requirements. Ezold hits on many good points to drive this home: Ezold warns that while enforcement of PHI rules have been lax in the past, the Department of Health and Human Services […]
The most dangerous HIPAA action of the year
The most dangerous HIPAA action you can do is very simple: DO NOTHING You may be under a false sense of security because none of these events have happened to your organizations: You haven’t had a HIPAA breach You haven’t received a HIPAA fine You didn’t need to use a Security Incident Response Plan You […]
Washington Post slams healthcare security
The Washington Post published a report that is highly critical of the security of patient information in the healthcare industry. A year-long examination of cybersecurity by The Washington Post has found that health care is among the most vulnerable industries in the country, in part because it lags behind in addressing known problem Avi Rubin […]
Protecting those shiny new smartphones
This year more and more employees are going to get smartphones this holiday season. And more and more employees will be asking for access to email and data via those new smartphones. You may take the stance and say “no” to access via smartphones. But these employees might have access to email and data already […]
ONC’s mobile device privacy and security website
ONC has launched a mobile device guidance page to help protect mobile devices. The page offers some good advice and tips to protect mobile devices including (go to the ONC page for more details on each): Use a password or other user authentication Install and enable encryption Install and activate remote wiping and/or remote disabling […]
Having a Security Incident Response Plan can lower your HIPAA fine
Having a Security Incident Response Plan (SIRP) will allow an organization to respond to a security incident. We define the steps of a SIRP here. An article over at Government Health IT has a question and answers segment that Leon Rodriguez, director of the Office of Civil Rights (OCR) at the Department of Health and Human Services […]
Get ready for OCR to hand out larger HIPAA fines in 2013
Leon Rodriguez, director of the Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) recently conducted an interview with HealthcareInfoSecurity. Click on the link to listen to the full interview. Rodriguez gave some valuable insight into OCR’s plans for 2013 and beyond as well as guidance that organizations should follow to protect […]
Deeper look at preventing EMR hijacking
In our post New reality: EMRs held hostage we discuss the Australian medical center that had their EMR encrypted. The hackers then demanded $4,000 ransom to decrypt the EMR. Let’s take a look at how something like this can happen. The more you know about how hackers can get into your network the better you […]
HIPAA audits to continue into 2013
Dom Nicastro over at HCPro gives insight into the status of the OCR audit program for 2013. Top OCR officials have made it clear the audit program will continue next year, says Mac McMillan, FHIMSS, CISM, cofounder and CEO of CynergisTek, Inc., in Austin, Texas. There will be more audits going forward; HITECH requires them, […]
New reality: EMRs held hostage
Data security and protecting valuable information is the new Wild West. There is a constant battle between trying to protect data and criminals intent on stealing or hacking data. In a story that broke yesterday, Russian cyber criminals have hacked into a medical organization and held their patient information ransom. The Australian medical center, Miami […]
Beyond the HHS Wall of Shame
By now many people have heard of the HHS Wall of Shame. The Wall of Shame refers to the list of organizations that have had a breach affecting 500 or more individuals. The list includes the name of the organization, the date of the breach, the approximate number of individuals affected, the type of breach […]
Practices with 1-100 employees account for 60% of all data breaches
According to a report produced by the Health Information Trust Alliance (HITRUST), there has been little progress in reducing the amount of healthcare related data breaches. A close look at the HHS data reveals that since 2009 the industry has experienced 495 breaches involving 21 million records at an estimated cost of $4 billion. With […]
OIG wants proof before making meaningful use payments
The Office of Inspector General (OIG) is criticizing CMS’ oversight of the Meaningful Use incentive program. They worry that CMS might be paying organizations who do not qualify for Meaningful Use incentives. This study is an early assessment of CMS’s oversight of the Medicare electronic health record (EHR) incentive program, for which CMS estimates it […]
Hurricane Sandy tests organization’s HIPAA availability requirements
When people think of the HIPAA Security Rule many think about protecting the privacy / confidentiality of patient information. Privacy is a major part of HIPAA security but also ensuring the availability of patient information is equally important. Let’s take a look at the HIPAA Security General Rules: § 164.306 Security standards: General rules. (a) […]
Terrifying reasons to protect patient information
We write a lot about protecting patient information and HIPAA security. It is widely known that over 20 million patient records have been breached in the past few years. Have you ever thought about some of the consequences of breach medical information? We came across a very interesting blog article over at 403 Blogs. 403 […]
MLEMA Testimonial
Below is an awesome testimonial from David Grossman, M.D. at Main Line Emergency Medicine Associates (MLEMA) I am the Compliance officer, for Main Line Emergency Medicine Associates (MLEMA), We are an emergency medicine practice, conducting provider services for Main Line Health hospitals, in southeasternPennsylvania. In February, 2012, our practice decided to get Breach insurance and […]
Healthcare Providers Insurance Exchange (HPIX) and HIPAA Secure Now! Announce Partnership
We are very excited to announce that Healthcare Providers Insurance Exchange (HPIX) and HIPAA Secure Now! have created a partnership to provide HIPAA risk assessments to all of HPIX clients. HPIX will pay for the risk assessment and provide the service free to their clients. HPIX will utilize our HIPAA Secure Now! service to perform […]
A closer look at the Alaska HIPAA fine
The Alaska Department of Health and Social Services (DHSS) was handed a $1.7 million fine by the Office of Civil Rights (OCR). The fine is one of the largest imposed on an organization. A closer look reveals why the fine was so large. Healthcare Info Security gives an in-depth look at the fine. The Alaska […]
A look at the OCR Audit Protocol
OCR released the details of the HIPAA audit protocol. There aren’t a lot of surprises in their list of items they look for during an audit. The protocol looks like a summary of the HIPAA Privacy and Security Rules with the addition of the Breach Notification Rule. There are 77 items for HIPAA Security and […]
Medical practices stand little chance against cyber-criminals
We wrote about LinkedIn having 6 million passwords stolen. eHarmony has also been a victim of 1.5 million passwords being stolen. The clear message here is that if these large websites can be victims of cyber-criminals, much smaller organizations stand little chance in defending its information. Both LinkedIn and eHarmony are well funded companies that […]
LinkedIn passwords hacked
By now you may have heard about the 6 million passwords that were stolen from LinkedIn. The passwords were posted on a Russian online forum. The passwords were encrypted but through the use of password cracking programs many of the passwords have been cracked. An article over at IT security company Qualys goes into details […]
The danger of HIPAA self risk assessments
There are many tools available to organizations that help them perform the required HIPAA and Meaningful Use Risk Assessment. The problem with an organization doing their own Risk Assessment revolves around the saying What you put in is what you get out In order to get an accurate analysis of risks to patient information it […]
The HIPAA speed trap
You have been driving 45 mph on the same 25 mph road for years. There are never any police on the road and there is really no reason to drive 25 mph. Then after years of ignoring the posted speed limit, one day a police officer is waiting behind a tree and pulls you over […]
HIPAA “Need to know basis”
There is a good article over at the Vormetric Security Blog that looks at restricting employee access to patient information. They argue that not all employees need full access and unless an employee can demonstrate that access is needed to perform their job function, no access to patient data should be given. The below paragraph […]
ONC’s Risk Assessment Myths and Facts
The office of National Coordinator for Health Information Technology (ONC) has published a useful guide to Privacy and Security of Health Information (PDF). One of the sections looks at common myths and facts about a security risk analysis / assessment. Let’s take a look at it in more detail. Below are ONC’s myths and facts: Let’s look […]
A closer look at phishing scams
There are many threats to patient information and financial resources and one that seems to be popping up a lot lately is phishing scams. A phishing scam is basically an email that looks like a legitimate email from a bank, credit card company, retail stores, social networks (Facebook, Twitter, LinkedIn, etc.). The email usually has […]
More on Phoenix Cardiac Surgery’s $100,000 HIPAA Fine
We have written about the $100,000 HIPAA fine that was handed down to Phoenix Cardiac Surgery. There is a very good article at AISHealth that details the case and provides some good insight by industry professionals. One quote by well respected HIPAA attorney Jeff Drummond really sheds light on what happens when you ignore compliance […]
Make sure you encrypt your backup tapes
Many organizations are still using tapes to backup data. Those organizations that are still using backup tapes need to ensure that the tapes utilize encryption. Without encryption, a lost or stolen backup tape could result in a very large data breach. Best network practices call for performing a backup on all systems at least daily. […]
Changing landscape of healthcare IT
There should be no doubt that we are witnessing a changing landscape for healthcare IT. As the government gives billions of dollars in incentives to hospitals and medical practices to implement electronic health records the repercussions are being heard around the country. Medical practices are going from low-tech businesses that focused on paper charts and very little […]
Introducing our Small Business Package
We are excited to announce our new Small Business Package. The Small Business Package is for organizations with 10 or fewer employees. We have reduced the price of the complete HIPAA Secure Now! service from $1,750.00 to $999.00. The Small Business Package is exactly the same as our regular service and includes custom policies and […]
We are not another company selling HIPAA products
You’ve seen hundreds of companies selling HIPAA products. There are HIPAA training videos, policy templates, consultants, HIPAA books, HIPAA coffee mugs and the list goes on and on. And yet “become HIPAA compliant” is still on your long list of things to do. Have you asked yourself why you never seem to get to “become […]
How HIPAA Secure Now! would’ve helped Phoenix Cardiac Surgery
We have written about the HIPAA fine and reputation damage to Phoenix Cardiac Surgery. Phoenix Cardiac Surgery is a small 5 physician specialist in Phoenix, AZ. Let’s quickly review why the Office of Civil Rights fined Phoenix Cardiac Surgery $100,000. Lack of HIPAA Policies and Procedures Lack of HIPAA training for all workforce members Lack […]
OCR HIPAA fine and resolution agreement
The Phoenix Cardiac Surgery medical practice was handed a $100,000 fine for failing to protect patient information. The resulting resolution agreement from the Office of Civil Rights (OCR) is very interesting. Let’s take a look at is. The full resolution agreement can be found here (PDF). Lack of training for employees (a) From April 14, […]
Phoenix Cardiac Surgery – HIPAA violation
There has been a lot written recently about organizations that have received high profile HIPAA fines from the Office of Civil Rights (OCR). The Tennessee Blue Cross Blue Shield was handed a $1.5 million fine, Cignet Health was given a $4.3 million fine and Massachusetts General Hospital was awarded a $1 million fine. The only […]
The risk of business associates to patient data
In the Ponemon 2011 Cost of Data Breach Study, 41% of breaches were due to third party mistakes. Take a step back and think about the impact of that number. The use of third party organizations are more and more common. According to the HHS.gov website, some examples of third party / business associates include: […]
A look at the cost of healthcare data breaches
The annual Ponemon 2011 Cost of Data Breach Study has been released and it gives very good insight. The study looks at various costs of data breaches across industries such as media, retail, financial, healthcare and pharmaceutical. Let’s focus in on the costs of data breaches in the healthcare industry. Overall the average cost of […]
Encryption for data at rest
Part of the proposed requirements for Meaningful Use Stage 2 addresses encrypting data at rest. Let’s take a look at the exact wording conduct or review a security risk analysis in according with the requirements under 45 CFR 164.308(a)(1), including addressing the encryption/security of data at rest in accordance with requirements under 45 CFR 164.312(a)(2)(iv) […]
A practical look at a HIPAA Incident Response Plan
Many people ask us what is needed for an Incident Response Plan (IRP). It seems to be one of the HIPAA requirements that people have a hard time putting their arms around. So let’s take a practical look at what is needed. Incidents will happen The first thing that must be accepted and understood is […]
OCR video explaining the HIPAA Security Rule
The Office of Civil Rights (OCR) has released a series of videos to help practices and medical professionals understand the HIPAA regulations. Unfortunately as of today it is not a very well-known resource, each of the 4 videos has less than 75 views. Hopefully with more awareness of this resource, more people will watch the […]
OCR to offset budget cuts with fines it collects
In an interview with Howard Anderson over at healthcareinfosecurity.com, OCR’s Leon Rodriguez gives some interesting insight into OCR’s audit program. Some are some highlights of the interview: Due to funding cuts and capacity of KPMG, the firm hired to conduct the audits, the agency may come up short of the 150 planned audits OCR funding […]
Meaningful Use Stage 2 – IT impact
The proposed meaningful use stage 2 requirements were posted yesterday. The requirements are over 450 pages so we are still going through them and trying to digest them. As of now, two major IT related items jump out at us. The first IT related objective is focused on protecting and securing patient information. In stage […]
Meaningful Use Stage 2 and Encryption
As John Lynn and Neil Versel have both reported, it looks like the Meaningful Use (MU) Stage 2 proposal will be out in the next few weeks. One area of interest will be the wording around the use of encryption to protect patient information. Currently the HIPAA and HITECH regulations do not make the use […]
6 things you must know about HIPAA Security
There is a lot to know about HIPAA but let’s take a look at 6 things that you must know. HIPAA is not optional A lot of practices feel they are exempt from the HIPAA regulations. This may stem from the fact that “small practices” were granted a 1 year extension to comply with the […]
HIPAA audits have begun
Over at Healthcareinfosecurity.com there is an insightful article on the first HIPAA audits. Some highlights of the article include: In the pilot phase, OCR is auditing eight health plans, two claims clearinghouses plus 10 provider organizations, including three hospitals, three physicians’ offices, and a laboratory, a dental office, a nursing/custodial facility and a pharmacy. […]
The importance of HIPAA training and social networks
A recent incident shows just how important it is to train all workforce members on the HIPAA regulations. Notice how I used the words workforce members and not just employees. A temporary staff member of Providence Holy Cross Medical Center recently posted patient information on Facebook. The temporary staff member also made fun of […]
A look back and a glance forward
2011 has been a great year for us and we couldn’t be more excited for 2012. We had the opportunity to work with some really great people at a lot of different medical practices throughout the United States. We got to show that the HIPAA Secure Now! process really works and can help practices with […]
Taking a look at NIST HIPAA Security Rule Toolkit
The National Institute of Standards and Technology (NIST) has recently released a HIPAA Security Rule Toolkit to help organizations comply with the HIPAA Security Rule. From their website: The NIST HIPAA Security Toolkit Application is intended to help organizations better understand the requirements of the HIPAA Security Rule, implement those requirements, and assess those implementations […]
Guest blog | SPAM filiters
Kim Falkner from SPAMfighter is our guest blogger and gives her insight into hosted vs. in-house SPAM filters. It is a good topic because with SPAM comes risks to electronic protected health information (ePHI). Hosted spam filter? Better than in-house software? We do not have to delve on the fact that spam is an annoyance […]
You received a HIPAA audit notification, now what?
The Department of Health and Human Service (HHS) has announced that they will perform 150 HIPAA audits by the end of 2012. The chance of you getting audited is very small but what if you open up your mail one day and found a notice that your medical practice has been select to be audited? […]
150 HIPAA audits a preview of more to come
Leon Rodriquez the head of OCR, in an interview, stated that the 150 HIPAA audits is just a pilot program. OCR recently hired the consulting firm KPMG to launch a HIPAA compliance audit program, with 150 audits anticipated by the end of 2012. Because this is the first time the office is conducting audits, the […]
OCR’s Leon Rodriguez gives insight in HIPAA Audits
Howard Anderson, Executive Editor over at HealthcareInfoSecurity.com had an insightful interview with Leon Rodriguez, the new director of the Department of Health and Human Services’ Office for Civil Rights. Rodriquez a former prosecutor and defense lawyer talks about his priorities as the head of OCR. He states: Making enforcement a priority (because) enforcement promotes compliance […]
Practice Administrators are the key to HIPAA security
Every day we work with Practice Administrators (PAs) to help them with HIPAA compliance. It is amazing how much responsibility is placed on a PA’s plate. They are involved with hiring and firing of employees, billing, scheduling, personnel issues, insurance issues, patient issues, equipment issues, technology issues, provider issues and compliance issues. It is amazing […]
Don’t skip the meaningful use risk assessment
FierceEMR posted a story on how some providers are attesting to meaningful use measures but are actually not addressing all of the required measures. Specifically some providers are stating that they have performed a meaningful use risk assessment on how patient data is being protected but have not actually performed the risk assessment. The article […]
No doubt HIPAA enforcement is coming
It seems that every day it becomes more and more clear that the government is planning on enforcing HIPAA regulations. Patient data privacy and security is becoming their priority. This could have to do with the fact that almost 8 million patients have had their data breached over the past 2 years. And considering that […]
A look at the upcoming 150 HIPAA audits
The Department of Health and Human Services (HHS) announced that they have awarded a $9.2 million contract to the consulting firm KPMG. KPMG will develop the process and perform HIPAA audits. There will be an estimated 150 onsite audits by the end of 2012. The audits are a requirement under the HITECH act and have […]
7.9 million records breached and counting
According to a report to Congress from The Department of Health and Human Services (HHS), there have been almost 8 million records breached since 2009. That is a staggering number. What is worse it that the number of data breaches continues to increase. Another way of looking at it is that we are only in […]
HIPAA Security Tips and Reminders – Disasters
Security Tips: Disasters: Are You Prepared? Click on above to view in fullscreen mode!
How risk assessments lower the risk to patient data
One of the most important aspects of complying with the HIPAA Security Rule is to perform a risk assessment to evaluate how an organization is protecting patient data. The results of the risk assessment provide a playbook for how additional protections can lower the risk to patient information. Let’s take a closer look at the […]
Lesson from the KPMG data breach
In a very embarrassing and ironic turn of events, KPMG announced that they had a data breach that involved 4,500 patient records. KPMG has been selected by The Office of Civil Rights (OCR) to perform HIPAA compliance audits. So it appears that the company that will do HIPAA audits has experienced a HIPAA related data […]
Details of the HIPAA audits
Health Info Security has published the transcript from an interview with Susan McAndrew of the Department of Health and Human Services’ Office for Civil Rights. The article is very good and should be read in its entirety. Below are some of the key points. When asked if business associates as well as covered entities will […]
OCR’s McAndrew discusses upcoming HIPAA Audits
Susan McAndrew, deputy director of The HHS Office of Civil Rights (OCR) gives a very insightful interview to Howard Anderson, Executive Editor, HealthcareInfoSecurity.com. There are a lot of good points and I suggest reading the whole interview. I will point out a few of the highlights. When asked about who will be audited, McAndrew was […]
HHS to perform 150 HIPAA Audits by end of 2012
Last week the Department of Health and Human Services (HHS) announced that they have awarded a $9.2 million contract to the consulting firm KPMG. KPMG will develop the process and perform the HIPAA audits. There will be an estimated 150 onsite audits by the end of 2012. “Site visits conducted as part of every audit […]
Microsoft’s Office 365 Cloud Service to offer Business Associate Agreements
Microsoft’s latest cloud based service called Office 365 was recently released. More than 200,000 organizations participated in the beta testing period. Office 365 provides the following: Microsoft Office, Microsoft SharePoint Online, Microsoft Exchange Online and Microsoft Lync Online in an always-up-to-date cloud service, at a predictable monthly subscription. In addition, Microsoft is trying to target […]
Why people hate HIPAA
Working with clients over the years, we have come to the conclusion that most people hate HIPAA. There we said it! Fortunately we don’t take it personally because we actually understand why people hate HIPAA. Here are a few valid reasons. HIPAA is confusing HIPAA is boring HIPAA is expensive HIPAA gets in the way […]
HIPAA Secure Now! available to MedTech GPO
Entegration, Inc. Joins MedTech For Solutions Group Purchasing Organization as a New Vendor Morristown, NJ, June 04, 2011 –(PR.com)– Entegration, Inc. (Entegration) is pleased to announce that they have joined MedTech For Solutions Group Purchasing Organization (GPO) (MedTech) as a new vendor. This partnership will enable Entegration to provide Information Technology (IT) services to the […]
A closer look at a HIPAA Risk Assessment
In a previous post I discussed the risk of having patient information on smartphones. I ended the post with stating that a HIPAA Risk Assessment can help reveal where security measures are needed. Let’s look at that a little more in depth. Many people are confused as to what a HIPAA Risk Assessment is. Here […]
Choosing security products is difficult
The problem with HIPAA compliance and security in general is that there are so many products and services on the market, how does one decide which are the right ones? Let’s not discuss a HIPAA security service (although we hope you choose HIPAA Secure Now!) but let’s look at after you have taken the first […]
Beware of patient information on smartphones
I had a conversation with a group of physicians a couple weeks ago that shed some interesting light on where patient information resides and how to protect it. Each of the 5 physicians had a smartphone of various manufacturers. Two had iPhones, two had Android phones and one had a Blackberry phone. I asked the […]
When real life disasters happen
Joplin, MO was hit by a massive tornado on Sunday evening that did extensive damage to the St. John’s Regional Medical Center hospital. There are reports that x-rays from the hospital have been found in driveways 70 miles east of the hospital. On Twitter Steven Waldren sheds some very interesting and insightful perspectives: Steven’s quotes gets to […]
Why are HIPAA regulations ignored but IRS regulations aren’t?
The IRS audits about 1.5% of all tax returns that are filed. Looked at another way, there is a 98.5% chance that the IRS will not audit your return. Yet even with this very low percentage of people that get audited, most people are very frightened that they will be one of the unlucky individuals. […]
Why you need to invest in HIPAA Security
To be successfully in any business you need a few basic elements. Two of the elements include; customers that value your service and are willing to purchase your services. Secondly, you also need to eliminate or reduce liabilities that can damage or hurt your business. Implementing HIPAA security can help your business The first element […]
Insightful letter from OCR following a data breach
There is a great post over at Infosec Island regarding a letter that was received from the Office of Civil Rights (OCR) after a data breach that occurred at a small medical practice. The breach was the result of a burglary. No details were given on what was stolen or what kind of patient information […]
Encryption is too easy and cheap to not use it
It seems that at least twice a month we are hearing about a health care organization that has had a data breach because of a lost of stolen laptop. Every time I read about a new breach I shake my head and ask myself why aren’t these organizations using encryption to protect the contents on […]
5 easy steps to protecting patient data
Medical practices are not only tasked with protecting their patient’s health but now are responsible for protecting their patient’s electronic information as well. Protecting data is probably something that most practice employees have not been trained to do nor are they familiar with best security practices. Data security is usually left to IT consultants who […]
Dropbox is not HIPAA compliant
An article over at KevinMD.com on using Dropbox to store transcriptions has set off a lot of conversation on Twitter asking if Dropbox is HIPAA compliant. Let’s look at what the article references: www.dropbox.com Download the Dropbox software (free) and save files to your Dropbox in the cloud. Access Dropbox files from any computer with a web […]
Fear and destroy USB drives!
In what appears to be a reoccurring story, another hospital is notifying over 90,000 patients that their personal information has been breached. MidState Medical Center in Meriden, Conn., has notified around 93,000 patients that their information was stored on a USB drive and the drive is now lost. Information on the drive included names, addresses, […]
What does it take to be compliant with the HIPAA Security Rule?
One of the questions that I get asked a lot is; What does it take to be compliant with the HIPAA Security Rule? And when I start to answer the question, inevitably the person’s eyes glaze over. So to prevent your eyes from glazing over I will give the simple answer: A lot. OK, that […]
Looking for guest bloggers and partners!
Let’s work together! At HIPAA Secure Now! our main focus is on helping healthcare organizations become compliant with the HIPAA Security Rule and HITECH act. We realize that we are only a piece of the puzzle. We can help with policies and procedures, a risk assessment and training but there is a lot more to […]
HHS should embrace social media for HIPAA education
As we work with more and more clients to help them comply with the HIPAA Security Rule, it is becoming clear that many people don’t fully understand HIPAA. The good news is that we can help them understand HIPAA and all the things that need to be done to comply with HIPAA and to protect […]
Recruit employees to protect patient data
The Health and Human Services’ Office of Civil Rights (OCR) has handed out over $5 million in HIPAA fines in the past 2 weeks. OCR has also stated that more HIPAA enforcement is coming. So now is a very good time to think about how you can avoid regulatory penalties and even more importantly, how […]
Analysis of OCR’s message on HIPAA
OCR is serious about enforcement! That is a message that 3 officials from the U.S. Department of Health and Human Services’ Office for Civil Rights made clear as they presented at the 19th National HIPAA Summit. The 3 officials who presented (links below take you to their presentations [PDF] ) were: Susan McAndrew – Deputy Director for […]
OCR shows its serious about HIPAA enforcement
The Office for Civil Rights (OCR) showed once again that is serious about enforcing the HIPAA security and privacy regulations. OCR invited the 50 state attorneys general (AG) to 2 day in-person meetings to prepare them to better enforce the HIPAA regulations. The HITECH Act gave state attorneys general the authority to bring civil actions […]
Using patient record security as a competitive advantage
The following blog was written a year ago but the content is still relevant today. What if organizations looked at HIPAA security as a competitive advantage and not just something that is mandatory and required by the government? In two recent surveys a clear message is being sent. The message is that patients want doctors […]
Deeper look at the $4.3 million HIPAA fine
The Health and Human Services’ (HHS) Office of Civil Rights (OCR) issued a $4.3 million fine to Cignet Health of Prince George’s County, MD (Cignet) for violating the Privacy Rule of HIPAA. Cignet refused to provide 41 patients with access to their medical records. Under HIPAA, patients are entitled to have access to their medical […]
Huge security breach fines coming in 2011
According the Health Data Management magazine, The HHS Office for Civil Rights plans big changes to privacy and security regulations. Below are some sections from their article. Adam Greene, senior health IT and privacy advisor in the OCR, outlined a slew of changes to existing regulations. The final HITECH privacy, security and breach notification rules […]
Employee training might produce the best security ROI
There are countless security products on the market today. You can buy products from hardware firewalls, to anti-virus / anti-malware, to web content management, to email encryption, to log management platforms, the list goes on and on. All of these products have a place and help in protecting data and electronic protected health information (ePHI). […]
Free HIPAA Security Tips and Reminders
One of the administrative requirements of the HIPAA Security Rule is to implement a security awareness and training program. And one of the implementation specifics is to implement security reminders. (5)(i) Standard: Security awareness and training. Implement a security awareness and training program for all members of its workforce (including management). (ii) Implementation specifications. Implement: […]
Why perform a Risk Assessment?
A Risk Assessment is required in order to comply with the HIPAA Security Rule. The Security Management Process standard in the Security Rule requires organizations to “[i]mplement policies and procedures to prevent, detect, contain, and correct security violations.” (45 C.F.R. § 164.308(a)(1).) Risk analysis is one of four required implementation specifications that provide instructions to […]
Introducing HIPAA Secure Now!
We are proud to announce the launch of the HIPAA Secure Now! service. HIPAA Secure Now! is the first comprehensive and affordable HIPAA Security Rule service. The service includes: 18 Policy and Procedures covering the administrative, physical and technical safeguards as required by the HIPAA Security Rule. A thorough Risk Assessment that looks at all […]
Recent Posts
Archives
- December 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- October 2019
- September 2019
- August 2019
- July 2019
- June 2019
- May 2019
- April 2019
- March 2019
- February 2019
- January 2019
- November 2018
- October 2018
- September 2018
- August 2018
- July 2018
- June 2018
- May 2018
- April 2018
- March 2018
- February 2018
- January 2018
- December 2017
- November 2017
- October 2017
- September 2017
- August 2017
- July 2017
- June 2017
- May 2017
- April 2017
- March 2017
- February 2017
- January 2017
- December 2016
- November 2016
- October 2016
- September 2016
- August 2016
- July 2016
- June 2016
- May 2016
- April 2016
- March 2016
- February 2016
- January 2016
- December 2015
- November 2015
- October 2015
- September 2015
- August 2015
- June 2015
- May 2015
- April 2015
- March 2015
- February 2015
- January 2015
- December 2014
- November 2014
- October 2014
- September 2014
- August 2014
- July 2014
- June 2014
- May 2014
- April 2014
- March 2014
- February 2014
- January 2014
- December 2013
- November 2013
- October 2013
- September 2013
- August 2013
- July 2013
- June 2013
- May 2013
- April 2013
- March 2013
- February 2013
- January 2013
- December 2012
- November 2012
- October 2012
- September 2012
- July 2012
- June 2012
- May 2012
- April 2012
- March 2012
- February 2012
- January 2012
- December 2011
- November 2011
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
Categories
- Backup & Disaster Recovery
- Business Associates
- Client News
- Download
- Healthcare Industry
- HIPAA
- HIPAA Audits
- HIPAA Violations
- HSN News
- Legal
- MACRA
- Policies and Procedures
- Press Release
- Remote Workforce
- Risk Assessment
- Scams
- Security
- Security Reminders
- Security Training
- Telehealth
- Uncategorized
- Webinar
- Website
Recent Comments