Elizabeth Simpson reports: Chesapeake Regional Healthcare is notifying 2,100 patients from the hospital’s sleep center program that some of their electronic health information might have been compromised. Two portable hard drives were reported missing from the hospital’s sleep center on Feb. 6, which prompted contacting law enforcement, according to a Friday news release from the…
Category: U.S.
Oregon Amends Data Breach Notification and Information Security Laws
David Stauss of Ballard Spahr writes: In March, we reported that the Oregon legislature was considering amending its data breach notification and information security laws. That legislation has now passed the Oregon legislature and been signed into law by Oregon’s governor. A copy of the new law is available here. The most notable changes are as follows: Amendments to Oregon’s Breach Notification…
South Dakota Enacts Breach Notification Law
Hunton & Williams write: As reported in BNA Privacy Law Watch, on March 21, 2018, South Dakota enacted the state’s first data breach notification law. The law will take effect on July 1, 2018, and includes several key provisions: Definitions of Personal Information and Protected Information. The law defines personal information as a person’s first name or…
Is OCR Moving the Goal Posts on Vendor Management?
Yesterday, I posted an item about a settlement between New Jersey and Virtua Medical Group after a 2016 data leak by their transcription vendor exposed approximately 1,600 patients’ information on the internet. New Jersey took the position that this was a HIPAA violation and that the entity was responsible for what its vendor had done…
Virtua Medical Group Agrees to Pay Nearly $418,000, Tighten Data Security to Settle Allegations of Privacy Lapses Concerning Medical Treatment Files of Patients
There’s a follow-up to a breach previously reported on this site in 2016 in which a transcription vendor’s error resulted in the exposure of some Virtua Medical Group’s patients’ protected health information on the internet. It appears that New Jersey has settled charges against VMG over the incident. Of note, the charges are that the VMG…
What to Know About the Latest Data Breach Hitting Sears and Delta Customers
David Meyer reports: Both Sears and Delta Air Lines are facing the exposure of some of their customers’ credit card information, following a data breach at a mutual contractor. The company, a customer services operation called [24]7.ai, suffered the breach between Sept. 26 and Oct. 12 last year. It said in a statement that the…