One year after Excellus settled with OCR over a 2015 data breach, there is now a proposed settlement in a class action lawsuit that was filed in response to the breach. The terms of the settlement, which have not yet been approved by the court, do not involve paying even one dime to class members….
Category: Health Data
University of Arkansas for Medical Sciences notifying 518 patients after employee emailed PHI to her personal gmail account
Log Cabin Democrat reports: On Nov. 29, 2021, UAMS became aware that a former employee sent emails from her UAMS email to her personal Gmail account with patient information attached on November 15, 2021, while still employed with UAMS. The attachments consisted of Excel spreadsheets used for internal billing compliance auditing purposes and/or billing statements…
Revised Health Breach Notification Rule resources spell out companies’ legal obligations
Lesley Fair writes: Shoppers can find a plethora of apps, trackers, and sensors that hold or capture almost every conceivable form of personal health information. If your business or nonprofit offers products like that or provides certain services to entities that do – and you aren’t subject to HIPAA – you may be covered by…
HHS Brief: Log4J Vulnerabilities and the Health Sector
The HHS Cybersecurity Program has issued a new brief this week: Log4J Vulnerabilities and the Health Sector You can access it at https://www.hhs.gov/sites/default/files/log4j-vulnerabilities-health-sector.pdf
NYU Langone notified 1,123 patients of privacy issue due to mailing vendor error
NYU Langone Health notified patients the week of January 4, 2022, about a potential privacy incident resulting in misdirected, limited patient information. The incident occurred on or about November 12, 2021, when a communication was sent via U.S. mail to inform patients of a planned relocation of an NYU Langone Health oncology surgeon originally based…
GA: Peachtree Orthopaedic Clinic reports breach to HHS
It appears that Peachtree Orthopaedic Clinic in Georgia reported a breach to HHS on January 3 that impacted 53,686 patients. They reported the breach as “hacking — other.” There is nothing on their website at this time to explain the incident and so far, I have found no press release. The only additional information at…