Update: This incident was subsequently reported to HHS as affecting 125,000 patients. Lee News reports: BLOOMINGTON — Ivy Rehab Physical Therapy, which has locations in Bloomington, Decatur and Clinton, has reported a data security breach and offering free credit monitoring to concerned patients. […] In May, the company discovered some employee email accounts may have…
Category: Health Data
OCR Secures $2.175 Million HIPAA Settlement after Sentara Hospitals Failed to Properly Notify HHS of a Breach of Unsecured Protected Health Information
OCR has announced another settlement. This one involves Sentara Hospitals, and it’s a somewhat surprising one in the sense that Sentara not only seems to have gotten the fundamentals of HIPAA and notification compliance wrong, but then they seem to have insisted in their wrongheaded ways even after HHS told them what their obligations were. …
PA: UPMC Susquehanna admits employee snooped in co-worker’s medical records
John Beauge reports: UMPC Susquehanna admits that one of its employees improperly looked at the protected health information of a co-worker who had missed work following a brutal assault. The admission is contained in a letter attached to the Lycoming County court complaint of Taylor Fausnaught, who is suing the health system and employee Tasha…
NE: Great Plains Health hit by ransomware
NBC reports: According to Great Plains Health officials, around 7 p.m. Monday, ransomware was detected in the Great Plains Health computer network. The hospital’s information systems team immediately identified the issue and worked through the night to minimize the impact to local health services. Read more on NBC.
District Court (NY) Says It’s Powerless to Approve Class Settlement Arising Out of Data Breach Due to Lack of Art. III Cognizable Injury
Scott J. Hyman of Severson & Werson PC writes: In Steven v. Carlos Lopez & Assocs., No. 18-CV-6500 (JMF), 2019 U.S. Dist. LEXIS 203621 (S.D.N.Y. Nov. 22, 2019), Judge Furman declined to approve settlement of a data breach class due to the absence of Art. III standing. From the opinion: In June 2018, an employee…
110 Nursing Homes Cut Off from Health Records in Ransomware Attack; Attackers Demand $14M in BTC
Brian Krebs reports: A ransomware outbreak has besieged a Wisconsin based IT company that provides cloud data hosting, security and access management to more than 100 nursing homes across the United States. The ongoing attack is preventing these care centers from accessing crucial patient medical records, and the IT company’s owner says she fears this…