The HHS Office for Civil Rights (OCR) is producing a pre-recorded video presentation for HIPAA covered entities and business associates (regulated entities) on “recognized security practices,” as set forth in Public Law 116-321 (Section 13412 of the Health Information Technology for Economic and Clinical Health Act (HITECH). The statute requires OCR to take into consideration…
Choice Health Insurance notifying people after vendor error resulted in a data breach
On June 8, Choice Health Insurance began notifying people of a data breach caused by human error. According to their notification to the California Attorney General’s Office, they learned on May 14 that an unauthorized person was “offering to make available data allegedly taken from Choice Health.” In actuality, on May 9, the data had…
Analysis of the Fourth Circuit’s Opinion in In re Marriott International, Inc.
Gargi Chaudhuri and James Masella, III of Patterson Belknap Webb & Tyler LLP write: On April 21, 2022, the United States Court of Appeals for the Fourth Circuit affirmed the dismissal by the United States District Court for the District of Maryland of allegations that Marriott International had violated federal securities laws by omitting from…
Yuma Regional Medical Center notifying approximately 700,000 patients of ransomware attack
KYMA reports: Yuma Regional Medical Center (YRMC) said it mailed letters to thousands of patients whose information may have been involved in a recent cybersecurity incident. On April 25, 2022, YRMC identified a ransomware incident affecting some internal systems. Upon detecting the incident, YRMC shared with News 11 it took immediate action, taking systems offline,…
WA: MCG Health notifies patients and health plan members of data breach (updated)
Seattle-based MCG Health, LLC (“MCG”) provides patient care guidelines to providers and health care plans. According to a notice on their website that was also issued as a press release yesterday, on March 25, 2022, they determined that an unauthorized party had previously obtained personal information about some patients and members of certain MCG customers….
Shoprite Group issues warning on ‘suspected data compromise’ (UPDATED)
TimesLive reports: The Shoprite Group said on Friday evening it had become aware of a suspected data compromise, including names and ID numbers, which may affect some customers who engaged in money transfers to and within Eswatini and within Namibia and Zambia. “Affected customers will receive an SMS to the cell number supplied at the…