Author: Colington Consulting

  • The End of HIPAA Audits?

    Recently, Department of Health and Human Servicesโ€™ Office for Civil Rights Director Roger Severino signaled an end to the latest wave of HIPAA audits โ€“ but โ€œno slowdown in our enforcement efforts.โ€

    What does this mean for your medical practice and its liability under the Health Insurance Portability and Accountability Act of 1996 (HIPAA)?

    According to Severino, the Office for Civil Rights (OCR) is examining its regulations to determine whether โ€œundue burdenโ€ on the health care industry can be eased. Under the Trump administrationโ€™s executive order, two regulations need to be removed for every new regulation implemented. Acknowledging that โ€œwe are in a deregulatory environment,โ€ Severino disclosed that the U.S. Department of Health and Human Services (HHS), along with the OCR, are reviewing their regulations to see if benefits and outcomes are outweighing costs.

    As a result, the OCR has ended Phase 2 of the HIPAA audit program in which HHS had randomly requested documentation and evidence from organizations required to be HIPAA compliant. These โ€œdesk auditsโ€ were conducted to assess the overall compliance of both covered entities and business associates with plans to share the results gathered through the audit process and issue guidance identifying compliance challenges and best practices. The final phase of this audit program will be the compilation of those findings to be made public.

    However, Severino has warned that the OCR is โ€œstill looking for big, juicy egregious casesโ€ for enforcement of HIPAA rules and procedures, adding that entities large and small are still in the OCRโ€™s crosshairs. โ€œWeโ€™d like to put ourselves out of business [as an enforcement agency],โ€ Severino has said. โ€œUnfortunately, [cases] are growing steeply up.โ€

    In fact, since 2009, access to about 177 million medical records have been breached, resulting in 50 settlement agreements and three civil monetary penalty cases as a result. In 2016, the OCR collected nearly $25 million in HIPAA-related settlements and collected another $19.4 million in 2017.

    According to the OCR, 38 percent of reported cases of data breaches affecting 500 or more individuals were the result of theft, with about one in five of those breaches involving paper documents. Online hacking constituted 19 percent of reported security breaches and that number is growing.

    This is why due diligence when it comes to abiding by HIPAA rules and regulation remains a top priority for your practice โ€“ regardless of the desk audits being discontinued. The OCR is still focused on enforcement and issuing heavy fines to medical practices large and small that have experienced a breach of protected health information because of a violation of HIPAA privacy rules.

    To learn more about HIPAA compliance requirements and how it affects your practice, contact Colington Consulting at (800) 773-6379. We are experts in the field of HIPAA rules and procedures. Colington Consulting can help you avoid problems and steep fines by bringing your practice into complete HIPAA compliance. It is what we do best, allowing you to do what you do best โ€ฆ provide health care to your patients.

    This blog was previously posted June 1, 2018

  • The Danger of Disregarding Risk Analysis: The Anthem Case

    by Jay Hodes, President – Colington Consulting

    Anthem, Inc., a defined Business Associate that provided administrative support services for the Anthem Affiliated Covered Entities (Anthem ACE), has committed to a $16 million settlement to the U.S. Department of Health and Human Services, Office for Civil Rights (OCR). This is the largest settlement ever announced by OCR.ย  The outcome of this investigation determined a high risk of HIPAA Security Rule and HIPAA Privacy Rule violations due to a series of โ€œundetected continuous and targeted cyber attack[s] for the apparent purpose of extracting data, otherwise known as an advanced persistent threat attackโ€ that exposed the ePHI of approximately 79 million users between December 2, 2014 and January 27, 2015, including names, social security numbers, medical identification numbers, addresses, dates of birth, email addresses, and employment information.

    The risk was found to have originated via a malicious email phishing attack that at least one Anthem, Inc. employee responded to, thus allowing the cyber attackers easy access.

    The following are the potential violations uncovered by the HHS investigation:

    • The requirement to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI held by Anthem
    • The requirement to implement sufficient procedures to regularly review records of information system activity
    • The requirement to identify and respond to detection of the security incident leading to this breach
    • The requirement to implement sufficient technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights
    • The requirement to prevent unauthorized access to the ePHI of 78,800,000 individuals whose information was maintained in Anthem’s enterprise data warehouse

    The Corrective Action Plan (CAP) signed onto by Anthem includes the following terms:ย 

    • Conducting a detailed and thorough Risk Analysis within 90 days of the CAPโ€™s effective date, including a Statement of Work (SOW) submitted to HHS detailing the process of this Risk Analysis. After receiving appropriate or necessary feedback and input from HHS, then Anthem has 150 days to implement new or updated security measures based on the Risk Analysis findings as well as consequent responses made to the Analysis by HHS.
    • Conducting a thorough review of policies and procedures to ensure thorough compliance with the HIPAA Security Rule.
    • Distributing all updated policies and procedures throughout Anthemโ€™s network of employees and contractors, and ensuring proper transfer of training for this same content.

    As a CE or BA, not enough can be said about the dangers of storing ePHI without proper risk management and analysis.ย In my opinion, Anthem, Inc.โ€™s payment and CAP is considered disproportionate to the potential violations carried out due to this breach and the number of individuals affected.

    Consistent, periodic review of your organizationโ€™s security measures and risk management plan is key to ensuring ongoing compliance with the HIPAA Privacy Rule and HIPAA Security Rule.ย  Despite the size of your organization, effective overall HIPAA compliance program is vital and can help to prevent breaches from occurring.ย 

    This blog was previously posted November 13, 2018

  • Is a HIPAA Violation a Reportable Breach?

    Just because a member of an organizationโ€™s workforce violates HIPAA policies and procedures, it is not necessarily a breach reporting requirement. The significant determination is the extent to which any protected health information (PHI) may have been compromised based on breach rule guidance. So, before getting too technical regarding that determination, here are some cases to consider:

    1. An employee for a healthcare software company loses a computer containing the PHI of 2000 patients. Reportable breach?
    2. A hospital system is the victim of a ransomware attack. Reportable breach?

    A breach is generally an impermissible use or disclosure under the Privacy Rule that compromises the

    security or privacy of the PHI. An impermissible use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised based on a risk assessment of at least the following factors:

    • The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
    • The unauthorized person who used the PHI or to whom the disclosure was made;
    • Whether the PHI was actually acquired or viewed; and
    • The extent to which the risk to the PHI has been mitigated.

    Going through this type of breach โ€œrisk assessmentโ€ can be challenging, especially in trying to determine if any PHI was acquired or viewed. To further complicate this process, the guidance does not specify what exactly a โ€œlow probabilityโ€ is. So, this assessment process will take some work.

    Begin by using a decision tree and asking questions such as โ€œWas the PHI disclosure to a person who reasonably would have not been able to retain that information?โ€ and โ€œWas the PHI secured by encryption?โ€ The resulting series of yes or no responses will help to determine whether a breach notification is required.

    In most of these cases, the organizationโ€™s HIPAA Privacy and Security Officials should take the lead with this process. There may be a need to involve the organizationโ€™s healthcare and privacy attorney for advice. Experience and expertise with the process are clearly essential to helping determine probability.

    It is important to document the results, especially in those cases in which a determination was made that it was not a reportable breach. If, for some reason, any of the PHI was in fact compromised and a breach report was not made, demonstrating due diligence in the event an HHS Office for Civil Rights (OCR) investigation is necessary.

    Referencing the numbered case examples above:

    1. This would be a reportable breach if the PHI was not encrypted. However, if the PHI was encrypted, it could be an organizational HIPAA violation based on policies and procedures for mobile devices.
    2. This example is going to be a fact-specific determination. In 2016, OCR issued guidelines on the topic of ransomware attacks. If the PHI was encrypted, it may not be reportable. But any unsecured PHI will be a reportable breach. (See the full fact sheet.) In this case, the possibility exists that there may also be a HIPAA violation based on the cause of the attack and whether proper safeguards were followed by a workforce member or members.

    My advice is to make sure your organizationโ€™s HIPAA Sanction policies and procedures are clear for any violations, even for those cases that are not reportable. Ensure the organization has a comprehensive breach notification policy and accompanying procedures. Be familiar with the breach risk assessment process and be prepared should an impermissible use or disclosure occur.

    This blog was previously posted January 7, 2019

  • HIPAA Best Practices for Employee Termination

    On December 11, 2018, the HHS Office for Civil Rights (OCR) announced a settlement of $111,400 with Pagosa Springs Medical Center (PSMC) located in Colorado. The settlement was the outcome of a HIPAA enforcement action following the findings of an OCR investigation that was triggered by an allegation that a former employee of PSMC still had access to ePHI via a web scheduling client used by PSMC.

    According to OCR Director Roger Severino, โ€œitโ€™s common sense that former employees should immediately lose access to protected patient information upon their separation from employment.โ€ย 

    However, ensuring removal of access alone for the terminated employee would not have prevented PSMC as a Covered Entity (CE) from meeting other HIPAA requirements. OCRโ€™s investigation revealed that PSMC did not have a Business Associate Agreement (BAA) in place with either the web-based scheduling calendar vendor, nor with the employee, thus ensuring the ePHI of 557 individuals were made vulnerable to attacks.

    Under a two-year Corrective Action Plan, PSMC must now update its security management and business associate agreement, as well as its policies and procedures, and must now re-train its employees and workers so that they are up to speed on these changes.

    The takeaway from this settlement agreement is that organizations that do not have or follow procedures to terminate information access privileges upon employee separation that results in a breach face possible HIPAA enforcement action by OCR. It is also important to make sure any process that records, shares, transmits, or modifies ePHI is thoroughly detailed in the BAA. Some CEs attempt to save money and time by establishing a work-around, which involves anonymizing ePHI while using web-based scheduling or communication apps without a BAA. However, such an undertaking is difficult to standardize in the long run. It is ultimately more cost-effective for CEs to take the time and resources to set up a BAA with relevant vendors, in order to avoid an investigation for failing to enforce HIPAA privacy and security mandates.

    Best Practice Lessons from this case:

    • The CE representative facilitating an employeeโ€™s termination must also have the ability and training to revoke and remove any previous access authorizations held by the employee. This must take place at the same time as when the notice of termination is provided.
    • CEs must complete BAAs with any vendor who provides the CE with the ability to record, modify, transmit, or share ePHI.
    • At the time of onboarding, all employees must be made aware that their employer requires them to give up all access and authorizations upon termination or voluntary departure from the company.
    • Training materials for employee onboarding should include privacy and security awareness related to:

    a) use of third-party services and applications;

    b) terms and conditions that trigger the creation of a BAA;

    c) assurances provided by Bas regarding policies and procedures to secure ePHI;

    c) security incident reporting; and

    d) password management.

    • Supervisors and other responsible officials must be trained to undertake oversight of employees’ uses and disclosures of PHI, including ePHI, in order to ensure compliance with HIPAA regulations.

    This blog was previously posted January 14, 2019

  • What Comes Up, Must Go Down: Regulatory Trends and HIPAA

    Enforcement of HIPAA mandates by the HHS Office for Civil Rights (OCR) are more aggressive than ever before, โ€œtotaling $28.7 million from enforcement actionsโ€ in 2018, an increase of 22% from the last record total of $23.5 million in 2016. ย According to an OCR press release, 2018 saw that office establish โ€œan all-time record yearโ€ in HIPAA enforcement activity, settling โ€œ10 casesโ€ and being โ€œgranted summary judgment in a case before an Administrative Law Judge.โ€ One of these 10 cases was the watershed HIPAA settlement with Anthem, Inc. for $16 million.

    OCR Settlements* and Judgement** for 2018

    Jan – FileFax*ย  –ย  $100,000

    Jan – Fresenius Medical Care* – $3,500,000

    Jun – MD Anderson** – $4,348,000

    Augย  – Boston Medical Center*ย  –ย  $100,000

    Sep – Brigham & Womenโ€™s Hospital* – $384,000

    Sep – Mass. General Hospital* – $515,000

    Sep – Advanced Care Hospitalists* – $500,000

    Oct – Allergy Associates of Hartford* – $125,000

    Oct – Anthem, Inc* – $16,000,000

    Nov – Pagosa Springs* – $111,400

    Dec – Cottage Health* – $3,000,000

    Total โ€“ Settlements & Judgement:ย  $28,683,400

    While the current administration did and continues to tout a posture of deregulation, the reality on the ground for organizations that must comply with HIPAA is that OCR has only strengthened its enforcement mechanisms, showing very little tolerance for security and privacy breaches arising from:

    • The mismanagement, or lack of proper storage, transmission, or disposal of patient PHI and ePHI.
    • An incomplete or missing Business Associate Agreement (BAA) made with any and all vendors who might be considered a Business Associates (BA) under HIPAA.
    • Cyberattacks via successful email phishing attempts targeting not just Covered Entity (CE) workers or employees, but also workers or employees of any vendor affiliated with theย  CE.
    • Incompatible or insufficient risk analysis and risk management processes on the part of the CE.

    Out of these 11 instances of verified HIPAA violations,

    • 6 CEs were found to have mismanaged or improperly stored, transmitted, or disposed of patient PHI and ePHI (Fresenius Medical Care North America, FileFax, Inc., MD Anderson, Allergy Associates of Hartford, Pagosa Springs, and Cottage Health)
    • 3 CEs did not have a BAA in place to manage vendors who are considered to be BAs under HIPAA (Advanced Care Hospitalists, Pagosa Springs, and Cottage Health)ย ย 
    • 1 CE experienced an email phishing cyber-attack (Anthem, Inc.)ย 
    • 4 CEs made PHI or patient privacy vulnerable by exposing the same via TV shows, interviews, or recordings (Allergy Associates of Hartford, Boston Medical Center, Brigham and Womenโ€™s Hospital, and Massachusetts General Hospital)
    • 4 CEs lacked HIPAA-mandated risk assessment, risk analysis, risk notification, or risk management protocols (Cottage Health, MD Anderson, Advanced Care Hospitalists, and Fresenius Medical Care North America)

    From this analysis, it can be ascertained that CEs and BAs can avoid facing settlements and judgements due to violations of the HIPAA Privacy Rule and the HIPAA Security Rule by instituting the following โ€œgolden rulesโ€ and ensuring their staff are fully trained in the same:

    • Do have robust and comprehensive plan to assess, identify, report, respond, and manage all security or privacy risks.
    • Do ensure a signed and completed BAA is on file for all BAs
    • Do have highly specific protocols in place governing the collection, storage, transmission, and disposal of patient PHI and ePHI.

    Best practices include annual and periodic training for their workforce, conducting the required security risk assessment in an ongoing/periodic manner, and internally enforcing HIPAA policies and procedures to cover the organizationโ€™s security management processes.

    Organizations, large and small, must be aware of the aggressive posture of enforcement and record settlement amounts under OCR and this current administration. My advice for any organization is to conduct a thorough evaluation of the current HIPAA compliance in place. Make sure all the requirements are covered.ย  If a compliance program is not is place, consider outsourcing and let a consultant do the heavy lifting.ย Often times, a consultant can get the program in place much quicker than relying on the organizationโ€™s internal staff.

    This blog was previously posted February 12, 2019

  • How Do HIPAA Breach Reporting Requirements Affect State Reporting

    For those of us involved in the world of HIPAA compliance, we are certainly aware by now that the Breach Notification Rule requires Covered Entities (CE) and Business Associates (BA) to notify affected parties of any breach that has occurred to their protected health information. Those notification requirements and timelines are based on the โ€œ500 ruleโ€ of individuals affected, and there are different rules based on whether more or fewer than 500 were affected by the breach.

    But another important factor to consider, besides the Federal requirement, is what do State breach reporting laws require? This is a topic that has been getting a lot of attention lately.

    According to the National Conference of State Legislatures (NCSL), all 50 U.S. states and its territories have enacted laws that require both private and public entities to notify anyone who has been affected by a security breach of their personally identifiable information.

    The NCSL website explains that these laws specify exactly who must comply with the law, what constitutes โ€œpersonal information,โ€ what constitutes a breach, requirements for notice (e.g., timing or method of notice, who must be notified), and any exemptions that may apply.

    HIPAA Data Breach Reporting at the State Level

    At the State level, there exists a somewhat different landscape of potential pitfalls compared to the compromise of any of the 18 HIPAA Identifiers. Also, State reporting is not in lieu of the Federal reporting but in conjunction. Both Federal HIPAA and State breach reporting requirements must be adhered to.

    It is important to remember that State reporting timelines may be shorter than what is mandated by the HIPAA Breach Notification Rule.

    As an example, the State of California Civil Code states that for medical information, โ€œAffected patients and the California Department of Health Services must be notified no later than 15 business days after the unauthorized access, use, or disclosure has been detected by the licensee.โ€ There is an exception to delay the notification for law enforcement purposes in accordance with the Code.

    When Business Associates Are Breached

    Further complications to the breach notification requirements kick in when CEs engage the services of vendors that are designated BAs. We know about the requirement to execute Business Associate Agreements (BAA) when these vendors have accesses to a Covered Entityโ€™s ePHI/PHI. What happens when CEs have hundreds of BAs and then some of those BAs have subcontractor BAs? How does an organization keep track of all the timelines in reporting? Oftentimes, this is done with a time-consuming manual review, causing organizations to spend excessive funds on complying โ€“ or, more commonly, not doing this exercise at all.

    Organizations commonly try and use โ€˜standard templatesโ€™ to standardize timelines, but reporting timeframes are often the center of agreement negotiations and are often changed.

    The 500 Rule

    According to the Breach Rule, if a breach affects 500 or more people, then the entity that is responsible for the breach must notify the Secretary of the applicable governmental entity as soon as possible, and no later than 60 days after the breach occurred.

    If the breach affects fewer than 500 people, however, then the responsible entity is only required to notify the Secretary annually, and no more than 60 days past the affected calendar year. Therefore, if a CE gives a BA 60 days to make the report but the breach affects 500 or more individuals, that CE will actually fail to meet the reporting deadline.

    Managing this process of timeline reporting is critical, especially with downstream BA vendors.

    โ€œUnderstanding reporting time frames, both contractual and regulatory, is critical for healthcare organizations. But many compliance teams struggle to keep up with changing laws and the growth of their organizations as it relates to obligations to regulators and business partners,โ€ says Jason Silverstein, COO, PHIflow. โ€œRather than depending on manual document review (which is expensive and time-consuming) to understand reporting timeframes, todayโ€™s leading compliance and privacy departments leverage innovative new technologies to automate many of the mundane tasks previously associated with antiquated compliance processes.โ€

    A summary of U.S. State Data Breach Notification Statutes per state provided by NCSL can be accessed here: http://www.ncsl.org/research/telecommunications-and-information-technology/security-breach-notification-laws.aspx

    Need Help with HIPAA Compliance?

    If you would like to discuss how Colington Consulting can help your organization meet these ever-changing governmental standards, call us at (800) 733-6379 today.

  • Not Worried About Your Patients? Worry About Your Bottom Line?

    Weโ€™re always talking about how not complying with HIPAA regulations badly affects patients. Their data is exposed to malicious entities. Their trust in your organization wanes. Even if youโ€™re not worried about the moral implications or your public perception, the fact is youโ€™re not off the hook for noncompliance. There are severe penalties for not following the rules. And thatโ€™s what weโ€™ll be discussing in todayโ€™s article.

    A Breakdown of HIPAA Fines

    Penalties for HIPAA noncompliance are broken down into four categories of fines:

    1. Willful neglect with no corrective action taken.
    2. Willful neglect with corrective action taken.
    3. Reasonable cause for noncompliance.
    4. No knowledge of noncompliance.

    Each level of noncompliance comes with its own financial penalty for your company or organization. Letโ€™s take a closer look at what each one means, and what its penalty is.

    Willful Neglect with No Corrective Action

    This is by far the most severe form of noncompliance, and therefore comes tagged with the harshest of government fines. From a legal standpoint, willful neglect is defined as a “conscious, intentional failure or reckless indifference.โ€ If you work in the healthcare industry, thereโ€™s a good chance youโ€™ve at least heard of HIPAA. Weโ€™ve reached a point where it is very difficult for organizations to claim ignorance of it. If it looks as though you havenโ€™t even bothered to make the necessary changes, thereโ€™s a good chance you could be hit with this very serious charge. It comes with a nasty $50,000 minimum penalty for each violation, and can cost your organization up to a whopping $1,500,000 annually.

    Willful Neglect with Corrective Action

    If a company or organization is found guilty of willful neglect as defined above, resolving the noncompliance issue in a timely fashion will reduce the associated penalty. Itโ€™s still a hefty price thatโ€™s nothing to sneeze at however, and your best option of course is to comply with the regulations in the first place. After making the necessary changes, you could instead be hit with a $10,000 penalty for each violation, up to a maximum of $250,000 annually. The difference isnโ€™t negligible at least, and is greatly preferable to ignoring the problem – both for your patients and for your companyโ€™s bottom line.

    Reasonable Cause

    The legal definition for reasonable cause in regard to HIPAA compliance is as follows:

    โ€œAn act or omission in which a covered entity or business associate knew, or by exercising reasonable diligence would have known, that the act or omission violated an administrative simplification provision, but in which the covered entity or business associate did not act with willful neglect.โ€ While not as serious as โ€œwillful neglect,โ€ it still comes with a heavy price tag of $1,000 for each violation and up to $100,000 annually.

    No Knowledge

    Noncompliance is to be considered โ€œwithout knowledgeโ€ if the covered entity or individual did not know (and by exercising reasonable diligence would not have known) the action in question was a HIPAA violation. This is incredibly common, and is a huge culprit for many violations. This is why it is especially important to train your employees and make absolutely certain everyone knows and follows the regulations. Not rigorously training – and refreshing – your employees in HIPAA compliance can cost you $100 for every single violation, and up to $25,000 a year in damages. Teaching your staff the right way of doing things, taking the right precautions and putting processes in place will help you best to avoid these fines.

    Remember, there can be hefty fines for not following regulations. But most importantly, itโ€™s important to protect the people youโ€™re serving. Their lives are in your hands. Let us help you help them – and yourselves.ย  Give us a call today at 800-733-6379 for a free, no obligation, initial consultation.ย 

  • Protect Our Health by Protecting our Healthcare

    Our healthcare system, while far from perfect, is an absolute necessity for living. It would make sense then to be sure that it was well-protected.

    Unfortunately, this is often not the case. As we have seen over and over again, database breaches are more common in the healthcare industry than anywhere else. Weโ€™re not just experiencing a loss of data, but a loss of trust as well. How can people live their lives and stay safe from data theft at the same time?

    HIPAA Compliance

    It starts with a set of rules. Such a set has already been put together: The Health Insurance Portability and Accountability Act of 1996 (HIPAA). But rules are meaningless if no one is following them. According to the HIPAA journal, breaches in patient records during 2018 doubled to more than 13 million records. This is unacceptable – both from a patient standpoint and a legal one. And itโ€™s only going to get worse as technology grows.

    Data Breaches and Technology

    Our healthcare technology has improved in leaps and bounds since the 1990โ€™s. This is terrific. The average lifespan of Americans has also increased thanks to amazing breakthroughs and wearable devices like smart inhalers and insulin pens. Patients can have their glucose levels monitored from almost anywhere. We have remote MRI machines and smart beds. These are all helpful things. They greatly improve our quality of life.

    But what happens when all of these terrific inventions are used for ill purpose?

    Each of these devices works because theyโ€™re connected in some way shape or form to a database. Every patient uploads a massive amount of data about themselves whenever theyโ€™re used. Then, attackers breach these databases, access patients records, steal them and sell them on the dark web. In countries like the U.S., attackers from anywhere in the world can access expensive medical services, products, and drugs with the help of stolen medical records. The healthcare sector has proven to be extremely profitable for attackers, with a single record costing an average of $408.

    Data Breaches and Ransomware

    Itโ€™s not always about buying, selling, and manipulating patient data. Disturbingly often, itโ€™s about holding hospitals hostage to fund criminals, political actors abroad and even terrorism. That might sound like an extremely bold declaration, but itโ€™s an unfortunate and well-known truth. Ransomware attacks account for 85% of all the cyber-attacks on the healthcare sector. In one example which we mention in a previous article, Indiana-based healthcare system, Hancock Health, was hit by a ransomware attack that completely locked down all of their computers. In many instances, those computers were depended upon for keeping critical hospital systems running. They felt they had no choice but to pay the ransom in order to keep their patients safe. That attack had cost the company about $55,000 in Bitcoin.

    It was a risky move either way. Historically, only 19% of ransomware victims who pay the ransom actually get their files back. And the worst part is, that money goes to places that are in no way good.

    Our healthcare system is possibly the most important institution in our country. It definitely has its flaws, but itโ€™s literally what keeps us alive. The absolute least we can do is follow the rules that were originally put in place to protect it. Weโ€™re here to help you make sense of those rules.ย  Call us today at 800-733-6379 to schedule a free, initial consultation.

  • Ransomware Threatens More Than Livelihood – It Threatens Lives

    Ransomware does a lot more than hurt your organizationโ€™s bottom line. It can actually risk the lives of hospital patients. And weโ€™re not talking about just privacy concerns this time. A recent story in the news earlier in October has painted a truly frightening and all-too-real scenario: patients being sent away because of hospital systems being down.

    Hereโ€™s an overview of what happened.

    Which Hospitals Were Hit with Ransomware?

    There were a total of ten hospitals that were infected all around the same time. Seven of them were in Australia, and three of them were here in the U.S. in the state of Alabama. The two groupings are not suspected to be connected to the same attacker, but all ten were forced to take the same drastic actions. All three hospitals that make up the DCH Health System in Alabama were closed to new patients when the attack paralyzed the health network’s computer system.

    At the time this news broke, the hospitals – DCH Regional Medical Center in Tuscaloosa, Northport Medical Center, and Fayette Medical Center – were forced to turn away all but the most critical new patients. Non-critical patients were diverted to nearby hospitals, and even some emergency patients were also relocated once they were stabilized.

    How did the Hospitals Respond?

    DCH representatives wrote in a release that a criminal was limiting their ability to use their computer systems in exchange for a payment amount that was not known at the time. Eventually, the Alabama hospitals felt they had no choice but to pay the ransom demands in order to obtain the decryption keys necessary to rebuild their networks. The Tuscaloosa News reported that DCH officials made a payment to the people responsible for the ransomware attack, but didnโ€™t state how much was paid. In exchange for the payment, according to a statement from DCH, โ€œthis included purchasing a decryption key from the attackers to expedite system recovery and help ensure patient safety.โ€

    How Can HIPAA Compliance Prevent Ransomware?

    According to an FAQ published by DCH, the strain of ransomware that hit the hospitals is known as โ€œRyuk,โ€ which specializes in burrowing deep into infected networks to exact big payments. Thus far, Ryuk has nearly always been associated with phishing campaigns directed at employees of target companies. The United Statesโ€™ healthcare system is one of the largest targets by far for such campaigns, and itโ€™s quite possible that strict adherence to HIPAA guidelines could have potentially prevented this attack from happening altogether.

    Weโ€™ve reached a tipping point in the world of cybersecurity and data protection. Itโ€™s no longer just about protecting privacy. Even though the leaking of patient data can most certainly ruin lives, we are now seeing examples of how this battleground can physically endanger lives. You can be sure to see more such examples as technology continues to evolve.

    How can organizations expect to adapt to new challenges by applying new safeguards if theyโ€™re not yet following those standards that are already currently in place? HIPAA exists for a reason.

    Take Action Now

    Does your organization have a fully implemented HIPAA Risk Management Plan that includes how to address ransomware attacks? If not, we can develop one for you as part of our comprehensive package of HIPAA services.ย  Give us a call today at 800-733-6379 or drop us an email at info@cchipaa.com for a free, initial consultation.

  • Office for Civil Rights (OCR) – Two Significant Announcements

    The U.S. Department of Health and Human Services, Office for Civil Rights (OCR) had two significant announcements this past week resulting in total of $4.6 million for a settlement and imposed penalty.ย  The two cases, one involving a public agency, the Texas Health and Human Services Commission (TX HHSC) and the second, a university medical center, the University of Rochester Medical Center (URMC).

    Both cases demonstrate OCR is continuing on an aggressive path to address reported breaches and investigate how organizations are just not being proactive with HIPAA compliance requirements.These investigations uncovered a slew of problems, especially in the Texas case.ย  What was troubling about this case, is the TX HHSC had such poor audit controls, it could not determine the number of persons who inappropriately accessed the protected health information in question.

    In the URMC case, it determined โ€œidentification of a lack of encryption as a high risk to ePHI, URMC [still] permitted the continued use of unencrypted mobile devices.โ€ย  This is a clear case of somebody dropping the ball due to reasons one can only speculate about.ย 

    If OCRโ€™s track record is similar to recent years, expect more settlement announcements to be made before the end of the year.ย  With the holidays quickly approaching, OCR may not be spreading good cheer for some.

    Read the TX HHSC Press Release

    Read the URMC Press Release