Cybersecurity

The digital security of healthcare institutions and data is a growing concern, with an increasing number of cyberattacks each year against healthcare systems, which are seen as easy targets. Cyber attacks often use ransomware to target personal health information, patient data and medical devices to cut off access to the data until a ransom is payed to the hacker. Cybercriminals have become more sophisticated, using malware, ransomware and spyware to attack outdated and vulnerable systems and software. Due to the interconnected nature of hospital IT systems today, the weakest link can be older web-enabled medical devices, including clinical and non-clinical systems. Employees are also a major target of attacks via malicious e-mails that prompt them to open attachments that then download malware onto the hospital's IT system.

Hospital CEO faces wiretapping charges

An Idaho hospital CEO has been charged with spying on a former hospital physician by tapping phone calls.

$1.2M fine for health plan's HIPAA violations

The Department of Health & Human Services Office of Civil Rights has been warning healthcare providers to conduct risk analyses and act on any deficiencies discovered. A settlement between the government and Affinity Health Plan confirms that this advice is worth heeding.

Nurse fired for prying into patient records

A Canadian hospital has fired a nurse over allegations that she inappropriately accessed more than 1,300 patient records over the past nine years.

Few details revealed on Vermont home health breach

A stolen laptop is the source of a breach for patients of Caledonia Home Health Care & Hospice in St. Johnsbury, Vt., but the organization isn't revealing the number of patients affected or the extent of the types of protected health information at risk.

Stolen laptop impacts Calif. eye patients

Retinal Consultants Medical Group has announced the theft of an unencrypted laptop computer but has not revealed the scope of the breach, including how many patients are affected.

HITPC: Update on query, MU Stage 3 security requirements

Despite previous requests for more thoughtful discussion, the Privacy & Tiger Team re-affirmed its previous conclusions about nontargeted queries to the Health IT Policy Committee during its Aug. 7 meeting.

32K patients' data breached due to downed firewall

A breach of protected health information of approximately 32,000 patients in 48 states was the result of a health IT vendor's firewall being down for more than a month, allowing, in some cases, for patient data to be indexed by Google.   

Software glitch causes Missouri Medicaid breach

Missouri's state Medicaid program, MO HealthNet, is notifying 1,357 individuals that some of their personal information was mailed to an incorrect address by one of its IT infrastructure management contractors. The disclosure was caused by a software programming error.

Around the web

U.S. health systems are increasingly leveraging digital health to conduct their operations, but how health systems are using digital health in their strategies can vary widely.

When human counselors are unavailable to provide work-based wellness coaching, robots can substitute—as long as the workers are comfortable with emerging technologies and the machines aren’t overly humanlike.

A vendor that supplies EHR software to public health agencies is partnering with a health-tech startup in the cloud-communications space to equip state and local governments for managing their response to the COVID-19 crisis.