Cybersecurity

The digital security of healthcare institutions and data is a growing concern, with an increasing number of cyberattacks each year against healthcare systems, which are seen as easy targets. Cyber attacks often use ransomware to target personal health information, patient data and medical devices to cut off access to the data until a ransom is payed to the hacker. Cybercriminals have become more sophisticated, using malware, ransomware and spyware to attack outdated and vulnerable systems and software. Due to the interconnected nature of hospital IT systems today, the weakest link can be older web-enabled medical devices, including clinical and non-clinical systems. Employees are also a major target of attacks via malicious e-mails that prompt them to open attachments that then download malware onto the hospital's IT system.

Idaho university to pay $400K for HIPAA violations

Idaho State University will pay $400,000 to the Department of Health and Human Services to settle alleged violations of the HIPAA Security Rule. The settlement comes after ISU’s Pocatello Family Medicine Clinic disabled server firewall protections for a period of at least 10 months, resulting in the breach of electronic protected health information for 17,500 patients.

Data entry error causes La. breach

A data entry error in March caused a data breach affecting 8,330 patients of Louisiana State University Health System in Shreveport.

2,000 Piedmont HealthCare patients alerted to possible breach

North Carolina-based Piedmont Healthcare notified approximately 2,000 patients of a potential breach of their credit card information and other personal information, according to a May 16 Charlotte Observer story.

Indiana breach caused by stolen laptop

Another stolen laptop is the source of yet another data breach. A password-protected, unencrypted laptop was stolen from the care of an employee of Indiana University Health Arnett in Lafayette.

Unsecured email cause of Memphis breach

The Regional Medical Center in Memphis is notifying physical therapy patients of a HIPAA breach after an employee sent out three unsecure emails containing the protected health information and Social Security numbers of nearly 1,200 patients.

Rochester medical center suffers third breach

The University of Rochester Medical Center (URMC) suffered its third significant data breach after officials announced that one of its physicians misplaced an unencrypted USB drive containing the protected health information of 537 patients.

Vets sue over data breach

The William Jennings Bryan Dorn VA Medical Center in Columbia, S.C., faces a federal lawsuit following a breach that impacted more than 7,400 veterans. On Feb. 11, a laptop containing personal information--including names, birth dates and partial Social Security numbers--was stolen from the facility. The laptop was unprotected.

NIST updates privacy, security controls

A revision to the federal government’s foundational computer security guide, also applicable to and used in the private sector, is available.

Around the web

U.S. health systems are increasingly leveraging digital health to conduct their operations, but how health systems are using digital health in their strategies can vary widely.

When human counselors are unavailable to provide work-based wellness coaching, robots can substitute—as long as the workers are comfortable with emerging technologies and the machines aren’t overly humanlike.

A vendor that supplies EHR software to public health agencies is partnering with a health-tech startup in the cloud-communications space to equip state and local governments for managing their response to the COVID-19 crisis.

Trimed Popup
Trimed Popup