Cybersecurity

The digital security of healthcare institutions and data is a growing concern, with an increasing number of cyberattacks each year against healthcare systems, which are seen as easy targets. Cyber attacks often use ransomware to target personal health information, patient data and medical devices to cut off access to the data until a ransom is payed to the hacker. Cybercriminals have become more sophisticated, using malware, ransomware and spyware to attack outdated and vulnerable systems and software. Due to the interconnected nature of hospital IT systems today, the weakest link can be older web-enabled medical devices, including clinical and non-clinical systems. Employees are also a major target of attacks via malicious e-mails that prompt them to open attachments that then download malware onto the hospital's IT system.

Boston hospital settles HIPAA violations for $100,000

Beth Israel Deaconess Medical Center has been hit with a $100,000 fine for HIPAA violations due to one of its physicians failing to follow the hospital's laptop encryption policy and an unencrypted laptop was stolen.

Held-up physician results in Boston data breach

An armed robbery led to a breach of 999 patients' data at Brigham and Women's Hospital in Boston.

Thumbnail

Indiana court upholds $1.44M HIPAA verdict against Walgreens

The Indiana Court of Appeals upheld a $1.4 million verdict against Walgreens triggered when one of its pharmacists improperly accessed the protected medical information of a consumer who once dated her husband, reports Indystar. 

Thumbnail

FTC queries Apple on consumer data privacy practices

The Federal Trade Commission is questioning Apple about its practices regarding the privacy of sensitive health data collected by its smartwatch and other mobile devices, reports Reuters.

Hackers affect 60K state insurance plan members

Hackers were able to access a state insurance plan subcontractor's computer system for three months, putting thousands of plan members' records at risk.

Thumbnail

Malware puts patient data at N.C. dermatology center at risk

Malware on a server at North Carolina-based Central Dermatology Center put its patients’ personal and financial data at risk.

OCR guidance addresses patient privacy during emergencies

New guidance from the Office of Civil Rights reminds covered entities and their business associates that HIPAA privacy protections are not suspended during an emergency.

Thumbnail

Identity theft ring cause of Fla. data breach

Members of an identify theft criminal operation accessed the personal information of nearly 8,000 patients at Miami-based Jessie Trice Community Health Center, reports SC Magazine.

Around the web

The tirzepatide shortage that first began in 2022 has been resolved. Drug companies distributing compounded versions of the popular drug now have two to three more months to distribute their remaining supply.

The 24 members of the House Task Force on AI—12 reps from each party—have posted a 253-page report detailing their bipartisan vision for encouraging innovation while minimizing risks. 

Merck sent Hansoh Pharma, a Chinese biopharmaceutical company, an upfront payment of $112 million to license a new investigational GLP-1 receptor agonist. There could be many more payments to come if certain milestones are met.