Amazon has revealed that new security measures have been added to its cloud server that will make it much more difficult for users to misconfigure their S3 buckets and mistakenly leave their data accessible. While Amazon will complete a business associate agreement...
Experian Health Breach Impacts Cook County Health and Hospitals System Patients
Patients of Cook County Health and Hospitals System, a health system comprising two hospitals and more than a dozen community health centers in Cook County Illinois, have been made aware of a breach of their protected health information. The breach happened at...
305% Annual Rise in Breached Records According to 2017 Data Breach Report
There was been a 305% increase in the number of records exposed in data breaches in the 2017 according to a data breach report from Risk Based Security (RBS), a provider of real time information and risk analysis tools. For its most recent breach report, RBS analyzed...
Catholic Charities of the Diocese of Albany Find Long-Term Malware Infection
In August 2017 malware was discovered to have been installed on one of the computer servers used by Catholic Charities of the Diocese of Albany (CCDA) in its Glens Falls office, which served patients in Saratoga, Warren and Washington Counties in New York. It was...
NY AG Introduces SHIELD Act to Improve Security of PHI
Attorney General Eric T. Schneiderman has introduced the 'Stop Hacks and Improve Electronic Data Security Act (SHIELD Act)' into the legislature in New York.it is hoped that Act will protect New Yorkers from unnecessary breaches of their personal data and to ensure...
PHI of up to 2,000 Veterans Obtained Following Theft of USB Drives
Two USB drives storing the protected health information of up to 2,000 veterans have been stolen from the Man-Grandstaff VA Medical Center in Spokane, WA it has been reported. The two USB devices were being used to store protected data from a standalone, non-networked...
PHI of Almost 1,000 Texas Children’s Health Plan Subscribers Breached in Email
It has recently been discovered that a former employee of the Texas Children’s Health Plan has recieved the protected health information (PHI) of 932 members in a private email. The last known incident where the former employee emailed the data was late in 2016,...
WannaCry Ransomware Variant Attacks FirstHealth Data
A new WannaCry ransomware variant has been used to attack FirstHealth of the Carolinas, a Pinehurst, SC-based not for profit health network. WannaCry ransomware was used in worldwide attacks earlier in May. Over 230,000 computers were infected within 24 hours of the...
Brevard Physician Associates Clients Have PHI Exposed in Burglary
The protected health information (PHI) of almost 8,000 client of Brevard Physician Associates may have been accessed following the theft of an office computer in a recent break in. The burglary happened on September 4, 2017 – Labor Day – when the offices were shut...
HIPAA Breach at Briggs and Stratton Reported
A HIPAA Breach has been reported at lawnmower engine manufacturer Briggs Stratton which may have affected 12,789 of its employees and potentially resulted in the exposure of names, addresses, dates of birth, driver’s license numbers, Social Security numbers, health...
Theft of Patient Information and Tax Fraud Guilty Charge for Former Nurse Convicted
A former staff nurse, 41-year old Tangela Lawson-Brown from Midway, has been found guilty by a court in Tallahassee of the theft of patient information in order to commit aggravated identity theft and wire fraud, and to steal government funds. Between October 2011...
Advanced Spine & Pain Center HIPAA Breach Affect 8,362 Patients
The San Antonio, TX, Advanced Spine & Pain Center (ASPC) has advised clients of a possible breach that could have affected as many as 8,362 patients. ASPC became aware of a potential violation of ePHI on July 31, 2017 when some clients reported receiving a...
Michigan Health Provider Pays to Recover PHI Following Ransomware Attack
Over the weekend of August 12-13 an individual obtained access to a file server used by Ashland, MI-based Namaste Health Care and installed ransomware software encrypting data including patients’ protected health information. However, prior to the ransomware being...
Possible PHI Exposure Following Theft of Unencrypted Laptop from Virginia Health Practice
An unencrypted laptop device has been stolen from the automobile of an staff worker of Bassett Family Practice in Virginia, possible leading to the exposure of the protected health information of the Practice's clients. It is believed that the device, a laptop...
16,500 Patients Possibly Affected by Chase Brexton Health Care Phishing Attack
Chase Brexton Health Care has reported that the group experienced a phishing cyber attack on August 2 and August 3, 2017 and may have affected as many as 16,562 patients. The cyber attack involved multiple phishing emails being delivered to the inboxes of its...
Healthcare Organizations and Business Associates Connected by HIPAA Alliance Marketplace
Healthcare organizations often outsource many HIPAA transactions to third-party vendors, yet finding suitable companies that can provide the necessary services can be a time-consuming process. While there is unlikely to be a shortage of companies that could perform...
Email HIPAA Breach Affects 1300 Patients of RiverMend Health
RiverMend Health, a Augusta, GA-based specialty behavioral health provider has reported an unauthorized person has gained access to the email account of one of its employees after suspicious emails were identified being sent from that employee’s account. The...
Nurse Sacked for a HIPAA Violation Loses Legal Action Against Termination
A nurse sacked for a HIPAA violation has lost her legal action against the termination of her employment and a subsequent appeal. On May 7, 2013, Dianna Hereford – a Registered Nurse at the Norton Audubon Hospital in Louisville, KY – was assisting a transesophageal...
Unsecured Amazon S3 Bucket Leads to Breach of Medical Records and Test Results
Another unsecured Amazon S3 bucket used by a HIPAA-covered entity has been found by Kromtech Security. The unsecured bucket was storing contained 47.5GB of medical details relating to around 150,000 people. The medical details contained in the files included blood...
Naperville Psychiatrist May Have Had PHI of 10,500 Patients Exposed
The medical details of in excess of 10,000 patients of a Naperville, IL-based psychiatrist – Dr. Riaz Baber, M.D. – have been located in the basement of an Aurora residence by the female who rented the house from the psychiatrist. The files in question had been kept...
Certification of Compliance for Health Plans: HHS Withdraws Proposed Rule
At the beginning of 2014 the HHS proposed a new rule for certification of compliance for health plans which would have required all controlling health plans (CHPs) to complete a range of documentation. This would have shown the HHS that the CHPS were in compliance...
HIV Status of Subscribers May Have Been Revealed by Amida Care
Amida Care, the New York-based not-for-profit community health plan, advised that a possible HIPAA breach may have occurred impacting up to 6,231 of its subscribers. The group provides health coverage and coordinated care to Medicaid subscribers with chronic health...
U.S. House of Representatives Approves Internet of Medical Things Resilience Partnership Act
The U.S. House of Representatives has paased the Internet of Medical Things Resilience Partnership Act, aiming to put in place a public-private stakeholder partnership. This partnership will be charged with developing a cybersecurity framework that can be implemented...
Data Breach after Resold Fax Machine Starts to Print Private Data
A fax machine used by a Doctor at Grand Rapids, MI, based Spectrum Health System was recently found to contain the PHI of almost 20 patients. The fax machine was bought from resale shop by a local, who found documents were still stored in the memory of the machine....
Study Shows Majority of Workforce Lacks Privacy and Security Awareness
According to a recent study by MediaPro, a provider of privacy and security awareness training, best practices for privacy and security are still not well understood by 70% of U.S. employees. For the study, MediaPro questioned 1,012 U.S. workers and posed them a range...
CoPilot Texas-based Texas Patients Just Informed of 2015 Breach
Texas orthopedic clinic CoPilot are just now informing their patients that their protected health information may have been exposed in a 2015 CoPilot data breach. In October 2015, an online portal managed by CoPilot Provider Support Services was accessed by an...
$264,000 Settlement Agreed by Vermont Attorney General for SAManage USA Data Breach
A settlement of $264,000 has been agreed with the Vermont Attorney Genera and SAManage USA in relation to the 2016 data breach that resulted in the Social Security numbers of 660 Vermont residents being exposed online. SAManage USA, a technology group that supplies...
PeaceHealth: Former Employee Accessed Private Data for Over Six Years
A Catholic health system based in Vancouver, WA PeaceHealth, has revealed discovered that a former member of staff had accessed the medical history of almost 2,000 patients without any an adequate work reason. The unauthorized and inappropriate access was found by...
3,725 Veterans have Private Data Exposed Due to Stolen Laptop
Almost 4,000 people have potentially had their sensitive patient data exposed in Spokane, WA after a laptop computer once used by the Mann-Grandstaff VA Medical Center (MGVAMC) has been reported as missing. The laptop device was paired with a hematology analyzer and...
21,856 Individuals Have Data Breached After Attack on HIPAA Business Associate
Nebraska-based CBS Consolidated Inc., operating as Cornerstone Business & Management Solutions, completed a routine audit of system logs on July 10, 2017 and discovered a seemingly strange account on their servers. This case further highlights the importance of...
Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.
COMPREHENSIVE HIPAA TRAINING
Used in 1000+ Healthcare Organizations and 100+ Universities

Privacy is key to everything that we do at J Flowers Health Institute. We require the highest data privacy standards in our daily operations between our team members and patients. The HIPAA compliance and cyber security training we provide to our teams with ComplianceJunction creates enormous value for our organization.
Kevin DeLoach
Chief Operating Officer
J. Flowers Health Institute