Healthcare organizations often outsource many HIPAA transactions to third-party vendors, yet finding suitable companies that can provide the necessary services can be a time-consuming process. While there is unlikely to be a shortage of companies that could perform...
Email HIPAA Breach Affects 1300 Patients of RiverMend Health
RiverMend Health, a Augusta, GA-based specialty behavioral health provider has reported an unauthorized person has gained access to the email account of one of its employees after suspicious emails were identified being sent from that employee’s account. The...
Nurse Sacked for a HIPAA Violation Loses Legal Action Against Termination
A nurse sacked for a HIPAA violation has lost her legal action against the termination of her employment and a subsequent appeal. On May 7, 2013, Dianna Hereford – a Registered Nurse at the Norton Audubon Hospital in Louisville, KY – was assisting a transesophageal...
Unsecured Amazon S3 Bucket Leads to Breach of Medical Records and Test Results
Another unsecured Amazon S3 bucket used by a HIPAA-covered entity has been found by Kromtech Security. The unsecured bucket was storing contained 47.5GB of medical details relating to around 150,000 people. The medical details contained in the files included blood...
Naperville Psychiatrist May Have Had PHI of 10,500 Patients Exposed
The medical details of in excess of 10,000 patients of a Naperville, IL-based psychiatrist – Dr. Riaz Baber, M.D. – have been located in the basement of an Aurora residence by the female who rented the house from the psychiatrist. The files in question had been kept...
Certification of Compliance for Health Plans: HHS Withdraws Proposed Rule
At the beginning of 2014 the HHS proposed a new rule for certification of compliance for health plans which would have required all controlling health plans (CHPs) to complete a range of documentation. This would have shown the HHS that the CHPS were in compliance...
HIV Status of Subscribers May Have Been Revealed by Amida Care
Amida Care, the New York-based not-for-profit community health plan, advised that a possible HIPAA breach may have occurred impacting up to 6,231 of its subscribers. The group provides health coverage and coordinated care to Medicaid subscribers with chronic health...
U.S. House of Representatives Approves Internet of Medical Things Resilience Partnership Act
The U.S. House of Representatives has paased the Internet of Medical Things Resilience Partnership Act, aiming to put in place a public-private stakeholder partnership. This partnership will be charged with developing a cybersecurity framework that can be implemented...
Data Breach after Resold Fax Machine Starts to Print Private Data
A fax machine used by a Doctor at Grand Rapids, MI, based Spectrum Health System was recently found to contain the PHI of almost 20 patients. The fax machine was bought from resale shop by a local, who found documents were still stored in the memory of the machine....
Study Shows Majority of Workforce Lacks Privacy and Security Awareness
According to a recent study by MediaPro, a provider of privacy and security awareness training, best practices for privacy and security are still not well understood by 70% of U.S. employees. For the study, MediaPro questioned 1,012 U.S. workers and posed them a range...
CoPilot Texas-based Texas Patients Just Informed of 2015 Breach
Texas orthopedic clinic CoPilot are just now informing their patients that their protected health information may have been exposed in a 2015 CoPilot data breach. In October 2015, an online portal managed by CoPilot Provider Support Services was accessed by an...
$264,000 Settlement Agreed by Vermont Attorney General for SAManage USA Data Breach
A settlement of $264,000 has been agreed with the Vermont Attorney Genera and SAManage USA in relation to the 2016 data breach that resulted in the Social Security numbers of 660 Vermont residents being exposed online. SAManage USA, a technology group that supplies...
PeaceHealth: Former Employee Accessed Private Data for Over Six Years
A Catholic health system based in Vancouver, WA PeaceHealth, has revealed discovered that a former member of staff had accessed the medical history of almost 2,000 patients without any an adequate work reason. The unauthorized and inappropriate access was found by...
3,725 Veterans have Private Data Exposed Due to Stolen Laptop
Almost 4,000 people have potentially had their sensitive patient data exposed in Spokane, WA after a laptop computer once used by the Mann-Grandstaff VA Medical Center (MGVAMC) has been reported as missing. The laptop device was paired with a hematology analyzer and...
21,856 Individuals Have Data Breached After Attack on HIPAA Business Associate
Nebraska-based CBS Consolidated Inc., operating as Cornerstone Business & Management Solutions, completed a routine audit of system logs on July 10, 2017 and discovered a seemingly strange account on their servers. This case further highlights the importance of...
Mercy Health Love County Hospital Breach: Private Data of Almost 13k People Under Threat After
A HIPAA violation at Mercy Health Love County Hospital may have exposed the private information of in excess pf 13,000 patients in Oklahoma. On June 23, 2017, the health centre found that a member of staff employee had stolen a laptop computer and paper records from a...
Responding to Negative Yelp Comments Breached HIPAA
Some healthcare organizations have violated patient privacy and HIPAA Rules when responding to negative critiques on Yelp and otherreview sites according to a recent ProPublica report. For the report, ProPublica was given with access to around 1.7 million Yelp reviews...
HIPAA Omnibus Rule Set to Finally be Passed
The HIPAA Omnibus Rule (Health Insurance Portability and Accountability Act of 1996 Omnibus Rule) was drafted in July 2010; however the final release has been put off until this month some of the concerns raised by stakeholders about the latest HIPAA amendment can be...
Huge HIPAA Settlement Due to Unencrypted Data on Laptop
The U.S. Department of Health and Human Services Office for Civil Rights (OCR) has just received a joint settlement of $1,975,220 for the potential breaches of HIPAA arising following the theft of a laptop storing unencrypted ePHI data. The failure to adhere to the...
HIPAA Breach Response Program Guides Medical Group Though OCR Audit
The Californian multi-specialty physician’s group, Imperial Valley Family Care Medical Group (IVFCMG), has recently been audited by the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) following a potential breach of patients’ protected...
HIPAA Violations Legal Actions Settled with General Children’s Hospital
Less than one month after Boston’s Beth Israel Deaconess Medical Center reached a settlement with the Massachusetts Attorney General for HIPAA violations after a laptop was stolen containing unencrypted PHI, Boston Children’s Hospital has been fined for failing to...
13,000 Patients’ PHI Breached Following Hand Rehabilitation Specialists Suffering Data Theft
A security breach that has potentially impacted almost 13,000 patients has been announced by Hand & Upper Extremity Centers. The breach happened at Thousand Oaks, CA-based Hand Rehabilitation Specialists (HRS). While it is unclear when the breach actually...
Photographs of Patient’s Genital Injury Shared by Hospital Staff
An review has been completed into a privacy violation at the University of Pittsburgh Medical Center’s Bedford Memorial hospital, in a case which photographs and videos of a patient’s genitals were captured by hospital staff and in some cases, were shared with other...
Denver: Private Patient Health Records Found in Alley
Almost 70 patient files containing sensitive personal and medical data have been found in an alley in Denver, CO. The files include details of patients’ medical histories, insurance information, and Social Security numbers – The types of information chased by identity...
Hospital Sued After Informing Employer of Patient’s HIV Status
The Department of Health and Human Services’ Office for Civil Rights, earlier in 2017, settled a case with Mount Sinai St. Luke’s Hospital to resolve alleged breaches of HIPAA following a 2014 impermissible disclosure of a patient’s HIV positive status to his...
CareFirst Data Facing Supreme Court Heating Following Breach
In June 2014, hackers succeeded in accessing to a database controlled by CareFirst BlueCross BlueShield and the secured health information of 1.1 million of its members. The types of information exposed due to the hack included names, email addresses, dates of birth,...
AETNA Facing Legal Action for Patient HIV Status Breach
Aetna is facing a class action lawsuit following a privacy breach that saw the HIV positive status of up to 12,000 individuals disclosed against the patients' wishes. The individuals names and addresses were visible during a recent mail distribution when details of...
Breach Notification Rule is Violated by Delaying Breach Notifications
The HIPAA Breach Notification Rule (45 CFR §§ 164.400-414) states that all covered entities must notify the HHS’ Office for Civil Rights of a breach of unsecured protected health information and issue notification letters to affected people without unreasonable delay...
Partnership Between HITRUST and Trend Micro Announced
The Health Information Trust Alliance (HITRUST) is looking to improve its threat information sharing capabilities and provide more assistance to HIPAA covered entities to help them manage cyber threats more effectively. HITRUST is already providing detailed...
Healthcare Data Breach Trends Revealed by Protenus
The Breach Barometer mid year reviews has been released by Protenus, in conjunction with Databreaches.net. This report covers all data privacy breaches reported in health care over the past 6 months. It provides valuable insights into 2017 data breach trends for the...
Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.
COMPREHENSIVE HIPAA TRAINING
Used in 1000+ Healthcare Organizations and 100+ Universities
Privacy is key to everything that we do at J Flowers Health Institute. We require the highest data privacy standards in our daily operations between our team members and patients. The HIPAA compliance and cyber security training we provide to our teams with ComplianceJunction creates enormous value for our organization.
Kevin DeLoach
Chief Operating Officer
J. Flowers Health Institute






























