Advertisement

Cybersecurity

Morgantown, W.Va.-based Monongalia Health System and its affiliated hospitals began notifying patients Dec. 21 that their protected health information may have been exposed during an email phishing incident the health system experienced earlier this year. 

HHS' Office for Civil Rights issued new guidance Dec. 20 to explain how HIPAA covers healthcare providers who disclose protected health information to support instances of extreme risk protection orders. 

Hackensack, N.J.-based Regional Cancer Care Associates will pay $425,000 and implement new privacy and security measures to settle a 2019 data breach that exposed 105,200 patients' information, the New Jersey acting attorney general's office said Dec. 15. 

Advertisement

Certain Hillrom Welch Allyn cardiology products have an authentication vulnerability that could let hackers gain access to privileged accounts, the Cybersecurity and Infrastructure Security Agency recently announced. 

Advertisement