An investigation by HHS' Office of Inspector General found that the National Institutes of Health did not have proper security controls and policies in place to protect patient data in its EHR.
Cybersecurity
A bipartisan group of U.S. senators are probing Google and St. Louis-based Ascension again for more information on the controversial "Project Nightingale," according to The Wall Street Journal.
A former patient at Huntsville (Ala.) Hospital is claiming an employee improperly viewed her medical records, according to local news station WAFF.
Numerous privacy incidents at hospitals, pharmacy providers and other healthcare organizations captured public attention in February.
Walgreens is alerting consumers about a vulnerability in its mobile app that exposed users' personal information, according to ZDNet.
Honolulu-based The Queen's Health System began notifying nearly 2,900 patients Feb. 21 that their information may have been exposed when an employee emailed the wrong person.
New York City-based Northwell Health is alerting prospective employees about unauthorized individuals falsely using the health system’s name.
Nashville-based Tennessee Orthopaedic Alliance began alerting 81,146 patients Feb. 14 that their information may have been exposed in a phishing scheme.
Twenty-nine employees at Munson Healthcare fell victim to a phishing attack that allowed an unauthorized third party access to patient data, according to the Cadillac News.
Lake Success, N.Y.-based Personal-Touch Home Care, a branded home healthcare company that provides services across the state, has notified more than 157,000 patients that their information may have been exposed in a ransomware attack against a third-party vendor.