A Washington, D.C. District Court Judge ruled late Jan. 28 that sections of HIPAA that are designed to facilitate cheaper access to patients' medical records are not permissible under the Administrative Procedure Act, according to Politico's Morning eHealth newsletter.
Cybersecurity
Phoenix Children's Hospital began notifying 1,860 patients Jan. 14 that their information may have been exposed in a phishing attack.
Cook County (Ill.) Health began notifying 2,713 patients Jan. 24 that their personal information may have been sent to a third-party vendor who did not have a business agreement with the health system at the time.
A vulnerability in LabCorp's website allowed for thousands of medical documents, such as test results, to be searchable online, according to TechCrunch, which found the flaw.
Although technology companies can bring significant improvements to the healthcare industry, consumers should be wary about potential issues with data privacy, according to business columnist David Lazarus in the Los Angeles Times.
Patients of Georgetown, S.C.-based Tidelands Health have filed a class-action lawsuit claiming the health system failed to protect their personal health information following a malware attack, according to local ABC affiliate WPDE.
Southfield, Mich.-based Beaumont Health began notifying 1,182 patients Jan. 24 that their information may have been wrongfully disclosed, according to the Detroit Free Press.
The Cybersecurity and Infrastructure Security Agency released a notice Jan. 22 of an increase in the number of Emotet malware attacks.
Hackers using Maze ransomware have infected 231 stations from Medical Diagnostic Laboratories and are threatening to publicly disclose data on the computers if the company does not pay the ransom, according to Bleeping Computer.
Whittier, Calif.-based PIH Health began notifying 199,548 patients on Jan. 10 that their protected health information may have been exposed in a data breach.