eupolicy.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
This Mastodon server is a friendly and respectful discussion space for people working in areas related to EU policy. When you request to create an account, please tell us something about you.

Server stats:

217
active users

#hhsocr

0 posts0 participants0 posts today

So... apart from the fact that I don't think they should have dropped charges against this doctor, is HHS going to investigate why the hospital gave access to patient data to a former employee/resident who no longer worked there and was never these patients' doctor?

US Justice Department drops case against Texas doctor charged with leaking transgender care data:
wfaa.com/article/news/local/us

www.wfaa.comBefore you continue to YouTube

HHS OCR settles charges that Inmediata Health Group was exposing patient protected health info online for 3 years due to a webpage error.

Inmediata previously settled a class action lawsuit stemming from the 2016-2019 leak. They also settled a lawsuit by 33 state attorneys general last year. The HHS OCR settlement was for $250k monetary penalty; no corrective action plan was needed since the states' settlement already included a corrective action plan.

Direct link to the resolution agreement:

hhs.gov/hipaa/for-professional

Press release: hhs.gov/about/news/2024/12/10/

Inmediata even had trouble with their incident response, as noted on my blog at the time: databreaches.net/2019/04/30/in

#HHSOCR announced a $1.19M monetary penalty for Gulf Coast Pain Consultants stemming from a 2019 #databreach. Now we find out that the "third party" that accessed the data was a former contractor.

The covered entity got hit with a fine for failure to:

  • conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to ePHI in its systems;
  • implement procedures to regularly review records of activity in information systems;
  • implement procedures to terminate former workforce members’ access to ePHI; and
  • implement procedures for establishing and modifying workforce members’ access to information systems.

databreaches.net/2024/12/03/hh

HHS Office for Civil Rights Settles Ransomware Cybersecurity Investigation under HIPAA Security Rule for $250,000 - September 26, 2024

hhs.gov/about/news/2024/09/26/

This stemmed from a March 2017 #ransomware attack and #databreach affecting Cascade Eye & Skin Centers in WA. #HHSOCR became aware of it in May 2017.

Why did it take 7+ years to resolve this?

And btw, I never knew about this breach and even now, cannot find any major media coverage or disclosure of it at the time. And it never showed up on HHS's public breach tool during all this time. Why didn't it show up if it affected 291,000?

This is HHSOCR's 4th ransomware-related investigation under the #HIPAA Security Rule.

@brett @campuscodi