Topics: HIPAA, security, compliance
Earn CEUs with MPA's FREE Compliance Webinar!
Posted by Margaret Scavotto, JD, CHC on 4/5/23 10:08 AM
Sign up for MPA's FREE Compliance webinar:
All webinars start at 11:00 a.m. CST and are presented by Margaret Scavotto and Scott Gima
SNF Compliance Update
April 19, 2023
90 minutes
1.8 CCB CEUs
1.5 NAB CEUs
Topics: Training and Education, HIPAA, compliance
Earn CEUs with MPA’s Virtual HIPAA Training!
Posted by Margaret Scavotto, JD, CHC on 3/6/23 10:34 AM
Topics: Training and Education, HIPAA, Social Media, security, breach notification, privacy, webinar
- The attackers recently used phishing emails to gain access to a victim’s computer using legitimate remote monitoring and management (RMM) software in financial schemes.
- The same tactics can be used for other purposes such as cybersecurity attacks or network backdoor access to conduct cyber espionage.
- Attackers use legitimate remote management software that cannot be detected by normal security measures that prevent unauthorized software installation.
- RMM software is commonly used by IT departments and managed service providers to provide remote technical support and troubleshooting.
- Every managed service provider and IT department use RMM software.
- In mid-June 2022, a federal civilian employee received a phishing email containing a phone number.
- The employee called the number, which led them to visit the malicious domain, myhelpcare[.]online. CISA found additional similar attacks on multiple federal civilian department networks.
- Attacks also used emails with a malicious link that downloaded the RMM software.
- The CISA alert mentioned that legitimate RMM software vendors AnyDesk and ScreenConnect were identified in these attacks. CISA indicated that any legitimate RMM software can be used in these types of attacks.
Topics: HIPAA, data breach, security
Earn CEUs with MPA’s Virtual HIPAA Training!
Posted by Margaret Scavotto, JD, CHC on 2/22/23 8:30 AM
Topics: Training and Education, HIPAA, Social Media, security, breach notification, privacy, webinar
Fake Nursing Degree Scam Involving Three Florida Nursing Schools
Posted by Scott Gima on 2/21/23 9:15 AM
The scheme
- 25 people were charged with wire fraud – administrators and employees of three Florida nursing schools as well as recruiters.
- The recruiters sought out individuals that were willing to pay $10,000 to $15,000 for fake nursing school documents that allowed them to take national nursing licensure examinations.
- A total of 7,600 fake nursing diplomas and transcripts (completion of required courses and clinicals) were provided to individuals from all over the US. The buyers wanted to take licensing exams to become registered nurses, licensed practical nurses, or licensed vocational nurse licenses.
- The three now closed nursing schools that issued the fake documents were Siena College, Sacred Heart International Institute, and Palm Beach School of Nursing.
- None of the individuals that bought the fake documents have been charged (yet).
Why is this Important?
- In a NY Times article, the special agent in charge for the Miami region of the Office of Inspector General said approximately 2,800 buyers passed the licensure exam.
- A large percentage of the 2,800 that passed are working.
- The NY Times article stated that providers that hired these nurses “included Veterans Affairs hospitals in Maryland and New York, a hospital in Georgia, a skilled nursing facility in Ohio, a rehabilitation center in New York and an assisted-living facility in New Jersey.”
What to do?
Topics: HIPAA, data breach, security
OCR Announces Settlement for Banner Health’s 2016 Data Breach
Posted by Scott Gima on 2/15/23 10:52 AM
The OCR notes serious concerns with Banner Health’s pervasive noncompliance with the HIPAA Security Rule
Banner Health
- OCR’s investigation of Banner’s data breach in 2016 found evidence of long-term, pervasive noncompliance with the HIPAA Security Rule across Banner Health’s organization, a serious concern given the size of this covered entity.
- Banner Health is one of the largest non-profit health systems in the country, with over 50,000 employees and operating in six states.
Findings
- No analysis to determine risks and vulnerabilities to electronic protected health information (ePHI) across the organization
- Insufficient monitoring of its health information systems’ activity to protect against a cyber-attack
- Failure to implement an authentication process to safeguard its ePHI
- Failure to have security measures in place to protect ePHI from unauthorized access when transmitted electronically
The Attack
- Banner Health discovered unauthorized access to process payment card data at some Banner Health food and beverage locations during a two-week period in June and July 2016.
- The attackers targeted payment card data, including cardholder name, card number, expiration date, and internal verification code, as the data was being routed through affected payment processing systems.
- Banner Health learned that attackers accessed patient information, health plan member and beneficiary information, and physician and other healthcare provider information.
- The attack hit 27 locations and 3.7 million individuals.
Why is this Important?
- The OCR indicated that hacking is the largest threat to ePHI, with 74% of 2021 reported breaches involving hacking/IT incidents.
- This settlement and corrective action plan remind us that healthcare providers must take action to protect the privacy and security of PHI. It is just as important to document all measures taken to secure ePHI.
- The corrective action plan states that Banner must do the following to address the findings of the OCR’s investigation:
- Conduct an accurate and thorough risk analysis to determine risks and vulnerabilities to electronic patient/system data across the organization.
- Develop and implement a risk management plan to address identified risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
- Develop, implement, and distribute policies and procedures for a risk analysis and risk management plan, the regular review of activity within their information systems, an authentication process to provide safeguards to data and records, and security measures to protect electronic protected health information from unauthorized access when it is being transmitted electronically.
What you should do
(Hint: Turn Banner’s Corrective Action Plan into a checklist)
Topics: HIPAA, data breach, security
Earn CEUs with MPA's FREE Compliance & HIPAA Webinars!
Posted by Margaret Scavotto, JD, CHC on 2/14/23 9:15 AM
Sign up for MPA's FREE Compliance & HIPAA webinars:
All webinars start at 11:00 a.m. CST and are presented by Margaret Scavotto and Scott Gima
Plan a Successful Compliance Week in 2023
February 22, 2023
90 minutes
1.8 CCB CEUs
1.5 NAB CEUs
This program has been approved for Continuing Education for 1.5 total participant hours by AB/NCERS—Approval #20240221-1.50-A90033-DL.
SNF Compliance Update
April 19, 2023
90 minutes
1.8 CCB CEUs
1.5 NAB CEUs
This program has been approved for Continuing Education for 1.5 total participant hours by NAB/NCERS—Approval #20240418-1.50-A90034-DL
The Compliance Certification Board (CCB)® has approved these events for up to 1.8 ive CCB CEUs based on a 50-minute hour, each. Continuing Education Units are awarded based on individual attendance records. Granting of prior approval in no way constitutes endorsement by CCB of this event content or of the event sponsor.
Topics: Training and Education, HIPAA, compliance
Topics: Training and Education, HIPAA, Social Media, security, breach notification, privacy, webinar
Earn CEUs with MPA's FREE Compliance & HIPAA Webinars!
Posted by Margaret Scavotto, JD, CHC on 2/2/23 11:33 AM
Sign up for MPA's FREE Compliance & HIPAA webinars:
All webinars start at 11:00 a.m. CST and are presented by Margaret Scavotto and Scott Gima
Plan a Successful Compliance Week in 2023
February 22, 2023
90 minutes
1.8 CCB CEUs
1.5 NAB CEUs
This program has been approved for Continuing Education for 1.5 total participant hours by AB/NCERS—Approval #20240221-1.50-A90033-DL.
SNF Compliance Update
April 19, 2023
90 minutes
1.8 CCB CEUs
1.5 NAB CEUs
This program has been approved for Continuing Education for 1.5 total participant hours by NAB/NCERS—Approval #20240418-1.50-A90034-DL
The Compliance Certification Board (CCB)® has approved these events for up to 1.8 ive CCB CEUs based on a 50-minute hour, each. Continuing Education Units are awarded based on individual attendance records. Granting of prior approval in no way constitutes endorsement by CCB of this event content or of the event sponsor.
Topics: Training and Education, HIPAA, compliance