Community Health Systems reports GoAnywhere hacked

Community Health Systems reports GoAnywhere hacked

Community Health Systems filed with the Securities and Exchange Commission that it was notified by a third-party vendor for secure file transfer of an incident that resulted in unauthorized disclosure of its patient data.WHY IT MATTERS
The GoAnywhere managed file transfer platform first warned about a zero-day remote code injection exploit on February 1, according to the technical bulletin posted by noted security researcher Brian Krebs on Infosec.exchange. 
“The attack vector of this exploit requires access to the administrative console of the application, which in most cases is accessible only from within a private company network, through [virtual private network] or by allow-listed IP…

Continue Reading
The Path Forward for Healthcare’s People Matching Problem

The Path Forward for Healthcare’s People Matching Problem

The following is a guest article by Rachel Podczervinski MS, RHIA, Vice President of Professional Services at Harris Data Integrity Solutions.
Efforts to identify the right path forward for healthcare’s patient matching problem are gaining a foothold as stakeholders from across the spectrum come together to remove obstacles and implement effective solutions. Most notably, in 2022, efforts by industry organizations like Patient ID Now led to the temporary removal of Section 510 from the U.S. House and Senate Labor, Health and Human Services, Education, and Related Agencies (Labor-HHS) appropriations bills. While it was ultimately reinserted in the final version, its initial removal…

Continue Reading
Several Louisiana hospitals face online tracking lawsuits

Several Louisiana hospitals face online tracking lawsuits

The class action lawsuits filed by Herman Herman & Katz allege Meta Pixel code potentially analyzed, gathered and shared the sensitive medical data of hundreds of thousands of patients across the LCMC Health Systems and Willis-Knighton Health System networks.WHY IT MATTERS
Pixel technology uses a Java tracking script to send an organization’s data to the technology owner, which in this case, is Meta, owner of Facebook, Instagram and WhatsApp. Tracked data could be shared with network marketing partners who target individuals with offers and advertisements.
The new class action lawsuit alleges that visitors to the health system websites may have had their protected…

Continue Reading
What Is PHI, and How Can Healthcare Organizations Keep It Secure?

What Is PHI, and How Can Healthcare Organizations Keep It Secure?

What Is Protected Health Information?According to UC Berkeley’s Human Research Protection Program, PHI includes any information found in medical records or clinical data sets that can be used to identify an individual. In addition, this information must have been collected, used or disclosed while providing a healthcare service. PHI can be used during the diagnosis or treatment of a patient or in clinical research processes.
The HIPAA Privacy Rule and Security Rule require the protection of identifiable health information, such as:
Information collected by doctors, nurses and other healthcare providers in the medical record
Conversations between doctors and other healthcare providers about a patient’s…

Continue Reading