Community Health Systems reports GoAnywhere hacked

Community Health Systems reports GoAnywhere hacked

Community Health Systems filed with the Securities and Exchange Commission that it was notified by a third-party vendor for secure file transfer of an incident that resulted in unauthorized disclosure of its patient data.WHY IT MATTERS
The GoAnywhere managed file transfer platform first warned about a zero-day remote code injection exploit on February 1, according to the technical bulletin posted by noted security researcher Brian Krebs on Infosec.exchange. 
“The attack vector of this exploit requires access to the administrative console of the application, which in most cases is accessible only from within a private company network, through [virtual private network] or by allow-listed IP…

Continue Reading
Leveraging Technology to Bridge Gaps in Compliance

Leveraging Technology to Bridge Gaps in Compliance

Sean Eaton, Senior Compliance Solutions Specialist at GHXAmerican health systems, hospitals and post-acute care providers are required to comply with hundreds of regulatory requirements. Facilitating this compliance comes with a high cost. According to the American Hospital Association, the average-sized community hospital spends nearly $7.6 million annually on administrative activities to support regulatory compliance. With the impending end of the COVID-19 public health emergency set to shake up healthcare regulations, ongoing healthcare labor shortages, and skyrocketing levels of clinician burnout, a perfect storm for non-compliance is brewing. Even with significant investments in administration to support compliance, overwhelmed providers can inadvertently leave gaps…

Continue Reading
‘A Mindset Shift’: How Senior Care Communities Adapt to Modern Tech Expectations

‘A Mindset Shift’: How Senior Care Communities Adapt to Modern Tech Expectations

Glen Tibbitts, United Church Homes’ Corporate Director of IT and HIPAA Security Officer, says he’s noticed a “mindset shift” as residents’ expectations change. Photography by Leonardo Carrizo
“Otherwise, you’ll see people with a device that’s still in the box,” he says. “People will tend to engage with technology if they feel they have agency in the process. That’s really important.”
Looking ahead, UCH is piloting a number of clinical and lifestyle technologies, including a smart badge that transcribes the speech of employees and family members for deaf patients.
“It’s all about abundant life and abundant aging,” Tibbitts says. “We want to make the move…

Continue Reading
Health equity hindered by SDOH coding roadblocks

Health equity hindered by SDOH coding roadblocks

A new American Health Information Management Association study aimed at finding a better understanding of the operational realities of how social determinants of health data is used in real-world healthcare scenarios, finding a lack of standardization, insufficient training and limited cross-sector use.WHY IT MATTERS
The study, conducted by NORC at the University of Chicago, surveyed more than 2,600 AHIMA members and nonmembers from a pool of 41,000 potential respondents between August 24 and September 9, 2022.
Respondents included coding professionals; managers, directors and vice presidents of health information management; HIM team members and executives. 
SDOH data can offer additional insights to help enrich clinical decision-making…

Continue Reading
‘A Better Long-Term Solution’: How Health Systems Keep Workloads in the Cloud Secure

‘A Better Long-Term Solution’: How Health Systems Keep Workloads in the Cloud Secure

The evaluation process covers ­everything from compatibility to cost and the quality of customer service, but it also includes a comprehensive risk assessment led by the health system’s CISO.“Any vendor we’re potentially going to use must go through that assessment,” Meadows says. “We ask them about everything — their security infrastructure, their policy and procedure management, how they segment their networks — and then, based on their response, we can determine whether they’re a good fit or not.”
Cook Children’s also relies on a third-party system that allows it to check whether a particular vendor has experienced significant security issues in the…

Continue Reading
Hurdle, CloudLIMS Partner to Augment Diagnostic Lab Capabilities

Hurdle, CloudLIMS Partner to Augment Diagnostic Lab Capabilities

What You Should Know:– Hurdle (a Chronomics Inc. brand), a global bio-infrastructure platform that powers end-to-end diagnostics for life sciences, labs and healthcare providers, and CloudLIMS, a leading SOC 2 compliant and ISO 9001:2015 certified lab informatics provider, announced today that the companies have entered into a strategic partnership marking the first integration between a Diagnostic as a Service (DaaS) platform and a Software-as-a-Service (SaaS) LIMS provider.– The partnership brings together Hurdle’s remote diagnostic platform and CloudLIMS’s secure, purpose-built diagnostics LIMS to empower labs with the ability to offer at-home tests, and manage lab processes and data efficiently.Helping Diagnostic Labs Stay…

Continue Reading
Several Louisiana hospitals face online tracking lawsuits

Several Louisiana hospitals face online tracking lawsuits

The class action lawsuits filed by Herman Herman & Katz allege Meta Pixel code potentially analyzed, gathered and shared the sensitive medical data of hundreds of thousands of patients across the LCMC Health Systems and Willis-Knighton Health System networks.WHY IT MATTERS
Pixel technology uses a Java tracking script to send an organization’s data to the technology owner, which in this case, is Meta, owner of Facebook, Instagram and WhatsApp. Tracked data could be shared with network marketing partners who target individuals with offers and advertisements.
The new class action lawsuit alleges that visitors to the health system websites may have had their protected…

Continue Reading
How Healthcare Organizations Can Enhance Patient Experience & Trust During the Winter Surge

How Healthcare Organizations Can Enhance Patient Experience & Trust During the Winter Surge

Toni Land, Head of Clinical Healthcare Experience at MedalliaIt’s well known that the winter season typically creates spikes in illness and, consequently, a surge in healthcare visits. What might not be so obvious is that this time of increased demand is also the ideal opportunity for healthcare organizations to prioritize building trust and improving experiences for patients, clinicians and team members. Just as science grows more sophisticated each year, allowing practitioners to better treat a greater number of medical ailments, so should patient and team member experience efforts within the healthcare sector. That’s all the more true as the country now navigates…

Continue Reading
What Is PHI, and How Can Healthcare Organizations Keep It Secure?

What Is PHI, and How Can Healthcare Organizations Keep It Secure?

What Is Protected Health Information?According to UC Berkeley’s Human Research Protection Program, PHI includes any information found in medical records or clinical data sets that can be used to identify an individual. In addition, this information must have been collected, used or disclosed while providing a healthcare service. PHI can be used during the diagnosis or treatment of a patient or in clinical research processes.
The HIPAA Privacy Rule and Security Rule require the protection of identifiable health information, such as:
Information collected by doctors, nurses and other healthcare providers in the medical record
Conversations between doctors and other healthcare providers about a patient’s…

Continue Reading
Third-party data breach round-up: mscripts, Diligent, Mailchimp

Third-party data breach round-up: mscripts, Diligent, Mailchimp

This month, more than 114,000 individuals may have experienced personally identifiable information and protected health information exposures from these incidents, while an email marketing hack is a new source for phishing attacks.Medication adherence platform mscripts breached
On January 17, mscripts, a cloud-based mobile pharmacy platform that focuses on patient engagement and medication adherence solutions, reported to the U.S. Department of Health and Human Services unauthorized access/disclosure that involved protected health information of 66,372 individuals, according to the Office for Civil Rights cases under investigation list.
The San Francisco-based platform, owned by Dublin, Ohio-based Cardinal Health, uses interactive SMS messaging and branded mobile apps to…

Continue Reading