article thumbnail

DOJ Settles Civil Cyber Fraud Initiative Case with CHS and Imposes a $930,000 Penalty

HIPAA Journal

This is the first settlement to be reached under the DOJ Civil Cyber Fraud Initiative, which was launched in 2021. CHS staff scanned medical records for the EMR system but saved scanned copies of some of the records on an internal network drive, which could be accessed by non-clinical staff, including Iraqi nationals employed at the site.

Fraud 95
article thumbnail

2 DOJ Cyber Fraud Initiative Cases Net Almost $10 Million

Compliancy Group

Department of Justice’s (DOJ) Civil Cyber Fraud Initiative (CCFI). Details of DOJ Cyber Fraud Initiative Settlements. Even after staff raised concerns about the privacy of protected medical information, CHS did not take adequate steps to store the data exclusively on the EMR system.

Fraud 52
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

First Choice Community Healthcare and Arlington Skin Notify Patients About Cyberattacks

HIPAA Journal

Arlington Skin Notifies 17,468 Patients About Electronic Medical Record Data Breach. VPN Solutions managed the electronic medical records of patients of Arlington Skin via the Allscripts practice management solution and electronic medical records platform. Dr. Michelle A.

article thumbnail

U.S. Healthcare Compliance Frameworks: A Guide for International Vendors

Compliancy Group

Because care requires using and exchanging sensitive patient information, adherence to U.S. When personal health information transcends international borders, vendors outside the U.S. When unauthorized parties gain access to this information, identity theft, fraud, and diminished care often result. Specifically, the U.S.

article thumbnail

LifeBridge Health Agrees to $9.5 Million Settlement to Resolve 2016 Data Breach Claims

HIPAA Journal

In March 2018, LifeBridge Health discovered a malware infection that provided unauthorized individuals with access to a server that hosted its electronic medical records, patient registration, and billing systems. The breach investigation determined the initial intrusion occurred 18 months previously in September 2016.

article thumbnail

CommonSpirit Health Facing Class Action Lawsuit over Ransomware Attack and Data Breach

HIPAA Journal

The attack forced the shutdown of its electronic medical record system and caused considerable disruption over several weeks, with the catholic health system having to cancel many appointments. Michael Medical Center. Lawsuits often fail when they are based solely on an elevated risk of identity theft and fraud.

article thumbnail

Washington Hospital Pays $240,000 HIPAA Penalty After Security Guards Access Medical Records

HIPAA Journal

The HHS’ Office for Civil Rights (OCR) investigates all reported breaches of the protected health information of 500 or more individuals and some smaller breaches to determine if the breach was caused by the failure to comply with the HIPAA Rules.

HIPAA 89