• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

Recent HIPAA, Ransomware & Data Privacy Issues to Put at The Top of Your List

December 12, 2022/in Blog, Data Privacy, HIPAA, Risk Management

Recent HIPAA, Ransomware & Data Privacy Issues to Put at The Top of Your List

Guest Author: Rachel V. Rose, JD, MBA

The Holidays are always a hectic time of year. Here are some timely events that healthcare industry participants should appreciate.

First, a significant number of people at one point in their lives, have “peaked” at presents before the actual holiday. When it comes to medical records “peaking” out of curiosity, self-gain, and/or financial remuneration is prohibited under HIPAA and may lead to either a civil and/or criminal action, as well as adverse action from a state licensure board. A recent example occurred at a health system in Kentucky, where software detected a physician’s illegal access of patient records, including mental health records. Specifically, the physician accessed “the patient records of women he wanted to pursue romantically.” The health system’s Chief Medical Officer filed a related grievance with the Kentucky Board of Medical Licensure and the physician was terminated as a member of the medical staff. The Kentucky Board investigated, the physician underwent additional training, his attorney was involved in the communications, and the physician’s medical license is on probation for five years.

Second, most people have “regifted” an item at some point. Many forms of ransomware are “opened” by one person, only to be “reopened” again by another individual. On November 21, 2022, the Office of Information Security (HHS) and the Health Sector Cybersecurity Coordination Center issued a report about Lorenz Ransomware. This particular ransomware has been around for approximately two years and engages in “big-game hunting” or whale phishing – that is targeting larger organizations in the extortion process. “Lorenz is known to target organizations globally using customized code, and can demand hundreds of thousands of dollars in ransoms.” One of the key take-aways from the report follows:

Lorenz is human-operated ransomware, run by operators known to be customize their executable code, tailoring it for their targets. This implies that they may maintain persistent access for reconaissance purposes for some extended period of time prior to ransomware deployment. They often follow the pattern of initial access, followed by reconaissance and lateral movement, ultimately seeking a Windows domain controller in search of administrator credentials.

As articulated in my recent Physicians Practice article, cybercriminals use holidays and weekends to strike. Be sure to have appropriate safeguards and remain vigilant in both personal and professional transactions.

Finally, for those who celebrate Christmas, an alignment of incentives often occurs between children and adults – improved behavior because Santa is watching. On November 28th, HHS issued a Notice of Proposed Rule Making (NPRM) that “would implement provisions of Section 3221 of the Coronavirus Aid, Relief, and Economic Security Act (CARES Act) that, among other things, require HHS to bring [42 CFR] Part 2 into greater alignment with certain aspects of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Breach Notification, and Enforcement Rules.” Part 2 and HIPAA currently diverge in relation to substance use disorder (SUD) records – posing different requirements and creating barriers and compliance challenges. Public comments are due 60 days after November 28, 2022. HHS is encouraging all stakeholders, including patients and their families, as well as facilities and medical professionals, to submit comments. The key areas follow:

Today’s proposed rule outlines several important changes that can help safeguard the health and outcomes of individuals with SUD and create greater flexibility for information sharing envisioned by Congress in its passage of Section 3221 of the CARES Act. Proposed changes include:

  • Permitted use and disclosure of Part 2 records based on a single patient consent given once for all future uses and disclosures for treatment, payment, and health care operations.
  • Permitted redisclosure of Part 2 records in any manner permitted by the HIPAA Privacy Rule, with certain exceptions.
  • New patient rights under Part 2 to obtain an accounting of disclosures and to request restrictions on certain disclosures, as also granted by the HIPAA Privacy Rule.
  • Expanded prohibitions on the use and disclosure of Part 2 records in civil, criminal, administrative, and legislative proceedings.
  • New HHS enforcement authority, including the imposition of civil money penalties for violations of Part 2.
  • Updated breach notification requirements to HHS and affected patients.
  • Updated HIPAA Privacy Rule Notice of Privacy Practices requirements to address uses and disclosures of Part 2 records and individual rights with respect to those records.

In sum, maintaining a culture of compliance is critical for any person. The Holiday Season can be particularly challenging; however, the stakes are high.

Rachel V. Rose, JD, MBARachel V. Rose, JD, MBA, advises clients on compliance, transactions, government administrative actions, and litigation involving healthcare, cybersecurity, corporate and securities law, as well as False Claims Act and Dodd-Frank whistleblower cases.

Originally posted on: physicianspractice.com

Tags: ransomware
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2022/12/dec_2022_article_ft.jpg 758 1200 FHC Staff https://1sthcc.com/wp-content/uploads/2022/10/1sthcc-logo-1024x378.jpg FHC Staff2022-12-12 12:29:412025-04-15 12:41:51Recent HIPAA, Ransomware & Data Privacy Issues to Put at The Top of Your List
You might also like
Data Breach Top 3 Factors to Reduce Costs of Data Breach
Why Healthcare Organizations Need to Take a New Approach to Cybersecurity & Data Privacy Training
The Insecurity of Everything: The Vital Importance of Hardware Data Security
Combatting Ransomware in Healthcare
Data Privacy and Cyber Security – What’s New?
HIPAA Cybersecurity Criminal Webinar The Criminal Side of Cybersecurity and HIPAA – Audio Version of the Webinar

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers
  • 5 Benefits of Automating Incident Reporting in Healthcare
  • Compliance Primer Series: Fraud, Waste and Abuse

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only