home.social

#hhsocr — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #hhsocr, aggregated by home.social.

  1. DATE: May 20, 2026 at 04:06PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    @HHSOCR Revamps #HIPAA Enforcement Agency: How Might Restructuring Affect #Breach Investigations, Rulemaking, Guidance and Other Efforts?
    t.co/JRdN4ivPPJ #HHSOCR #HHS

    Here are any URLs found in the article text:

    t.co/JRdN4ivPPJ

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  2. DATE: May 20, 2026 at 04:06PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    @HHSOCR Revamps #HIPAA Enforcement Agency: How Might Restructuring Affect #Breach Investigations, Rulemaking, Guidance and Other Efforts?
    t.co/JRdN4ivPPJ #HHSOCR #HHS

    Here are any URLs found in the article text:

    t.co/JRdN4ivPPJ

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  3. DATE: May 20, 2026 at 04:06PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    @HHSOCR Revamps #HIPAA Enforcement Agency: How Might Restructuring Affect #Breach Investigations, Rulemaking, Guidance and Other Efforts?
    t.co/JRdN4ivPPJ #HHSOCR #HHS

    Here are any URLs found in the article text:

    t.co/JRdN4ivPPJ

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  4. DATE: May 20, 2026 at 04:06PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    @HHSOCR Revamps #HIPAA Enforcement Agency: How Might Restructuring Affect #Breach Investigations, Rulemaking, Guidance and Other Efforts?
    t.co/JRdN4ivPPJ #HHSOCR #HHS

    Here are any URLs found in the article text:

    t.co/JRdN4ivPPJ

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  5. DATE: April 17, 2025 at 05:41PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Guam Hospital Pays @HHSOCR $25K to Settle #HIPAA Investigation t.co/icn0x1ShGs #HHSOCR #GMHA

    Here are any URLs found in the article text:

    t.co/icn0x1ShGs

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  6. The Office of Civil Rights in the Department of Health and Human Services (HHS/OCR) used to do a fairly good job of protecting patient's sensitive information. They did this by enforcing the HIPAA security rules and penalties for non-compliance included fines, mandatory compliance programs, and CEO liability.

    No longer.

    HHS/OCR has now been weaponized to enforce anti-DEI initiatives of the current administration. Here is the recent headline from HHS/OCR:

    "OCR Investigates a Major Medical School in California for Reportedly Prioritizing Discriminatory Race-Based Criteria over Academic Merit"

    Right. What nonsense. Welcome aboard - your pilot is Dangerous and your Co-pilot is Stupid. Have a good flight.

    This will not be good.

    #HIPAA #HHS #HHSOCR

  7. The Office of Civil Rights in the Department of Health and Human Services (HHS/OCR) used to do a fairly good job of protecting patient's sensitive information. They did this by enforcing the HIPAA security rules and penalties for non-compliance included fines, mandatory compliance programs, and CEO liability.

    No longer.

    HHS/OCR has now been weaponized to enforce anti-DEI initiatives of the current administration. Here is the recent headline from HHS/OCR:

    "OCR Investigates a Major Medical School in California for Reportedly Prioritizing Discriminatory Race-Based Criteria over Academic Merit"

    Right. What nonsense. Welcome aboard - your pilot is Dangerous and your Co-pilot is Stupid. Have a good flight.

    This will not be good.

    #HIPAA #HHS #HHSOCR

  8. The Office of Civil Rights in the Department of Health and Human Services (HHS/OCR) used to do a fairly good job of protecting patient's sensitive information. They did this by enforcing the HIPAA security rules and penalties for non-compliance included fines, mandatory compliance programs, and CEO liability.

    No longer.

    HHS/OCR has now been weaponized to enforce anti-DEI initiatives of the current administration. Here is the recent headline from HHS/OCR:

    "OCR Investigates a Major Medical School in California for Reportedly Prioritizing Discriminatory Race-Based Criteria over Academic Merit"

    Right. What nonsense. Welcome aboard - your pilot is Dangerous and your Co-pilot is Stupid. Have a good flight.

    This will not be good.

    #HIPAA #HHS #HHSOCR

  9. The Office of Civil Rights in the Department of Health and Human Services (HHS/OCR) used to do a fairly good job of protecting patient's sensitive information. They did this by enforcing the HIPAA security rules and penalties for non-compliance included fines, mandatory compliance programs, and CEO liability.

    No longer.

    HHS/OCR has now been weaponized to enforce anti-DEI initiatives of the current administration. Here is the recent headline from HHS/OCR:

    "OCR Investigates a Major Medical School in California for Reportedly Prioritizing Discriminatory Race-Based Criteria over Academic Merit"

    Right. What nonsense. Welcome aboard - your pilot is Dangerous and your Co-pilot is Stupid. Have a good flight.

    This will not be good.

    #HIPAA #HHS #HHSOCR

  10. DATE: March 25, 2025 at 05:35PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    @HHSOCR Launches New Round of @HIPAA @ComplianceAudits t.co/H1mTSpm4G3 #HHSOCR

    Here are any URLs found in the article text:

    t.co/H1mTSpm4G3

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  11. Breach notifications needed to be made faster in 2024. Instead, they were made more slowly.

    Some findings from #Bluesight 2025 Breach Barometer report plus additional observations and my frustration with #HHSOCR for not enforcing the notification requirements in #HIPAA and #HITECH.

    databreaches.net/2025/03/13/br

    #databreach

  12. Breach notifications needed to be made faster in 2024. Instead, they were made more slowly.

    Some findings from #Bluesight 2025 Breach Barometer report plus additional observations and my frustration with #HHSOCR for not enforcing the notification requirements in #HIPAA and #HITECH.

    databreaches.net/2025/03/13/br

    #databreach

  13. Breach notifications needed to be made faster in 2024. Instead, they were made more slowly.

    Some findings from #Bluesight 2025 Breach Barometer report plus additional observations and my frustration with #HHSOCR for not enforcing the notification requirements in #HIPAA and #HITECH.

    databreaches.net/2025/03/13/br

    #databreach

  14. Breach notifications needed to be made faster in 2024. Instead, they were made more slowly.

    Some findings from #Bluesight 2025 Breach Barometer report plus additional observations and my frustration with #HHSOCR for not enforcing the notification requirements in #HIPAA and #HITECH.

    databreaches.net/2025/03/13/br

    #databreach

  15. Breach notifications needed to be made faster in 2024. Instead, they were made more slowly.

    Some findings from #Bluesight 2025 Breach Barometer report plus additional observations and my frustration with #HHSOCR for not enforcing the notification requirements in #HIPAA and #HITECH.

    databreaches.net/2025/03/13/br

    #databreach

  16. So... apart from the fact that I don't think they should have dropped charges against this doctor, is HHS going to investigate why the hospital gave access to patient data to a former employee/resident who no longer worked there and was never these patients' doctor?

    US Justice Department drops case against Texas doctor charged with leaking transgender care data:
    wfaa.com/article/news/local/us

    #HealthSec #HIPAA #SecurityRule #databreach #privacy #confidentiality #insiderthreat #HHS #HHSOCR

  17. So... apart from the fact that I don't think they should have dropped charges against this doctor, is HHS going to investigate why the hospital gave access to patient data to a former employee/resident who no longer worked there and was never these patients' doctor?

    US Justice Department drops case against Texas doctor charged with leaking transgender care data:
    wfaa.com/article/news/local/us

    #HealthSec #HIPAA #SecurityRule #databreach #privacy #confidentiality #insiderthreat #HHS #HHSOCR

  18. So... apart from the fact that I don't think they should have dropped charges against this doctor, is HHS going to investigate why the hospital gave access to patient data to a former employee/resident who no longer worked there and was never these patients' doctor?

    US Justice Department drops case against Texas doctor charged with leaking transgender care data:
    wfaa.com/article/news/local/us

    #HealthSec #HIPAA #SecurityRule #databreach #privacy #confidentiality #insiderthreat #HHS #HHSOCR

  19. So... apart from the fact that I don't think they should have dropped charges against this doctor, is HHS going to investigate why the hospital gave access to patient data to a former employee/resident who no longer worked there and was never these patients' doctor?

    US Justice Department drops case against Texas doctor charged with leaking transgender care data:
    wfaa.com/article/news/local/us

    #HealthSec #HIPAA #SecurityRule #databreach #privacy #confidentiality #insiderthreat #HHS #HHSOCR

  20. So... apart from the fact that I don't think they should have dropped charges against this doctor, is HHS going to investigate why the hospital gave access to patient data to a former employee/resident who no longer worked there and was never these patients' doctor?

    US Justice Department drops case against Texas doctor charged with leaking transgender care data:
    wfaa.com/article/news/local/us

    #HealthSec #HIPAA #SecurityRule #databreach #privacy #confidentiality #insiderthreat #HHS #HHSOCR

  21. HHS OCR settles charges that Inmediata Health Group was exposing patient protected health info online for 3 years due to a webpage error.

    Inmediata previously settled a class action lawsuit stemming from the 2016-2019 leak. They also settled a lawsuit by 33 state attorneys general last year. The HHS OCR settlement was for $250k monetary penalty; no corrective action plan was needed since the states' settlement already included a corrective action plan.

    Direct link to the resolution agreement:

    hhs.gov/hipaa/for-professional

    Press release: hhs.gov/about/news/2024/12/10/

    Inmediata even had trouble with their incident response, as noted on my blog at the time: databreaches.net/2019/04/30/in

    #HIPAA #HHSOCR #SecurityRule #Exposure #Databreach #dataleak #healthsec #Infosecurity

  22. HHS OCR settles charges that Inmediata Health Group was exposing patient protected health info online for 3 years due to a webpage error.

    Inmediata previously settled a class action lawsuit stemming from the 2016-2019 leak. They also settled a lawsuit by 33 state attorneys general last year. The HHS OCR settlement was for $250k monetary penalty; no corrective action plan was needed since the states' settlement already included a corrective action plan.

    Direct link to the resolution agreement:

    hhs.gov/hipaa/for-professional

    Press release: hhs.gov/about/news/2024/12/10/

    Inmediata even had trouble with their incident response, as noted on my blog at the time: databreaches.net/2019/04/30/in

    #HIPAA #HHSOCR #SecurityRule #Exposure #Databreach #dataleak #healthsec #Infosecurity

  23. HHS OCR settles charges that Inmediata Health Group was exposing patient protected health info online for 3 years due to a webpage error.

    Inmediata previously settled a class action lawsuit stemming from the 2016-2019 leak. They also settled a lawsuit by 33 state attorneys general last year. The HHS OCR settlement was for $250k monetary penalty; no corrective action plan was needed since the states' settlement already included a corrective action plan.

    Direct link to the resolution agreement:

    hhs.gov/hipaa/for-professional

    Press release: hhs.gov/about/news/2024/12/10/

    Inmediata even had trouble with their incident response, as noted on my blog at the time: databreaches.net/2019/04/30/in

    #HIPAA #HHSOCR #SecurityRule #Exposure #Databreach #dataleak #healthsec #Infosecurity

  24. HHS OCR settles charges that Inmediata Health Group was exposing patient protected health info online for 3 years due to a webpage error.

    Inmediata previously settled a class action lawsuit stemming from the 2016-2019 leak. They also settled a lawsuit by 33 state attorneys general last year. The HHS OCR settlement was for $250k monetary penalty; no corrective action plan was needed since the states' settlement already included a corrective action plan.

    Direct link to the resolution agreement:

    hhs.gov/hipaa/for-professional

    Press release: hhs.gov/about/news/2024/12/10/

    Inmediata even had trouble with their incident response, as noted on my blog at the time: databreaches.net/2019/04/30/in

    #HIPAA #HHSOCR #SecurityRule #Exposure #Databreach #dataleak #healthsec #Infosecurity

  25. HHS OCR settles charges that Inmediata Health Group was exposing patient protected health info online for 3 years due to a webpage error.

    Inmediata previously settled a class action lawsuit stemming from the 2016-2019 leak. They also settled a lawsuit by 33 state attorneys general last year. The HHS OCR settlement was for $250k monetary penalty; no corrective action plan was needed since the states' settlement already included a corrective action plan.

    Direct link to the resolution agreement:

    hhs.gov/hipaa/for-professional

    Press release: hhs.gov/about/news/2024/12/10/

    Inmediata even had trouble with their incident response, as noted on my blog at the time: databreaches.net/2019/04/30/in

    #HIPAA #HHSOCR #SecurityRule #Exposure #Databreach #dataleak #healthsec #Infosecurity

  26. #HHSOCR announced a $1.19M monetary penalty for Gulf Coast Pain Consultants stemming from a 2019 #databreach. Now we find out that the "third party" that accessed the data was a former contractor.

    The covered entity got hit with a fine for failure to:

    • conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to ePHI in its systems;
    • implement procedures to regularly review records of activity in information systems;
    • implement procedures to terminate former workforce members’ access to ePHI; and
    • implement procedures for establishing and modifying workforce members’ access to information systems.

    databreaches.net/2024/12/03/hh

    #HIPAA #HealthSec #SecurityRule #InsiderThreat #Access

  27. #HHSOCR announced a $1.19M monetary penalty for Gulf Coast Pain Consultants stemming from a 2019 #databreach. Now we find out that the "third party" that accessed the data was a former contractor.

    The covered entity got hit with a fine for failure to:

    • conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to ePHI in its systems;
    • implement procedures to regularly review records of activity in information systems;
    • implement procedures to terminate former workforce members’ access to ePHI; and
    • implement procedures for establishing and modifying workforce members’ access to information systems.

    databreaches.net/2024/12/03/hh

    #HIPAA #HealthSec #SecurityRule #InsiderThreat #Access

  28. #HHSOCR announced a $1.19M monetary penalty for Gulf Coast Pain Consultants stemming from a 2019 #databreach. Now we find out that the "third party" that accessed the data was a former contractor.

    The covered entity got hit with a fine for failure to:

    • conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to ePHI in its systems;
    • implement procedures to regularly review records of activity in information systems;
    • implement procedures to terminate former workforce members’ access to ePHI; and
    • implement procedures for establishing and modifying workforce members’ access to information systems.

    databreaches.net/2024/12/03/hh

    #HIPAA #HealthSec #SecurityRule #InsiderThreat #Access

  29. #HHSOCR announced a $1.19M monetary penalty for Gulf Coast Pain Consultants stemming from a 2019 #databreach. Now we find out that the "third party" that accessed the data was a former contractor.

    The covered entity got hit with a fine for failure to:

    • conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to ePHI in its systems;
    • implement procedures to regularly review records of activity in information systems;
    • implement procedures to terminate former workforce members’ access to ePHI; and
    • implement procedures for establishing and modifying workforce members’ access to information systems.

    databreaches.net/2024/12/03/hh

    #HIPAA #HealthSec #SecurityRule #InsiderThreat #Access

  30. #HHSOCR announced a $1.19M monetary penalty for Gulf Coast Pain Consultants stemming from a 2019 #databreach. Now we find out that the "third party" that accessed the data was a former contractor.

    The covered entity got hit with a fine for failure to:

    • conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to ePHI in its systems;
    • implement procedures to regularly review records of activity in information systems;
    • implement procedures to terminate former workforce members’ access to ePHI; and
    • implement procedures for establishing and modifying workforce members’ access to information systems.

    databreaches.net/2024/12/03/hh

    #HIPAA #HealthSec #SecurityRule #InsiderThreat #Access

  31. HHS Office for Civil Rights Settles Ransomware Cybersecurity Investigation under HIPAA Security Rule for $250,000 - September 26, 2024

    hhs.gov/about/news/2024/09/26/

    This stemmed from a March 2017 #ransomware attack and #databreach affecting Cascade Eye & Skin Centers in WA. #HHSOCR became aware of it in May 2017.

    Why did it take 7+ years to resolve this?

    And btw, I never knew about this breach and even now, cannot find any major media coverage or disclosure of it at the time. And it never showed up on HHS's public breach tool during all this time. Why didn't it show up if it affected 291,000?

    This is HHSOCR's 4th ransomware-related investigation under the #HIPAA Security Rule.

    @brett @campuscodi

  32. HHS Office for Civil Rights Settles Ransomware Cybersecurity Investigation under HIPAA Security Rule for $250,000 - September 26, 2024

    hhs.gov/about/news/2024/09/26/

    This stemmed from a March 2017 #ransomware attack and #databreach affecting Cascade Eye & Skin Centers in WA. #HHSOCR became aware of it in May 2017.

    Why did it take 7+ years to resolve this?

    And btw, I never knew about this breach and even now, cannot find any major media coverage or disclosure of it at the time. And it never showed up on HHS's public breach tool during all this time. Why didn't it show up if it affected 291,000?

    This is HHSOCR's 4th ransomware-related investigation under the #HIPAA Security Rule.

    @brett @campuscodi

  33. HHS Office for Civil Rights Settles Ransomware Cybersecurity Investigation under HIPAA Security Rule for $250,000 - September 26, 2024

    hhs.gov/about/news/2024/09/26/

    This stemmed from a March 2017 #ransomware attack and #databreach affecting Cascade Eye & Skin Centers in WA. #HHSOCR became aware of it in May 2017.

    Why did it take 7+ years to resolve this?

    And btw, I never knew about this breach and even now, cannot find any major media coverage or disclosure of it at the time. And it never showed up on HHS's public breach tool during all this time. Why didn't it show up if it affected 291,000?

    This is HHSOCR's 4th ransomware-related investigation under the #HIPAA Security Rule.

    @brett @campuscodi

  34. HHS Office for Civil Rights Settles Ransomware Cybersecurity Investigation under HIPAA Security Rule for $250,000 - September 26, 2024

    hhs.gov/about/news/2024/09/26/

    This stemmed from a March 2017 #ransomware attack and #databreach affecting Cascade Eye & Skin Centers in WA. #HHSOCR became aware of it in May 2017.

    Why did it take 7+ years to resolve this?

    And btw, I never knew about this breach and even now, cannot find any major media coverage or disclosure of it at the time. And it never showed up on HHS's public breach tool during all this time. Why didn't it show up if it affected 291,000?

    This is HHSOCR's 4th ransomware-related investigation under the #HIPAA Security Rule.

    @brett @campuscodi

  35. HHS Office for Civil Rights Settles Ransomware Cybersecurity Investigation under HIPAA Security Rule for $250,000 - September 26, 2024

    hhs.gov/about/news/2024/09/26/

    This stemmed from a March 2017 #ransomware attack and #databreach affecting Cascade Eye & Skin Centers in WA. #HHSOCR became aware of it in May 2017.

    Why did it take 7+ years to resolve this?

    And btw, I never knew about this breach and even now, cannot find any major media coverage or disclosure of it at the time. And it never showed up on HHS's public breach tool during all this time. Why didn't it show up if it affected 291,000?

    This is HHSOCR's 4th ransomware-related investigation under the #HIPAA Security Rule.

    @brett @campuscodi