Healthcare IT News December 8, 2023
This agency’s first data breach settlement under HIPAA for a phishing attack involved the alleged failure to conduct a risk analysis to identify potential ePHI threats or vulnerabilities across the Lafourche Medical Group network.
The U.S. Department of Health and Human Services Office for Civil Rights said Thursday it has settled with Lafourche Medical Group closing an investigation over a phishing attack that affected the electronic protected health information of approximately 34,862 individuals.
WHY IT MATTERS
A hacker gained access to an email account that contained ePHI owned by Lafourche Medical Group, a provider of emergency medicine, occupational medicine and laboratory testing in Louisiana on March 30, 2021.
OCR said its investigation revealed that before the reported breach, the provider...