c.im is one of the many independent Mastodon servers you can use to participate in the fediverse.
C.IM is a general, mainly English-speaking Mastodon instance.

Server stats:

2.8K
active users

#hipaa

30 posts13 participants0 posts today

DATE: April 01, 2025 at 06:09PM
SOURCE: HIPAA Watch from JD Supra

Direct article link at end of text block below.

HIPAA Regulations & Business Associate Agreements In The Age Of Digital Collaboration t.co/4XhSw1B1vP

Here are any URLs found in the article text:

t.co/4XhSw1B1vP

Articles can be found by scrolling down the page at jdsupra.com/ under the title "Latest Updates".

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

JD SupraHIPAA Regulations & Business Associate Agreements In The Age Of Digital Collaboration | JD SupraThe healthcare industry has come up against unprecedented pressure in recent years. Digital transformation has had a significant role to play when it...

DATE: April 01, 2025 at 05:34PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Experts: Staff Cuts to @FDA Could Hamper #MedicalDevice #Cyber Efforts t.co/GmxEvOWQXC #EnergyandCommerceCommittee

Here are any URLs found in the article text:

t.co/GmxEvOWQXC

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

Team R: be careful what you wish for.

It would seem that they overlook the importance of #HIPAA to them. By weakening (or eliminating) it you open the possibility of someone exposing your dirty laundry. You cannot expect more privacy than what you grant others.

rawstory.com/abortion-rules-in

Raw Story · 17 states seek to end abortion privacy rule. A federal judge is questioning HIPAA itselfBy Kelcie Moseley-Morris, States Newsroom

DATE: April 01, 2025 at 12:36PM
SOURCE: HIPAA Watch from JD Supra

Direct article link at end of text block below.

Healthcare Regulatory Check-Up Newsletter | February 2025 Recap t.co/D6PXFrACm3

Here are any URLs found in the article text:

t.co/D6PXFrACm3

Articles can be found by scrolling down the page at jdsupra.com/ under the title "Latest Updates".

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

JD SupraHealthcare Regulatory Check-Up Newsletter | February 2025 Recap | JD SupraThis issue of McDermott’s Healthcare Regulatory Check-Up highlights regulatory activity for February 2025, including long-awaited proposed and final...

DATE: April 01, 2025 at 09:14AM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

Azura Vascular Care Agrees to $3.15 Million Data Breach Settlement - t.co/xCBC8FJSB3

Here are any URLs found in the article text:

t.co/xCBC8FJSB3

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

DATE: April 01, 2025 at 09:13AM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

173,000 Patients Affected by Chord Specialty Dental Partners Email Data Breach - t.co/kj2YldGbvQ #healthcare #databreach

Here are any URLs found in the article text:

t.co/kj2YldGbvQ

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

DATE: March 31, 2025 at 04:38PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

@FTC: @23andMe's Buyer Must Uphold Co.'s Data #Privacy Pledge t.co/IFNSWyTT6J #FTC #23andMe

Here are any URLs found in the article text:

t.co/IFNSWyTT6J

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: March 31, 2025 at 03:53PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

#Oracle Health Responding to Hack of Legacy #Cerner #EHR Data t.co/LncLsn8RT9

Here are any URLs found in the article text:

t.co/LncLsn8RT9

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: March 31, 2025 at 09:51AM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

Virginia Consumer Protection Act Updated to Include Reproductive and Sexual Health Information t.co/0uM15asE2R

Here are any URLs found in the article text:

t.co/0uM15asE2R

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

DATE: March 31, 2025 at 09:50AM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

Oracle Health Breach Affects Patients of Multiple U.S. Multiple Hospitals t.co/42e13gaQaa #healthcare #databreach

Here are any URLs found in the article text:

t.co/42e13gaQaa

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

🛑 Oracle Health Breach: What IT Leaders Must Learn

Multiple U.S. hospitals are facing a nightmare: EHR data stolen from legacy Cerner servers still awaiting cloud migration.

🔐 Attack vector: Compromised customer credentials
⚠️ Impact: Multi-org data theft, extortion attempts, and HIPAA compliance chaos
🧾 Oracle told hospitals:
・They must notify patients
・They must assess HIPAA exposure
・Oracle won’t send official notifications—just paper memos

The response strategy—avoiding emails, no formal breach announcement—has left healthcare IT teams frustrated and exposed.

This incident reinforces the importance of:
・Decommissioning legacy systems
・Zero-trust access controls across shared vendor infrastructure
・Clear contractual breach notification roles

👉 bleepingcomputer.com/news/secu

Replied in thread

@Catawu @briankrebs I’m not really interested in their frame of reference or what they think about the people impacted. That’s not because I don’t care, but because I think it's irrelevant to the deeper underlying issues.

I’m actually more interested to what extent this situation may violate #HIPAA and other #patientprivacy laws. Part of the functional challenge in what is currently going on at the federal level is that many privacy and #healthcare safeguards such as HIPAA are a complex mixture of laws passed by Congress and regulations defined by the executive branch to implement those laws.

I am not a lawyer, but I do deal with #privacyregulations and #regulatorycompliance issues professionally. To the extent that the administration is arguing that they have constitutional authority to make changes to the implementations developed and overseen by the executive branch itself, the extent of what is being done seems unprecedented but may not be illegal per se. I am not qualified to make that determination, but I think it's the foundational question that needs to be asked.

On the other hand, the parts of HIPAA and other federally-enacted laws regarding #healthcare and privacy are in fact laws established within our country’s constitutional framework. The executive branch can’t simply wish clearly-established laws into the cornfield. Unfortunately, many laws leave a great deal of the implementation details—whether unintentionally or through deliberate delegation—to the executive branch, the states, or various regulatory agencies. In turn, many of those regulators also operate to one extent or another under the executive branch, and that further complicates the picture.

Many federal laws leave a great deal of wiggle room for interpretation to the executive and judicial branches whether not by design, but congressionally-enacted laws and protections provided by the Constitution itself cannot simply be ignored. While there's definitely a difference, separating a "law" from the "regulations" that implement that law isn't necessarily a simple exercise.

The real challenge is that our republic was designed as a Venn diagram of overlapping roles, responsibilities, and authority that were meant to operate in a state of carefully-balanced tension. The republic's framework has never been tested this broadly within my lifetime, if ever. Even though how our three branches of government should work is material covered in any decent highschool civics class, the complexity of statutory vs. regulatory authority requires legal and Constitutional scholarship that is more than the average citizen can bring to bear on the matter. I'd like to think I understand these issues better than most—and I certainly have my own personal and professional instincts about what's right and wrong—but I wouldn't dream of claiming to understand all the nuances involved.

Professionally, I am taking a deliberately apolitical approach to what is a very legitimate set of questions about constitutional authority. Likewise, my apolitical but professional experience tells me that there is entirely too much gray area around the constitutional and legal topics to determine with certainty what is legal as opposed to what is moral or ethical. In my professional experience, what is right and what is lawful aren't always the same.

Unless society as a whole is willing to revisit some of the underlying assumptions collectively made over the past several hundred years about the differences between legislative laws and the administrative regulations that implement them, this problem is unlikely to go away anytime soon. In fact, it is likely to spread to other areas with similar gray areas. As an argument by analogy, the current legal mess around #copyright and #LLM training may be similar in terms of being pure sophistry where the term "fair use" is clearly being used in an intellectually dishonest way, but apparently it's far enough into the gray to pass legal muster right now. Decades or centuries of legislative layering has led to a legal framework that never envisioned modern realities. Revisiting and revising centuries of legal accretion would require a strong moral compass, a great deal of political courage, and in-depth analysis by legal and constitutional scholars (among others) in order to address the very real institutional unraveling we're observing.

Sadly, in a society that frequently classifies expertise as “elitism" such a brutally honest conversation is unlikely to happen soon. A broad reconsideration of how our republic was designed to function and a hard look at how it actually functions would require high levels of both personal and political courage. It's even less likely to be rapidly prioritized without sufficiently clear political self-interest from a majority of those with the remaining authority to materially affect the outcome.

What I’ve said may strike some as political opinion rather than strictly analytical observation. However, my statements are deliberately based on well-established sociological and psychological norms rather than current politics. I feel confident in asserting that the likelihood of Congress or the Supreme Court—much less the general public—addressing these things effectively in the near term is essentially zero. For any elected or appointed official acting alone, the risk of asserting constitutional prerogatives vastly exceeds both the collective will of their respective institutions and the already-ceded institutional powers required to do so effectively.

Our latest newsletter is out, get it while it's hot!

🗞️ opalsec.io/daily-news-update-f

Key stories:

🏥 Oracle's under fire: A breach at Oracle Health compromised patient data, with Oracle allegedly shifting responsibility to hospitals and avoiding documentation. This follows hot on the heels of denial regarding an alleged Oracle Cloud breach, raising serious questions about their security culture.

🛒 Clop's back in the headlines: Sam's Club - a Walmart subsidiary - is investigating claims of a Clop ransomware attack, potentially linked to the Cleo file transfer vulnerability that has already hit other organizations hard.

📡Don't miss this bizarre twist: Cable operator WideOpenWest (WOW!) is dealing with a breach claimed by Arkana Group, who are publicizing the stolen data (usernames, passwords, etc.) with a… Russian music video. The alleged attack vector? Infostealer malware.

Get up to speed with these stories and more: opalsec.io/daily-news-update-f

If you'd like to get the latest Cyber Security news wrapped up and delivered to your inbox every day, subscribe to our newsletter here!

📨opalsec.io/daily-news-update-f

Opalsec · Daily News Update: Saturday, March 29, 2025 (Australia/Melbourne)A breach at Oracle Health compromised patient data, with Oracle allegedly shifting responsibility to hospitals and avoiding documentation. A Walmart subsidiary is investigating claims of a Clop ransomware attack, potentially linked to the Cleo file transfer vulnerability.

Our latest newsletter is out, get it while it's hot!

🗞️ opalsec.io/daily-news-update-f

Key stories:

🏥 Oracle's under fire: A breach at Oracle Health compromised patient data, with Oracle allegedly shifting responsibility to hospitals and avoiding documentation. This follows hot on the heels of denial regarding an alleged Oracle Cloud breach, raising serious questions about their security culture.

🛒 Clop's back in the headlines: Sam's Club - a Walmart subsidiary - is investigating claims of a Clop ransomware attack, potentially linked to the Cleo file transfer vulnerability that has already hit other organizations hard.

📡Don't miss this bizarre twist: Cable operator WideOpenWest (WOW!) is dealing with a breach claimed by Arkana Group, who are publicizing the stolen data (usernames, passwords, etc.) with a… Russian music video. The alleged attack vector? Infostealer malware.

Get up to speed with these stories and more: opalsec.io/daily-news-update-f

If you'd like to get the latest Cyber Security news wrapped up and delivered to your inbox every day, subscribe to our newsletter here!

📨opalsec.io/daily-news-update-f

Opalsec · Daily News Update: Saturday, March 29, 2025 (Australia/Melbourne)A breach at Oracle Health compromised patient data, with Oracle allegedly shifting responsibility to hospitals and avoiding documentation. A Walmart subsidiary is investigating claims of a Clop ransomware attack, potentially linked to the Cleo file transfer vulnerability.

DATE: March 28, 2025 at 05:24PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

#RevenueCycleManagement Firm Hack Affects Patients, Clients t.co/Zf8QF6ROvY #ALNMedical #HealthPrime #RCM

Here are any URLs found in the article text:

t.co/Zf8QF6ROvY

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: March 28, 2025 at 12:39PM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

Website Tracking Lawsuit Against Orlando Health Survives Motion to Dismiss t.co/8S0Z8oWvBu

Here are any URLs found in the article text:

t.co/8S0Z8oWvBu

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

DATE: March 28, 2025 at 12:31PM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

More Than One-Third of Data Breaches Due to Third-Party Compromises t.co/zCWZaHMKcl #healthcare #cybersecurity

Here are any URLs found in the article text:

t.co/zCWZaHMKcl

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

DATE: March 28, 2025 at 12:05PM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

Healthcare Data Breaches Reported in Georgia, Washington & New Hampshire t.co/D8BTKN45UC #healthcare #databreach

Here are any URLs found in the article text:

t.co/D8BTKN45UC

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

DATE: March 28, 2025 at 11:39AM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

Beacon Health System Affected by Two Business Associate Data Breaches t.co/MSckF3HC6g #healthcare #databreach

Here are any URLs found in the article text:

t.co/MSckF3HC6g

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

DATE: March 28, 2025 at 11:39AM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

OCR Gives Update on Proposed HIPAA Security Rule t.co/BOxrzwU9F3 #hipaa #compliance

Here are any URLs found in the article text:

t.co/BOxrzwU9F3

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------