Lawsuits Increasing Following HIPAA Breaches

Almost as surely as summer follows spring, lawsuits follow breaches of protected health information. Here’s a roundup of recent HIPAA breach lawsuits and settlements. Lawsuits Increasing Following HIPAA Breaches - Facts and Figures The law firm BakerHostetler published its annual Data Security Incident Response Report based on findings from 1,270 data security incidents managed by the firm in 2021.  Highlights included: 23% [...]

2022-05-27T16:58:52-04:00May 27th, 2022|

Colorado Privacy Act Becomes Third Comprehensive State Data Privacy Law

The Colorado Privacy Act (CPA) is a comprehensive consumer data privacy law passed in July 2021. The CPA taking effect on July 1, 2023, regulates the personal information of Colorado residents. Details of the Colorado Privacy Act are provided below. Who Is Regulated Under the Colorado Privacy Act? The Colorado Privacy Act regulates certain businesses that the law terms “controllers.” To qualify [...]

2022-05-06T17:03:31-04:00March 24th, 2022|

Utah Consumer Privacy Act Goes to Governor for Signature

The Utah Consumer Privacy Act (UCPA) is legislation unanimously passed in the Utah Legislature. The final version of this Utah privacy law now awaits the signature of Governor Spencer Cox. If, as expected, the Governor signs the legislation by March 24, 2022, Utah will become the fourth state in the nation with a comprehensive consumer privacy law. The details of the Utah Consumer Privacy Act are [...]

2022-05-06T17:03:32-04:00March 14th, 2022|

Settlement Reached in Excellus HIPAA Class Action Lawsuit

The final chapter of the Excellus Health Plan 2015 data breach that affected more than 9.3 million patients nationwide may be in sight. A settlement has been reached between the plaintiffs’ attorneys and the company in the Excellus HIPAA class action lawsuit, pending judicial review. Basis of Excellus HIPAA Class Action Lawsuit Attorneys announced the settlement on January 24, 2022, with Excellus, [...]

2022-05-06T17:03:39-04:00January 27th, 2022|

NY AG SHIELD UP! Vision Benefits Provider Settles Email Data Breach

In January of 2022, EyeMed Vision Care LLC, a New York vision benefits provider, settled an action brought by the New York State Attorney General against it for failing to implement adequate data security measures, including multifactor authentication, password management, and logging of email accounts.  These deficiencies resulted in a 2020 email data breach during which hackers accessed an EyeCare email account [...]

2022-05-06T17:03:39-04:00January 26th, 2022|

Data Breach Lawsuit Filed After Theft of Nearly 320k Records

Electronic Health Record (EHR) services provider QRS Inc. is facing a data breach lawsuit following an August cyberattack that may have compromised the privacy of 319,778 patients. Background of QRS Data Breach Lawsuit In a statement on their website, QRS confirmed their discovery on August 26, 2021, that a threat actor had accessed a server and may have obtained electronic protected health [...]

2022-05-06T17:03:41-04:00January 14th, 2022|

Quest Diagnostics Subsidiary Hit with Data Breach Lawsuit

Quest Diagnostics subsidiary, ReproSource Fertility Diagnostics has been sued by a patient over alleged security deficiencies. The Quest data breach lawsuit was filed one month after the October 8, 2021 announcement of a ransomware attack that potentially exposed the protected health information (PHI) of 350,000 individuals. Details of the Quest Data Breach Lawsuit According to the notification provided by ReproSource, the company’s [...]

2022-05-06T17:03:43-04:00December 31st, 2021|

New Jersey State Attorney General Settles HIPAA Claims Against Printing Companies

In November of 2021, the New Jersey State Attorney General’s (AG) Office, Division of Consumer Affairs, settled 2 HIPAA claims, one HIPAA claim against Command Marketing Innovations (CMI), and another HIPAA claim against CMI’s business associate, Strategic Content Imaging, LLC (SCI). This $130,000 resolution settled each company’s potential HIPAA Security Rule and Privacy Rule violations. The printing companies were drummed into New Jersey court for having [...]

2022-05-06T17:03:45-04:00December 21st, 2021|

Illinois Medical Marijuana HIPAA Compliance Required

The deadline for Illinois Medical Marijuana dispensaries to become HIPAA compliant was December 1, 2021. As of this date, Illinois medical marijuana HIPAA compliance is required for all dispensaries in the state that provide marijuana products to patients. This includes completion of a security risk assessment and encryption of electronic devices and networks that contain the protected health information (PHI) of patients. [...]

2022-05-06T17:03:46-04:00December 14th, 2021|

Planned Parenthood Class Action Lawsuit Filed Following Data Breach

Planned Parenthood Los Angeles faces a class-action lawsuit in the wake of an October cyberattack that potentially exposed the protected health information (PHI) of 409,759 patients. The Planned Parenthood class-action lawsuit is discussed in detail below Planned Parenthood Class-Action Lawsuit – Details of Lawsuit Filed on December 9, 2021, by an unnamed patient, the lawsuit alleges that the patient and class members [...]

2022-05-06T17:03:47-04:00December 10th, 2021|