By
Kyle Brasseur2023-12-08T16:48:00
Louisiana-based Lafourche Medical Group agreed to pay $480,000 as part of the first phishing attack-related settlement the Department of Health and Human Services’ Office for Civil Rights (HHS OCR) has reached under the Health Insurance Portability and Accountability Act (HIPAA).
Lafourche additionally consented to be monitored by the OCR for a period of two years, as well as agreeing to a corrective action plan, the agency announced Thursday.
In May 2021, Lafourche reported to the HHS it was breached through a phishing attack that occurred two months prior. The attack affected the electronic protected health information of nearly 35,000 individuals, the agency’s investigation found.
You are not logged in and do not have access to members-only content.
If you are already a registered user or a member, SIGN IN now.
2024-03-14T19:45:00Z By Adrianne Appel
Change Healthcare, a health payment processor hit by a crippling cyberattack in February, is under investigation by the Department of Health and Human Services’ Office for Civil Rights.
2024-02-07T21:51:00Z By Adrianne Appel
Montefiore Medical Center agreed to pay $4.75 million to settle allegations by the Department of Health and Human Services’ Office for Civil Rights that failures by the New York City nonprofit facility allowed an employee to steal and sell patient information for six months.
2023-12-07T18:34:00Z By Adrianne Appel
Hospitals can soon expect to see new draft cybersecurity regulations and benchmarking goals, according to the Department of Health and Human Services.
2026-03-31T23:31:00Z By Neil Hodge
Companies face large fines if they spread false marketing claims or fake reviews about their products and services—as well as those by suppliers—under a toughened competition regime in the U.K. aimed at enhancing consumer protection.
2026-03-30T17:24:00Z By Adrianne Appel
Visa, Mastercard, PayPal, and Stripe have received letters from the Federal Trade Commission, warning the companies to end any policies or terms of service that may result in the “debanking” of customers.
2026-03-24T19:09:00Z By Adrianne Appel
The ink was barely dry on the U.S. Department of Justice’s new corporate enforcement policy (CEP) when the agency announced it would not prosecute Balt SAS for alleged bribery violations.
Site powered by Webvision Cloud