Cybersecurity
Solara Medical Supplies Pays $3 Million to Settle HIPAA Security Rule Violations
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a $3 million settlement with Solara Medical Supplies, a California-based supplier of insulin pumps and continuous glucose monitors, resolving potential violations of the HIPAA Security Rule and Breach Notification Rule. The case stemmed from a 2019 phishing attack that compromised…
Read MoreChildren’s Hospital Colorado Pays Over $500,000 for MFA Failures Leading to HIPAA Breach
HHS Office for Civil Rights reached a settlement with Children’s Hospital Colorado following a data breach that exposed the protected health information of thousands of patients. The breach was tied directly to failures in implementing multi-factor authentication (MFA) across critical systems, resulting in a penalty exceeding $500,000. OCR’s investigation determined that the hospital had not…
Read MoreCybersecurity Compliance Deadlines Loom
Earlier this year, the New York State Department of Financial Services laid out new cybersecurity requirements for financial services companies. These rules (codified in 23 NYCRR 500) took effect on March 1 and established an array of “regulatory minimum standards” that companies must now meet. When all is said and done, financial services companies will…
Read More