Risk & Quality Management
RSSArticles
-
Hospital Crippled by Days-Long Cyberattack
Lurie Children’s Hospital, Chicago’s largest pediatric provider, experienced a cyberattack that crippled its email systems and most of its phone service for nearly two weeks.
-
HHS Proposes Cybersecurity Requirements for Hospitals
The Department of Health and Human Services (HHS) recently released a concept paper outlining its cybersecurity strategy for the healthcare sector, focusing specifically on strengthening resilience for hospitals threatened by cyberattacks. HHS outlined four pillars for action, including new voluntary healthcare-specific cybersecurity performance goals.
-
Patient and Family Complaints Require Careful Response
Healthcare organizations should have processes for responding to complaints from patients and families. The nature and seriousness of the complaint will dictate how much of a response is required.
-
‘Safe Harbors’ Can Address ED Providers’ Malpractice Fears
Many emergency physicians want to follow evidence-based guidelines to reduce unnecessary testing — but worry about liability if they do not order a diagnostic test and a patient sues. The Choosing Wisely campaign, an initiative of the American Board of Internal Medicine Foundation, aims to reduce the overuse of potentially harmful tests and procedures.
-
Pediatric Boarding Increases Safety Concerns in EDs
Boarding is a common occurrence in most EDs. However, it has been studied more often in adult EDs than pediatric EDs.
-
Is Diagnosis Uncertain in the ED? Clear Communication Is Needed
Patients likely expect to leave the emergency department with a definite understanding of what is wrong. Yet many patients are discharged or admitted with an uncertain diagnosis.
-
When a Privacy Breach Is Not a Breach
Language is important when talking about noncompliance with HIPAA. Not every instance of noncompliance is a breach.
-
Ransom Demands Decrease and More Companies Refuse to Pay
The number of ransomware victims opting to pay the ransom has fallen to a record low. At the beginning of 2019, 85% of ransomware victims paid a ransom. However, that figure fell to 46% in the middle of 2021 and 29% in the last quarter of 2023.
-
HHS Issues HIPAA Best Practices for Telehealth
The Department of Health and Human Services published a resource guide to assist telehealth providers in explaining the privacy and security risks to patients, but the guidance makes clear HIPAA does not require this education. However, the goal is for the resource guide to help providers who would like to discuss potential risks with the patient.
-
First HIPAA Settlement for Ransomware, Fine for Phishing
The Office for Civil Rights achieved two firsts recently: a settlement agreement related to a ransomware attack on a business associate and the first fine issued for a phishing attack. Both cases hold lessons for other covered entities.