Why Entities Should Review Their Online Tracker Use ASAP episode artwork

EPISODE · Sep 19, 2023

Why Entities Should Review Their Online Tracker Use ASAP

from Info Risk Today Podcast · host InfoRiskToday.com

Any healthcare organization that embeds tracking technologies in its website should carefully review whether it is inadvertently violating HIPAA or other federal regulations, said Nick Heesters, senior adviser for cybersecurity at the Department of Health and Human Services' Office for Civil Rights.

Episode metadata supplied by the publisher feed · Published Sep 19, 2023

Embed this episode

NOW PLAYING

Why Entities Should Review Their Online Tracker Use ASAP

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Mary Ann Kolbasak, the executive editor at Information Security Media Group, and I'm here at the HIM Cyber Forum in Boston, speaking with Nick Heasters, who is senior advisor for Cybersecurity at the Department of Health and Human Services, Office of Rights. Hi, Nick. I'm Mary Ann. How are you?

Good. Thanks so much for doing this. So, Nick, as HHS OCR gets thousands of HIPAA complaints and hundreds of breach notices or breach reports so far just this year, what are some of the main trends that you're seeing and what's changing that really healthcare sector covered entities and business associates should be paying more attention to? You know, hacking's been an issue for a while, it's been a push for you by the back, says, when it comes to complaints.

You know, anything new that you're seeing? I think there's just more of the same, and I think that here at HIM's in Boston, there has some good discussion to talk about some of those trends. I think we had someone to talk about the secure file transfer issues that those have resulted in a lot of breaches, and there's someone who talked about the malicious chain of that's typical in a hacking attack, you know, a phishing being an initial effector to come in, getting a toehold in the system through some type of malware drop, being able to somehow escalate privileges and getting some kind of domain admin rights moving laterally within that system, without major obstructions, looking for information, exfiltrated information, removing backups, deploying ransomware, deploying back doors to come back in later, that was described as something that's fairly common by one of the speakers who is the system of a health system, and as we see over and over again in OCR as well, so we can really emphasize that that is the continued chain of attack that we see that is fairly common. So you mentioned the secure file transfer software companies, the progress software had of vulnerability that was exploited, we had Fortra earlier this year, and we see breaches still being reported involving hacks at healthcare sector entities involving those products.

Are those vendors among the biggest business associates sort of breaches you're seeing this year? Because I know in the past we've seen other large vendor breaches that resulted in a lot of covered entities reporting breaches in large breaches, but does that seem to be some of the dominant things you're seeing in terms of the business associates this year so far? Creatures that are related to the movement in particular that those have been more recently in the past year have been several breaches affecting fairly large individuals per report. But more generally, the trend if you have a business associate that specifically caters to healthcare industry, you're going to have healthcare clients, if there is a breach at that business associate, there is certainly the possibility that you're going to have multiple healthcare clients be a part of that breach, have their health information from multiple clients be a part of that breaches may in fact be larger because of that particular business model.

And now, A2.js OCR also has various rulemaking in the works including HIPAA privacy rule proposals related to enhancing protections over reproductive health information and there's also other rulemaking in the works. How soon might we see a final rule for the reproductive health information proposals and what else to be watching for in the near term? Right, for as long as rulemaking activity, I'd refer folks to the federal register and what the first status is there. I don't have a comment on this, you know, I'm going to take a great taste for those.

And now, A2.js OCR and the Federal Trade Commission have both been repeatedly warning the healthcare sector about the risk in using online tracking tools such as Metapixel and Google Analytics, you know, saying that those web trackers could be in violation of HIPAA and FTC regulations depending on how their view is because they disclose to third parties, consumer and patient health information and other identifiers that the individuals might not be aware of. And HHS OCR and FTC recently sent 130 letters to organizations specifically telling them they should be reviewing how they're using these web trackers. And just a few days ago, HHS OCR and FTC made public, you know, the letters that were actually sent out to 130 organizations. When it comes to the onlookers, the companies out there who did not receive one of these letters, but they're using web trackers, if it's a HIPAA covered entity, what should they be thinking right now?

What should they be doing? Should they be going back and checking to see if they're using web trackers and if so, how? I think that's right. So I think our bulletin made clear that entities that are going to be using online tracking technologies need to really understand what those are actually doing in their environments.

If HIPAA applications apply, they have to do apply to ensure that they are complying with HIPAA rules in their use of those web tracking technologies and, you know, between the guidance and the joint letter with the FTC, you know, we're just trying to make people understand that this could implicate HIPAA that this is something to highlight that HIPAA rules may apply in a situation. So if an entity that deploys online tracking devices or what have you, technologies, that if they did not look at that through the lens of potential publications, that they should do so. So in terms of the 130 organizations that did receive letters, how are they chosen? Were they, kind of in some instances, a few of these covered entities had previously reported reaches to HHSOCR related to their previous use of web trackers.

But then there was, you know, a long list of other companies that kind of have seen kind of random. Have HHSOCR and FTC received complaints about certain companies, you know, do either of the agencies sort of have, you know, scanning tools to see how these web trackers might be being used by some covered entities and regulated organizations, how did you guys kind of zero in on who to warn? I was not involved in that process of identifying at least the same letters too, so I really don't know the methodology under which they were chosen. And in terms of enforcement actions, we've seen some from the FTC, there's been at least a handful, maybe two, three, so far.

And HHSOCR has previously said that it is actively investigating, you know, these cases involving web trackers. Any sense of one you might see in enforcement action from HHSOCR? No particular dates on when we may see some type of, you know, published enforcement action or whatnot. But you're correct.

I mean, there are web tracking issues that we are investigating. Has HHSOCR given technical assistance to organizations at this point that have been using web trackers perhaps in a potentially, you know, non-compliant way, but, you know, trying to help them not to do that? I'm not really sure of where investigations are on a, you know, case by case basis. So, you know, I would certainly think that that's a possibility, but I really would not know if that had happened yet or had already happened, so I really can't comment.

And in terms of guidance, any forthcoming topics of guidance that we should be watching for from HHSOCR at this point of the year, or looking into next year for that matter? Well, it's always an opportunity is to provide, you know, guidance on compliance with the HIPAA rules to our regulated community members. So we're looking at different areas to explore based on, you know, what the current trends are with cybersecurity issues and breaches in the best way to approach that in communicating better ways to comply with HIPAA. You know, what we do have coming out is the new version of the Security Risk Assessment Tool.

It's going to be version 3.4. It's going to have, you know, several enhancements, you know, one of the things that, you know, has been talked about here at HIMS is the, it's a new version of HICOP, the health industry and cybersecurity practices, and that's been updated for 2023. The SRA tool had references to the prior version of HICOP in the free version, so one of the enhancements is to update those references to, to refer to those new 2023 addition practices. And when it comes to investigations into breaches that are reported to HHS and the, so called you know, recognize security practices that these entities should be following, and if they are, that will be taken into consideration by HHS, OCR, in terms of potential enforcement.

How are you guys sort of incorporating this into the investigations at this point when you look to see if there's a checklist of different things that, you know, these organizations do between like risk assessments or risk analysis and how comprehensive these risk analysis is, you know, how timely they are, how are you incorporating, you know, HICOP and other sort of recognized security practices when you do do these investigations or reviews of entities and report breaches? Well, the recognized security practices of which HICOP is one of the recognized practices are entirely voluntary. So if entity is not meeting the measure of implementing the HICOP, cybersecurity practices or implementing the, in this time, security framework, there is not going to be a penalty from an OCR perspective. So OCR enforcement, the HIPAA rules, you know, we're looking, you know, we look at the recognized security practices if we're presented with those, if they want us to see if they, you know, have implemented, if they can demonstrate, implement them for the previous 12 months, and as you said, that's something that we may take consideration for potential mitigation of, you know, penalties or whatnot.

But as far as OCR's regulatory obligations, you know, we enforce HIPAA rules, so you wouldn't receive a violation for not implementing HICOP, but as far as if you are able to demonstrate compliance with HIPAA rules, you know, that could lead to such violations. And finally, in terms of anything else that we should be looking for to come from HHS OCR, you know, this year or in the coming months, anything that we should be looking for? I can't really think of too much. I guess the one thing that we just refer back to, we are having the 3.4 release of the security risk assessment tool, but we do ONC on that, and I believe there's going to be a couple of webinars coming up on that to discuss new enhancements and the use of that tool.

So if your listeners are a member or they have signed up for the OCR listserv, they would have gotten a notification of that and they can register for a new session if they wish. Great. Thank you so much, Nick. I've been speaking to Nick Heasters of HHS OCR.

I'm Mary Ann Kolbasek-McGhee of Information Security Media Group. Thanks for joining us.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on September 19, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!