mathstodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for maths people. We have LaTeX rendering in the web interface!

Server stats:

2.8K
active users

#healthitsecurity

0 posts0 participants0 posts today

DATE: April 17, 2025 at 04:57PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Lawsuit: #Hospital #Therapist Accessed Nude Breast Photos of 425 Women t.co/cGz8LHiz0l

Here are any URLs found in the article text:

t.co/cGz8LHiz0l

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: April 10, 2025 at 08:51AM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Is #Oracle's potential involvement in #TikTok's divestiture a bad idea for #nationalsecurity and #dataprivacy? t.co/kpeu0TeFx8

Here are any URLs found in the article text:

t.co/kpeu0TeFx8

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: April 09, 2025 at 03:48PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Senate Intel Vice Chair @MarkWarner Prods #Trump Over #TikTok Plans: Says Talk of #Oracle's Involvement Worrisome Due to Recent #Data Breaches t.co/kpeu0TeFx8

Here are any URLs found in the article text:

t.co/kpeu0TeFx8

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: March 13, 2025 at 10:47AM
SOURCE: BECKERS CYBERSECURITY HEALTH IT

TITLE: 38 passwords that take 1 second to crack

URL: beckershospitalreview.com/cybe

Cybersecurity is more important than ever as healthcare providers are being targeted by foreign hackers. Nordpass released a report of passwords in the U.S. it typically takes less than one second to hack.

URL: beckershospitalreview.com/cybe

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org
.
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information..
.
-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

www.beckershospitalreview.com38 passwords that take 1 second to crack

DATE: January 27, 2025 at 03:38PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Why #AI in #Healthcare Harkens Back to Early #SocialMedia Use t.co/fYZHxXifUL

Here are any URLs found in the article text:

t.co/fYZHxXifUL

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: January 17, 2025 at 03:17PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

#Biotech Firm #EnzoBiochem to Pay $7.5M to Settle Class Action Lawsuit in 2023 Hack Affecting Nearly 2.5 Million t.co/oECuK7qrY2

Here are any URLs found in the article text:

t.co/oECuK7qrY2

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: December 02, 2024 at 04:37PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Feds Propose #ArtificialIntelligence 'Guard Rails' for #MedicareAdvantage Plans t.co/yLiXnyvUOq #CMS #HHSgov #AI #MA

Here are any URLs found in the article text:

t.co/yLiXnyvUOq

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

t.coFeds Propose AI 'Guard Rails' for Medicare Advantage PlansThe Centers for Medicare and Medicaid Services has issued proposed "guard rails" to help ensure that the use of artificial intelligence for Medicare

DATE: November 08, 2024 at 04:58PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Feds Warn #Healthcare Sector of an Array of #Cyberthreats t.co/ttIojzgtbl

Here are any URLs found in the article text:

t.co/ttIojzgtbl

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

t.coFeds Warn Health Sector of an Array of CyberthreatsFederal authorities are warning the healthcare sector of an array of cyberthreats - including Scattered Spider hacks, living-off-the-land attacks, and bad actors

DATE: November 08, 2024 at 08:42AM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

What sorts of data #security and #privacy risks do #lawfirms pose to their own clients? t.co/toKdQ0raLi

Here are any URLs found in the article text:

t.co/toKdQ0raLi

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

t.coLaw Firm Hack Compromises Health System's Patient DataA hacking incident at Thompson Coburn, a national law firm based in Missouri, has affected an unspecified number of patients of a healthcare sector client,

DATE: August 16, 2024 at 09:10AM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Breach Roundup: #Microsoft's August Patch Contains 90 Fixes; Also: #Azure Health Bot Vulnerabilities Expose Risks in Cloud-Based #Chatbots t.co/Tb4brRoWZE

Here are any URLs found in the article text:

t.co/Tb4brRoWZE

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: August 15, 2024 at 08:19AM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Why did three state attorneys general fine a #biotech firm $4.5M in a #ransomware #databreach? t.co/okCEO76X1L

Here are any URLs found in the article text:

t.co/okCEO76X1L

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: August 02, 2024 at 05:26PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

@HHSOCR Hits #Ambulance Company With Big #HIPAA 'Right of Access' Fine t.co/6Ml7ltv8lf #AMR

Here are any URLs found in the article text:

t.co/6Ml7ltv8lf

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: July 31, 2024 at 08:52PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Do #electronichealthrecord #software vendors have a fiduciary duty to protect patients’ sensitive information? #EHR t.co/TJR1naVQRj

Here are any URLs found in the article text:

t.co/TJR1naVQRj

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

All,

(See article link above & below)
beckershospitalreview.com/cybe

This issue strikes me as a potential emergency. All American health professionals need to be writing our professional associations to demand that they oppose what The American Hospital Association is trying to do here.

I will be writing ACA, and -- time permitting -- will publish more on this later.

The problem in a nutshell is that every time hospitals -- or any other medical source -- make use of 3rd party trackers like Google Analytics, they provide data that can identify a patient. It is a HIPAA violation. They will argue that -- depending upon what is provided -- it does not actually give away enough information to identify the patient, but that is a bogus argument. Google Analytics (and many other outside tech tools) collect databases of information so they can put together profiles over time.

So -- for example -- if a hospital gives Google Analytics a web browser cookie showing that the client logged into their site, the cookie MIGHT just identify the web browser without the client name. BUT -- when that same client goes and logs into their Google account later (for which they have previously given their name), Google can observe the same "anonymous" cookie in the web browser and deduce that this is the same person who logged into the hospital website. If it happens to be an abortion clinic, then Google knows roughly the services provided. If the hospital sends the cookie from psychotherapist John Smith LCPC's telehealth page, then Google knows that the patient sees psychotherapist John Smith.

If hospitals need the tools that Google and other tech companies are providing, they need to buy internal versions of such to run on their own systems. If hospitals need to do marketing, then they need to run the 3rd party trackers only on the most public parts of their websites. therapyappointment.com is a good example of being a good citizen about this -- they run about eight 3rd party trackers on their home page, but only 1 tracker once a therapist has logged in. And that one tracker is for Amazon Cloud Services -- arguably a tracker that is necessary to the operation of their website.

I could see narrow exceptions allowing for 3rd party trackers that might make sense (AHA is making heavy use of these fringe cases in the article). Most of the time its a big problem.

I'm disgusted that the AHA is taking this position. It means they have NO respect for the data privacy they supposedly support!

-- Michael

@rsstosecurity @infosec
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords #telehealth #netneutrality #socialengineering #AHA #americanhospitalassociation #APA #americanpsychologicalassociation #ACA #americancounselingassociation #NASW #nationalassociationofsocialworkers #AMA #americanmedicalassociation #EHR #medicalnotes #progressnotes @psychotherapist @psychotherapists @psychology @socialpsych @socialwork @psychiatry #technology #healthcare #patientportal
#HIPAA #dataprotection #infosec #doctors #hospitals #BAA #businessassociateagreement #congress #senate #lobbying

www.beckershospitalreview.comAHA: HHS should withdraw health-data tracking ruleThe American Hospital Association is asking Congress to urge HHS to rescind a rule restricting the use of third-party tracking technologies by hospitals and health systems.

Marcus Hutchins at Malwaretech posted about a new "feature" of Chrome that reports to 3rd parties what websites you visit.

This means YOUR CLIENTS can have the URLs of your TELEHEALTH system reported to 3rd parties.

So -- for example, if you use Psychology Today for telehealth, they will know the client is seeing a mental health professional. If you use Zoom, they will LIKELY just know the client went on a Zoom call -- but then you have a unique Zoom URL link, so its possible someone will bother to catalogue that your particular Zoom link is medical. So, again, same problem.

This is not a HIPAA problem under your control, but perhaps some client education on browser privacy settings is in order?

infosec.exchange/@malwaretech/

For people who for some reason still want to use Chrome:
Settings > Privacy >Ad privacy, then just toggle everything off.

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

Infosec ExchangeMarcus Hutchins :verified: (@malwaretech@infosec.exchange)Attached: 1 image For anyone unaware, Google Chrome is currently rolling out an update that track your interests based on browsing history, then share them with 3rd party websites. The notification page makes it sound like they added a new privacy feature, but in actuality they automatically enrolled you into their tracking system and you have to go and manually opt out.