Hello world,
Today’s Paubox Weekly is 554 words - a 2 minute read.
Want to get this type of content delivered to your inbox every Friday? Subscribe to Paubox Weekly.
Email security breaches at Children’s Health Care in Minnesota and the Los Angeles County Department of Mental Health exposed the protected health information (PHI) of thousands of patients.
What happened: The compromised information includes names, medical record numbers, and treatment details, raising concerns about patient privacy.
Train staff to prioritize email security
The Paubox team is in Newport, RI, for the 2024 NESHCo Annual Conference hosted by the New England Society for Healthcare Communications.
In the know: A hot topic of discussion at NESHCo was the ever-increasing threat of cyberattacks and crisis communication in the wake of the Change Healthcare debacle.
Healthcare marketing demands continuous innovation
As the healthcare industry deals with the fallout of the Change Healthcare data breach, providers are urgently seeking clarity from the HHS on their obligations regarding breach reporting and patient notification.
Why it matters: One of the primary concerns raised by provider groups is the potential for duplicate notifications, which could confuse and overwhelm patients.
Who should handle the breach notifications?
Threat actors use email address verification to ensure their spoofed emails appear legitimate and are more likely to reach and deceive recipients by mimicking trusted healthcare provider names.
Go deeper: Using email address verification tools, they compile lists of valid email addresses, ensuring their emails reach real users rather than bouncing back due to invalid addresses.
Impersonates legitimate organizations, including healthcare providers
Slack, a cloud-based team communication platform, was caught using users' data and information to train its AI tools without explicit consent.
Why it matters: Slack was supposed to obtain consent from the users after telling them how their data would be used. Slack’s use of its customer data without obtaining consent violates users' data privacy rights.