• Skip to primary navigation
  • Skip to main content
Dean Dorton – CPAs and Advisors
  • Services
        • Audit & Assurance
          • Audits, Reviews & Compilations
          • ESG Programs & Reporting
          • Internal Audit
          • International Financial Reporting
          • Lease Accounting Managed Services
          • Peer Review Services
          • SOC Reporting
        • Family Office
        • Consulting & Advisory
          • Business Valuation Services
          • Forensic Accounting
          • Fractional CFO
          • Litigation Support
          • Matrimonial Dissolution
          • Merger & Acquisition
          • SEC Services
          • Succession Planning
          • Transaction Advisory Services
          • Whistleblower Hotline
        • Outsourced Accounting
        • Private Wealth
        • Healthcare Consulting
          • Finance
          • Health Systems Operational Transformation
          • Medical Billing and Credentialing
          • Risk Management & Compliance
          • Strategic Growth for Private Practices
          • Strategy and Strategy Implementation
          • Technology & Data Analytics
        • Tax
          • Business Tax
          • Cost Segregation Studies
          • Credits and Incentives
          • Estates and Trusts
          • Individual Tax
          • International Tax
          • SEC Provision and Compliance
          • State and Local Tax
        • Technology & Cybersecurity
          • Accounting Software
          • Cybersecurity, IT Audit, & Compliance
            • Cybersecurity Assessments
            • Cybersecurity Maturity Model Certification (CMMC)
            • Cybersecurity Scorecard Assessment
            • Data Privacy Laws
            • Security Awareness Training
            • SOC Reporting
            • Virtual Information Security Office
          • Data Analytics & AI
          • IT Infrastructure & Cloud Solutions
            • Automation
            • Backup and Disaster Recovery
            • Cloud Strategy
            • Data Center
            • Enterprise Network
            • Network Security
            • Phone and Video Conferencing
            • User Identity Management Solutions
            • Webex
          • Managed IT Services
  • Industries
        • Construction
        • Distilleries and Craft Breweries
        • Energy and Natural Resources
        • Equine
        • Financial Institutions
        • Government
        • Healthcare
        • Higher Education
        • Life Sciences
        • Manufacturing and Distribution
        • Nonprofit
        • Real Estate
  • Insights
    • Articles
    • Guides
    • Case Studies
  • Events
  • Company
        • News
        • Our Team
        • Experiences
        • Careers
          • College Students
          • Experienced Professionals
        • Locations
        • Lexington, KY

          250 West Main Street
          Suite 1400
          Lexington, KY 40507
          859-255-2341

        • Louisville, KY

          435 North Whittington Parkway
          Suite 400
          Louisville, KY 40222
          502-589-6050

        • Louisville, KY

          700 North Hurstbourne Parkway
          Suite 115
          Louisville, KY 40222
          502-589-6050

        • Ft. Wright, KY

          810 Wright’s Summit Parkway
          Suite 300
          Fort Wright, KY 41011
          859-331-3300

        • Cincinnati, OH

          312 Walnut Street
          Suite 3330
          Cincinnati, OH 45202
          859-331-3300

        • Blue Ash, OH

          9987 Carver Rd
          Suite 120
          Blue Ash, OH 45242
          513-891-5911

        • West Chester, OH

          9025 Centre Pointe Drive
          Suite 310
          West Chester, OH 45069
          513-985-6240

        • Indianapolis, IN

          5975 Castle Crk Pkwy Dr N
          Suite 400
          Indianapolis, IN 46250
          317-469-0169

        • Raleigh, NC

          4130 Parklake Avenue
          Suite 400
          Raleigh, NC 27612
          919-782-9265

  • Contact Us

Healthcare IT

Article 05.6.2024 Autumn Hines

Data privacy and security have never been more important in a digital age where information flows freely. Despite warnings as recently as 2023 to enhance and bolster cybersecurity defenses, ransomware attacks continue resulting in significant operational impact to all sectors of healthcare.

Recently, two major healthcare providers, Kaiser Permanente and City of Hope, found themselves in the spotlight regarding data privacy concerns. Let’s delve into what transpired and how these organizations responded.

Kaiser Permanente

Kaiser Permanente apologized to its vast network of 13.4 million members after discovering that certain search information may have inadvertently been shared with external platforms, including Google and social media sites. The company attributed this data transmission to previous online technologies installed on its websites and apps. While the shared information did not include sensitive details like usernames or financial information, it did encompass IP addresses, usernames, indications of account activity, and health-related search terms.

Upon identifying the issue, Kaiser Permanente promptly removed the problematic technologies from its online platforms and assured members that there had been no reported instances of personal information misuse. Nevertheless, the organization took proactive measures by informing all affected members, both current and former, about the incident. Additionally, they expressed regret for the oversight and outlined steps, guided by experts, to prevent similar incidents in the future.

City of Hope

In a parallel scenario, City of Hope, another healthcare provider, faced a data breach affecting its members. The breach, which took place between September 19 and October 12, 2023, involved unauthorized access to a plethora of member information, ranging from email addresses to sensitive data like Social Security numbers and medical records.

City of Hope responded swiftly upon discovering the breach, implementing mitigation measures, and bolstering security protocols with the assistance of cybersecurity experts. Furthermore, they extended a gesture of goodwill to affected members by offering two years of free identity monitoring services. In tandem with this, they promptly notified relevant authorities, including law enforcement and regulatory bodies, and launched an internal investigation into the incident to ascertain its scope and impact.

Cybersecurity is an urgent issue in healthcare, but the risk is growing exponentially, and it’s poised to keep rising with no signs of stopping. Consequently, the expansive landscape of healthcare creates additional vulnerabilities where data attackers can outpace your organization, disrupting patient care. What steps is your organization taking to prepare?

Contact Dean Dorton for expertise in healthcare, cybersecurity, and the dynamic place where they intersect.

Filed Under: Cybersecurity, Healthcare, Technology Tagged With: Cybersecurity, Healthcare IT, Technology

Article 12.7.2020 Dean Dorton

Sometimes government does pass laws with well-intentioned motives and the 21st Century Cures Act (Cures Act) is a good example of one. However, government has a much shorter list of passing laws that are simple and easy to understand. Perhaps significant endeavors require complexity. Regardless, interpretation and compliance falls on our shoulders.

Let’s look at the most immediately relevant aspects of the Cures Act. Trying to address the entire Cures Act, even summarized, can be overwhelming.

The Cures Act applies to:

  • Healthcare Providers
  • Health Information Networks
  • Health IT Developers

A revised time line was provided in late October. This time line contains more than just the immediately relevant items, however, we do need to have in the back of our mind a concept of the end goal.

  • Information blocking provisions
  • Information Blocking CoC/MoC requirements
  • Assurances CoC/MoC requirements
  • API CoC/MoC requirement – compliance for current API criteria
  • Communications CoC/MoC requirements (except for the notice requirement for 2020
  • 2015 Edition health IT certification criteria updates (except EHI export, which is extended until December 31, 2023)
  • New standardized API functionality
  • Submission of initial attestations
  • Submission of initial plans and results of real-world testing

We will only be focusing on the items with a compliance date of April 5, 2021 for the remainder. These fall into the category of information blocking provisions/requirements. Determining how to apply this depends on what type of actor you are. The following constitutes information blocking and applies to all actors.

Information Blocking Provisions Include

Imposing formal or informal restrictions on access, exchange, or use of EHI

Implementing health information technology in ways that are likely to restrict the access, exchange, or use of EHI

Discouraging efforts to develop or use interoperable technologies or services

Discrimination that frustrates or discourages efforts to enable interoperability

Rent-seeking and opportunistic pricing practices that make information sharing cost prohibitive

However, there are exceptions to the information blocking rules.

Allowable Information Blocking Exceptions

Practices that are likely to interfere with access, exchange, or use of EHI may be justified if the practices are reasonable and necessary to prevent harm to a patient or another person

An actor does not have to fulfill a request to access, exchange, or use EHI in a way that is prohibited under state or federal privacy laws

Practices that are likely to interfere with access, exchange, or use of EHI may be justified in order to safeguard EHI when the practice is tailored to specific security

Legitimate practical challenges may limit an actor’s ability to comply with requests for access, exchange, or use of EHI

Reasonable and necessary practices that temporarily make health IT unavailable or that degrade the health IT’s performance may be permitted for regular maintenance

May be permitted to limit the content of a response to a request to access, exchange, or use EHI or the manner in which it fulfills a request if content and manner conditions are met

Actors may charge fees, including fees that result in a reasonable profit margin, related to the development/provision of technologies and services that enhance interoperability

Protects the value of actors’ innovations and allows the charge of reasonable royalties to earn returns on investments made to develop, maintain, and update those innovations

The remaining items within information blocking related to CoC/MoC requirements are applicable to actors developing applications and interfaces. Typically these are the Health Information Networks and Health IT Developers. However, as applications and interfaces are implemented it will also be the responsibility of the Healthcare providers to ensure Cures Act requirements are being met.

Lastly, here is what you can do now to prepare for the Cures Act.

Kevin Cornwell, CPA, CISA, CITP
IT Audit Associate Director
502.566.1011 | kcornwell@ddaftech.com

Filed Under: Healthcare, Industries, Services, Technology Tagged With: Cures Act, Healthcare IT, Healthcare technology

  • Services
    • Outsourced Accounting
    • Audit & Assurance
    • Tax
    • Consulting & Advisory
    • Technology & Cybersecurity
    • Family Office
    • Wealth Management
  • Industries
  • Company
  • Locations
  • Careers
  • Insights
  • Events
  • Contact Us
facebook Dean Dorton - CPAs And Advisors On Facebook twitter twitter linkedin Dean Dorton - CPAs And Advisors On LinkedIn youtube Dean Dorton - CPAs And Advisors On YouTube

The matters discussed on this website provide general information only. The information is neither tax nor legal advice. You should consult with a qualified professional advisor about your specific situation before undertaking any action.

© 2026 Dean Dorton Allen Ford, PLLC. All Rights Reserved