Paubox is the easiest way to send and receive HIPAA compliant email. No portals. No plugins. No extra steps. Just secure email for both senders and recipients.
We recently sat down with Ben Holber, Founder CEO of YoDerm, for another episode of HIPAA Center.
Here is a transcript of how Ben is simplifying the dermatology prescription process. You can watch the entire interview here.
Ben Holber: How YoDerm is simplifying receiving dermatology prescriptions
Hoala Greevy: Now I understand you folks are also – and I think you alluded to it a few minutes ago – you’re also in the mix when it comes to the delivery of the treatments?
Ben Holber: Yeah, that’s right. Yeah, absolutely.
Hoala Greevy: That’s cool.
Ben Holber: Yeah we initially started off just doing the consultations and the prescriber would create your treatment plan for you and if there was a prescription, we’d send it off to say CVS and you’d go pick it up.
We found that regardless of how easy we made the consult, it’s actually still really difficult to obtain the meds. You’re dealing with navigating your maze of co-pay, co-insurance, max amount of pocket, all that stuff.
And ultimately, you still have to find time to go to the pharmacy. We can make getting the treatment plan as conveniently as possible but if medication is still difficult, the treatment plan doesn’t matter, right?
So for a handful of conditions, we’re doing the fulfillment as well with partner pharmacies so we can send it directly to patients. And we found that our retention and our patient compliance has shot through the roof because of it.
Hoala Greevy: Oh, that’s great.
Ben Holber: Yeah, yeah. It’s a win-win for everybody.
Hoala Greevy: The last mile.
Ben Holber: Exactly.
Hoala Greevy: That’s awesome.
About YoDerm
YoDerm is the easiest way to get prescription medications from a board certified dermatologist. Their mission is to expand the access to dermatology services by making them more convenient and affordable.
…there was a breach in personal information related to some Polk County social work assessments.
There are 2,042 individuals whose information was included in the breach, which happened during the assessment period of some child and dependent adult abuse cases. Letters were mailed this week notifying these Iowans of the breach.
This occurred when two workers used personal email accounts, personal online storage accounts and personal electronic devices for work purposes. That caused confidential data to be transmitted outside the DHS secure network. The incidents happened over a 5-year period starting in 2008.
“There are no reports that any of the information was misused before it was deleted,” said Pat Penning, service area manager for the region including Polk County. “We’ve sent notification to individuals whose information was transmitted outside the secure network.”
The types of information involved included name, mailing address, Social Security number, state identification number, date of birth, health information and incident information.
The department began an internal investigation on January 17, 2014, once the issue was identified by a social work supervisor. Officials found that the workers did not follow DHS policy, which prohibits use of personal devices and transmitting information outside of the agency’s network. Appropriate personnel action was taken.
“The chance that this information was accessed through these password-protected accounts and devices was small,” said Penning, “but we realize the Iowans involved in these cases may wish to take steps to be sure their information wasn’t misused.”
DHS is taking further action including blocking access to online file storage sites, providing updated materials to staff on the department’s information technology policy and standard operating procedures, and continuing to require yearly cyber-security training for all employees.
HHS Wall of Shame
The HHS Wall of Shame is a website under the jurisdiction of HHS that lists all HIPAA breaches reported within the last 24 months. The Wall of Shame displays breaches that are currently under investigation by the Office for Civil Rights.
As part of section 13402(e)(4) of the HITECH Act, the HHS Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.
HIPAA Breach Report
The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame.
Millions of Americans suffer from some type of skin condition – whether it’s acne that affects 50 million Americans, or rosacea, or even male pattern baldness.
Wait times to see a dermatologist can be one to two months, and considering most conditions need ongoing treatment, the period between appointments can feel like forever.
Ben Holber was one dermatology patient who was tired of waiting, so he created YoDerm: an on-demand dermatology service that takes care of your skin on your time.
YoDerm is the easiest way to get prescription medications from a board certified dermatologist. Their mission is to expand the access to dermatology services by making them more convenient and affordable.
On April 5, 2018, Diagnostic Radiology & Imaging submitted a HIPAA Email Breach to the U.S. Department of Health and Human Services (HHS).
Located in Greensboro, NC, Diagnostic Radiology & Imaging’s email breach affected 800 individuals’ protected health information.
Diagnostic Radiology & Imaging is classified as a Healthcare Provider.
According to Diagnostic Radiology & Imaging’s press release:
On January 31, 2018, DRI became aware of an impermissible disclosure of limited health information about approximately 800 patients. An investigation revealed that on November 11, 2017, an employee of DRI became the victim of a phishing attack. “Phishing” is a type of cybercrime in which individuals are targeted and tricked into revealing sensitive or confidential information. In this case, an attacker emailed DRI employees using an email address that appeared to be legitimate, and one DRI employee revealed information to the attacker that allowed the attacker to access the DRI employee’s work-related email account. Within that DRI employee’s email account, we found a limited amount of information about patients, including names, a general description of imaging services received (including date, type, and location of imaging service), medical record numbers, and in some cases, email addresses and phone numbers. In just a few cases, the patient’s date of birth was also included. As a result, the attacker gained access to that information.
Please note that the attacker did not have access to any of our patients’ Social Security Numbers or other financial information, and for that reason, we do not believe there is any risk of financial harm to our affected patients as a result of this phishing attack.
In accordance with DRI policy, and as required by federal law, DRI is notifying affected patients via first-class mail.
We take the confidentiality and secure handling of patients’ information seriously. Our investigation involved external forensic investigators as well as attorneys with experience in handling these types of incidents. We have policies and procedures in place regarding the confidentiality and security of patient information, and we train our employees on these policies and procedures on a regular basis. In response to this cybercrime, we have retrained our employees and contractors on our policies and procedures relating to privacy and security. We have also implemented more specific training on phishing and other types of cybercrimes to better educate our employees and contractors.
We are very sorry that this happened, and we are taking steps to try to prevent situations like this in the future.
HHS Wall of Shame
The HHS Wall of Shame is a website under the jurisdiction of HHS that lists all HIPAA breaches reported within the last 24 months. The Wall of Shame displays breaches that are currently under investigation by the Office for Civil Rights.
As part of section 13402(e)(4) of the HITECH Act, the HHS Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.
HIPAA Breach Report
The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame.
Guardian Pharmacy of Jacksonville, LLC (“Guardian”) is notifying certain patients of the unauthorized access to certain limited pieces of patient information, including patient name, prescription medication information, treatment details, and diagnosis information.
For a small number of individuals, this information also included Social Security numbers and health insurance information. Although we are unaware of any actual or attempted misuse of protected health information, Guardian is providing its impacted patients with information about the event, steps taken since discovering the incident to mitigate the risk of misuse of the information, and what can be done to better protect against potential harm resulting from this event.
On October 3, 2017, Guardian identified unusual activity in an employee email account. As part of Guardian’s immediate and ongoing investigation into the event, on February 14, 2018, it was determined that certain pieces of patient information were accessible to an unauthorized individual(s).
“We take this event very seriously,” Khristy McCelland, President of Guardian Pharmacy of Jacksonville, stated. “Upon learning of the event, we immediately changed the credentials to the email account and launched an extensive internal investigation, which was supported by a third-party forensic investigation firm, into the nature and scope of the incident. Once we confirmed that protected health information was accessible to an unauthorized individual(s), we immediately took steps to mitigate the risk to our impacted patients and to notify them of the incident. In response to this incident, we have augmented our password security policies and provided additional training to employees.”
In addition to mailing letters to its impacted patients, Guardian disclosed this incident to the U.S. Department of Health and Human Services, the Florida Attorney General, and the major consumer reporting agencies on March 30, 2018.
Guardian is unaware of any actual or attempted misuse of its patients’ information and cannot confirm if their information was accessed without authorization.
Nevertheless, Guardian encourages its patients to review their Guardian account statements, health insurance account records, and explanation of benefits forms for suspicious activity. Any suspicious activity should be immediately reported to the institution that issued the record. Credit monitoring and identity restoration services are being offered to patients whose Social Security numbers were potentially impacted by this event.
HHS Wall of Shame
The HHS Wall of Shame is a website under the jurisdiction of HHS that lists all HIPAA breaches reported within the last 24 months. The Wall of Shame displays breaches that are currently under investigation by the Office for Civil Rights.
As part of section 13402(e)(4) of the HITECH Act, the HHS Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.
HIPAA Breach Report
The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame.
Paubox Encrypted Email redefines the secure email experience. By eliminating portals, plug-ins and extra steps, Paubox is the only solution that enables zero-step encryption on all sent emails and eliminates frustration for your staff and recipients.
If you have Salesforce’s Lightning Experience, you can send Salesforce emails from your Gmail or Office 365 account. Emails sent in Lightning Experience look like they were sent from your Gmail or Office 365 inbox. You can also see the emails you’ve sent in your Gmail or Office 365 Sent Items folder.
If you enable this Salesforce feature and are a Paubox encrypted email user, you can inherently send HIPAA compliant emails from Salesforce.
Follow the tutorial below to activate this Paubox secret bonus in Salesforce.
How to send HIPAA compliant emails from Salesforce
To get started, enable two basic user permissions: permission to send email and permission to access to the record the email is sent from. Move on to the next step after enabling these permissions.
Salesforce still sends workflow emails and trigger emails. However, external email accounts do not support bounce management.
Also, email delivery information when sending emails through Gmail or Office 365 is not available in the Salesforce email logs. Obtain email logs from your Gmail or Office 365 instead.
To integrate Salesforce with your G Suite or Office 365 account:
From your personal settings, enter My Email Settings in the Quick Find box, and select My Email Settings.
Select how you’d like to send your email. Your Salesforce admin can enable either Gmail or Office 365 for your organization. You can’t choose between the two.
Click Save.
After completing these steps, you will have successfully configured your G Suite or Office 365 account to send email from your Salesforce account.
Your outbound mail flow will now look like this: Salesforce > GSuite/Office365 > Paubox > delivered securely to your end recipient.
Thank you for choosing Paubox to secure your emails. Happy emailing!
When you hear the phrase “medical home”, you might think of a nursing home, but actually, a medical home is a place where a patient can receive everything they need for primary care (such as behavioral health, community resources, etc.)
Laura Merrick, Operations Project Manager of Medical Home Network, shares how their work not only affects the primary care community, but also hospitals.
Hoala Greevy: Howzit, this is Hoala Greevy, Founder CEO of Paubox. We’re here at HIMSS18 in Las Vegas. I’m here with Laura Merrick and she’s with Medical Home Network. I just met her a few minutes ago, so let’s get started with another version of HIPAA Center. Laura, thanks for joining us.
Laura Merrick:Thank you for having me.
Hoala Greevy:Can you tell us more about the scope of your work at Medical Home Network?
Laura Merrick:Certainly, certainly. So Medical Home Network is a formal provider collaborative that was founded and funded in Chicago, Illinois. Our focus was improving healthcare delivery and innovation, focusing on reinforcing the centrality of the medical home.
So we began our work about 9 years ago, bringing providers together to share around a common vision to support the Medicaid patients that were so disparately separated across the southside of Chicago.
We had several opportunities along the way and one of those was that we formed a Medicaid ACO known as the MHN ACO.
So the Medical Home Network ACO, known as MHN ACO, supports 9 federally qualified health centers and 3 Hospital systems through an Innovative – through our Innovation and technology in healthcare delivery. We are connected with 25 hospitals around the county area and 180 unique medical homes to support the care for Medicaid recipients outside on the southside of Chicago.
Hoala Greevy:Medical home, is that a skilled nursing home? What exactly is that?
Laura Merrick:No, don’t let our name fool you. At the time, when we first started the work we were really focused on, reinforcing Primary Care – a term for a medical home is a term where a patient can receive everything that they need around primary care. That might be access to behavioral health or Community Resources, and it’s a place where they can not only seek the care that they need but also the help to get the care that they need by their care manager.
So the network that we created in the beginning of our work was really about bringing providers together both in that medical home setting to drive that primary care model. We were able to do that with not only the primary care community but also hospitals, and really drive communication and that was really key to really engaging and reaching patients.
Hoala Greevy:Healthcare is notorious for lack of. Definitely.
Laura Merrick:Right.
Hoala Greevy:So MHN has been around for 9 years if I heard you correctly. How long have you been with the company?
Laura Merrick:Since it was founded, I believe it was 2008. I was one of the second employees.
Hoala Greevy:Wow. So almost from the beginning.
Laura Merrick:Yes.
Hoala Greevy:Wow. So HIMSS18, what was your biggest takeaway from this year?
Laura Merrick:You know, I think for the work that we do, it’s validation that we’re on the right track: driving innovation across our area. That there are opportunities to share best practices with others that are doing the work that we’re doing across the nation, and that there is more that we can do around improving access to data, and ultimately the care for our patients.
Hoala Greevy:Laura, is HIMSS part of your annual conference schedule or is it your first time here?
Laura Merrick:It is my first time here.
Hoala Greevy:Oh wow. Well you picked the right location because last year it was Orlando, and I – this is more preferably for me. Closer and a bit more fun.
Laura Merrick:Yeah.
Hoala Greevy:Great, and last question – where do you see the future of your industry going?
Laura Merrick:I think it’s innovation, it’s healthcare innovation. And that is wrapped around not only technology but how we implement the technology and the meaning behind how we connect data to get access to care for these patients. So I really think it’s continued innovation to empower care management activities, to empower reaching beyond the healthcare ecosystem into the community, and to really think a little bit bigger about how we really provide care.
Hoala Greevy:Man, Laura, thanks for submitting time with us, we really appreciate it. Nice to meet you. Aloha!
Medical Home Network
Medical Home Network (MHN) is a not-for-profit collaborative that has fundamentally changed how care is delivered.
Their proven model of care unites provider communities and diverse healthcare entities around a common goal: to redesign healthcare delivery and transform the way care is managed at the practice level.
Medical Home Network provides the tools and processes to help care teams engage patients and help them become an accountable member of the team. By connecting providers and delivering real-time information, they enable coordinated care management, improve transitions of care, and promote timely follow-up.