HIPAA Breach News

Delta Health Systems Alerts Plan Members to Exposure of SSNs Over Internet

Employees of Turlock Irrigation District in California who are members of their employer-sponsored health plan are being notified that some of their protected health information has been exposed online as a result of an error at a business associate.

Delta Health Systems (DHS) provides administrative services related to the health plan and requires access to certain protected health information. Some of that information was made accessible over the internet through a link to a DHS webpage.

The error was made by third-party website developer. While the website had been configured to restrict access, there was a conflicting setting which provided general access to the document which took precedence.

Affected plan members have been told that their billing statement for their employee-sponsored health plan could have been accessed by unauthorized individuals during the time it was accessible over the internet. The billing statement contained the plan member’s first and last name, employer’s name and address, DHS ID number, and Social Security number.

All affected members have been offered one year of free membership to credit monitoring and identity theft protection services through Experian.

The issue was identified and corrected on April 18, 2019. It was not possible to determine when the error was introduced and for how long plan members’ personal information was exposed. It was not possible to determine whether any unauthorized individuals accessed the billing statements while they were unprotected.

In addition to correcting the problem, DHS has contacted search engines to request the removal of all cached content. DHS is also revising its security policies and procedures and has built a new, more secure website that lacks the software that was misconfigured.

The incident has been reported to the California Attorney General but has not yet been listed on the HHS’ Office for Civil Rights website, so it is currently unclear how many plan members have been affected.

Ellwood City Medical Center Investigating Cyberattack

Officials at Ellwood City Medical Center, in Ellwood City, PA, are currently investigating a cyberattack that compromised part of its systems. The attack appears to have started on or around Saturday May 27, although at this stage, no further information has been released. Analyses are ongoing to determine whether any patient records have been compromised.

The cyberattack comes at a time when the Americore Health-owned medical center is embroiled in problems associated with billing and payroll and is being investigated over late payments of wages to staff.

The post Delta Health Systems Alerts Plan Members to Exposure of SSNs Over Internet appeared first on HIPAA Journal.

AMCA Data Breach Tally Passes 20 Million as BioReference Laboratories Added to List of Impacted Entities

The total number of victims of the American Medical Collections Agency (AMCA) data breach has now passed 20 million, as yet another healthcare organizations has been confirmed as being affected by the breach.

New Jersey-based laboratory and clinical testing company BioReference Laboratories is the latest confirmed victim, with approximately 422,600 of its customers having had their personal information exposed in the AMCA data breach.

BioReference Laboratories joins Quest Diagnostics/Optum360 (11.9 million records) and LabCorp (7.7 million records), with the total number of compromised records now standing at 20,022,600 records. That number may well continue to grow as the investigation progresses and more healthcare entities are notified that their data has also been compromised.

BioReference Laboratories confirmed the breach in an 8-K Security and Exchange Commission (SEC) filing on Monday. The OPKO Health subsidiary was notified it has been impacted by the breach on June 3, 2019.

The breach at AMCA occurred between August 1, 2018 and March 30, 2019, during which time hackers had access to the AMCA web payment page, which included data of several healthcare clients.

Patients who had received BioReference Laboratories testing services had the following information compromised: Name, address, phone number, date of birth, date of service, email address, provider information, balance information, and bank account information. No Social Security numbers, medical information, test results, or passwords/security questions and answers were exposed.

AMCA has confirmed that approximately 6,600 customers of BioReference Laboratories whose financial information has been exposed have been notified by AMCA and offered complimentary credit monitoring and identity theft protection services for 2 years.

As is the case with the other affected entities, only basic information has so far been provided by AMCA. No company affected by the breach has so far been provided with full details of the individuals affected, so breach notification letters cannot yet be sent.

BioReference Laboratories said it is attempting to obtain further information about the breach from AMCA and when that information is received additional steps will be taken. BioReference Laboratories notes that no collection requests have been sent to AMCA since October 2018 and a request has been submitted to AMCA to stop working on any pending collections requests.

Several state Attorneys General have confirmed that they have launched investigations and have contacted AMCA and the breached entities demanding further information.

“This data breach is yet another example of how fragile our information infrastructure is, and how vulnerable all of us are to cyber hacking,” said Michigan Attorney General Dana Nessel. “Here in Michigan, we continue to rely on media reports that alert us to these terrible situations because – unlike most other states – we have no law on the books that requires that our office be notified when a breach occurs.”

Nessel is particularly concerned about the length of time hackers had access to the AMCA payment page before the breach was detected and that the attack appears to have been conducted specifically to obtain sensitive patient information, which places affected individuals at a high risk of fraud.

New York Attorney General Letitia James, Minnesota Attorney General Keith Ellison, and North Carolina Attorney General Josh Stein have also confirmed that they have started investigating the data breach. Two New Jersey senators have also demanded answers New Jersey-based Quest Diagnostics. However, it appears that the affected companies are still very much in the dark about what exactly has happened and who has been affected. Only limited information has been provided as AMCA continues to investigate.

AMCA has confirmed it has already taken steps to improve security, including taking its web payments page offline, migrating its services to another third-party vendor, and has hired a cybersecurity firm to assess cybersecurity protections and install additional security measures. Third-party forensics experts are continuing to investigate the breach and identify other data that may have been affected.

The post AMCA Data Breach Tally Passes 20 Million as BioReference Laboratories Added to List of Impacted Entities appeared first on HIPAA Journal.

Misconfigured University of Chicago Medicine ElasticSearch Instance Exposed More Than 1.68 Million Records

It is certainly a week of massive data breaches. 11.9 million Quest Diagnostics records were exposed, 7.7 million records at LabCorp have potentially been compromised, and now University of Chicago Medicine has discovered more than 1.68 million of its records have been exposed.

The records were stored on a misconfigured ElasticSearch server which had had protections removed allowing it to be accessed over the internet without the need for any authentication. The misconfiguration allowed a database to be accessed which contained 1,679,993 records of donors and prospective donors.

The exposed database was discovered by Security Discovery researcher Bob Diachenko on May 28. Diachenko had performed a search using the search engine Shodan to identify unsecured databases. Even though awareness has been raised following the discovery of a large number of exposed ElasticSearch instances and other NoSQL databases in recent months, Security Discovery researchers are still identifying between 5 and 10 ‘big cases’ of unsecured databases every month.

The latest find was a sizable cluster containing 34GB of data. The cluster, named data-ucmbsd2, had been indexed by Shodan and could be accessed over the internet by anyone. The database contained a range of information including names, addresses, phone numbers, email addresses, dates of birth, gender, marital status, wealth information and current financial status, and notes about past communications.

Diachenko determined that the data belonged to UC Medicine and sent a notification and the ElasticSearch instance was secured within 48 hours.

UC Medicine has issued a statement confirming a comprehensive forensic investigation was conducted, which determined the database was not subjected to unauthorized access other than by Diachenko. Diachenko confirmed that he only accessed some of the records to determine who they belonged to and did not download the database. Fortunately, the window of opportunity was short. Diachenko discovered the database one day after it had been indexed by Shodan.

ElasticSearch instances should be configured so they are only accessible over an internal network and authentication controls should be implemented to ensure only authorized individuals have access. Misconfigurations not place data at risk of theft, there have also been instances where the lack of authentication has allowed hackers to encrypt databases using ransomware or even totally delete all stored data.

The post Misconfigured University of Chicago Medicine ElasticSearch Instance Exposed More Than 1.68 Million Records appeared first on HIPAA Journal.

Up to 7.7 Million Patients of LabCorp Impacted by AMCA Breach

Following the news that the data breach at American Medical Collection Agency (AMCA) exposed the records of 11.9 million Quest Diagnostics patients, comes news of another healthcare company that has been affected by the breach.

On June 4, 2019, LabCorp, another national network of blood testing centers, announced that 7.7 million individuals whose blood samples were processed by the company may have had their sensitive information exposed.

As was the case with Quest Diagnostics, LabCorp disclosed the breach through a U.S. Securities and Exchange Commission (SEC) filing. LabCorp said it had been notified by AMCA that its data had also been exposed as a result of the cyberattack on AMCA’s web payment portal, which saw hackers gain access to the system between August 1, 2018 and March 30, 2019. LabCorp said AMCA held data on 7.7 million of its customers.

According to the AMCA website, the company manages more than $1 billion in annual receivables for a diverse client base, which includes “”laboratories, hospitals, physician groups, billing services, and medical providers all across the country.”

It is therefore unsurprising that another healthcare organization has announced that it too has been impacted by the data breach at AMCA. It is likely that over the course of the next few days and weeks that there will be several other announcements by healthcare organizations that have also been impacted by the breach.

The number of healthcare records known to have been exposed is now 19.6 million and only two healthcare companies have so far announced that they have been affected.

The LabCorp data did not include Social Security numbers, unlike Quest Diagnostics, but did include names, addresses, phone numbers, dates of birth, dates of service, provider information, balance information, and some banking and credit card information. LabCorp notes that no diagnostic information, medical test results, or insurance information were provided to AMCA. As was the case with Quest Diagnostics, LabCorp has stopped using AMCA for billing collections.

Around 200,000 individuals whose financial information was exposed are being notified by AMCA and have been offered 2 years of credit monitoring and identity theft protection services. LabCorp has not yet received full details on the individuals that have been impacted by the breach, so notifications to other customers cannot yet be issued.

As reported yesterday, Gemini Advisory discovered around 200,000 credit cards listed for sale on a darknet marketplace and tipped off AMCA to the breach. Those credit card numbers were not from LabCorp customers as the data set included Social Security numbers, which were not provided by LabCorp to AMCA.

The post Up to 7.7 Million Patients of LabCorp Impacted by AMCA Breach appeared first on HIPAA Journal.

AMCA Data Breach Impacts 12 Million Quest Diagnostics Patients

A hacker has gained access to the systems of Elmsford, NY-based billing collections company American Medical Collection Agency (AMCA) and potentially viewed and copied the protected health information of 11.9 million patients of Quest Diagnostics.

Quest Diagnostics is one of the largest blood testing laboratories in the United States but is just one entity that uses AMCA services. It is possible that the breach could be much larger and impact patients of other healthcare organizations. At almost 12 million records, it is already the second largest healthcare data breach ever to be reported, behind Anthem’s 78.8 million record data breach of 2015.

The data breach first came to light in May 2019 when researchers at Gemini Advisory notified databreaches.net that they had discovered the payment card details of around 200,000 patients listed for sale on a darknet marketplace. Gemini Advisory determined that the credit card details came from AMCA and appeared to have been obtained between September 2018 and March 2019.

Gemini Advisory notified AMCA about the potential breach, although no response was received. The matter was then reported to law enforcement which contacted AMCA to confirm that a breach had occurred.

AMCA provides billing collection services to Optum360, which is a business associate of Quest Diagnostics and a unit of the health insurer UnitedHealth Group. AMCA notified Quest Diagnostics and the revenue cycle management vendor Optum360 about the breach on May 14, 2019.

AMCA said a breach had occurred that resulted in the exposure of patient data between August 1, 2018 and March 30, 2019. Computer forensics experts have been retained to investigate the breach and determine exactly how many patients had been affected and the investigation is ongoing.  AMCA suspects around 11.9 million Quest patients have been impacted by the breach. AMCA also confirmed the compromised system contained data from entities other than Quest Diagnostics.

The hackers gained access to systems containing information such as names, personal information, Social Security numbers, financial information, and medical information, although no laboratory test results were compromised.

While Quest Diagnostics and Optum360 have been made aware of the scale of the breach, they have not yet received full information about the patients that have been affected. Quest Diagnostics also said it has not yet ben able to verify the accuracy of the information provided by AMCA.

Quest Diagnostics has issued a statement saying it is working closely with Optum360 and will send notification letters to all affected individuals when AMCA provides full details of the breach.

The post AMCA Data Breach Impacts 12 Million Quest Diagnostics Patients appeared first on HIPAA Journal.

7 Month Data Breach Discovered by Communities Connected for Kids

Port St. Lucie, FL-based Communities Connected for Kids (CCK) has discovered an unauthorized individual gained access to databases containing the protected health information of child clients, their parents and staff members.

The breach was identified when suspicious activity was detected in the databases by one of its third-party vendors. An external computer forensics expert was hired to conduct an investigation which revealed access to the databases was first gained in August 2018. The breach was detected in March 2019 and access to the databases was promptly blocked.

During the 7 months that the individual had access to the databases, range of sensitive information was potentially viewed and downloaded.

The information exposed varied from individual to individual, but may have included name, contact information, date of birth, Social Security number, financial information, family information, Medicaid number, medical record number, prescription information, health insurance information, and medical and clinical information such as diagnoses and treatment information.

According to the breach report submitted to the Department of Health and Human Services’ Office for Civil Rights, 501 individuals were impacted by the breach. That figure may rise, as CCK is still conducting a review of the databases to determine the individuals whose information has been exposed. Once all individuals have been identified, notification letters will be sent, and affected individuals will be provided with free identity theft protection services.

CCK has identified the vulnerabilities which were exploited to gain access to the databases and is working hard to address those issues to ensure that security is improved and further breaches are prevented.

New York Health and Human Services Agency Breach Impacts 1,000 Individuals

People Inc., a not-for profit health and human services agency in Western New York which provides services to seniors and individuals with developmental disabilities, has experienced a phishing attack that has impacted approximately 1,000 individuals.

An investigation was launched on February 19, 2019 following the discovery of unauthorized access to its systems. A forensic investigation confirmed that an unauthorized individual had gained access to two employee email accounts after they responded to phishing emails.

Emails and attachments in the compromised accounts were discovered to include protected health information including names, addresses, Social Security numbers, insurance information, driver’s license numbers, government ID numbers, medical information and financial information.  At this stage, no information has been received to suggest any patient information has been misused.

People Inc., is offering affected individuals free credit monitoring services for one year. The HHS will be notified when People Inc., has confirmed the exact number of individuals affected. The FBI has already been notified about the breach.

The post 7 Month Data Breach Discovered by Communities Connected for Kids appeared first on HIPAA Journal.

Health Quest Patients Notified of Historic Phishing Breach

Health Quest has announced it has suffered a phishing attack that has resulted in the exposure of certain patients’ protected health information.

The breach affected its affiliates Health Quest Medical Practice, Health Quest Urgent Care and Hudson Valley Newborn Physician Services, and the exposed information related to medical services provided to patients of those affiliates.

According to the breach notice on the Health Quest website, on April 2, 2019, Quest Health learned that patient information was contained in emails and email attachments in several employee email accounts that had been compromised as a result of a phishing attack.

Compromised protected health information included names, diagnoses, treatment information, dates of service, provider names, health insurance claims information and other information related to services received between January 2018 and June 2018.

When the breach was detected, the accounts were secured, and a leading cybersecurity firm was engaged to assist with the investigation. Quest Health has since implemented multi factor authentication and has strengthened email security to prevent further breaches. Breach notification letters are being mailed to affected individuals and should be received in the mail by June 10, 2019.

While the time frame for sending notifications appears to be in line with HIPAA requirements (April to June), the phishing attack actually occurred and was detected in July 2018.

According to Health Quest, “On January 25, 2019, Health Quest Affiliates identified email attachments that contained certain health information, and on April 2, 2019, were determined to contain patient information.”

Notification letters were therefore sent 11 months after the email accounts were compromised, and five months after it was first determined that some health information had been exposed. It is unclear why it took so long to determine that the compromised accounts contained PHI.

Breach Reporting Delays Can Prove Costly

There have been several breaches reported recently where the breaches have occurred several months previously, and notifications have only been issued after investigations have been completed.

Naturally, it is not possible to send notifications to affected individuals until those individuals have been identified, but the HHS is quite clear about the requirement to report breaches promptly and within 60 days of the discovery of the breach.

The discovery date is the date when the breach is discovered, not the date when the total number of individuals affected has been determined. OCR notifications are required within 60 days and addenda can be added to the breach reports when further information becomes available, such as the total number of affected individuals.

State attorneys general and OCR have taken action against organizations in the past over delayed breach notifications and have issued regulatory fines.

The post Health Quest Patients Notified of Historic Phishing Breach appeared first on HIPAA Journal.

Data Breaches Reported by TriHealth, Centura Health, and Columbus Community Hospital

The Cincinnati-based health system TriHealth is alerting 2,433 patients about an impermissible disclosure of their protected health information (PHI) to a student mentee.

The student was acting under the direct supervision of a former TriHealth physician and accessed patient information for a potential research project. On June 8 and June 9, 2018, the student was provided with patient information including first and last names, dates of birth, ethnicity, life status, cancer diagnosis information, and zip codes.

TriHealth does not believe that there were any further uses or disclosures of patient information nor that any patient information has been misused. PHI was accessed solely in relation to the potential research project.

Since the student was not an approved TriHealth workforce member, access to patient information was prohibited. As such, this was an impermissible disclosure of patient information which warranted breach notifications to be issued to affected patients. Those notification letters have now been sent.

In its website breach notice, TriHealth said all employees are educated on the hospital’s privacy policies when they are hired and are required to undergo annual re-training. In the event of a violation of hospital policy, corrective action is taken which can include discharge from employment. That process was followed in this case.

Centura Health Email Compromise Impacts 7,515 Patients

The Centennial, CO-based health system Centura Health is alerting 7,515 patients about an email security incident that exposed some of their PHI.

Centura Health discovered the breach on April 16, 2019 and promptly secured the affected email account. A forensic investigation confirmed that the account had been accessed by an unauthorized individual who may have viewed or obtained patient information contained in emails and email attachments. No evidence was uncovered to suggest PHI has been accessed, stolen, or misused, but patients are being notified as a precaution. Letters started to be sent on May 22, 2019.

Patients affected by the breach had some or all of the following information exposed: Name, date of birth, demographic information, medical record number, account number, dates of service, treating physician, services received, medical device supplied, and other clinical information. No health insurance information, financial data, or Social Security numbers were exposed.

Centura Health has taken steps to reduce the risk of further email security breaches, including re-educating the workforce on email security, establishing and using strong passwords, and strengthening email security protections.

Phishing Attack Reported by Columbus Community Hospital

Columbus Community Hospital in Columbus, WI, is alerting certain patients that some of their PHI has been exposed as a result of a phishing attack on one of its business associates.

On April 8, 2019, the claims management service provider OS, Inc., notified Columbus Community Hospital that an unauthorized individual had gained access to the email account of one of its employees and may have viewed patient information.

The information in the compromised account includes names, hospital account numbers, insurer names, summaries of charges, and categories of service. A limited number of patients also had their insurance ID number and/or Social Security number exposed. No evidence of data access, theft, or misuse has been identified to date.

OS Inc., provides claims management services to several hospitals. It is currently unclear whether the breach was limited to Columbus Community Hospital or if patients of other hospitals have also been affected.

The breach has yet to appear on the HHS’ Office for Civil Rights website so it is not yet known how many individuals have been affected.

The post Data Breaches Reported by TriHealth, Centura Health, and Columbus Community Hospital appeared first on HIPAA Journal.

Multi-State Action Results in $900,000 Financial Penalty for Medical Informatics Engineering

Medical Informatics Engineering (MIE) is required to pay a financial penalty of $900,000 to resolve a multi-state action over HIPAA violations related to a breach of 3.9 million records in 2015. The announcement comes just a few days after the HHS’ Office for Civil Rights settled its HIPAA violation case with MIE for $100,000.

MIE licenses a web-based electronic health record application called WebChart and its subsidiary, NoMoreClipboard (NMC), provides patient portal and personal health record services to healthcare providers that allow patients to access and manage their health information. By providing those services, MIE and NMC are business associates and are required to comply with HIPAA Rules.

Between May 7 and May 26 2015, hackers gained access to a server containing data related to its NMC service.  Names, addresses, usernames, passwords, and sensitive health information were potentially accessed and stolen.

A lawsuit was filed in December 2018 alleging MIE and NMC had violated state laws and several HIPAA provisions. 16 state attorneys general were named as plaintiffs in the lawsuit: Arizona, Arkansas, Connecticut, Florida, Indiana, Iowa, Kansas, Kentucky, Louisiana, Michigan, Minnesota, Nebraska, North Carolina, Tennessee, West Virginia, and Wisconsin.

The plaintiffs’ investigation into the breach revealed hackers had exploited several vulnerabilities, MIE had poor password policies in place, and security management protocols had not been followed.

Under the terms of the consent judgement, in addition to the financial penalty, MIE must implement and maintain an information security program and deploy a security incident and event monitoring (SIEM) solution to allow it to detect and respond quickly to cyberattacks.

Data loss prevention technology must be deployed to prevent the unauthorized exfiltration of data, controls must be implemented to prevent SQL injection attacks, and activity logs must be maintained and regularly reviewed.

Password policies must be implemented that require the use of strong, complex passwords and multi-factor authentication and single sign-on must be used on all systems that store or are used to access ePHI.

Additional controls need to be implemented covering the creation of accounts that have access to ePHI. MIE must refrain from using generic accounts that can be accessed via the Internet and no generic accounts are allowed to have administrative privileges.

MIE is also required to comply with all the administrative and technical safeguards of the HIPAA Security Rule and states’ deceptive trade practices acts with respect to the collection, maintenance, and safeguarding of consumers’ protected health information. Reasonable security policies and procedures must be implemented and maintained to protect that information. MIE must also provide appropriate training to all employees regarding its information security policies and procedures at least annually.

In addition, MIE is required to engage a third-party professional to conduct an annual risk analysis to identify threats and vulnerabilities to ePHI each year for the next five years. A report of the findings of that risk analysis and the recommendations must be sent to the Indiana Attorney General within 180 days and annually thereafter.

The consent judgement has been agreed by all parties and resolves the alleged HIPAA violations and violations of state laws. The consent judgement now awaits court approval. The consent judgement can be found on the website of the Florida Office of the Attorney General – PDF.

The post Multi-State Action Results in $900,000 Financial Penalty for Medical Informatics Engineering appeared first on HIPAA Journal.