HIPAA Breach News

Mailing Vendor Blamed for Blue Cross and Blue Shield of Rhode Island Privacy Breach

Blue Cross and Blue Shield of Rhode Island (BCBSRI) is alerting 1,567 plan members that some of their protected health information has been impermissibly disclosed by one of its business associates.

A BCBSRI vendor was contracted to sent explanation of benefits statements to plan members which contain summaries of the healthcare services members have received under their health plan.

However, an error was made which resulted in statements being sent to incorrect individuals. The explanation of benefits statements included members’ BCBSRI ID number, their service provider(s), the service(s) provided, and the cost of the claims.

The impermissible disclosure of PHI was attributed to an error made by the vendor when combining the explanation of benefits statements for certain individuals who are covered under the same policy. Combining the statements was intended to reduce the number of summaries received by some members.

The error resulted in some explanation of benefits statements being incorrectly combined in the mid-July mailings, which resulted in the summaries being sent to incorrect family members or other individuals in the household that were covered by the same policy.

Upon discovery of the error, BCBSRI instructed the vendor to stop combining the statements and individual summaries will continue to be sent to members while BCBSRI looks for a different solution.

BCBSRI issued a statement about the incident confirming that the error only resulted in the disclosure of PHI to family members or other individuals in the same household covered by the policy, not to any other members.

Since members’ Social Security numbers and dates of birth are not detailed in the summaries, and only family members received the summaries, the risk of any information being misused is believed to be very low.

All individuals who have been impacted by the incident will be notified about the privacy breach by mail in the next few days.

The post Mailing Vendor Blamed for Blue Cross and Blue Shield of Rhode Island Privacy Breach appeared first on HIPAA Journal.

Independence Blue Cross Notifies 17,000 Members of Online Exposure of Their PHI

Independence Blue Cross is notifying thousands of plan members that some of their protected health information has been exposed online and has potentially been accessed by unauthorized individuals.

The Independence Blue Cross privacy office was informed about the exposed information on July 19 and immediately launched an investigation. A leading forensics investigation firm was hired to investigate the incident and establish whether any plan members’ information was accessed during the time it was exposed.

Independence Blue Cross said an employee had uploaded a file containing plan members’ protected health information to a public facing website on April 23, 2018. The file remained accessible until July 20 when it was removed from the website.

The information contained in the file was limited. No financial information or Social Security numbers were exposed. Affected plan members only had their name, diagnosis codes, provider information, date of birth, and information used for processing claims exposed.

Despite a thorough investigation, it was not possible to determine whether any unauthorized individuals accessed the file during the time it was on the website. No reports have been received to date to suggest any protected health information has been misused.

According to a statement from the health insurer, the breach affects certain Independence Blue Cross members and members of its subsidiaries AmeriHealth HMO and AmeriHealth Insurance Co. of New Jersey. Fewer than 1% of plan members – approximately 17,000 individuals – were affected by the breach.

Affected individuals have now been notified of the breach and, out of an abundance of caution, Independence Blue Cross is offering all affected individuals 24 months of free triple-bureau credit monitoring and identity theft protection services.

The Philadelphia-based health insurer has taken steps to prevent further breaches of this nature and ‘appropriate action’ has been taken with the employee who uploaded the file to the website.

The post Independence Blue Cross Notifies 17,000 Members of Online Exposure of Their PHI appeared first on HIPAA Journal.

CMS: Fairview Southdale Hospital Videotaped Patients Without Knowledge or Consent

The HHS’ Centers for Medicare and Medicaid Services (CMS) has investigated Fairview Southdale Hospital in Edina, MN over an alleged violation of patient privacy and discovered that some patients were videotaped during psychiatric evaluations in the emergency department without their knowledge or consent. The hospital was cited for violating patient privacy.

According to the Star Tribune, the CMS launched an investigation following a complaint from a patient who had been taken to the hospital for a psychiatric evaluation against her will in May 2017. The patient was escorted to the hospital as police officers were concerned about her state of mental health and feared she may cause harm to herself or others.

After being released, the patient took legal action over her admission to the hospital and how she was treated by the police. As part of that lawsuit, the patient requested a copy of the security camera footage from the hospital. While the patient expected to receive a copy of the videotape from the front of the hospital showing her entering the facility, the videotape showed her entire visit, including her psychiatric evaluation and her changing into hospital scrubs. The videotape only showed the patient’s back as she was getting changed.

The patient was horrified that the entire visit had been recorded without her knowledge and claimed that there were no warning signs in the emergency room advising patients that they were being recorded.

Fairview Southdale Hospital does indicate on its consent form for treatment that patients may be videotaped for the purpose of medical education, but in this case the patient refused to read to sign the consent form as she was not in the hospital of her own free will and had refused treatment.

Fairview Southdale Hospital cooperated fully with the investigation and informed the CMS that an additional 8 video cameras had been installed in rooms in the emergency department that were used for psychiatric evaluations following an increase in the number of incidents in which patients had become violent.

CMS found that cameras were used in those rooms, although there were no signs warning patients that they were being videotaped. The camera footage was visible in the nursing station but was out of public view.

Typically, footage from the cameras is permanently erased, although in this case the footage was retained as the patient had also made a complaint to the hospital about her visit.

Sue Abderholden, executive director of the Minnesota chapter of the National Alliance on Mental Illness, told the Star Tribune, “Healthcare facilities that videorecord patients for security reasons should notify them… If you’re going to do it, there should be a sign and you should orally tell the person.”

Following the investigation, the hospital retrained staff and informed its nurses to instruct patients that they may be filmed during their emergency room visits. Privacy screens have now been installed to prevent patients from being filmed while changing and from September, the hospital has discontinued recording video footage, but will continue to use the cameras for medical education purposes and for safety reasons.

The post CMS: Fairview Southdale Hospital Videotaped Patients Without Knowledge or Consent appeared first on HIPAA Journal.

Fetal Diagnostic Institute of the Pacific Experiences Ransomware Attack

The Fetal Diagnostic Institute of the Pacific (FDIP) in Honolulu, HI, experienced a ransomware attack on June 30, 2018. File-encrypting software was installed on an FDIP server and encrypted a wide range of file types, including patient medical records.

FDIP engaged the services of a leading cybersecurity company to conduct a full investigation into the breach to determine whether patient data was accessed by the attackers and also to assist with breach remediation. The investigation did not uncover any evidence to suggest that patients’ protected health information was accessed, viewed, or stolen by the individuals behind the attack, although it was not possible to rule out data access and data theft with a high level of confidence.

Consequently, the incident is being treated as a HIPAA breach, patients are being notified, and the Department of Health and Human Services’ Office for Civil Rights (OCR) has been informed.

An analysis of the files encrypted by the ransomware revealed they contained a range of protected health information. Patients affected by the security breach may have had their full name, home address, date of birth, account number, diagnoses, and “other types of information” exposed. No financial information was exposed as a result of the attack. The breach report submitted to OCR indicates 40,800 current and former patients have been affected by the breach.

FDIP reports that prompt action was taken to address the breach and remove the malicious software and restore all encrypted files. Its systems have now been cleansed and no trace of any malware remains. Steps have also been taken to improve security protections to prevent any further security breaches and unauthorized disclosures of patient data.

FDIP does not expect patients to experience any harm as a result of the ransomware attack, although patients have been urged to get in touch with FDIP immediately if they become aware of any suspicious activity that they believe is related to the breach.

This is only the fifth data breach of more than 500 records to have been reported to OCR by a Hawaii-based covered entity since data breach summaries first started being published by OCR in 2009.

The post Fetal Diagnostic Institute of the Pacific Experiences Ransomware Attack appeared first on HIPAA Journal.

Email Security Breaches Reported by Hopebridge (IN) and United Methodist Homes (NY)

Hopebridge, an Indiana-based network of 28 autism treatment centers throughout the Midwest, has discovered it has been the victim of a phishing attack that has potentially resulted in an unauthorized individual gaining access to the protected health information (PHI) of its patients.

A security breach was detected on July 19, 2018 prompting a thorough investigation. A leading third-party computer forensics firm was engaged to assess the nature and scope of the breach and all accounts and systems were immediately secured to lock out the attacker.

The investigation revealed several employees had been fooled by phishing emails that had been sent between March and July 2018. Several email accounts were compromised as a result of employees’ responses to those emails. An analysis of the compromised email accounts revealed they contained a limited amount of patients’ PHI – Their names, the services they received from Hopebridge, and an inferred autism diagnosis.

The results of the forensic investigation suggest that it was not the intention of the attacker to gain access to PHI, instead the attacks appear to have been an attempt to gain access to employees’ financial information.

The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates 1,411 patients have been impacted by the incident. Hopebridge says there is no indication that any patient information has been misused.

The breach has prompted Hopebridge to implement stronger access controls, IP address whitelisting, and 2-factor authentication on email accounts. Hopebridge is also now masking patient names on internal emails and reports

Former Employee Stole Information of United Methodist Homes Residents

United Methodist Homes, a network of Independent and Assisted Living facilities for seniors in New York, has discovered an employee stole the protected health information of some of its current and former residents.

A spreadsheet containing information on 843 current and former residents of its Elizabeth Church and Hilltop campuses was emailed to the employee’s personal email account. The spreadsheet contained information such as residents’ names, addresses, phone numbers for residents’ contact person(s) and the relationship of those individuals to the residents. No highly sensitive information such as financial data, health data, health insurance information, or Social Security numbers were recorded in the spreadsheet.

Following the discovery of the incident on July 13, 2018, the employee was questioned, and United Methodist Homes observed the employee deleting the email and spreadsheet from his personal email account. The individual is no longer employed by United Methodist Homes.

Even though the information in the spreadsheet was extremely limited, United Methodist Homes has offered complimentary credit monitoring services to affected individuals for 12 months.

The post Email Security Breaches Reported by Hopebridge (IN) and United Methodist Homes (NY) appeared first on HIPAA Journal.

Texas Nurse Fired for Social Media HIPAA Violation

A nurse at a Texas children’s hospital has been fired for violating Health Insurance Portability and Accountability Act (HIPAA) Rules by posting protected health information on a social media website.

The pediatric ICU/ER nurse worked at Texas Children’s Hospital and posted a series of comments on Facebook about a rare case of measles at the hospital. The nurse was an anti-vaxxer and posted about the experience of seeing a boy at the hospital suffering from the disease – a disease that could have been prevented through vaccination.

Her comments explained how the disease was much worse that she expected it to be, having not encountered anyone with the measles in the past.  She explained that it was a “rough” experience seeing the boy suffering from the disease.

She also explained in one of her posts, “I think it’s easy for us non-vaxxers to make assumptions, but most of us have never and will never see one of these diseases,” according to the Houston Chronicle, which obtained screenshots of her Facebook posts. “By no means have I changed my vax stance, and I never will. But this poor kid was bad off and as a parent, I could see vaccinating out of fear.”

Due to a high rate of vaccination (94.5%) in Houston, a measles case is very rare. Over the past ten years there have fewer than 10 confirmed cases in the city. While the nurse did not post the child’s name on Facebook, her job was listed on her profile, along with the hospital where she worked, and information about the boy and his condition. Due to the information contained in the posts and the rarity of the disease, it is possible that the child could have been identified.

Texas Children’s Hospital suspended the nurse when officials found out about her social media posts and an investigation was launched. After receiving the suspension, the nurse appeared to realize that she had shared too much information and deleted several of her posts. Four days after the nurse was suspended the decision was taken to fire her for the HIPAA violation. An official from Texas Children’s Hospital confirmed the nurse lost her job as a result of violating hospital policies and federal laws by posting protected health information on a social media website, and not for her anti-vaxxing views.

The HIPAA Privacy Rule places restrictions on the allowable uses and disclosures of protected health information. Most healthcare professionals will be well aware that the posting of any protected health information on a social media website constitutes a HIPAA violation.

However, as this incident shows, the patient does not need to be mentioned by name in order for them to potentially be identified. If any personally identifiable protected health information is posted on social media without consent first being obtained from the patient, it constitutes a violation of the HIPAA Privacy Rule.

A good rule of thumb is to keep work and private lives separate, and never to post any information about patients on a social media platform, even if you do not think that a patient could be identified from the post.

At HIMSS 2017, the former deputy director of health information privacy at the HHS’ Office for Civil Rights (OCR) explained that OCR plans to issue guidance on HIPAA and social media and what is and is not acceptable.

The post Texas Nurse Fired for Social Media HIPAA Violation appeared first on HIPAA Journal.

Phishing Attack on Acadiana Computer Systems Exposed the PHI of 31,000 Individuals

Acadiana Computer Services Inc., a Lafayette, LA-based provider of software and business solutions for the healthcare industry, has discovered an unauthorized individual has gained access to the email account of one of its employees.

The security breach was detected on July 6, 2018 and external access to the account was immediately disabled. An independent cybersecurity expert was retained to conduct a forensic analysis of the breach and determine the nature and scope of the attack.

An analysis of the emails in the compromised account revealed they contained the personal information of several of its clients’ patients. The information potentially accessed was limited to names, addresses, treatment information, billing information, and for a limited number of individuals, Social Security numbers.

The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates 31,151 individuals have had their protected health information exposed as a result of the email account breach.

Those individuals had previously received medical services from the following healthcare providers

  • Radiology and Interventional Associates of Metairie
  • LSU Healthcare Network
  • LSU Health Sciences Center Shreveport
  • Poly Ryon (Oakbend) Medical Group
  • Oceans Acquisition, Inc.
  • South Louisiana Medical Associates
  • Southern Surgical
  • Truman Medical Centers
  • University Hospital and Clinics
  • University of South Alabama
  • Willis-Knighton Medical Center

Acadiana Computer Services is sending notification letters to all individuals whose protected health information was potentially accessed and is providing further information on the steps they can take to monitor and protect their personal information.

Out of an abundance of caution, Acadiana Computer Services is covering the cost of identity monitoring services for all affected patients.

Acadiana Computer Services has already taken steps to reduce the risk of further breaches, which include augmenting email account security, retraining staff, and reviewing and updating its policies and procedures.

The post Phishing Attack on Acadiana Computer Systems Exposed the PHI of 31,000 Individuals appeared first on HIPAA Journal.

Reliable Respiratory Phishing Attack Impacts 21,000 Patients

The Norwood, MA-based respiratory care provider Reliable Respiratory has experienced a phishing attack that has affected several thousand of its patients.

A cyberattack was suspected on July 3, 2018, following the detection of usual activity in an employee’s email account. An investigation was launched to determine the cause of that activity, which revealed the employee had been targeted with a phishing campaign. The response to a phishing email resulted in the disclosure of that individual’s login credentials.

The unusual account activity was detected on July 3 and the account was immediately secured. Computer forensic specialists were retained to determine the nature and extent of the breach. The breach investigation confirmed that the account had been accessed by an unauthorized individual between June 28 and July 2. An analysis of the emails contained in the account showed a wide range of protected health information could potentially have been accessed by the attacker.

Patients are now being notified of the breach by mail and have been advised to monitor their account statements and explanation of benefits statements closely for signs of identity theft and fraud. No mention was made in its substitute breach notice about whether credit monitoring and identity theft protection services are being offered to affected patients.

Patients affected by the breach may have had the following types of protected health information exposed: Name, date of birth, medical record number, medical diagnosis, treatment information, medication/prescription information, username and password, patient claim/billing information, health insurance information, driver’s license number, state identification number, Social Security number, passport number, bank or financial account information, and credit or debit card information.

Reliable Respiratory will be implementing additional safeguards to improve the security of its systems and will update its policies and procedures to reduce the risk of experiencing future cyberattacks.

The report submitted to the Department of Health and Human Services’ Office for Civil Rights shows 21,311 patients were affected by the phishing attack.

Carpenters Benefit Funds of Philadelphia Email Security Incident

A similarly sized email breach was reported to OCR by Carpenters Benefit Funds of Philadelphia on August 31, 2018. The email hacking incident resulted in the exposure and possible theft of 20,015 plan members’ records.

A substitute breach notice has not yet been uploaded to the Carpenters Benefit Funds of Philadelphia website and a prominent media outlet does not appear to have been notified of the breach at the time of writing, so the exact nature of the breach is not yet known.

The post Reliable Respiratory Phishing Attack Impacts 21,000 Patients appeared first on HIPAA Journal.

Medical Records from New Mexico Hospital Found Scattered in Street

The New Mexico Department of Health is currently investigating how the private medical records of some of its patients came to fall from a truck during transportation from the hospital to a secure storage facility.

The records came from Turquoise Lodge Hospital, a rehabilitation center run by the New Mexico Department of Health that specializes in the treatment of parents and pregnant women who are recovering from substance abuse.

The hospital had arranged for patients’ medical records to be collected and transported to a new location for storage. The paperwork was collected from the hospital on Thursday August 30; however, during transit some of those records fell out of the delivery truck onto a busy Albuquerque street.

KRQE News 13 sent reporters to the scene who discovered medical records strewn along Avenida Cesar Chavez at I-25. Some of the paperwork had been collected by members of the public.

The paperwork contained highly sensitive personally identifiable information (PII) and protected health information (PHI), including patients’ names, their medical histories, billing information, and Social Security numbers.

The New Mexico Department of Health was notified about the incident and sent a cleanup crew to collect the remaining paperwork on Friday August 31, at least 12 hours after the records had fallen off the truck. It is currently unclear whether all the records have been recovered.

An investigation has been launched to determine why the medical records were not secured in transit and how they were able to fall from the delivery truck. At this stage it is unclear exactly how many patients have had their health information exposed.

When those individuals are identified, the New Mexico Department of Health will send out notification letters in the mail. A report will also be submitted to the Department of Health and Human Services’ Office for Civil Rights and state authorities.

The post Medical Records from New Mexico Hospital Found Scattered in Street appeared first on HIPAA Journal.