HIPAA Breach News

Multiple Data Breaches Reported by Dignity Health

Dignity Health has discovered multiple data breaches and violations of HIPAA Rules in the past few weeks. One incident involved an employee accessing the PHI of patients without authorization, an error occurred that allowed a business associate to receive PHI without a valid BAA being in place, and most recently, a 55,947-record unauthorized access/disclosure incident has been reported to the Department of Health and Human Services’ Office for Civil Rights (OCR).

Business Associate Agreement Error Discovered

On May 10, 2018, Dignity Health notified OCR of a data breach affecting patients of its St. Rose Dominican Hospitals at the San Martin, Siena, and Rose de Lima campuses in Nevada. Dignity Health reports that on April 6, 2018, St Rose Dominican Hospitals shared the protected health information of 6,036 patients with a third-party contractor to process health-related court documents for hearings.

The contractor had been used for ten years and a valid business associate agreement was previously in place; however, that document had expired and data continued to be shared with the contractor due to a clerical error. Dignity Health reports that the manner in which the PHI was shared did not differ in any way to when the BAA was in place.

The matter has been rectified and further controls have been put in place to prevent similar errors from occurring in the future.

Inappropriate Accessing of PHI by St. Joseph’s Hospital and Medical Center Employee

On June 2, Dignity Health’s St. Joseph’s Hospital and Medical Center announced it had discovered an employee had been accessing the health information of patients without authorization for five months. During that time, portions of 229 patients’ records were inappropriately accessed.

The inappropriate accessing of health information was discovered during periodic review of PHI access logs. That review revealed one employee had been accessing patients’ health information from October 13, 2017 to March 29, 2018. During that time, the records of 229 patients were accessed.

The types of information that could have been viewed by the employee were restricted to names, dates of birth, demographic information, physicians’ and nurses’ notes and diagnostic information. The accessing of the information appears to have taken place out of curiosity rather than malicious intent.

Since no financial data or Social Security numbers were accessed, patients have been told they do not need to take any actions to protect their identities. Notifications have been issued as a precaution and to satisfy the requirements of HIPAA.

Dignity Health reports that appropriate disciplinary action has been taken against the employee for the violation of hospital policies and HIPAA Rules.

55,947-Record Email Breach Reported

On May 31, Dignity Health submitted a breach report to OCR that has been listed as an unauthorized access/disclosure incident involving email. The breach report indicates there was some business associate involvement in the incident, although no further information on the breach is currently available.

HIPAA Journal has contacted Dignity Health for clarification on the nature of the breach, although a response has yet to be received. This post will be updated when further information becomes available.

The post Multiple Data Breaches Reported by Dignity Health appeared first on HIPAA Journal.

Purdue University Uncovers Data Security Incidents that Potentially Compromised PHI

Two security breaches have been discovered by Purdue University’s security team that have potentially resulted in unauthorized individuals gaining access to the protected health information of patients.

In April, Purdue University’s security team discovered a file on computers used by Purdue University Pharmacy indicating the devices had been remotely accessed by an unauthorized individual. The file was placed on the devices around September 1, 2017.

The computers contained a limited amount of protected health information including patients’ names, dates of birth, dates of service, identification numbers, internal identification numbers, diagnoses, treatment information, and amounts billed. No personal financial information or Social Security numbers were stored on the computer.

An investigation into the breach did not uncover any evidence to suggest any patient information was stolen and no reports have been received to suggest any patient data have been misused. However, since it was not possible to rule out unauthorized PHI access with a high degree of certainty, patients have been notified of the breach.

During the course of the investigation, the security team also discovered a malware infection on a computer used by Family Health Clinic of Carrol County in Delphi, IN. The malware was detected on May 4. The investigation revealed it has been installed on the computer on or around March 15, 2018.

The type of malware used in the attack was not disclosed, although it is possible it allowed unauthorized individuals to gain access to PHI.

Information stored on the computer included patients’ names, health insurance numbers, and some patients’ driver’s license numbers and Medicare numbers. While data access was possible, no evidence was uncovered to suggest any PHI was viewed or stolen in the attack, although since this could not be totally ruled out patients have been notified. Patients whose driver’s license number and/or Medicare number were exposed have been offered free credit monitoring services for a year.

The breaches have prompted Purdue University’s security team to implement additional security controls and enhance monitoring. The network will also be segmented and full drive encryption will be implemented.

The post Purdue University Uncovers Data Security Incidents that Potentially Compromised PHI appeared first on HIPAA Journal.

42,600 Patients Potentially Impacted by Aultman Health Foundation Phishing Attack

Aultman Health Foundation, which runs Aultman Hospital in Canton, OH, is notifying approximately 42,600 patients that some of their protected health information may have been compromised as a result of a phishing attack.

Unauthorized and unknown individuals succeeded in gaining access to several email accounts used by employees of Aultman Hospital, its AultWorks Occupational Medicine division, and certain Aultman physician offices.

The unauthorized access was first detected on March 28, 2018 prompting a full investigation to determine the scope of the breach and whether any sensitive information was potentially accessed. Third-party information security experts were engaged to assist with the investigation and determined access to the email accounts occurred on several occasions starting in mid-February and continued until the breach was detected and remediated in late March.

The breach was limited to email accounts. The system that stores electronic medical records was not compromised. Email accounts used by Aultman hospital and certain physician practices contained names, addresses, clinical information, medical record numbers, and physicians’ names.

Individuals tested by AultWorks Occupational Medicine had a greater range of information exposed including name, address, date of birth, medical history, reports on physical examinations, the results of drug, hearing, and breathing tests, and other lab test results. Certain AultWorks Occupational Medicine patients also had their driver’s license number and/or Social Security number exposed. Social Security numbers were only exposed in cases where employers use Social Security numbers to identify employees/potential employees.

When the phishing attack was discovered Aultman Health Foundation performed a password reset to prevent any further unauthorized accessing of email accounts and ensured only strong, complex passwords could be set. Security monitoring has been improved to detect any future breaches more quickly and further security controls have been applied to email accounts to block future attacks. Employees have also been provided with further training to improve resilience to phishing attacks.

Aultman Health Foundation explained in a security breach FAQ that it was not possible to determine whether emails and email attachments containing PHI were opened and read by the individual(s) behind the attack; however, no reports have been received to date to suggest any information in the accounts has been misused.

All patients impacted by the incident have been advised to check their credit reports and Explanation of Benefits statements carefully for any sign of fraudulent use of their information and individuals whose driver’s license number or Social Security number were exposed have been offered complimentary credit monitoring services.

The post 42,600 Patients Potentially Impacted by Aultman Health Foundation Phishing Attack appeared first on HIPAA Journal.

More than 6,500 Patients Potentially Impacted by Minnesota Ransomware Attack

Rochester, MN-based Associates in Psychiatry and Psychology (APP) has experienced a ransomware attack that affected several computers containing patients’ protected health information.

The ransomware attack was discovered on March 31, 2018. Patient information stored on the affected computers was not in a “human-readable” format, and no evidence was uncovered to suggest any protected health information was accessed or copied by the attackers.

Since it was not possible to rule out data access with 100% certainty, all patients whose data were stored on the affected devices have been notified of the security breach. The types of information potentially accessed includes names, birth dates, addresses, Social Security numbers, insurance information, and treatment records.

APP acted promptly when the attack was discovered and took its systems offline to prevent the spread of the ransomware and limit the potential for further encryption of data and data theft. APP’s systems remained offline for four days while the attack was assessed.

APP notes in its Q&A about the incident that the attack is believed to have commenced between the evening of Friday, March 30 and the morning of Saturday, March 31. The type of ransomware used in the attack was “Triple-M.” APP explained that this variant of ransomware uses the RSA-2048 encryption protocol and extremely long keys to encrypt data. The system restore function was also disabled and the attackers reformatted the network storage device that was used to store backups.

APP’s IT Director, Steve Patton, confirmed to databreaches.net that the ransom was paid as it was not possible to restore files from backups due to the actions taken by the attackers. Initially, a ransom demand of 4 Bitcoin was issued – Around $30,000 – although the practice managed to negotiate with the attackers and paid 0.5 BTC (approx. $3,758) for the keys to recover the encrypted data.

All systems and data have now been restored, additional layers of security and encryption have been implemented, and APP’s remote access policies have been updated.

According to the breach report submitted to the Department of Health and Human Services’ Office for Civil Rights, 6,546 patients were potentially impacted. APP notes that there was clear evidence that protected health information was not viewed by the attackers; however, as a precautionary measure, APP has suggested affected individuals monitor their credit reports for any sign of fraudulent use of their information.

The post More than 6,500 Patients Potentially Impacted by Minnesota Ransomware Attack appeared first on HIPAA Journal.

OCR Plans to Share HIPAA Violation Settlements with Breach Victims

The Health Information Technology for Economic and Clinical Health (HITECH) Act was enacted in 2009 and includes a provision that calls for the Department of Health and Human Services to share a percentage of HIPAA settlements with victims of HIPAA violations and data breaches.

This month has seen some progress in that area. The Department of Health and Human Services’ Office for Civil Rights has announced it is planning on issuing an advance notice of proposed rulemaking in November about sharing a percentage of the fines it collects through its HIPAA enforcement activities with the victims of data breaches.

OCR officials have previously made it clear that steps will be taken to meet the requirements of this HITECH provision, but little progress has been made. This is not the first time that OCR has announced it plans to issue an advance notice of proposed rulemaking on the matter only for the advance notice of proposed rulemaking to be delayed.

If OCR follows through on its plans this fall, feedback will be sought from the public and industry stakeholders on how it can achieve that aim and the methodology that should be employed.

One thing is clear, such a step would certainly be a challenge. How would OCR decide on the percentage of any HIPAA settlement or fine that should be paid to the victims of HIPAA violations and data breaches and how would it be possible to share the money fairly between affected patients?

Should every individual affected by a violation/breach receive an equal share of any settlement or should the amount received be determined by the type of PHI that has been exposed or the level of harm caused? In the case of the latter, how would it be possible to quantify harm and ensure appropriate payments are made?

Settlements to resolve HIPAA violations are not only determined by the number of individuals affected and the severity of the violation. OCR also takes the ability of a covered entity to pay a penalty into account. The amount paid to breach victims of virtually carbon-copy HIPAA violations at different covered entities would likely be vastly different.

The more people impacted by a data breach, the less the share would likely be for affected individuals. For example, New York Presbyterian Hospital settled HIPAA violations with OCR for $2,200,000 in 2016 and MAPFRE Life Insurance Company of Puerto Rico settled its case with OCR for the same amount. The NYPH settlement resolved violations that affected a handful of patients, whereas the MAPFRE breach impacted 2,200 individuals. The relative payments if the percentage was fixed would differ considerably.

Potentially, HIPAA financial penalties could significantly increase if a percentage of funds are given to breach victims to ensure patients get a reasonable payment, especially for HIPAA violations and data breaches where considerable harm has been caused – The unauthorized disclosure of the HIV positive status of a patient for example or breaches where patients’ PHI has clearly been obtained by identity thieves and used for malicious purposes.

The methodology used would have to be very carefully considered to ensure funds are shared fairly. Even if the advance notice of proposed rulemaking is issued in November, it is likely to be some time before a fair methodology is decided and any payments are made.

OCR has also proposed other rules that could see HIPAA Rules modified in the near future. OCR has proposed a change to the HIPAA Privacy Rule provision requiring healthcare providers to obtain acknowledgment from patients of receipt of the notice of privacy practices. Currently healthcare providers are required to make a good faith effort to obtain written acknowledgements from patients, or must explain why acknowledgements have not been obtained. That requirement could well be removed.

Feedback will also be sought from the public on modifications to the HIPAA Privacy Rule to incorporate the accounting of protected health information disclosures of the HITECH Act, which has not yet been implemented due to the perceived cost to healthcare organizations.

OCR also proposes a change to the HIPAA Privacy Rule – Presumption of Good Faith of HealthCare Providers – that would “clarify that healthcare providers are presumed to be acting in the individual’s best interests when they share information with an incapacitated patient’s family members unless there is evidence that a provider has acted in bad faith.”

The post OCR Plans to Share HIPAA Violation Settlements with Breach Victims appeared first on HIPAA Journal.

538,000 Patients Notified of LifeBridge Health Data Breach

Earlier this month, the Baltimore-based healthcare provider LifeBridge Health announced it had experienced a data breach. A press release about the breach was issued on May 16, although there was no mention of the number of patients impacted. Further information has now been released on the extent of the breach.

On March 18, 2018, LifeBridge Health discovered malware had been installed on a server that hosted the electronic medical record system used by LifeBridge Potomac Professionals and LifeBridge Health’s patient registration and billing systems.

The discovery of malware prompted a through investigation to determine when access to the server was first gained. LifeBridge Health contracted a national computer forensics firm to assist with the investigation with the firm establishing that access to the server was first gained 18 months previously on September 27, 2016.

The types of information stored on the server included patients’ names, dates of birth, addresses, diagnoses, medications prescribed, clinical and treatment information, insurance details, and a limited number of Social Security numbers.

LifeBridge Health has uncovered no evidence to suggest any patients’ protected health information has been misused, but as a precaution, all patients whose Social Security numbers were potentially accessed by the attackers will be offered credit monitoring and identity theft protection services for 12 months without charge.

Because insurance information was exposed, all patients have been advised to carefully check their billing and explanation of benefits statements for any medical services charged but not received. Patients have been advised to report any discrepancies to their insurance carriers as soon as possible.

LifeBridge Health has not disclosed how access to the server was gained, although its response to the incident provides some clues. In its breach notice, the healthcare provider said it has “enhanced the complexity of its password requirements and the security of its system.”

The LifeBridge Health data breach is the second largest healthcare data breach to be reported this year. The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights shows 538,127 patients have potentially been impacted.

While this data breach is smaller than the security breach reported by the California Department of Developmental Services (CDDS) in April, it is certainly more serious for the individuals affected.

The CDDS breach, which potentially impacted 582,174 patients, was a burglary and it is questionable whether any PHI was actually viewed or acquired by unauthorized individuals. All electronic equipment taken by the thieves was protected with encryption and no paperwork appeared to have been removed.

While there have been no reports of misuse of data as a result of the LifeBridge Health data breach, the threat actors had access to the server for 18 months before the breach was detected. It is reasonable to assume that during that time the server would have been explored and PHI discovered.

The post 538,000 Patients Notified of LifeBridge Health Data Breach appeared first on HIPAA Journal.

Indiana Physicians Group Suffers SamSam Ransomware Attack

Allied Physicians Group of Michiana has experienced a ransomware attack that took part of its network out of action.

The attack occurred on Thursday May 17, 2018 and resulted in the encryption of several files on its network. It is currently unclear whether any protected health information encrypted. An investigation into the security incident is continuing to determine whether any protected health information was compromised in the attack.

The attack was detected promptly and action was immediately taken to shut down its network to protect the PHI of patients. Allied Physicians Group of Michiana has been working with its incident responder, outside counsel, and other professionals to determine the scope of the breach and recover encrypted data.

The Indiana Physicians Group reports that all data have now been recovered in a secure format and the attack did not cause significant disruption to patients. Steps have already been taken to improve security and prevent future attacks of this nature from occurring.

CEO Shery Roussarie explained in a May 21 press release that the attack involved a variant of SamSam ransomware, which has been used in several cyberattacks so far this year, including the ransomware attack on the City of Atlanta.

The cybercriminal gang behind these SamSam ransomware attacks attempts to extort money from victims with ransom payments typically in the region of $45,000. While a ransom payment was issued by the attackers, it is not clear how much the ransom was and whether it was paid. In the press release Roussarie said, “The Company declines to confirm whether a ransom was paid or, if so, the amount.”

Allied Physicians Group of Michiana is working with the FBI and all relevant regulatory agencies to thoroughly define the scope of the incident. Further information will be released when it becomes available and patients will be notified if their PHI was compromised.

The post Indiana Physicians Group Suffers SamSam Ransomware Attack appeared first on HIPAA Journal.

Healthcare Data Breach Report: April 2018

April was a particularly bad month for healthcare data breaches with both the number of breaches and the number of individuals impacted by breaches both substantially higher than in March.

There were 41 healthcare data breaches reported to the Department of Health and Human Services’ Office for Civil Rights in April. Those breaches resulted in the theft/exposure of 894,874 healthcare records.

Healthcare Data Breach Trends

For the past four months, the number of healthcare data breaches reported to OCR has increased month over month.

Healthcare data breaches by month

For the third consecutive month, the number of records exposed in healthcare data breaches has increased.

HEalthcare records exposed by month

Causes of Healthcare Data Breaches in April 2018

The healthcare industry may be a big target for hackers, but the biggest cause of healthcare data breaches in April was unauthorized access/disclosure incidents. While cybersecurity defences have been improved to make it harder for hackers to gain access to healthcare data, there is still a major problem preventing accidental data breaches by insiders and malicious acts by healthcare employees.

Causes of Healthcare Data Breaches in April 2018

Records exposed by breach type (April 2018)

Largest Healthcare Data Breaches in April 2018

More than half of the healthcare records exposed in April were the result of a single security incident at the California Department of Developmental Services. Thieves broke into California Department of Developmental Services offices, stole electronic equipment, and started a fire. Digital copies of PHI on the stolen equipment were encrypted and were therefore not exposed. Most of the PHI was in physical form and it does not appear any paperwork was taken by the burglars.

While hacking usually results in the highest number of exposed/stolen records, in April the most serious breaches in terms of the number of individuals affected, were unauthorised access/disclosure incidents. In April there were 11 major breaches involving the theft/exposure of more than 10,000 records.

Covered Entity Entity Type Records Exposed Breach Type
CA Department of Developmental Services Health Plan 582,174 Unauthorized Access/Disclosure
Center for Orthopaedic Specialists – Providence Medical Institute (PMI) Healthcare Provider 81,550 Hacking/IT Incident
MedWatch LLC Business Associate 40,621 Unauthorized Access/Disclosure
Inogen, Inc. Healthcare Provider 29,528 Hacking/IT Incident
Capital Digestive Care, Inc. Healthcare Provider 17,639 Unauthorized Access/Disclosure
Iowa Health System d/b/a UnityPoint Health Business Associate 16,429 Hacking/IT Incident
Knoxville Heart Group, Inc. Healthcare Provider 15,995 Hacking/IT Incident
Athens Heart Center, P.C. Healthcare Provider 12,158 Hacking/IT Incident
Fondren Orthopedic Group L.L.P. Healthcare Provider 11,552 Unauthorized Access/Disclosure
Kansas Department for Aging and Disability Services Healthcare Provider 11,000 Unauthorized Access/Disclosure
Carolina Digestive Health Associates, PA Healthcare Provider 10,988 Unauthorized Access/Disclosure

Location of Breached PHI

One of the main causes of healthcare breaches in April was phishing attacks. There were nine data breaches involving the hacking of email accounts in April. The high number of phishing attacks highlights the need for healthcare organizations to invest in technology to prevent malicious emails from being delivered to employees’ inboxes and to improve security awareness of the workforce.

Location of Breached PHI (April 2018)

Data Breaches by Covered Entity

The majority of breaches in April were reported by healthcare providers, followed by health plans and business associates. While five breaches were reported by business associates, there was business associate involvement in at least 11 incidents in April.

Data Breaches by Covered Entity (April 2018)

Healthcare Data Breaches by State

California is the most populated state and often tops the list for healthcare data breaches, although in April Illinois was the worst affected state with 6 reported breaches. California was second worst with 5 breaches, followed by Texas with 3 breaches.

Florida, Iowa, Kansas, Louisiana, Maryland, Minnesota, North Carolina, New Jersey, Virginia, and Wisconsin each has two breaches reported, while Georgia, Kentucky, Montana, Nebraska, New York, Pennsylvania, and Tennessee each had one reported breach in April.

Financial Penalties for HIPAA Covered Entities

The HHS’ Office for Civil Rights has only issued two financial penalties for HIPAA violations so far in 2018, with no cases resolved since February.

There was one HIPAA violation case resolved by a state attorney general in April. Virtua Medical Group agreed to resolve violations of state and HIPAA laws with the New Jersey attorney general’s office for $417,816.

The breach that triggered the investigation exposed the names, diagnoses, and prescription information of 1,654 New Jersey residents. The information was accessible over the Internet as a result of a misconfigured server.

A Division of Consumer Affairs investigation alleged Virtua Medical Group had failed to conduct a thorough risk analysis and did not implement appropriate security measures to reduce risk to a reasonable and acceptable level.

The post Healthcare Data Breach Report: April 2018 appeared first on HIPAA Journal.

Former Employee of Nuance Communications Stole PHI of 45,000 Patients

In a recent filing with the U.S. Securities and Exchange Commission, Burlington, MA-based Nuance Communications disclosed it experienced a data breach involving the protected health information of 45,000 individuals in December 2017.

Nuance Communications stated in its May 10, 2018 SEC filing that a third party accessed certain reports hosted on a single Nuance transcription platform, which was promptly shut down when unauthorized access was discovered. The filing states law enforcement was notified about the breach and assisted with the investigation and apprehended the individual responsible.

There is no mention of when the breach was discovered, although the company has notified all customers who used the platform to allow them to issue notifications to affected individuals.

One of those customers, The San Francisco Health Network, published a substitute breach notice on its website on May 11 providing further information on the breach.

The breach notice explains that the protected health information of 895 patients who received medical services at Zuckerberg San Francisco General Hospital or Laguna Honda Hospital was accessed between November 20 and December 9, 2017.

The types of information accessed includes names, birth dates, medical record numbers, patient numbers, and dictated notes. The notes included providers’ assessments of patients, diagnoses, dates of service, and treatment and care plans.

The law enforcement investigation uncovered the identity of the individual – a former employee of Nuance Communications – and determined that individual accessed a transcription platform without authorization. The Justice Department told the San Francisco Health Network that all stolen data have been recovered and no evidence has been found to suggest the PHI was disclosed to other individuals or used for any purpose.

The FBI and the U.S. Department of Justice requested notifications be delayed while the criminal investigation into the breach was conducted. It is unclear whether criminal charges have been filed against the individual responsible.

The SEC filing also includes details of the cost of the NotPetya wiper attack on Nuance Communications in June 2017. Most of the costs associated with the attack were covered in fiscal year 2017, which included a loss of $68 million in revenues primarily due to service disruption and reserves established for customer refund credits. The remediation and restoration efforts also cost an additional $24 million.

There attack also contributed to “a year-over-year decline in the annualized line run-rate in our on-demand healthcare solutions and in the estimated three-year value of on-demand contracts; a year-over-year decline in hosted revenue and an increase in restructuring and other charges.” Nuance Communications expects to have to cover additional costs throughout the remainder of fiscal year 2018 to enhance and upgrade its information security protections to prevent future cyberattacks.

The post Former Employee of Nuance Communications Stole PHI of 45,000 Patients appeared first on HIPAA Journal.