HIPAA Breach News

Law Enforcement Notifies Cambridge Health Alliance About PHI Breach

Cambridge Health Alliance (CHA) in Massachusetts has been notified by law enforcement that the protected health information of some of its patients has been discovered in the possession of an unauthorized individual.

On January 31, 2018, Everett Massachusetts Police Department notified CHA that files containing the PHI of some of its patients had been discovered in the possession of an individual unauthorized to have the information. After being notified of the breach, CHA conducted an internal investigation into the breach and examined the files.

At least one of the files contained PHI related to billing which included patients’ names, addresses, dates of birth, Social Security numbers, employer information, charges for healthcare services, and discharge dates. The data related to billing from 2013.

According to a breach notice sent to affected individuals by the law firm BakerHostetler on behalf of CHA, the breach impacted four individuals in New Hampshire, all of whom have been offered complimentary credit monitoring and identity theft protection services through Experian.

While the breach notice states that only four individuals were impacted, the Boston Globe has reported that notification letters have been sent to approximately 2,500 patients. The details of the breach are the same apart from the number of individuals impacted.

According to the Boston Globe, CHA spokesman David Cecere confirmed that the incident is still being investigated and it is currently unclear how the information came to be stolen. Cecere said it could have been a hack or the information could have accidentally been made public.

In addition to the internal investigation, CHA has retained a computer forensics firm to provide assistance and attempt to determine exactly how the data was stolen.

The post Law Enforcement Notifies Cambridge Health Alliance About PHI Breach appeared first on HIPAA Journal.

6,800 CareFirst BCBS Members Impacted by Phishing Attack

A phishing attack on CareFirst Blue Cross Blue Shield has resulted in the exposure of 6,800 plan members’ protected health information.

The attack was detected by CareFirst on March 12, 2018, prompting a thorough investigation, which included a forensic analysis of the email system and CareFirst’s systems in general. In addition to the internal investigation by the CareFirst IT security team, a third-party information security firm also investigated the attack.

The analyses did not uncover any evidence to suggest emails in the compromised account had been opened by the attacker; however, the emails in the account did contain some protected health information and data access could not be ruled out with a high degree of certainty.

Once access to the account was gained, the attacker sent phishing emails to individuals in a contact list. Those individuals were not employed by or affiliated with CareFirst BCBS. The emails were sent with the intention of gaining further login credentials. No malware was involved.

While 6,800 individuals have potentially been impacted by the incident, only 8 Social Security numbers were exposed. Other types of information that could potentially have been viewed include members’ names, birth dates, and member ID numbers. No financial information was exposed and neither any health information.

The potential for the information in the account to be used for identity theft and fraud is low, but to ensure plan members are protected, all have been offered identity theft protection and credit monitoring services for two years without charge.

CareFirst BCBS explained in its breach notice that it is already mandatory for employees to undergo annual security awareness training. All employees are educated on the risks of cyberattacks, the tactics used to gain access to sensitive data, and told how they must remain vigilant for potential phishing attacks. In addition to the formal training sessions, CareFirst provides ongoing security awareness training throughout the year.

The post 6,800 CareFirst BCBS Members Impacted by Phishing Attack appeared first on HIPAA Journal.

Security Breaches in Healthcare in the Last Three Years

There have been 955 major security breaches in healthcare in the last three years that have resulted in the exposure/theft of 135,060,443 healthcare records. More than 41% of the population of the United States have had some of their protected health information exposed as a result of those breaches, which have been occurring at a rate of almost one a day over the past three years.

There has been a steady rise in reported security beaches in healthcare in the last three years. In 2015 there were 270 data breaches involving more than 500 records reported to the Department of Health and Human Services’ Office for Civil Rights. The figure rose to 327 security breaches in 2016, and 342 security breaches in 2017.

reported healthcare data breaches in 2017

More healthcare security breaches are being reported than at any other time since HIPAA required covered entities to disclose data breaches, although the number of individuals affected by healthcare data breaches has been declining year-over year for the past three years.

In 2015, a particularly bad year for healthcare industry data breaches, 112,107,579 healthcare records were exposed or stolen. The majority of those records were exposed in three data breaches. The 78.8 million-record data breach at Anthem Inc., the 11 million-record breach at Premera Blue Cross, and the 10 million-record breach at Excellus Health Plan.

Other major security breaches in 2015 include the University of California Los Angeles Health breach of 4.5 million records and Medical Informatics Engineering breach of 3.9 million records.

In 2016, 14,679,461 healthcare records were exposed or stolen, with three incidents involving more than 1 million records: The 3.62 million-record breach at Banner Health, the 3.46 million-record breach at Newkirk Products, Inc., and the 2.21 million-record breach at 21st Century Oncology.

In 2017, the worst year for healthcare security incidents in terms of the number of breaches reported, there were 3,286,498 healthcare records exposed or stolen. There were two breaches involving more than half a million records. The 500,000-record breach at Airway Oxygen, Inc., and the 697800-record breach at Commonwealth Health Corporation

15 Largest Security Breaches in Healthcare in the Last Three Years

 

Rank Year Covered Entity Entity Type Records Exposed/Stolen Breach Cause
1 2015 Anthem, Inc. Affiliated Covered Entity Health Plan 78800000 Hacking/IT Incident
2 2015 Premera Blue Cross Health Plan 11000000 Hacking/IT Incident
3 2015 Excellus Health Plan, Inc. Health Plan 10000000 Hacking/IT Incident
4 2015 University of California, Los Angeles Health Healthcare Provider 4500000 Hacking/IT Incident
5 2015 Medical Informatics Engineering Business Associate 3900000 Hacking/IT Incident
6 2016 Banner Health Healthcare Provider 3620000 Hacking/IT Incident
7 2016 Newkirk Products, Inc. Business Associate 3466120 Hacking/IT Incident
8 2016 21st Century Oncology Healthcare Provider 2213597 Hacking/IT Incident
9 2015 CareFirst BlueCross BlueShield Health Plan 1100000 Hacking/IT Incident
10 2016 Valley Anesthesiology Consultants, Inc. d/b/a Valley Anesthesiology and Pain Consultants Healthcare Provider 882590 Hacking/IT Incident
11 2016 County of Los Angeles Departments of Health and Mental Health Healthcare Provider 749017 Hacking/IT Incident
12 2017 Commonwealth Health Corporation Healthcare Provider 697800 Theft
13 2015 Virginia Department of Medical Assistance Services (VA-DMAS) Health Plan 697586 Hacking/IT Incident
14 2016 Bon Secours Health System Incorporated Healthcare Provider 651971 Unauthorized Access/Disclosure
15 2015 Georgia Department of Community Health Health Plan 557779 Hacking/IT Incident

 

Main Causes of Security Breaches in Healthcare in the Last Three Years

The three main causes of security breaches in healthcare in the last three years were hacking/IT incidents, unauthorized access and disclosure incidents, and the loss/theft of physical records and unencrypted electronic devices containing ePHI.

There has been a downward trend in the number of theft/loss incidents over the past three years as healthcare organizations have started encrypting records on portable electronic devices. However, improper disposal incidents have risen year over year as have hacking incidents. In 2017, hacking/IT incidents were the main cause of healthcare data breaches.

healthcare data breaches in 2017 (hacking)

healthcare data breaches in 2017 (Unauthorized access/disclosures)

Healthcare Data Breaches in 2017 (loss/theft)

Financial Penalties for Security Breaches in Healthcare in the Last Three Years

In addition to annual increases in data breaches, financial penalties for HIPAA violations have also been increasing, both in terms of number of settlements and civil monetary penalties issued and the penalty amounts.

The HHS’ Office for Civil Rights is now enforcing HIPAA Rules far more aggressively and multi-million-dollar fines are regularly issued. The last three years have seen 29 HIPAA covered entities and business associates financially penalized for data breaches that have occurred as a result of noncompliance with HIPAA Rules.

In the last three years, the HHS’ Office for Civil Rights has collected $49,091,700 in financial penalties from its enforcement actions. The average settlement amount in 2017 was $1.94 million.

The post Security Breaches in Healthcare in the Last Three Years appeared first on HIPAA Journal.

3,751 Patients’ PHI Exposed on Internet for More Than 30 Months

The Arc of Erie County New York (The Arc), a provider of person-centered services to individuals with developmental disabilities, has discovered two spreadsheets containing the protected health information of 3,751 patients were accessible on the Internet without the need for authentication for more than 30 months.

Between July 2015 and February 2018, the two spreadsheets could be accessed over the Internet by unauthorized individuals as a result of a coding error on the website. The coding error saw a link included on the website that allowed the spreadsheets to be accessed.

Individuals affected by the breach, many of whom are developmentally disabled, had been enrolled in certain programs offered by The Arc. The Arc spreadsheets contained sensitive information such as names, Social Security numbers and diagnosis codes.

When the error was discovered in February, The Arc deactivated the link to prevent any further disclosures of PHI and contacted a computer forensics and data security firm to investigate the breach and help take corrective action to limit the harm caused to patients. The Arc has also contacted search engine providers to remove any reference to the information from the search engine listings. It is unclear whether the spreadsheets were accessed by unauthorized individuals and if any PHI has been viewed or copied.

All affected individuals have been notified of the breach and offered complimentary credit monitoring and identity theft protection services for 12 months.

To prevent further privacy breaches, The Arc has reviewed and updated its policies and practices and strengthened its privacy and data security practices. Additional training has also been given to appropriate staff.

The post 3,751 Patients’ PHI Exposed on Internet for More Than 30 Months appeared first on HIPAA Journal.

3,751 Patients’ PHI Exposed on Internet for More Than 30 Months

The Arc of Erie County New York (The Arc), a provider of person-centered services to individuals with developmental disabilities, has discovered two spreadsheets containing the protected health information of 3,751 patients were accessible on the Internet without the need for authentication for more than 30 months.

Between July 2015 and February 2018, the two spreadsheets could be accessed over the Internet by unauthorized individuals as a result of a coding error on the website. The coding error saw a link included on the website that allowed the spreadsheets to be accessed.

Individuals affected by the breach, many of whom are developmentally disabled, had been enrolled in certain programs offered by The Arc. The Arc spreadsheets contained sensitive information such as names, Social Security numbers and diagnosis codes.

When the error was discovered in February, The Arc deactivated the link to prevent any further disclosures of PHI and contacted a computer forensics and data security firm to investigate the breach and help take corrective action to limit the harm caused to patients. The Arc has also contacted search engine providers to remove any reference to the information from the search engine listings. It is unclear whether the spreadsheets were accessed by unauthorized individuals and if any PHI has been viewed or copied.

All affected individuals have been notified of the breach and offered complimentary credit monitoring and identity theft protection services for 12 months.

To prevent further privacy breaches, The Arc has reviewed and updated its policies and practices and strengthened its privacy and data security practices. Additional training has also been given to appropriate staff.

The post 3,751 Patients’ PHI Exposed on Internet for More Than 30 Months appeared first on HIPAA Journal.

Data Breach Impacts Almost 14,000 Family Members of Subscribers

The Special Agents Mutual Benefit Association (SAMBA) health plan is alerting almost 14,000 individuals about a February 2018 breach of protected health information.

The breach affects eligible family members of subscribers who were covered by the Federal Employees Health Benefits Plan in 2017.

It is an Internal Revenue Service (IRS) requirement for SAMBA to mail a copy of Form 1095-B to all plan subscribers each tax year. The form supports plan members’ and covered family members’ compliance with the Affordable Care Act’s individual mandate.

The forms for the 2017 tax year were mailed on or soon after February 19, 2018; however, a programming error resulted in the forms being populated with information relating to other subscribers’ family members.

Instead of detailing the subscribers’ family members covered by their health plan, the forms included the names and Social Security numbers of other subscribers’ family members and the dates of health insurance coverage in 2017.  The forms were also incorrectly dated 2016.

SAMBA notes that no subscribers’ Social Security numbers were disclosed. The breach was restricted to subscribers’ family members. An investigation into the error revealed the incorrect mailing affected 13,942 individuals.

The error was detected on February 22, 2018, and a second mailing was sent with the correct tax year and family members’ details on the forms. Notification letters have also been sent to family members impacted by the breach, and subscribers who received an incorrect copy of Form 1095-B have also been notified and instructed to destroy the 2016 version of the form.

SAMBA has not received any reports to suggest the impermissibly disclosed information has been misused in any way; however, as a precaution against identity theft, all affected individuals have been advised to exercise caution and obtain credit reports and check them and their Explanation of Benefits statements carefully for any sign of fraud.

“We are taking steps to prevent any future data incident, and as always will continue to review and improve our processes, policies, and procedures that address data privacy,” said SAMBA’s Executive Director, Walter E. Wilson.

The post Data Breach Impacts Almost 14,000 Family Members of Subscribers appeared first on HIPAA Journal.

Data Breach Impacts Almost 14,000 Family Members of Subscribers

The Special Agents Mutual Benefit Association (SAMBA) health plan is alerting almost 14,000 individuals about a February 2018 breach of protected health information.

The breach affects eligible family members of subscribers who were covered by the Federal Employees Health Benefits Plan in 2017.

It is an Internal Revenue Service (IRS) requirement for SAMBA to mail a copy of Form 1095-B to all plan subscribers each tax year. The form supports plan members’ and covered family members’ compliance with the Affordable Care Act’s individual mandate.

The forms for the 2017 tax year were mailed on or soon after February 19, 2018; however, a programming error resulted in the forms being populated with information relating to other subscribers’ family members.

Instead of detailing the subscribers’ family members covered by their health plan, the forms included the names and Social Security numbers of other subscribers’ family members and the dates of health insurance coverage in 2017.  The forms were also incorrectly dated 2016.

SAMBA notes that no subscribers’ Social Security numbers were disclosed. The breach was restricted to subscribers’ family members. An investigation into the error revealed the incorrect mailing affected 13,942 individuals.

The error was detected on February 22, 2018, and a second mailing was sent with the correct tax year and family members’ details on the forms. Notification letters have also been sent to family members impacted by the breach, and subscribers who received an incorrect copy of Form 1095-B have also been notified and instructed to destroy the 2016 version of the form.

SAMBA has not received any reports to suggest the impermissibly disclosed information has been misused in any way; however, as a precaution against identity theft, all affected individuals have been advised to exercise caution and obtain credit reports and check them and their Explanation of Benefits statements carefully for any sign of fraud.

“We are taking steps to prevent any future data incident, and as always will continue to review and improve our processes, policies, and procedures that address data privacy,” said SAMBA’s Executive Director, Walter E. Wilson.

The post Data Breach Impacts Almost 14,000 Family Members of Subscribers appeared first on HIPAA Journal.

Server Misconfiguration Results in the Exposure of 42,000 Patients’ PHI

Tens of thousands of patients of a New York medical practice have had their protected health information exposed online due to a misconfigured server. It is currently unclear if anyone other than the security researcher who discovered the problem has accessed the data.

The server misconfiguration was identified on January 25, 2018 by Chris Vickery, director of cyber risk research at Upguard. In a March 26 blog post Vickery explained that he identified an exposed port typically used for remote synchronization (rsync).

While access should have been limited to specific whitelisted IP addresses, the port was misconfigured and allowed anyone to access the data. All that was required to access the server was its IP address.

Vickery identified two sections in the repository, one of which – named backupwscohen – was publicly accessible and contained several files that included highly sensitive information. A virtual hard drive was also accessible that was discovered to contain staff details, including spouse information, children’s names, and in some cases, Social Security numbers. An Outlook pst file was also left unsecured. The file contained a large number of email communications.

Vickery also found a database with more than 42,000 patients’ names, dates of birth, health insurance information, phone numbers, addresses, Social Security numbers, email addresses, ethnicities, and clinical notes. The clinical notes included more than 3 million observations.

Vickery traced the data to the Huntington, New York medical practice of Cohen, Bergman, Klepper & Romano MDs PC. Starting on February 12, Vickery made several attempts to contact the doctors to alert them about the problem. Direct contact was attempted and via a local hospital, with Databreaches.net contacted to assist with locating the physicians.

It took until March 19 for a message to reach the physicians and action to be taken to secure the leaky server. The PHI of all patients has now been secured.

The post Server Misconfiguration Results in the Exposure of 42,000 Patients’ PHI appeared first on HIPAA Journal.

Research Suggests Healthcare Data Breaches Cause 2,100 Deaths a Year

A researcher at Vanderbilt University has conducted a study that suggests mortality rates at hospitals increase following a data breach as a result of a drop in the standard of care. The researcher estimates healthcare data breaches may cause as many as 2,100 deaths a year in the United States.

The study was conducted by Owen Graduate School of Management researcher, Dr. Sung Choi. The findings of the study were presented at a recent cyberrisk quantification conference at Philadelphia’s Drexel University LeBow College of Business.

Cyberattacks can have a direct impact on patient care, which has been clearly highlighted on numerous occasions over the past 12 months. Ransomware and wiper malware attacks have crippled information systems and have forced healthcare providers to cancel appointments, while the lack of access to patient health records can cause treatment delays. Notable attacks that caused major disruption were the NotPetya wiper and WannaCry ransomware attacks last year, with the latter causing major problems for the National Health Service in the UK.

Choi explained that data breaches can be a distraction for physicians and the after affects of breaches can last for years. HIPAA covered entities face investigations and litigation which Choi suggests could result in disruption to medical services and delays in providing treatment. The cost of mitigating attacks, including purchasing additional security solutions and dealing with the fallout from data breaches can see resources diverted away from patient care.

For the study, Choi compared mortality rates at hospitals before and immediately after a data breach had occurred. One of the metrics used to assess a potential fall in the quality of care was the percentage of heart attack patients who died within 30 days of admission to hospital.

Choi notes that the control group and breached hospitals had similar mortality rates, although after a data breach, the mortality rate for the control group remained the same but increased at hospitals that had experienced a breach. Choi’s analysis showed there was a 0.23% increase in the mortality rate one year following a data breach and an increase of 0.36% two years after a breach. That equates to 2,160 deaths a year.

Choi also noted that the time taken to administer electrocardiographs was longer for newly admitted patients after a hospital had experienced a data breach.

The study was presented just a few days before the Department of Health and Human Services’ Office for Civil Rights issued a reminder to HIPAA covered entities about the need to develop contingency plans for emergencies such as cyberattacks and ransomware incidents. OCR explained that HIPAA Rules on contingency planning help to ensure a fast recovery from a natural disaster, cyberattack, or other emergency situation.

This research suggests that the development of an effective contingency plan and a rapid response to data breaches can save lives.

The post Research Suggests Healthcare Data Breaches Cause 2,100 Deaths a Year appeared first on HIPAA Journal.