HIPAA Breach News

Pedes Orange County Discovers Physician Accessed and Disclosed PHI Without Authorization

Pedes Orange County Inc., a California healthcare provider specializing in treatments for vascular disease, is alerting some of its patients that a physician accessed their medical records, without authorization, and provided some of that information to an attorney.

Pedes shares its facilities with another medical group, which conducts surgical procedures at the facility during the week. A scheduling tool is also shared with other physicians that use the same facility.

On November 14, 2017, Pedes became aware that a physician employed by a different medical group had accessed its electronic medical records database and viewed the records of some of its patients. Pedes did not provide authorization for the EMR to be accessed.

Pedes reports that the physician subsequently shared some of the information in the database with an attorney. After discovering the breach, the physician was contacted and Pedes has been working to ensure all copies of patients’ PHI that were obtained from its EMR system are securely destroyed and that no copies remain.

The types of information potentially compromised includes names, diagnoses, treatments, dates of service, and other treatment related data. No financial information or Social Security numbers were stored in the database and remained secure at all times.

While information was taken from the database, Pedes has no reason to believe any PHI has been misused. However, since the incident is classed as a security breach under HIPAA Rules, notifications about the breach must be sent to patients.

Although data misuse is not suspected, patients have been advised to take precautions and examine their Explanation of Benefits statements and other information from their health insurers for any medical treatments listed by not provided.

The incident has prompted Pedes to conduct a review of its security protocols, which will be updated to ensure that this type of security breach does not happen again.

The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates the PHI of up to 917 patients was accessed and potentially disclosed.

The post Pedes Orange County Discovers Physician Accessed and Disclosed PHI Without Authorization appeared first on HIPAA Journal.

Analysis of Q4 2017 Healthcare Security Breaches

Q4, 2017 saw a 13% reduction in healthcare security breaches reported to the Department of Health and Human Services’ Office for Civil Rights. There were 99 data breaches reported in Q3, 2017. In Q4, there were 86 security breaches reported.

There were 27 healthcare security breaches reported in September, following by a major decline in breaches in November, when 21 incidents were reported. However, December saw a significant uptick in incidents with 38 reported breaches.

Q4 2017 Healthcare Security Breaches by Month

Accompanied by the quarterly decline in security incidents was a marked decrease in the severity of breaches. In Q3, there were 8 data breaches reported that impacted more than 50,000 individuals. In Q4, no breaches on that scale were reported. The largest incident in Q4 impacted 47,000 individuals.

 Largest Q4, 2017 Healthcare Security Breaches

 

Covered Entity Entity Type Number of Records Breached Cause of Breach
Oklahoma Department of Human Services Health Plan 47000 Hacking/IT Incident
Henry Ford Health System Healthcare Provider 43563 Theft
Coplin Health Systems Healthcare Provider 43000 Theft
Pulmonary Specialists of Louisville, PSC Healthcare Provider 32000 Hacking/IT Incident
SSM Health Healthcare Provider 29579 Unauthorized Access/Disclosure
UNC Health Care System Healthcare Provider 27113 Theft
Emory Healthcare Healthcare Provider 24000 Unauthorized Access/Disclosure
Franciscan Physician Network of Illinois and Specialty Physicians of Illinois, LLC (formerly known as WellGroup Health Partners, LLC) Healthcare Provider 22000 Loss
Chase Brexton Health Care Healthcare Provider 16562 Hacking/IT Incident
Hackensack Sleep and Pulmonary Center Healthcare Provider 16474 Hacking/IT Incident
Longs Peak Family Practice, P.C. Healthcare Provider 16238 Hacking/IT Incident
Shop-Rite Supermarkets, Incorporated Healthcare Provider 12172 Improper Disposal
Sinai Health System Healthcare Provider 11347 Hacking/IT Incident
The Medical College of Wisconsin, Inc. Healthcare Provider 9500 Hacking/IT Incident
Golden Rule Insurance Company Health Plan 9305 Unauthorized Access/Disclosure

 

There was a steady increase in breached records each month in Q4. In October, 71,377 records were breached, rising to 107,143 records in November and 341,621 records in December. Even December’s high total was lower than any month in the previous quarter.

Q4 2017 Healthcare Security Breaches - breached records

 

Hacking/IT incidents tend to involve the highest number of exposed/stolen records and Q4 was no exception. 7 of the top 15 security incidents (47%) were due to hacks and IT incidents. Loss and theft incidents accounted for 27% of the worst healthcare security breaches in Q4, followed by unauthorized access/disclosures on 20%.

Causes of Q4 2017 Healthcare Security Breaches

 

While hacking/IT incidents resulted in the exposure/theft of the most records, unauthorized access/disclosure incidents were the most numerous. Out of the 86 reported healthcare security breaches in Q4, 33 were unauthorized access/disclosures (38.37%). There were 29 hacking/IT incidents (33.7%), and 20 incidents (23.3%) involving the loss/theft of PHI and electronic devices containing ePHI. Four incidents (4.7%) involved the improper disposal of PHI/ePHI.

In Q4, paper records/films were involved in the most breaches, showing how important it is to physically secure records. 21 incidents (24.4%) involved physical records. As was the case in Q3, email was also a top three cause of breaches, with many healthcare organizations suffering phishing attacks in Q4. Network server attacks completed the top three locations of breached PHI.

Q4 2017 Healthcare Security Breaches - location of breached PHI

 

 

Healthcare providers reported the most security breaches in Q4, following by health plans and business associates of HIPAA-covered entities, as was the case for most of 2017.

Q4 2017 Healthcare Security Breaches by covered entity

 

In Q4, 2017, healthcare organizations based in 35 states reported security breaches. Unsurprisingly, being the most populous state in the US, California topped the list for the most reported healthcare security breaches with 7 incidents in Q4.

In close second on 6 breaches were Florida and Maryland, followed by New York with 5 incidents. Kentucky, Michigan, and Texas each had four reported breaches, and Colorado, Illinois, New Jersey, and Pennsylvania each suffered 3 incidents.

Q4 2017 Healthcare Security Breaches - by state

 

 

 

The post Analysis of Q4 2017 Healthcare Security Breaches appeared first on HIPAA Journal.

Allscripts Ransomware Attack Impacts Cloud EHR and EPCS Services

An Allscripts ransomware attack occurred on Thursday January 18, resulting in several of the firms applications being taken offline, including its cloud EHR and electronic prescriptions platform. The attack comes just a few days after two Indiana hospitals experienced SamSam ransomware attacks.

The Allscripts ransomware attack is also believed to have involved a variant of SamSam ransmware – a ransomware family extensively used in attacks on healthcare providers.

Allscripts is a popular electronic health record (EHR) system and Electronic Prescriptions for Controlled Substances (EPCS) provider, with its platform used by many U.S healthcare organizations, including 2,500 hospitals and 19,000 post-acute care organizations. More than 180,000 physicians, 100,000 electronic prescribing physicians, and 40,000 in-home clinicians use Allscripts.

The Allscripts ransomware attack commenced in the early hours of Thursday morning. Rapid action was taken to remove the ransomware and restore data, with the incident response teams at Microsoft and Cisco called in to assist. An investigation has also been launched by cybersecurity firm Mandiant to determine how the ransomware was installed.

Allscripts’ Pro EHR and EPCS services were most severely affected, although users of other applications also experienced some downtime. The Chicago-based firm is still experiencing issues with its Pro EHR system, although EPCS services were restored on Saturday. Some applications are likely to continue to be adversely affected throughout Monday, while efforts are made to restore the malware-encrypted data.

IT teams have been working round the clock to remove the infection and restore files from backups. Regular backups are performed so data loss is expected to be minimal.

This appears to have been a random ransomware attack. The purpose of the attack appears to have solely been an attempt to extort money from the company. Data theft is not suspected. Allscripts does not believe it was specifically targeted by cybercriminals.

Indiana Hospitals Attacked With SamSam Ransomware Variant

Adams Memorial Hospital in Decatur, IN, has also been attacked with ransomware – The second Indiana hospital to be attacked in the past few days. The ransomware attack occurred on January 11, 2017, and initially caused a slowing of the network before files became inaccessible. File extensions were allegedly renamed as ‘imsorry’.

The ransomware attack caused some disruption to services, with medical histories and appointment schedules rendered inaccessible. However, patients continued to be treated and there was no need to cancel appointments.  The Adams Health Network said at no point was patient care or safety affected.

Some parts of the system have been brought back online, although the IT department is still working on restoring the affected servers. It is unclear whether the Adams Health Network paid the ransom demand to regain access to data or if files were recovered from backups.

The attack happened on the same day as the ransomware attack on Greenfield, IN-based Hancock Health. Hancock Health made the decision to pay the 4 Bitcoin ransom. Approximately $50,000 was paid for the keys to unlock the encryption, even though backups existed. The cost of recovering files from backups was seen to be far higher than paying the ransom, due to downtime that would be experienced while that process took place.

Both of the Indiana attacks are believed to have involved a new variant of SamSam ransomware, although this is understood to be a different variant to the one used in the Allscripts ransomware attack.

The post Allscripts Ransomware Attack Impacts Cloud EHR and EPCS Services appeared first on HIPAA Journal.

Email Hack Sees PHI of 53,000 Pharmacy Patients Exposed

53,173 patients who received services from Onco360 and CareMed Specialty Pharmacy have been notified that some of their protected health information has been compromised.

A security breach was suspected on November 14, 2017, when suspicious activity involving an employee’s email account was detected.

Third party computer forensics experts were called in to conduct an investigation to determine the nature and scope of the breach. On November 30, it was determined that the breach involved three email accounts.

An analysis of the emails in those accounts revealed some messages contained the PHI of patients, which could potentially have been accessed and stolen by the hacker.

The information potentially compromised included names, demographic information, clinical information, details of medications provided by the pharmacy, Social Security numbers, and health insurance information. A limited number of patients may also have had some financial information exposed.

No reports have been received to suggest any protected health information has been misused, although patients have been advised to exercise caution and check their credit reports, billing statements, and Explanation of Benefit statements for any sign of fraudulent activity. Patients have also been offered complimentary credit monitoring and identity theft protection services through ID Experts for 12 months.

The security breach appears to have occurred as a result of employees opening phishing emails. All staff have now received further training to help them recognize malicious emails and email security controls have been improved to prevent future attacks.

The post Email Hack Sees PHI of 53,000 Pharmacy Patients Exposed appeared first on HIPAA Journal.

Summary of Healthcare Data Breaches in December 2017

There was a sharp rise in healthcare data breaches in December, reversing a two-month downward trend. There were 38 healthcare data breaches in December 2017 that impacted more than 500 individuals: An increase of 81% from last month.

 

December 2017 Healthcare Data Breaches

 

Unsurprisingly given the sharp increase in reported breaches, the number of records exposed in December also increased month over month. The records of 341,621 individuals were exposed or stolen in December: An increase of 219% from last month.

 

Records Exposed in December 2017 Healthcare Data Breaches

 

December saw a similar pattern of breaches to past months, with healthcare providers experiencing the most data breaches; however, there was a notable increase in breaches reported by health plans in December – rising from 2 in November to six in December.

 

December 2017 Healthcare Data Breaches by Covered Entity Type

Causes of Healthcare Data Breaches in December 2017

As was the case last month, hacking/IT incidents and unauthorized access/disclosures were the most common causes of healthcare data breaches in December, although there was a notable increase in theft/loss incidents involving portable electronic devices and paper records.

 

December 2017 healthcare data breaches by incident type

 

While hacking incidents usually result in the greatest number of records being exposed/stolen, this month saw a major increase in records exposed due to the theft of portable electronic devices. The theft of devices containing PHI – and paper records – resulted in 122,921 patients’ protected health information being exposed. The mean number of records exposed in theft incidents was 20,487 and the median was 15,857 – Both higher than any other cause of data breach.

 

Causes of Healthcare Data Breaches (Dec 2017)

 

Records Exposed by Breach Type (Dec 2017)

 

Network server incidents were the most numerous in December with 12 incidents, although there were 9 incidents involving paper records, showing that while healthcare organizations must ensure appropriate technological defenses are in place to protect electronic data, physical security is also essential to ensure paper records are secured.

 

Location of Breached PHI (Dec 2017)

 

10 Largest Healthcare Data Breaches in December 2017

In December, there were 9 data breaches that impacted more than 10,000 individuals reported to the Office for Civil Rights by HIPAA covered entities. In contrast to past months when hacking incidents dominated the top ten breach list, there was an even spread between hacking incidents, unauthorized access/disclosures, and theft of healthcare records and electronic devices.

The largest data breach reported in December affected Oklahoma Department of Human Services. However, this was not a recent data breach. The breach occurred in April 2016, but a breach report was not submitted to the Office for Civil Rights at the time of discovery. It took 18 months after the 60-day deadline for the breach to be reported.

Name of Covered Entity Covered Entity Type Individuals Affected Type of Breach
Oklahoma Department of Human Services Health Plan 47000 Hacking/IT Incident
Henry Ford Health System Healthcare Provider 43563 Theft
Coplin Health Systems Healthcare Provider 43000 Theft
SSM Health Healthcare Provider 29579 Unauthorized Access/Disclosure
UNC Health Care System Healthcare Provider 27113 Theft
Emory Healthcare Healthcare Provider 24000 Unauthorized Access/Disclosure
Franciscan Physician Network of Illinois and Specialty Physicians of Illinois Healthcare Provider 22000 Loss
Longs Peak Family Practice, P.C. Healthcare Provider 16238 Hacking/IT Incident
Sinai Health System Healthcare Provider 11347 Hacking/IT Incident
Golden Rule Insurance Company Health Plan 9305 Unauthorized Access/Disclosure

December 2017 Healthcare Data Breaches by State

California experienced the most healthcare data breaches in December with 5 reported incidents, followed by Michigan with 4 data breaches.

Eight states experienced two data breaches each – Florida, Illinois, Minnesota, New England, Nevada, New York, Philadelphia and Texas.

13 states each had one reported breach: Colorado, Georgia, Iowa, Indiana, Massachusetts, Missouri, New Jersey, North Carolina, Ohio, Oklahoma, Oregon, Tennessee, and West Virginia.

Data source: Department of Health and Human Services’ Office for Civil Rights.

The post Summary of Healthcare Data Breaches in December 2017 appeared first on HIPAA Journal.

Aetna Settles Class Action Lawsuit Filed by Victims of HIV Status Data Breach

Aetna has agreed to settle a class action lawsuit filed by victims of a mailing error that resulted in details of HIV medications prescribed to patients being visible through the clear plastic windows of the envelopes. Aetna was not directly responsible for the mailing, instead an error was made by a third-party vendor.

For some of the patients, the letters had slipped inside the envelope revealing the patient had been prescribed HIV drugs. In many cases, those envelopes were viewed by flat mates, family members, neighbors, friends, and other individuals, thus disclosing each patient’s HIV information. Is not known how many patients had their HIV information disclosed, although the mailing was sent to 13,487 individuals. Some of the patients were being prescribed medications to treat HIV, others were taking the medication as Pre-exposure Prophylaxis (PrEP) to prevent contracting the disease.

Many of the patients who were outed as a result of the breach have faced considerable hardship and discrimination. Several patients have had to seek alternative accommodation after been forced to leave their homes by flat mates and relatives. Others have had personal and family relationships severely damaged as a result of the disclosure.

The Legal Action Center, AIDS Law Project of Pennsylvania, and Berger & Montague, P.C., filed a lawsuit in August seeking damages for the victims of the breach. That lawsuit has been settled for $17,161,200 by Aetna, pending Court approval, with no admission of liability. The settlement also requires Aetna to update its policies and procedures to ensure similar privacy breaches are prevented in the future.

There were two alleged breaches of privacy. There was an improper disclosure of protected health information to Aetna’s legal counsel in July, in addition to the mailing of the Benefit Notices that revealed patients were taking HIV medications. Those privacy breaches violated the Health Insurance Portability and Accountability Act (HIPAA) and several state laws according to the lawsuit.

Individuals who had their PHI improperly disclosed will receive a base payment of $75, while class members who were sent the envelopes with the clear plastic windows will receive a base payment of $500. There are almost 1,600 individuals who will receive the $75 payment and almost 12,000 who will receive a payment of $500.

A fund has also been set up for individuals who have suffered additional harm or losses as a result of the disclosure. Those individuals can apply for additional funds by completing a claim form documenting the financial and non-financial harm they have suffered as a result of the privacy breach.

“Through our outreach efforts, immediate relief program, and this settlement we have worked to address the potential impact to members following this unfortunate incident,” said a spokesperson for Aetna. “In addition, we are implementing measures designed to ensure something like this does not happen again as part of our commitment to best practices in protecting sensitive health information.”

The post Aetna Settles Class Action Lawsuit Filed by Victims of HIV Status Data Breach appeared first on HIPAA Journal.

Deadline for Reporting 2017 HIPAA Data Breaches Approaches

The deadline for reporting 2017 HIPAA data breaches to the Department of Health and Human Services’ Office for Civil Rights is fast approaching.

HIPAA-covered entities have a maximum of 60 days from the discovery of a data breach to report security incidents to OCR and notify affected patients. Smaller breaches of PHI do not need to be reported to OCR within this time frame, instead covered entities can delay reporting those breaches to OCR until the end of the calendar year.

The maximum allowable time for reporting breaches impacting fewer than 500 individuals is 60 days from the end of the year in which the breach was experienced. The final day for reporting 2017 HIPAA data breaches to OCR is therefore March 1, 2018.

A HIPAA data breach is defined as an “acquisition, access, use, or disclosure” of unsecured protected health information (PHI) that is not permitted by the HIPAA Privacy Rule. Unsecured PHI is defined as PHI that is “not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology,” such as encryption. A breach of encrypted PHI is not reportable unless the key to unlock the encryption is also reasonably believed to have also been compromised.

Covered entities should be aware that ransomware incidents are usually reportable HIPAA data breaches, even if PHI has not been stolen in the attack. To avoid reporting a ransomware incident, a covered entity must be able to demonstrate a low probability of PHI being compromised in the attack. That determination must be based on a risk assessment (See 45 CFR § 164.402)

While covered entities can submit details of all ‘small’ PHI breaches at the same time, each breach must be reported as a separate event. They can not all be uploaded to the breach portal together.

While the HIPAA Breach Notification Rule allows covered entities additional time to report data breaches impacting fewer than 500 individuals, notifications for individuals impacted by those data breaches cannot be delayed. They must be issued within 60 days of the discovery of the breach, and without unnecessary delay, regardless how many individuals have been impacted by the breach.

It is a good best practice to report all breaches of PHI within 60 days of discovery. Oftentimes, full information about the breach is not available at the time of reporting, but it is possible to add further information to the OCR data breach reports when further information becomes available. If the number of individuals affected by the breach has not been confirmed, estimates should be provided. The final total can then be submitted to OCR as an update to the breach report when the number of individuals impacting has been determined.

The penalties for the late reporting of data breaches can be severe, and OCR made it clear in January 2017 that ignoring the deadline for reporting breaches, or unnecessarily delaying breach reports, is a HIPAA violation that will not be ignored. Presense Health became the first covered entity to be fined solely for delaying breach notifications and settled the HIPAA violation with OCR for $475,000.

OCR has yet to issue a financial penalty to a covered entity for the late reporting of small data breaches, but since OCR tends to set examples with its breach settlements, 2018 could well see the first penalty issued.

To avoid a HIPAA penalty, ensure all small breaches of PHI are reported to OCR between now and the end of February 2018 and no later than midnight on March 1.

The post Deadline for Reporting 2017 HIPAA Data Breaches Approaches appeared first on HIPAA Journal.

1,300 Patients’ Medical Records Viewed Without Authorization by Palomar Health Nurse

More than 1,300 patients of Palomar Medical Center Escondido are being notified that a former nurse viewed their medical records without authorization while they were receiving treatment at the hospital.

The privacy violations occurred over a 15-month period between February 10, 2016 and May 7, 2017. The unauthorized access was discovered when access logs were reviewed. The audit revealed a pattern of access that was not consistent with the nurse’s work duties.

The audit showed the nurse had viewed the records of patients that had been assigned to her, in addition to patients assigned to another nurse in the same unit.

The incident appears to be a case of snooping, rather than data access with malicious intent. Palomar Health has uncovered no evidence to suggest any information was recorded and removed from the hospital, and no reports have been received to suggest any patient information has been misused. Following an internal investigation into the privacy violations, the nurse resigned.

The information viewed was limited to names, dates of birth, genders, medical record numbers, treatment locations, diagnoses, allergies, and medications for 1,309 patients. Financial information, insurance details, and Social Security numbers of four patients were present in a part of the medical record system that was accessed by the nurse. Those four patients have been offered identity theft protection services.

Palomar Health is currently implementing a new system that will automatically audit the logs created when medical records are viewed and when access attempts are made. The system will allow the health system to rapidly identify cases of snooping and data theft. Staff at the hospital will also receive additional privacy and security awareness training.

The post 1,300 Patients’ Medical Records Viewed Without Authorization by Palomar Health Nurse appeared first on HIPAA Journal.

Indiana Health System Pays $55K Ransom to Recover Files

A ransomware attack on Greenfield, Indiana-based Hancock Health on Thursday forced staff at the hospital to switch to pen and paper to record patient health information, while IT staff attempted to block the attack and regain access to encrypted files.

The attack started around 9.30pm on Thursday night when files on its network started to be encrypted. The attack initially caused the network to run slowly, with ransom notes appearing on screens indicating files had been encrypted. The IT team responded rapidly and started shutting down the network to limit the extent of the attack and a third-party incident response firm was called upon to help mitigate the attack.

An attack such as this has potential to cause major disruption to patient services, although Hancock Health said patient services were unaffected and appointments and operations continued as normal.

An analysis of the attack uncovered no evidence to suggest any patient health information was stolen by the attacker(s). The purpose of the attack was solely to cause disruption and lock files to force the hospital to pay a ransom to recover its files.

According to a report in the Greenfield Reporter, the attack involved a variant of ransomware called SamSam. The ransomware variant has been used in numerous attacks on healthcare organizations in the United States over the past 12 months. The unknown attacker(s) demanded a payment of 4 Bitcoin to supply the keys to unlock the encryption.

As required by HIPAA, Hancock Health had performed backups and no data would have been lost as a result of the attack; however, the process of recovering files from backups takes a considerable amount of time. The hospital would not have had access to files and information systems for several days – potentially even weeks – if backups were used to recover data. On Saturday, the decision was taken to pay the ransom.

The decision to pay the ransom was not taken lightly. While patient services were not affected, restoring files from backups would almost certainly have impacted patients and paying the ransom was seen to be the best option to avoid disruption. The keys to unlock the encryption were supplied within two hours of the ransom being paid and the network was brought back online on Sunday.

Typically, these attacks occur as a result of employees responding to phishing emails or visiting malicious websites, although Hancock Health says this attack was not caused by an employee responding to a phishing email.

The attack was sophisticated. “This was not a 15-year-old kid sitting in his mother’s basement,” said Hancock Health CEO Steve Long.

Hancock Health has now implemented software that can detect atypical network activity indicative of an intrusion or ransomware attack, which will allow rapid action to be taken to block, and limit the severity, of any further attacks. Hancock Health is continuing to work with national law enforcement to learn more about the incident.

The post Indiana Health System Pays $55K Ransom to Recover Files appeared first on HIPAA Journal.