HIPAA Breach News

20% of RNs Had Breaches of Patient Data at Their Organization

A recent survey conducted by the University of Phoenix College of Health Professions indicates registered nurses (RNs) are confident in their organization’s ability to prevent data breaches.

The survey was conducted on 504 full time RNs and administrative staff across the United States. Respondents had held their position for at least two years.

Almost half of RNs (48%) and 57% of administrative staff said they were very confident that their organization could prevent data breaches and protect against the theft of patient data, even though 19% of administrative staff and 20% of RNs said their organization had had a data breach in the past. 21% did not know if a breach had occurred.

The survey confirmed that healthcare organizations have made many changes over the years to better protect data and patient privacy, with most of the changes occurring in the past year, according to a quarter of RNs and 40% of administrative staff.

Those changes have occurred across the organization. The biggest areas for change were safety, quality of care, population health, data security and the digitalization of health records.

67% of RNs said privacy and data access policies were being implemented to better protect patient data, while data surveillance was an initiative to improve data privacy and security according to 56% of respondents. 59% of RNs said their organization was implementing role based access to medical records.

69% of administrative staff who took part in the survey said privacy and access policies were being updated, 60% said their organization was implementing role based access, and 55% said data surveillance was a major focus area.

Privacy and security training is being provided to RNs and administrative staff, although 34% of administrative staff and 23 of RNs do not recognize the benefit of such training; however, half of administrative staff respondents and two in five RNs felt they could benefit from further training in his area.

The post 20% of RNs Had Breaches of Patient Data at Their Organization appeared first on HIPAA Journal.

43,000 Patients of Coplin Health Systems Potentially Impacted by Laptop Theft

West Virginia-based Coplin Health Systems has informed 43,000 patients that their PHI has potentially been exposed as a result of the theft of an unencrypted laptop computer from the vehicle of an employee.

Coplin Health was alerted to the theft on November 2, 2017. The theft was immediately reported to law enforcement and an investigation was launched, although at the time of issuing notifications, the laptop computer has not been recovered.

While it is possible that protected health information of patients was stored on the laptop, Coplin Health does not believe that was the case, although the possibility of data exposure cannot be ruled out with 100% certainty.

Coplin Health notes that the laptop had various security protections in place to ensure the privacy of patients in the event of the laptop being stolen. While the laptop could potentially be used to gain access to patient data, a password would have been required and it is not suspected that the thief had “the sophisticated knowledge and resources necessary to bypass the laptop’s security mechanisms.”

Further, Coplin Health’s IT department took rapid action to limit the potential for harm. The employee’s login credentials were changed to prevent the laptop from being used to access Coplin Health’s systems, and no attempts have been made to access its systems using the laptop since the device was stolen.

The chance of patient data being stored locally on the device is believed to be low, although if that was the case, the device would have contained files that included patient names, addresses, Social Security numbers, birth dates, financial information and health information. Out of an abundance of caution, 43,000 patients have been notified of the potential exposure of their PHI.

The incident has prompted Coplin Health to conduct a review of its security protections and actions have been taken to prevent a recurrence. Coplin Health will also increase monitoring to make sure policies and procedures are being following by its employees and any future breach of policies will result in disciplinary action being taken against the employees concerned.

The Health Insurance Portability and Accountability Act (HIPAA) requires covered entities to consider the use of encryption, although the use of encryption is not mandatory. The decision about the use of encryption should be based on a risk assessment. If encryption is not implemented, alternative, equivalent measures must be used in its place. Coplin Health has not said whether it plans to augment its security protections with encryption in the future.

The post 43,000 Patients of Coplin Health Systems Potentially Impacted by Laptop Theft appeared first on HIPAA Journal.

St. Rose Dominican Hospital Patients Impacted by DJO Global PHI Breach

DJO Global, a provider of medical technologies to help patients maintain and regain natural motion, has discovered that some patients’ information has been exposed, and potentially disclosed, to unauthorized individuals.

Individuals who had received a DJO Global device in the emergency room, Urgent Care Site, or the Same Day Surgery Center of the Siena, San Martin or De Lima campuses of St. Rose Dominican Hospital in Las Vegas, NV between July 17 and October 16, 2017 have potentially been affected.

Those individuals are likely to have signed a DJO Global Patient Product Agreement confirming they had received one of the company’s devices. Those consent forms should have been sent to DJO Global; hhowever, a batch of consent forms was not received.

A DJO employee collected the forms from St. Rose Dominican Hospital and should have taken them to DHL to be delivered to DJO Global; however, the forms were lost in transit. They are believed to have been lost between collection from the hospital and delivery to DHL.

The forms contained the following information: Name, phone number, address, birth date, physician name and location, product order date, product information, date of injury, diagnosis code(s), health plan identification number, and health plan information. Some patients whose health plan uses Social Security number as patient identifiers would also have had their Social Security number exposed.

DJO Global has not received any reports to suggest patients’ exposed information has been misused, although since it is possible that the forms have been obtained by a third party, data misuse is a possibility. To ensure that patients are protected, all have been offered complimentary credit monitoring services for 12 months. Patients have also been advised to place a fraud alert on their credit files, to obtain copies of their credit reports, and to check their explanation of Benefits statements carefully for any sign of fraudulent activity.

DJO Global has responded to the incident by changing polices and procedures for mailing and has implemented new quality controls to prevent similar incidents from occurring in the future. Its vendor has also received further training on the importance of securing and protecting patient health information.

Patients impacted by the incident have now been notified by mail, and the Department of Justice and Department of Health and Human Services’ Office for Civil Rights have been notified of the incident.

The post St. Rose Dominican Hospital Patients Impacted by DJO Global PHI Breach appeared first on HIPAA Journal.

Lack of Encryption on Hard Drive Results in the Exposure of 9387 Patients’ PHI

Framingham, MA-based Charles River Medical Associates has discovered the danger of failing to use encryption to protect data stored on portable hard drives.

In late November, the practice discovered one of its portable hard drives was missing. The device contained x-ray images, names, patient ID numbers, and birth dates. Every patient who had visited the Framingham radiology lab for a bone density scan since 2010 had their x-ray images exposed – almost 9,400 individuals.

The hard drive was used by the practice as a backup device and updated the stored data each month with bone density scans from the past four weeks. The last time the device was used was for the October data backup. In late November, when the monthly backup was scheduled to be made, the portable drive could not be found.

A full search of the premises was conducted, which took several weeks, but the device could not be located. All staff members were questioned about the whereabouts of the drive, but no one had seen the device in the past four weeks.

Charles River Medical Associates has now declared the device lost and the search has been called off. Brian Parillo, executive director of Charles River Medical Associates said, “It’s hard to speculate on what could have happened to it.”

The loss of any device containing unencrypted protected health information is a reportable incident under HIPAA Rules and patients must be notified of the potential breach of their information. In compliance with HIPAA Rules, the incident has now been reported to the Department of Health and Human Services’ Office for Civil Rights (OCR) and patients have been informed of the breach by mail.

While the drive is believed to have been lost rather than stolen, it is possible that the device has been found and the information stored on the drive viewed by unauthorized individuals. Patients have therefore been advised to take steps to guard against any negative impact from the incident, including obtaining credit reports and checking their credit accounts for any sign of fraudulent activity.

However, since no Social Security numbers, financial information, or health insurance details were stored on the device, the potential for identity theft and fraud is low.

As a result of the incident, the decision has been taken to stop using unencrypted portable drives to store backups. A full security review has also been conducted to identify other potential vulnerabilities to the confidentiality, integrity, and availability of PHI, a review of hardware has been conducted, and staff have been retrained on privacy workflows.

The breach report submitted to OCR indicates 9,387 patients have been impacted by the incident.

The post Lack of Encryption on Hard Drive Results in the Exposure of 9387 Patients’ PHI appeared first on HIPAA Journal.

Oklahoma State University Center for Health Sciences Informs Patients of PHI Breach

Oklahoma State University Center for Health Sciences (OSUCHS) has discovered an unauthorized individual has gained access to parts of its computer network and potentially accessed files containing billing information of Medicaid patients.

The security breach was discovered on November 7, 2017 with access to the network terminated the following day. Third party computer forensics experts were called upon to conduct a comprehensive investigation to determine which parts of the network had been accessed, and whether patient health information had been accessed or stolen.

The investigation confirmed that patient health information could potentially have been viewed, although it was not possible to determine whether patient information had been accessed or stolen. OSUCHS reports that it has not received conclusive information to suggest any patient information has been misused.

Out of an abundance of caution, all individuals potentially impacted by the incident have been notified of the breach by mail and advised that they should be alert to the possibility that their personal information could potentially be misused.

OSUCHS says medical records were not compromised and the breach was limited to names, healthcare provider names, Medicaid numbers, dates of service, and a limited amount of treatment information. Only one Social Security number was present on the compromised server.

The breach has prompted OSUCHS to conduct a review of security protections and additional measures have now been implanted to better protect patient information in the future.

The incident has yet to appear on the Department of Health and Human Services’ Office for Civil Rights breach portal so it is currently unclear exactly how many individuals have been impacted.

The post Oklahoma State University Center for Health Sciences Informs Patients of PHI Breach appeared first on HIPAA Journal.

Phishing Attack on Florida Agency for Health Care Administration Impacts 30,000 Medicaid Recipients

The Agency for Health Care Administration in Florida has discovered an unauthorized individual has gained access to a single email account as a result of an employee falling for a phishing scam.

The employee received and responded to the malicious phishing email on November 15, 2017 and disclosed login credentials that allowed the attacker to remotely access his/her email account and, potentially, the protected health information of as many as 30,000 Medicaid enrollees.

The agency discovered the security breach on November 20 and performed a password reset to prevent further access. The incident was also reported to the agency’s inspector general, who launched an investigation into the attack. Preliminary findings of that investigation were released late last week.

According to an agency press release issued on Friday, the unauthorized individual may have partially or fully accessed information such as names, Medicaid ID numbers, addresses, dates of birth, diagnoses, medical conditions, and Social Security numbers. Approximately 6% of individuals impacted by the incident had either their Medicaid ID or Social Security number exposed.

While data access was possible, Florida’s Agency for Health Care Administration has not uncovered any evidence to suggest the compromised protected health information has been misused. Since sensitive information has potentially been viewed and stolen, individuals impacted by the incident have been told to be vigilant and check their accounts for signs of fraudulent activity. All individuals impacted by the breach have been offered complimentary credit monitoring services for 12 months.

Prior to the phishing attack, the Florida Agency for Health Care Administration had implemented an ongoing staff training program, although the incident has prompted a review of that program and staff have now been reeducated on proper security protocols and the dangers of phishing. The agency is also considering additional security controls to reduce the risk from phishing in the future.

The post Phishing Attack on Florida Agency for Health Care Administration Impacts 30,000 Medicaid Recipients appeared first on HIPAA Journal.

Compassion Care Hospice Hack Impacts 1,128 Patients

Compassionate Care Hospice Las Vegas (CCHLV) has discovered an unauthorized individual gained access to its network and server and potentially viewed 1,128 patients’ protected health information.

On October 28, 2017, CCHLV discovered its network had been accessed by an unauthorized individual. Upon discovery of the breach, CCHLV hired third-party forensics experts to conduct a thorough investigation to determine the nature of the breach and to identify all patients who were potentially affected.

While the investigation confirmed access to data was possible, no evidence was uncovered to suggest any sensitive information was viewed or stolen by the attacker. However, it was not possible to rule out data access and theft with 100% certainty.

The types of information stored on the parts of the network that could have been accessed included names, dates of birth, addresses, Medicare numbers, medical treatment information, health insurance information, and archived electronic health records. Financial information was not stored on the part of the network compromised in the attack and remained secure at all times.

Once access to the network and server had been blocked, CCHLV conducted a comprehensive risk analysis to identify potential vulnerabilities to the confidentiality, integrity, and availability of PHI and has reviewed and revised network security policies accordingly. To ensure that any future cyberattacks are detected and mitigated rapidly, CCHLV has now implemented intrusion detection and monitoring systems.

CCHLV notified all affected individuals by mail on December 14, 2017 and reported the incident to the Department of Health and Human Services’ Office for Civil Rights. Upon discovery of the attack, law enforcement was notified and CCHLV is continuing to assist with the investigation.

Out of an abundance of caution, all patients impacted by the breach have been offered complimentary credit monitoring and identity theft restoration services for 12 months through Kroll.

The post Compassion Care Hospice Hack Impacts 1,128 Patients appeared first on HIPAA Journal.

Kaiser Permanente Reports Two Security Incidents Impacting 5,000 Members

Kaiser Permanente has experienced two security incidents which have recently been reported to the Department of Health and Human Services’ Office for Civil Rights. In total, more than 5,000 individuals have been impacted by the breaches.

Both breaches affect members of the Kaiser Foundation Group Health Plan. The most serious incident, in terms of the number of individuals impacted, was an email-related breach affecting 4,389 health plan members in the San Bernardino County area of Southern California.

An unauthorized individual was discovered to have gained access to the email account of a Southern California Permanente physician, which contained a limited amount of protected health information.

Kaiser Permanente conducted an extensive investigation to determine the nature and full extent of the breach. While the email account was accessed, Kaiser Permanente believes the risk to plan members is low due to the nature of data contained in the email account.

The email account did not contain highly sensitive information such as bank account details, credit card numbers, insurance information, or Social Security numbers. The breach was limited to plan members’ names, ages, dates of service, medical record numbers, phone numbers, limited medical information, and flu shot data.

Affected members have been informed of the breach by mail and Kaiser Permanente is exploring additional technology that can be implemented to prevent similar breaches from occurring in the future.

One week later, Kaiser Permanente reported a second breach, this time involving the PHI of 638 plan members. The second breach occurred between October 9 and October 13, 2017 and was a mis-mailing incident. Letters containing a limited amount of protected health information were sent to incorrect plan members in the West Los Angeles area.

No Social Security numbers, medical record numbers, financial information, or other highly sensitive information was involved. Affected members have been notified and mailing workflow processes have been reviewed and updated to prevent a recurrence.

The post Kaiser Permanente Reports Two Security Incidents Impacting 5,000 Members appeared first on HIPAA Journal.

Largest Healthcare Data Breaches of 2017

This article details the largest healthcare data breaches of 2017 and compares this year’s breach tally to the past two years, which were both record-breaking years for healthcare data breaches.

2015 was a particularly bad year for the healthcare industry, with some of the largest healthcare data breaches ever discovered. There was the massive data breach at Anthem Inc., the likes of which had never been seen before. 78.8 million healthcare records were compromised in that single cyberattack, and there were also two other healthcare data breaches involving 10 million or more records. 2015 was the worst ever year in terms of the number of healthcare records exposed or stolen.

2016 was a better year for the healthcare industry in terms of the number of healthcare records exposed in data breaches. There was no repeat of the mega data breaches of the previous year. Yet, the number of incidents increased significantly. 2016 was the worst ever year in terms of the number of breaches reported by HIPAA-covered entities and their business associates. So how have healthcare organizations fared in 2017? Was 2017 another record-breaking year?

Healthcare Data Breaches Increased in 2017

The mega data breaches of 2015 were fortunately not repeated in 2017, and the decline in massive data breaches continued in 2017.

Last year, there were three breaches reported that impacted more than one million individuals and 14 breaches of more than 100,000 records.

In 2017, there was only one reported data breach that impacted more than 500,000 people and 8 breaches that impacted 100,000 or more individuals. The final total for individuals impacted by breaches last year was 14,679,461 – considerably less than the 112,107,579 total the previous year.

The final figures for 2017 cannot yet be calculated as there is still time for breaches to be reported to OCR. The HIPAA Breach Notification Rules allows covered entities up to 60 days to report data breaches of more than 500 records, so the final figures for 2017 will not be known until March 1, 2018. However, based on current data, 2017 has been a reasonably good year in terms of the number of exposed healthcare records. The current total stands at 3,286,498 records – A 347% reduction in breached records year on year.

While it is certainly good news that the severity of breaches has reduced, that only tells part of the story. Breaches of hundreds of thousands of records have reduced, but breaches of more than 10,000 records have remained fairly constant year over year. In 2015, there were 52 breaches of 10,000 or more records. That figure jumped to 82 in 2016. There were 78 healthcare data breaches in 2017 involving more than 10,000 records.

The bad news is there has been a significant rise in the number of healthcare data breaches in 2017.  As of January 4, 2017, there have been 342 healthcare security breaches listed on the OCR breach portal for 2017. It is likely more incidents will be added in the next few days.

The final total for 2015 was 270 breaches, and there were 327 breaches reported in 2016. The severity of healthcare security incidents may have fallen, but the number of incidents continues to rise year on year.

 

reported healthcare data breaches in 2017

 

Unfortunately, there is little evidence to suggest that the annual rise in healthcare data breaches will stop in 2018. Many cybersecurity firms have made predictions for the coming year, and they are united in the view that healthcare data breaches will continue to increase.

The 20 Largest Healthcare Breaches of 2017

The list of the 20 largest healthcare data breaches of 2017 is listed below.

Position Breached Entity Entity Type Records Exposed Cause of Breach
1 Commonwealth Health Corporation Healthcare Provider 697,800 Theft
2 Airway Oxygen, Inc. Healthcare Provider 500,000 Hacking/IT Incident
3 Women’s Health Care Group of PA, LLC Healthcare Provider 300,000 Hacking/IT Incident
4 Urology Austin, PLLC Healthcare Provider 279,663 Hacking/IT Incident
5 Pacific Alliance Medical Center Healthcare Provider 266,123 Hacking/IT Incident
6 Peachtree Neurological Clinic, P.C. Healthcare Provider 176,295 Hacking/IT Incident
7 Arkansas Oral & Facial Surgery Center Healthcare Provider 128,000 Hacking/IT Incident
8 McLaren Medical Group, Mid-Michigan Physicians Imaging Center Healthcare Provider 106,008 Hacking/IT Incident
9 Harrisburg Gastroenterology Ltd Healthcare Provider 93,323 Hacking/IT Incident
10 VisionQuest Eyecare Healthcare Provider 85,995 Hacking/IT Incident
11 Washington University School of Medicine Healthcare Provider 80,270 Hacking/IT Incident
12 Emory Healthcare Healthcare Provider 79,930 Hacking/IT Incident
13 Salina Family Healthcare Center Healthcare Provider 77,337 Hacking/IT Incident
14 Stephenville Medical & Surgical Clinic Healthcare Provider 75,000 Unauthorized Access/Disclosure
15 Morehead Memorial Hospital Healthcare Provider 66,000 Hacking/IT Incident
16 Primary Care Specialists, Inc. Healthcare Provider 65,000 Hacking/IT Incident
17 Enterprise Services LLC Business Associate 56,075 Unauthorized Access/Disclosure
18 ABCD Pediatrics, P.A. Healthcare Provider 55,447 Hacking/IT Incident
19 Network Health Health Plan 51,232 Hacking/IT Incident
20 Oklahoma Department of Human Services Health Plan 47,000 Hacking/IT Incident

The Largest Healthcare Data Breaches of 2017 Were Due to Hacking

One thing is abundantly clear from the list of the largest healthcare data breaches of 2017 is hacking/IT incidents affect more individuals than any other breach type. Hacking/IT incidents accounted for all but three of the largest healthcare data breaches of 2017.

In 2016, hacking incidents only accounted for 11 out of the top 20 data breaches and 12 of the top 20 in 2015. Hacking incidents therefore appear to be rising.

 

healthcare data breaches in 2017 (hacking)

 

The rise in hacking incidents can partly be explained by the increase in ransomware attacks on healthcare providers in 2017. Healthcare organizations are also getting better at discovering breaches.

Other Major Causes of Healthcare Data Breaches in 2017

Unauthorized access/disclosures continue to be a leading cause of healthcare data breaches, although there was a slight fall in numbers of these incidents in 2017. That decrease is offset by an increase in incidents involving the improper disposal of physical records and electronic devices used to store ePHI.

 

healthcare data breaches of 2017 (Unauthorized access/disclosures)

 

The use of encryption for stored data is more widespread, with many healthcare organizations having implemented encryption on all portable storage devices and laptops, which has helped to reduce the exposure of ePHI when electronic devices are stolen.

 

Healthcare Data Breaches of 2017 (loss/theft)

Minimizing the Risk of Healthcare Data Breaches

This year saw OCR publish the preliminary findings of its HIPAA compliance audits on HIPAA-covered entities. The audits revealed there is still widespread non-compliance with HIPAA Rules.

One of the biggest problems was not a lack of cybersecurity defenses, but the failure to conduct an enterprise-wide risk analysis.

Even with several layers of security, vulnerabilities are still likely to exist. Unless a comprehensive risk analysis is performed to identify security gaps, and those gaps are addressed, it will only be a matter of time before they are exploited.

Complying with HIPAA Rules will not prevent all data breaches, but it will ensure healthcare organizations achieve at least the minimum standard for data security, which will prevent the majority of healthcare data breaches.

There is a tendency to invest cybersecurity budgets in new technology, but it is important not to forget the basics. Many healthcare data breaches in 2017 could have been prevented had patches been applied promptly, if secure passwords had been chosen, and if cloud storage services and databases had been configured correctly. Many data breaches were caused as a result of employees leaving unencrypted laptops in risky locations – in unattended vehicles for instance.

Phishing remains one of the main ways that malicious actors gain access to protected health information, yet security awareness training is still not being provided frequently. As a result, employees are continuing to fall for phishing and social engineering scams. Technological solutions to block phishing emails are important, but healthcare organizations must also educate employees about the risks, teach them how to recognize scams, and reinforce training regularly. Only then will organizations be able to reduce the risk from phishing to an acceptable and appropriate level.

Insiders continue to be a major threat in healthcare. The value of data on the black market is high, and cash-strapped healthcare employees can be tempted to steal data to sell to identity thieves. Healthcare organizations can hammer the message home that data theft will be discovered and reported to law enforcement, but it is the responsibility of healthcare organizations to ensure policies and technologies are implemented to ensure that the unauthorized accessing of records – theft or snooping – is identified rapidly.  That means frequent audits of access logs and the use of automated monitoring solutions and user behavior analytics.

2017 was a bad year for ransomware attacks and extortion attempts on healthcare organizations. There is no sign that these attacks will slow in 2018, and if anything, they are likely to increase. Ensuring data is backed up will allow organizations to recover files in the event of an attack without having to pay a ransom. The rise in sabotage attacks – NotPetya for example – mean data loss is a real possibility if backups are not created.

By getting the basics right and investing in new technologies, it will be possible for the year on year rise in data breaches to be stopped. But until healthcare organizations get the basics right and comply with HIPAA Rules, healthcare data breaches are likely to continue to rise.

The post Largest Healthcare Data Breaches of 2017 appeared first on HIPAA Journal.