HIPAA Breach News

Largest Healthcare Data Breaches of 2017

This article details the largest healthcare data breaches of 2017 and compares this year’s breach tally to the past two years, which were both record-breaking years for healthcare data breaches.

2015 was a particularly bad year for the healthcare industry, with some of the largest healthcare data breaches ever discovered. There was the massive data breach at Anthem Inc., the likes of which had never been seen before. 78.8 million healthcare records were compromised in that single cyberattack, and there were also two other healthcare data breaches involving 10 million or more records. 2015 was the worst ever year in terms of the number of healthcare records exposed or stolen.

2016 was a better year for the healthcare industry in terms of the number of healthcare records exposed in data breaches. There was no repeat of the mega data breaches of the previous year. Yet, the number of incidents increased significantly. 2016 was the worst ever year in terms of the number of breaches reported by HIPAA-covered entities and their business associates. So how have healthcare organizations fared in 2017? Was 2017 another record-breaking year?

Healthcare Data Breaches Increased in 2017

The mega data breaches of 2015 were fortunately not repeated in 2017, and the decline in massive data breaches continued in 2017.

Last year, there were three breaches reported that impacted more than one million individuals and 14 breaches of more than 100,000 records.

In 2017, there was only one reported data breach that impacted more than 500,000 people and 8 breaches that impacted 100,000 or more individuals. The final total for individuals impacted by breaches last year was 14,679,461 – considerably less than the 112,107,579 total the previous year.

The final figures for 2017 cannot yet be calculated as there is still time for breaches to be reported to OCR. The HIPAA Breach Notification Rules allows covered entities up to 60 days to report data breaches of more than 500 records, so the final figures for 2017 will not be known until March 1, 2018. However, based on current data, 2017 has been a reasonably good year in terms of the number of exposed healthcare records. The current total stands at 3,286,498 records – A 347% reduction in breached records year on year.

While it is certainly good news that the severity of breaches has reduced, that only tells part of the story. Breaches of hundreds of thousands of records have reduced, but breaches of more than 10,000 records have remained fairly constant year over year. In 2015, there were 52 breaches of 10,000 or more records. That figure jumped to 82 in 2016. There were 78 healthcare data breaches in 2017 involving more than 10,000 records.

The bad news is there has been a significant rise in the number of healthcare data breaches in 2017.  As of January 4, 2017, there have been 342 healthcare security breaches listed on the OCR breach portal for 2017. It is likely more incidents will be added in the next few days.

The final total for 2015 was 270 breaches, and there were 327 breaches reported in 2016. The severity of healthcare security incidents may have fallen, but the number of incidents continues to rise year on year.

 

reported healthcare data breaches in 2017

 

Unfortunately, there is little evidence to suggest that the annual rise in healthcare data breaches will stop in 2018. Many cybersecurity firms have made predictions for the coming year, and they are united in the view that healthcare data breaches will continue to increase.

The 20 Largest Healthcare Breaches of 2017

The list of the 20 largest healthcare data breaches of 2017 is listed below.

Position Breached Entity Entity Type Records Exposed Cause of Breach
1 Commonwealth Health Corporation Healthcare Provider 697,800 Theft
2 Airway Oxygen, Inc. Healthcare Provider 500,000 Hacking/IT Incident
3 Women’s Health Care Group of PA, LLC Healthcare Provider 300,000 Hacking/IT Incident
4 Urology Austin, PLLC Healthcare Provider 279,663 Hacking/IT Incident
5 Pacific Alliance Medical Center Healthcare Provider 266,123 Hacking/IT Incident
6 Peachtree Neurological Clinic, P.C. Healthcare Provider 176,295 Hacking/IT Incident
7 Arkansas Oral & Facial Surgery Center Healthcare Provider 128,000 Hacking/IT Incident
8 McLaren Medical Group, Mid-Michigan Physicians Imaging Center Healthcare Provider 106,008 Hacking/IT Incident
9 Harrisburg Gastroenterology Ltd Healthcare Provider 93,323 Hacking/IT Incident
10 VisionQuest Eyecare Healthcare Provider 85,995 Hacking/IT Incident
11 Washington University School of Medicine Healthcare Provider 80,270 Hacking/IT Incident
12 Emory Healthcare Healthcare Provider 79,930 Hacking/IT Incident
13 Salina Family Healthcare Center Healthcare Provider 77,337 Hacking/IT Incident
14 Stephenville Medical & Surgical Clinic Healthcare Provider 75,000 Unauthorized Access/Disclosure
15 Morehead Memorial Hospital Healthcare Provider 66,000 Hacking/IT Incident
16 Primary Care Specialists, Inc. Healthcare Provider 65,000 Hacking/IT Incident
17 Enterprise Services LLC Business Associate 56,075 Unauthorized Access/Disclosure
18 ABCD Pediatrics, P.A. Healthcare Provider 55,447 Hacking/IT Incident
19 Network Health Health Plan 51,232 Hacking/IT Incident
20 Oklahoma Department of Human Services Health Plan 47,000 Hacking/IT Incident

The Largest Healthcare Data Breaches of 2017 Were Due to Hacking

One thing is abundantly clear from the list of the largest healthcare data breaches of 2017 is hacking/IT incidents affect more individuals than any other breach type. Hacking/IT incidents accounted for all but three of the largest healthcare data breaches of 2017.

In 2016, hacking incidents only accounted for 11 out of the top 20 data breaches and 12 of the top 20 in 2015. Hacking incidents therefore appear to be rising.

 

healthcare data breaches in 2017 (hacking)

 

The rise in hacking incidents can partly be explained by the increase in ransomware attacks on healthcare providers in 2017. Healthcare organizations are also getting better at discovering breaches.

Other Major Causes of Healthcare Data Breaches in 2017

Unauthorized access/disclosures continue to be a leading cause of healthcare data breaches, although there was a slight fall in numbers of these incidents in 2017. That decrease is offset by an increase in incidents involving the improper disposal of physical records and electronic devices used to store ePHI.

 

healthcare data breaches of 2017 (Unauthorized access/disclosures)

 

The use of encryption for stored data is more widespread, with many healthcare organizations having implemented encryption on all portable storage devices and laptops, which has helped to reduce the exposure of ePHI when electronic devices are stolen.

 

Healthcare Data Breaches of 2017 (loss/theft)

Minimizing the Risk of Healthcare Data Breaches

This year saw OCR publish the preliminary findings of its HIPAA compliance audits on HIPAA-covered entities. The audits revealed there is still widespread non-compliance with HIPAA Rules.

One of the biggest problems was not a lack of cybersecurity defenses, but the failure to conduct an enterprise-wide risk analysis.

Even with several layers of security, vulnerabilities are still likely to exist. Unless a comprehensive risk analysis is performed to identify security gaps, and those gaps are addressed, it will only be a matter of time before they are exploited.

Complying with HIPAA Rules will not prevent all data breaches, but it will ensure healthcare organizations achieve at least the minimum standard for data security, which will prevent the majority of healthcare data breaches.

There is a tendency to invest cybersecurity budgets in new technology, but it is important not to forget the basics. Many healthcare data breaches in 2017 could have been prevented had patches been applied promptly, if secure passwords had been chosen, and if cloud storage services and databases had been configured correctly. Many data breaches were caused as a result of employees leaving unencrypted laptops in risky locations – in unattended vehicles for instance.

Phishing remains one of the main ways that malicious actors gain access to protected health information, yet security awareness training is still not being provided frequently. As a result, employees are continuing to fall for phishing and social engineering scams. Technological solutions to block phishing emails are important, but healthcare organizations must also educate employees about the risks, teach them how to recognize scams, and reinforce training regularly. Only then will organizations be able to reduce the risk from phishing to an acceptable and appropriate level.

Insiders continue to be a major threat in healthcare. The value of data on the black market is high, and cash-strapped healthcare employees can be tempted to steal data to sell to identity thieves. Healthcare organizations can hammer the message home that data theft will be discovered and reported to law enforcement, but it is the responsibility of healthcare organizations to ensure policies and technologies are implemented to ensure that the unauthorized accessing of records – theft or snooping – is identified rapidly.  That means frequent audits of access logs and the use of automated monitoring solutions and user behavior analytics.

2017 was a bad year for ransomware attacks and extortion attempts on healthcare organizations. There is no sign that these attacks will slow in 2018, and if anything, they are likely to increase. Ensuring data is backed up will allow organizations to recover files in the event of an attack without having to pay a ransom. The rise in sabotage attacks – NotPetya for example – mean data loss is a real possibility if backups are not created.

By getting the basics right and investing in new technologies, it will be possible for the year on year rise in data breaches to be stopped. But until healthcare organizations get the basics right and comply with HIPAA Rules, healthcare data breaches are likely to continue to rise.

The post Largest Healthcare Data Breaches of 2017 appeared first on HIPAA Journal.

29,000 Patients Notified of Employee-Related Data Breach at SSM Health

The St. Louis, MO-based not-for-profit health system SSM Health has discovered a former employee has been accessing the health records of patients without any legitimate work reason for doing so for 8 months.

The former employee worked in SSM Health’s customer service call center, and as such, did not have access to financial information, only demographic, health, and clinical information.

The improper access was detected by SSM health on October 30, prompting a thorough investigation to determine the records that had been accessed and which patients were potentially at risk. The investigation revealed the records of patients in multiple states were accessed by the employee between February 13 and October 20, 2017.

The employee was primarily interested in the records of patients of a primary care physician in the St. Louis area, specifically patients who had been prescribed a controlled substance. While that subset of patients was relatively small, it was not possible to determine the full scope of the privacy breach, so SSM Health took the decision to notify all patients whose records had been accessed by the former employee. In many cases, that access will have been for legitimate work purposes.

In total, 29,000 patients have been notified of the incident and warned that their protected health information may have been improperly accessed and could potentially have been misused. Those patients have been offered identity theft protection services without charge.

SSM Health has also changed its procedures to require an additional identifier to be used when patients request prescription refills via its call center. Internal policies and procedures have been reviewed and employee access monitoring tools have been strengthened to ensure any future illegal employee activity is identified more rapidly.

The incident has been reported to the Department of Health and Human Services’ Office for Civil Rights and law enforcement has been notified.

SSM Health privacy officer, Scott Didion, said, “We take very seriously our role of safeguarding our patients’ personal information, and we deeply regret any inconvenience or concern this situation may have caused our patients.”

This is the second incident to be reported by SSM Health this year. In May, SSM Health reported that an electromyography device containing the PHI of 836 patients had been stolen from DePaul Hospital St Louis in Bridgeton, MO.

The post 29,000 Patients Notified of Employee-Related Data Breach at SSM Health appeared first on HIPAA Journal.

Colorado Practice Hacked Twice in a Week

A family and sports medicine practice in Colorado has discovered a hacker gained access to its systems and encrypted files with ransomware.

Longs Peak Family Practice (LPFP) in Longmont CO, identified suspicious activity on its network on November 5, 2017 and took rapid action to secure its systems. However, before that was possible, the attacker ran ransomware code which encrypted files on certain parts of its network.

LPFP was prepared for such attacks, and was able to recover the encrypted files and rebuild its systems from backups. However, five days after the initial intrusion was detected, LPFP discovered a second attack had occurred, and its systems had been accessed in a second attack. Ransomware was not involved in the second incident.

While the first incident was dealt with internally, when the second attack was discovered, LPFP called in a leading computer forensics form to assist with the investigation, conduct scans for malware and backdoors, and ensure that unauthorized access to its systems was blocked.

That investigation revealed that an unauthorized individual had accessed certain parts of LPFP’s network on November 5, 9, and 10th. The forensic investigation took until December 5 to complete, but did not uncover any specific evidence to suggest the attacker had opened any files or stolen data.

However, it was not possible to rule out data access and theft with 100% certainty, and while no evidence was uncovered to suggest the ransomware infection did anything other than blindly encrypt files, it is possible that the malware could have been used to download some computer files.

Files stored on the compromised computers included the following patient information: Names, addresses, email addresses, driver’s license details, Social Security numbers, dates of birth, internal patient ID numbers, insurance carriers, insurance payment codes and costs, dates of service, copies of notes made by LPFP physicians and other healthcare providers, medical conditions, medications, diagnoses, data from diagnostic studies, and lab test results.

Potentially, final statements for accounts that had been sent to a collection agency may have been compromised, but no financial information, invoices for medical services, or credit/debit card details were exposed.

LPFP had already implemented a range of defenses to prevent the unauthorized accessing of patient data, but these attacks revealed vulnerabilities existed in its defenses.  Those vulnerabilities have now been addressed and changes have been made to how its network can be accessed. A new, enhanced firewall has been purchased and implemented, further training is being provided to staff on privacy and security, and the practice is looking into further tools and procedures that will help to improve security.

Due to the sensitive nature of the information that was potentially accessed, LPFP is offering patients 12 months of identity theft repair and credit monitoring services through AllClear without charge.

The post Colorado Practice Hacked Twice in a Week appeared first on HIPAA Journal.

24,000 Patients Impacted by Emory Healthcare Data Breach

Emory Healthcare (EHC) has discovered a former employee obtained the protected health information of several thousand EHC patients and uploaded the data to a Microsoft Office 365 OneDrive account, where it could potentially be accessed by other individuals.

The former employee was a physician at Emory Healthcare, who now works for the University of Arizona (UA) College of Medicine. EHC says patient information was taken without authorization and without its knowledge. EHC was alerted to the incident by the University of Arizona, and received a list of affected individuals on October 18, 2017.

The OneDrive account could only be accessed by the physician, other former EHC physicians now at UA, UA staff who investigated the incident, and potentially a limited number of other UA staff members who had a specific type of UA email account. PHI was not exposed on the Internet and no other individuals are believed to have been able to view the information.

UA hired a third-party forensic team to conduct an investigation, although no evidence was uncovered to suggest patient information was accessed or used in any way. UA has confirmed that all EHC patient information has been permanently and securely deleted from the account and its systems.

EHC says no Social Security numbers, financial information, addresses, phone numbers, driver’s license numbers, or credit card information was exposed. The data uploaded to the account was limited to names, dates of service at EHC, provider names, medical record numbers, diagnoses, treatment information, treatment locations, and in some cases, dates of birth. The information was largely restricted to patients who had received radiology services at EHC between 2004 and 2014.

EHC is now notifying patients by mail that their protected health information has been exposed, and potentially disclosed. EHC has received no reports to suggest any of the information has been misused; however, as a precautionary measure, patients have been advised to remain vigilant and to take steps to protect themselves against potential fraudulent use of their information.

EHC is now taking steps to prevent incidents such as this from occurring in the future, including enhancing its patient care team education programs and reviewing and improving security measures.

The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates 24,000 patients have been impacted by the breach.

The post 24,000 Patients Impacted by Emory Healthcare Data Breach appeared first on HIPAA Journal.

Jones Memorial Hospital Alerts Patients to Ongoing Cyberattack

University of Rochester Medicine’s Jones Memorial Hospital in Wellsville, NY is currently experiencing a cyberattack that has caused unexpected downtime.

The attack is understood to have started on Wednesday December 27 and has caused disruption to some of its information services. At the time of writing, the nature of the cyberattack is unclear and it has yet to be resolved.  The cyberattack is limited to Jones Memorial Hospital. No other locations have been impacted.

While some systems are unavailable, Jones Memorial Hospital has announced on its website that the financial and medical information of its patients does not appear to have been compromised. If the investigation concludes that there has been a breach of health information, patients will be notified accordingly. Further information on the attack will also be posted on the hospital’s website as and when new information becomes available.

The hospital notified law enforcement and the New York State Department of the attack when its systems went down. Hospital IT staff are being assisted by the IT departments at the University of Rochester, St. James Hospital, and Noyes Health to restore all systems back to full functionality.

Jones Memorial Hospital has prepared for incidents such as this. Emergency procedures are regularly tested, and employees are trained how to respond to cyberattacks and system downtime. Consequently, medical services are continuing to be provided, with information being recorded manually on patient charts while its systems are offline.

However, without access to electronic patient health information, the hospital is advising all patients to bring their insurance card with them, as well as full lists of medications and if possible, details of their medical history.

Systems will be brought back online as soon as is possible, but in the meantime, the hospital is focused on maintaining patient safety and quality of care.

The post Jones Memorial Hospital Alerts Patients to Ongoing Cyberattack appeared first on HIPAA Journal.

Scrub Nurse Fired for Photographing Employee-Patient’s Genitals

A scrub nurse who took photographs of a patient’s genitals and shared the images with colleagues has been fired, while the patient, who is also an employee at the same hospital, has filed a lawsuit seeking damages for the harm caused by the incident.

The employee-patient was undergoing incisional hernia surgery at Washington Hospital. She alleges in a complaint filed in Washington County Court, that while she was unconscious, a scrub nurse took photographs of her genitals on a mobile phone and shared the photographs with co-workers.

Photographing patients without their consent is a violation of HIPAA Rules, and one that can attract a significant financial penalty. Last Year, New York Hospital settled a HIPAA violation case with the Department of Health and Human Services’ Office for Rights and paid a financial penalty of $2.2 million. In that case, a television crew had been authorized to film in the hospital, but consent from the patients in the footage had not been obtained.

In the Washington Hospital HIPAA breach, the patient, identified in the lawsuit only as Jane Doe, claims she became aware that photos had been shared the day after her operation. She also claims the scrub nurse showed her the photographs that had been taken. Horrified at the violation of her privacy, she reported the incident to her supervisors. The scrub nurse was subsequently fired for the HIPAA violation.

However, in the lawsuit Jane Doe claims that was not the end of the matter. She said, taking action against the scrub nurse resulted in her “being treated like the wrongdoer, not the victim.” As a result of the complaint she was “forced to endure harassment, humiliation and backlash,” and “extreme hostility” at work. That harassment has allegedly continued outside the hospital.

Jane Doe was given two weeks of paid leave as a healing period, and returned to her unit in the same position. However, she suffered migraines, anxiety, and insomnia as a result of the incident. She requested further paid leave of 3 months, as recommended by her physician, but the request was denied. She subsequently took unpaid leave under the Family Medical Leave Act and was terminated in October.

The lawsuit names the hospital, a doctor who was in the operating room but failed to stop the scrub nurse from taking photos and did not report the incident, and several other workers at the hospital. Jane Doe seeks in excess of $75,000 in damages for the “severe physical, emotional and psychological stress” caused. The patient’s husband is also a plaintiff and is suing for loss of consortium.

The post Scrub Nurse Fired for Photographing Employee-Patient’s Genitals appeared first on HIPAA Journal.

Children’s Hospital Los Angeles Alerts Parents to Impermissible Disclosure of Children’s PHI

Children’s Hospital Los Angeles is notifying parents of a privacy breach that saw the protected health information (PHI) of children disclosed to incorrect insurance payors.

The privacy breach was discovered on November 29, 2017, with notifications sent to affected patients on December 19.

The impermissible disclosure of PHI included names, addresses, medical record numbers, birth dates, dates of service, and descriptions of the services provided.

Upon discovery of the privacy breach, the insurance payors were contacted and instructed to delete the information. Satisfactory assurances have been received that the information has now been deleted and the medical records of affected patients have been updated to include correct payor information.

No reports have been received to suggest any of the disclosed information has been used inappropriately; however, out of an abundance of caution, affected patients have been offered credit monitoring/protection services with ID Experts without charge.

In the breach notification letters, parents have been advised to monitor insurance communications, including Explanation of Benefits statements, for any services that have not been received by their children and to be alert to the possibility of inappropriate use of their child’s PHI.

The incident has prompted Children’s Hospital Los Angeles to re-enforce education of vendors and staff on the importance of safeguarding patient information.

The incident has been reported to the California Attorney General’s Office and will be reported to the HHS’ Office for Civil Rights. At this stage it is unclear exactly how many individuals have been impacted by the incident.

The post Children’s Hospital Los Angeles Alerts Parents to Impermissible Disclosure of Children’s PHI appeared first on HIPAA Journal.

Phishing Attack on Colorado Mental Health Institute Sees PHI Exposed

The Colorado Mental Health Institute at Pueblo has discovered one of its employees has fallen for a phishing scam that potentially allowed the attacker to gain access to the protected health information of as many as 650 patients.

The Colorado Mental Health Institute at Pueblo is a 449-bed hospital providing inpatient care for patients. The hospital serves patients with pending criminal charges that require competency evaluations, individuals found by the courts to be incompetent to proceed, and individuals found not guilty of crimes due to insanity.

The phishing attack occurred on November 1, 2017. The employee inadvertently disclosed login credentials that allowed the attacker to gain access to a state-issued computer. Unauthorized activity on the computer was detected the following day and access to the device was promptly blocked.

The forensic investigation did not uncover any evidence to suggest the protected health information of patients had been accessed or stolen, although the possibility of unauthorized access and data theft could not be ruled out with complete certainty.

All patients impacted by the incident have been notified of the security breach, as is required by HIPAA. They have been informed that potentially compromised information “could include, but is not limited to name, date of birth, Social Security number, address, phone number, insurance information, admission and discharge dates.”

The phishing attack has prompted the Colorado Mental Health Institute to implement new technical safeguards to prevent future phishing attacks. Privacy policies and procedures have also been reviewed and updated and staff have received further training on the risks from phishing. The Colorado Mental Health Institute said the individual who fell for the phishing scam has been dealt with “in accordance with CDHS policy and applicable law.”

The post Phishing Attack on Colorado Mental Health Institute Sees PHI Exposed appeared first on HIPAA Journal.

Access to Dental Records Lost for 5 Days Due to Ransomware

A dental practice in Reno, NV has experienced a ransomware attack that prevented dental records and images from being accessed for five days.

Wager Evans Dental experienced the ransomware attack on October 30, 2017. The malicious software was installed on one computer and one server used by the practice.

Ransomware can be installed in a number of ways, although most commonly attacks occur via email. That appears to be the case with this attack, with the practice suspecting ransomware was downloaded when an employee clicked on a malicious hyperlink or email attachment.

IT staff and other experts were able to restore the encrypted files and remove the ransomware, although the process took five days. Access to patient records and images was not regained until November 4.

The files encrypted by the ransomware contained sensitive information such as names, dates of birth, addresses, diagnoses, treatment plans, images, health insurance information, and Social Security numbers.

A comprehensive investigation of the attack was conducted and while it is possible that data could have been viewed by the attackers, the sole intention of the attack appears to be an attempt to extort money from the practice.

The investigation into the breach is ongoing, although so far there are no indications that the attackers viewed or stole PHI. Since it is not possible to determine with absolute certainty that data access/theft did not occur, all patients have been notified of the attack, and out of an abundance of caution, those individuals have been offered credit monitoring services for one year without cost.

The attack has prompted the practice to enhance its security to prevent similar incidents from occurring in the future. In the breach notification letter, Brian E. Evans, DDS, said “We have retained security experts and made significant upgrades to our network and computer security.

The post Access to Dental Records Lost for 5 Days Due to Ransomware appeared first on HIPAA Journal.