HIPAA Breach News

Protenus Releases November Healthcare Data Breach Report

Protenus has released its November healthcare data breach report – a summary of healthcare data breaches reported by HIPAA-covered entities. The report shows there has been a month on month fall in healthcare data breaches, and a major reduction in the number of records exposed by data breaches.

November saw the lowest total of the year to date for breaches with 28 incidents included in the report – four incidents fewer than February, the previous best month when 32 breaches were reported. This is the second consecutive month when reported breaches have fallen. There were 46 breaches reported in September and 37 in October.

November was also the best month of the year in terms of the number of records exposed. 83,925 individuals were impacted by healthcare data breaches in November. The previous lowest total was May, when 138,957 records were exposed. November was the third consecutive month where the number of breached records fell.

While the November healthcare data breach report offers some good news, the fall in breaches and breached records should be taken with a large pinch of salt. Healthcare organizations have a maximum of 60 days to report breaches, so the figures do not indicate there has been a reduction in incidents. Also, figures have only been obtained for 25 of the 28 breaches. As Kira Caban, Director of Public Relations at Protenus, notes, “The number of both data breach incidents and affected patient records are lower than any other month thus far in 2017, but it may also just indicate that people wanted to get ready for Thanksgiving, so they delayed reporting.”

In November, insider breaches outnumbered hacking incidents with nine incidents (32%) due to insiders with eight incidents attributed to hacking (28%). 25% of breaches involved the loss or theft or records or devices containing ePHI. Seven of the breaches involved paper records.

The November healthcare data breach report shows hacking incidents resulted in the highest number of exposed records by a nose -36,804 records. Insider incidents resulted in the exposure of 36,447 records: 27,228 due to insider error and 9,219 due to insider wrongdoing. 5,324 records were exposed due to the theft or loss of physical records or devices containing unencrypted ePHI.

As is typical, healthcare providers reported the most breaches (82.1%), followed by health plans (10.7%). Three incidents (3.6%) are known to have involved business associates of HIPAA-covered entities.

It is difficult to make a determination whether healthcare organizations managed to discover breaches more quickly, as figures were only available for four incidents. The average time to detect a breach was 55 days, with a median of 33 days. One breach took 153 days to discover.

Data are better for the time to report breaches. The median time to report the incidents to HHS was 57 days, with an average time of 61 days. The figures show healthcare organizations are still waiting until the last minute to report breaches. It should be noted that while HIPAA allows up to 60 days to report data breaches, incidents should be reported without unnecessary delay, and well within that 60-day window.  At least three covered entities have risked a financial penalty for delayed breach notifications, with one taking 134 days to report the breach.

While California is usually the state with the most reported breaches, that unenviable accolade was taken by Kentucky in November, with three reported breaches. Healthcare organizations based in Massachusetts, Texas, Colorado, Indiana, Florida, and California each reported two breaches.

The post Protenus Releases November Healthcare Data Breach Report appeared first on HIPAA Journal.

Almost 10,000 Patients Impacted by Nebraska Ransomware Attack

Columbus Surgery Center, LLC and Eye Physicians, P.C., in Columbus, Nebraska have experienced a ransomware attack that has potentially resulted in the protected health information of almost 10,000 patients being accessed by the attackers.

The ransomware attack occurred on October 7, 2017 and saw a wide range of files on some servers being encrypted by the ransomware. A ransom demand was issued by the attackers, although it was not paid. The encrypted files were restored from a recent backup to allow services to be continued to be offered to patients.

Third-party computer forensics professionals were called in to assist with the investigation of the attack to determine whether the attackers gained access to, viewed, or copied patient information and to investigate how access to the servers was gained and how the ransomware was installed.

The investigation did not uncover evidence to suggest any patient health information was stolen, but data access could not be ruled out with a high degree of confidence. Consequently, the incident was reportable to the Department of Health and Human Services’ Office for Civil Rights under HIPAA Rules and notifications to patients were warranted. Those notifications have now been mailed.

Eye Physicians reports that the breach involved information such as names, dates of birth, and ophthalmic imagery, and that no financial information or Social Security numbers were exposed.

As a result of the attack, an external IT security consultant was contracted to conduct a comprehensive security risk assessment to identify potential vulnerabilities, and hardware and software have been upgraded as a result of that assessment. It is hoped that the improvements to security will help to prevent similar incidents from occurring in the future.

The incident affected 7,721 patients of the Columbus Surgery Center and 2,620 patients of Eye Physicians, according to the breach reports submitted to OCR.

The post Almost 10,000 Patients Impacted by Nebraska Ransomware Attack appeared first on HIPAA Journal.

Potential Data Theft Incident Reported by Austin Manual Therapy

1,750 patients of Austin Manual Therapy (AMT) have been notified that some of their protected health information may have been accessed and stolen by a criminal attacker who gained access to their system.

A forensic investigation by a leading national cybersecurity team revealed access was first gained on October 3, 2017 and continued until October 9, when the intrusion was detected and blocked. According to the breach notice posted on the AMT website, access was not gained to the company’s electronic medical record system. Only a limited portion of the network was accessed – one computer and a shared file system.

While the forensic investigation confirmed that access to some files had been gained, it was not clear how much information was viewed and which, if any, documents had been stolen. An analysis of the file system and computer showed that the following information could have been accessed: Names, addresses, dates of birth, phone numbers, dates of service, charge amounts, occupations, insurance coverage and policy information, health screening information, diagnoses, driver’s license information, referring physician information, and partial and full Social Security numbers.

The breach investigation has largely been completed, although TMD said it is continuing to actively work with forensic investigators and that the investigation will likely continue until the end of the year.

Additional security measures have now been implemented to prevent this type of attack from occurring in the future. While the exact nature of the attack was not detailed in the TMD breach report, Databreaches.net has reported that this was an extortion attempt by the hacking group TheDarkOverlord.

Individuals impacted by the breach have been advised that they can obtain free credit reports and place a fraud alert and security freeze on their accounts, but it would not appear that credit monitoring or identity theft protection services have been offered.

The post Potential Data Theft Incident Reported by Austin Manual Therapy appeared first on HIPAA Journal.

1,900 MidMichigan Medical Center Patients Notified After Documents Found in the Street

MidMichigan Medical Center (MMC) in Alpena has alerted patients to a potential breach of their health information, which may have literally fallen into the hands of individuals unauthorized to view the information.

On the evening of November 18, a MMC cardiologist removed patient files from the Alpena cardiology office without authorization. The files were transported to the cardiologist’s vehicle in a storage container, but the container had not been properly secured.

Close to a parking lot near 12th Avenue/Chisholm Street, the container was dropped, spilling the contents on the ground. The documents were caught by the wind and started blowing round the street.

Some of the documents were picked up by members of the public, who informed the hospital that documents containing sensitive patient information was blowing around the street. The hospital contacted law enforcement to provide assistance collecting the paperwork.

Dr. Richard Bates, vice president of medical affairs at MMC issued a statement saying all of the paperwork is believed to have been retrieved, so the risk to patients is thought to be low. However, since it cannot be confirmed that every document has been recovered, patients have been notified of the potential breach of their PHI.

The reasons why the cardiologist, Dr. Christopher Walls, removed the records from the office is not known. However, removing documents containing patient information is a violation of hospital policies, and as a result of that violation, Dr. Walls is no longer employed at MMC.

Approximately 1,900 patients have been notified of the potential breach, which may have included names along with addresses, Social Security numbers, and clinical data. As a precautionary measure, affected patients have been offered complimentary identity theft protection services.

“We take matters related to the security of our patients’ personal information very seriously because it is our responsibility to protect their privacy. We have rigorous processes and procedures in place to detect breaches and to protect patients’ rights,” said Bates.

The post 1,900 MidMichigan Medical Center Patients Notified After Documents Found in the Street appeared first on HIPAA Journal.

Two Healthcare Providers Announce Incidents Involving the Improper Disposal of Patient Data

Two healthcare providers have announced they have experienced incidents involving the improper disposal of protected health information; one involving paper records and the other a hard drive containing electronic health information.

NYU Langone Health System discovered a binder containing a log of presurgical insurance authorizations was accidentally recycled by a cleaning company in October. The binder contained records relating to around 2,000 patients.

Information in the binder included names, birth dates, dates of service, current procedural terminology code, diagnosis codes, insurer names, and insurance ID numbers. In some cases, brief notes may have been present, along with insurance approvals/denials and inpatient/outpatient status. No Social Security numbers were recorded in the paperwork, and neither any financial information.

As required by HIPAA, NYU Langone Health System had implemented a policy that requires all PHI to be disposed of securely when it is no longer required, typically by shredding documents. Since the binder was taken for recycling by accident, that did not occur.

Since insurance ID numbers were present in the logs, NYU Langone Health System has offered all affected patients complimentary identity theft protection services and cyber monitoring services through ID Experts for one year.

To prevent similar incidents from occurring in the future, staff have been reeducated on the importance of safeguarding patient information and practice workflow has been updated to improve the protections for sensitive patient information. No reports have been received to suggest any information has been used inappropriately.

The second incident was reported by the Pequannock, NJ Chilton Medical Center (CMC). In this case, patient records, including names, addresses, medical record numbers, dates of birth, details of allergies and medications received at CMC were stored on a hard drive that was discovered to have been removed by an employee and sold on the Internet.

The sale of the hard drive was not authorized by CMC and was in breach of the medical center’s policies. The incident has been reported as a theft and the Morris County Prosecutor’s Office has been notified. According to the breach notice placed on the medical center’s website, the employee no longer works at CMC.

Upon discovery of the incident, an internal investigation was launched, and it became apparent that this was not the first time that computer hardware and assets had been removed by the former employee and sold online. Those additional devices and assets are not believed to have contained any patient information, although the investigation is ongoing.

Patients impacted by the incident had visited CMC for medical services between May 1, 2008 and October 15, 2017. All patients impacted were notified of the security incident on December 15, 2017. CMC said additional processes and controls have been put in place to prevent incidents such as this from occurring in the future.

The incident has yet to appear on the breach portal of the Department of Health and Human’ Services Office for Civil Rights, it is currently unclear exactly how many patients have been affected.

The post Two Healthcare Providers Announce Incidents Involving the Improper Disposal of Patient Data appeared first on HIPAA Journal.

$2.3 Million 21st Century Oncology HIPAA Settlement Agreed with OCR

A 21st Century Oncology HIPAA settlement has been agreed with the Department of Health and Human Services’ Office for Civil Rights (OCR) to resolve potential HIPAA violations discovered during the investigation of a 2015 breach of 2.2 million patients’ PHI.

The breach in question was discovered by the Federal Bureau of Investigation (FBI) in 2015. The FBI informed 21st Century Oncology on November 13 and December 13, 2015, that an unauthorized individual accessed and stole information from one of its patient databases.

21st Century Oncology conducted an investigation with the assistance of a third-party computer forensics company and discovered the network SQL database was potentially first accessed on October 3, 2015. The database was accessed through Remote Desktop Protocol from an Exchange Server within 21st Century Oncology’s network. The database contained the protected health information of 2,213,597 individuals.

As occurs after all data breaches that impact more than 500 individuals, OCR conducted an investigation into the 21st Century Oncology data breach. That investigation uncovered multiple potential violations of HIPAA Rules.

OCR determined that 21st Century Oncology failed to conduct a comprehensive, organization-wide risk assessment to determine the potential risks to the confidentiality, integrity, and availability of electronic protected health information, as required by 45 C.F.R. § 164.308(a)(1)(ii)(A).

21st Century Oncology was also determined to have failed to implement sufficient measures to reduce risks to an appropriate and acceptable level to comply with 45 C.F.R. § 164.306(A).

21st Century Oncology also failed to implement procedures to regularly review logs of system activity, including audit logs, access reports, and security incident tracking reports, as required by 45 C.F.R. §164.308(a)(1)(ii)(D).

The breach resulted in the impermissible disclosure of the protected health information of 2,213,597 patients.

Further, protected health information of patients was disclosed to business associates without first entering into a HIPAA-compliant business associate agreement and obtaining satisfactory assurances that HIPAA requirements would be followed.

To resolve those potential HIPAA violations, 21st Century Oncology agreed to pay OCR $2.3 million. In addition to the financial settlement, 21st Century Oncology has agreed to adopt a comprehensive corrective action plan (CAP) to bring its policies and procedures up to the standards demanded by HIPAA.

Under the CAP, 21st Century Oncology must appoint a compliance officer, revise its policies and procedures with respect to system activity reviews, access establishment, modification and termination, conduct an organization-wide risk assessment, develop internal policies and procedures for reporting violations of HIPAA Rules, and train staff on new policies.

21st Century Oncology is also required to engage a qualified, objective, and independent assessor to review compliance with the CAP.

Separate $26 Million Settlement Resolves Meaningful Use, Stark Law, and False Claims Act Violations

In addition to the OCR settlement to resolve potential HIPAA violations, 21st Century Oncology has also agreed to a $26 million settlement with the Department of Justice to resolve allegations that it submitted false or inflated Meaningful Use attestations in order to receive incentive payments. 21st Century Oncology self-reported that employees falsely submitted information relating to the use of EHRs to avoid downward payment adjustments. Fabricated reports were also submitted, and the logos of EHR vendors were superimposed on reports to make them appear genuine.

The settlement also resolves allegations that the False Claims Act was violated by submitting or enabling the submission of claims that involved kickbacks for physician referrals, and also violations of the Stark Law, which covers physician self-referrals.

According to the Department of Justice, “The Stark Law prohibits an entity from submitting claims to Medicare for designated health services performed pursuant to referrals from physicians with whom the entity has a financial relationship unless certain designated exceptions apply.”

“We appreciate that 21st Century Oncology self-reported a major fraud affecting Medicare, and we are also pleased that the company has agreed to accept financial responsibility for past compliance failures,” said Middle District of Florida Acting U.S. Attorney Stephen Muldrow.

In addition to paying the settlement amount, 21st Century Oncology has entered into a 5-year Corporate Integrity Agreement with the HHS’ Office of Inspector General (OIG).

The post $2.3 Million 21st Century Oncology HIPAA Settlement Agreed with OCR appeared first on HIPAA Journal.

Texas and Pennsylvania Data Breaches Exposed More than 5,000 Patients’ PHI

Midland Memorial Hospital in Midland, TX, and Washington Health System Greene in Waynesburg, PA, have announced they have discovered patients’ protected health information has been exposed.

Washington Health System Greene Discovers Hard Drive Missing

Washington Health System Greene is alerting 4,145 patients that some of their protected health information has been exposed after a hard drive was discovered to be missing.

A portable hard drive used with a bone densitometry machine in the Radiology department was discovered to be missing on October 11, 2017. While it is possible that the hard drive may have been misplaced, a search of the hospital did not uncover the device, and the missing device has been reported to the Pennsylvania State Police Department as a potential theft.

The device contained information on patients who visited the hospital for bone density scans between 2007 and October 11, 2017. The information stored on the device was limited to names, height, weight, race, and gender, while some patients also had details of health issues, the name of their prescribing physician, and medical record numbers stored on the device. No financial information, Social Security numbers, insurance details, or other highly sensitive information was exposed.

As required by HIPAA, patients have been notified of the breach. Due to the limited nature of data exposed, even if the device has been stolen, Washington Health Greene does not believe patients are at risk of identity theft or fraud.

Midland Memorial Hospital Discovers Email Account Compromise

Midland Memorial Hospital has experienced a breach of a limited amount of patients’ protected health information. More than 1,000 patients are understood to have been affected.

Midland Memorial Hospital discovered an unauthorized individual gained access to the email account of an employee at the hospital, in what appears to be an attempted Business Email Compromise (BEC) attack. The aim of the attacker appeared to be to fool employees into making bank account transfers to an inappropriate bank account.

The breach was discovered on October 13, 2017, with access to the email account believed to have been gained on or around October 10.  Upon discovery of the security breach, access the email account was terminated and a full investigation was conducted. The email account was determined to contain some protected health information including first and last names, medical record numbers, account numbers, and information relating to radiology procedures that had been performed at the hospital between August and September 2017. No financial information, driver’s license numbers, or Social Security numbers were exposed, and no evidence has been uncovered to suggest any patient information has been used inappropriately.

Midland Memorial Hospital has taken steps to prevent further incidents of this nature from occurring, including revising policies and procedures and retraining staff.

The post Texas and Pennsylvania Data Breaches Exposed More than 5,000 Patients’ PHI appeared first on HIPAA Journal.

Illinois Physicians Network Discovers Paper Records Missing from Storage Facility

Over the past two months there have been several data breaches reported by HIPAA-covered entities involving the loss or theft of physical records. In November, 7 breaches involving paper records were reported to the HHS’ Office for Civil Rights, and a further 5 incidents were reported the previous month.

Now another incident has been reported in Illinois. Franciscan Physician Network of Illinois and Specialty Physicians of Illinois LLC have discovered payment records that were kept in a storage facility are missing. The storage facility in Chicago Heights was shared by both physician groups.

The loss/theft of the paperwork is one of the largest breaches of the past few months, potentially impacting as many as 22,000 patients. The payment records were from 2015-2017 and 2010.

The boxes of files were confirmed as missing on November 21, 2017, with notifications issued on December 13, 2017. The loss of files was discovered following a routine records request, but the records could not be located. An inventory of the storage facility was conducted, and 40 boxes of files were determined to be missing and potentially stolen.

The records only contained a limited amount of patient information related to payments received, and included names and addresses, payment methods, payment amounts, office location, and the last four digits of credit card numbers. For a limited number of patients who paid their bill by check, their routing number, bank account number and Social Security number were also present in the files.

Some of the records from 2010 may also have included insurance ID numbers, facility-assigned account numbers, dates of birth, type of visit, diagnoses, provider names and addresses, dates of service, descriptions of services provided, and procedure codes.

While it is a possibility that the files have been stolen, foul play is not suspected. Out of an abundance of caution, individuals impacted by the incident have been offered two years of identity theft protection services without charge.

The post Illinois Physicians Network Discovers Paper Records Missing from Storage Facility appeared first on HIPAA Journal.

November 2017 Healthcare Data Breach Report

In November 2017, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) received 21 reports of healthcare data breaches that impacted more than 500 individuals; the second consecutive month when reported breaches have fallen.

healthcare data breaches by month (November 2017)

While the number of breaches was down month on month, the number of individuals impacted by healthcare data breaches increased from 71,377 to 107,143.

breached healthcare records November 2017

Main Causes of November 2017 Healthcare Data Breaches

In November there was an even spread between hacking/IT incidents, unauthorized disclosures, and theft/loss of paper records or devices containing ePHI, with six breaches each. There were also three breaches reported involving the improper disposal of PHI and ePHI. Two of those incidents involved paper records and one involved a portable electronic device.

The two largest data breaches reported in November – the 32,000-record breach at Pulmonary Specialists of Louisville and the 16,474-record breach at Hackensack Sleep and Pulmonary Center – were both hacking/IT incidents. The former involved an unauthorized individual potentially gaining access to electronic medical records, while the latter was a ransomware attack.

Seven of the 21 breaches reported in November impacted more than 5,000 individuals. The mean breach size was 5,102 records. The median breach size was 1,551 records.

 

causes of healthcare data breaches November 2017

records exposed by breach type

Location of Exposed and Stolen Protected Health Information

The OCR breach reports show the importance of implementing physical safeguards to ensure the confidentiality of paper records. In November, one third of reported data breaches (7 incidents) involved paper/films. Last month there were five reported incidents involving paper records.

A recent Accenture/HIMSS Analytics survey revealed email was the most common vector in cyberattacks on healthcare organizations. That was the case in October when email was the common location of breached data. In November, email was the second most common location of breached PHI behind paper films, with four email-related breaches reported.  There was an even spread between all other locations of breached PHI.

Location of PHI in November 2017 healthcare data breaches

 

November 2017 Healthcare Data Breaches by Covered Entity Type

November 2017 saw 19 data breaches reported by healthcare providers and two breaches affecting health plans. The breach reports indicate no business associates of covered entities were involved in any incidents reported in November.

 November 2017 Healthcare Data Breaches by Covered Entity Type

 

Largest Healthcare Data Breaches of November 2017

 

Breached Entity Entity Type Breach Type Individuals Affected
Pulmonary Specialists of Louisville, PSC Healthcare Provider Hacking/IT Incident 32,000
Hackensack Sleep and Pulmonary Center Healthcare Provider Hacking/IT Incident 16,474
Shop-Rite Supermarkets, Incorporated Healthcare Provider Improper Disposal 12,172
The Medical College of Wisconsin, Inc. Healthcare Provider Hacking/IT Incident 9,500
Valley Family Medicine Healthcare Provider Unauthorized Access/Disclosure 8,450
Sports Medicine & Rehabilitation Therapy, Inc. Healthcare Provider Hacking/IT Incident 7,000
Humana Inc Health Plan Unauthorized Access/Disclosure 5,764
Alere Toxicology Healthcare Provider Unauthorized Access/Disclosure 2,146
Family & Cosmetic Dentistry of the Rockies Healthcare Provider Improper Disposal 1,850
Aetna Inc. Health Plan Unauthorized Access/Disclosure 1,600

 

November 2017 Healthcare Data Breaches by State

The reported breaches in November were spread across 15 states. The states worst affected were Kentucky and Massachusetts with 3 breaches apiece, followed by Colorado and New Jersey each with 2 breaches. One breach was reported by healthcare organizations based in Alabama, California, Connecticut, Florida, Indiana, New York, Pennsylvania, Texas, Virginia, Washington, and Wisconsin.

The post November 2017 Healthcare Data Breach Report appeared first on HIPAA Journal.