HIPAA Breach News

Hospital Employee Fired for Accessing Medical Records Without Authorization

Lowell General Hospital in Massachusetts has discovered the medical records of 769 patients have been accessed by an employee without any legitimate work reason for doing so.

By accessing the medical records, the employee breached hospital policies and violated the privacy of patients. Upon discovery of the breach, and completion of the subsequent investigation, the employee was terminated. Lowell General Hospital was satisfied that only one person was involved, and that this was not a widespread problem at the hospital.

Patients impacted by the security incident have been notified and a breach notice has been placed on the hospital website. Patients have been informed that the types of information accessed by the former employee included names, dates of birth, medical diagnoses, and information relating to treatments provided to patients.

No financial information, health insurance details, or Social Security numbers were viewed by the employee, and the investigation uncovered no evidence to suggest that any of the information that was accessed has been misused.

Lowell General Hospital provides training to all staff members, and clearly instructs employees that the accessing of medical records without a legitimate reason is strictly prohibited. While checks are performed to ensure that employees are abiding by hospital policies, the incident has prompted Lowell General Hospital to conduct a review of its privacy and security policies relating to its medical record system. Improvements will be made to ensure that any future instances of snooping are identified rapidly. The hospital will continue to provide ongoing training to staff on patient privacy.

What is not clear is how long the employee was able to improperly access medical records before the privacy violations were discovered. The number of patients impacted by the incident suggests the improper access had been ongoing for several months.

HIPAA required covered entities and their business associates to regularly monitor PHI access logs for unauthorized access. While “regularly” is open to interpretation, it is a good best practice to conduct ongoing audits of access logs to help identify unauthorized activity.

These audits can be conducted manually, although tools are available to reduce the administrative burden. Those tools are either rule-based or behavior-based. The former requires rules to be set which will trigger alerts if they are violated, while behavior based systems learn about normal access and trigger alerts if any anomalies are detected. These automated solutions can help to detect improper activity much more quickly, allowing rapid action to be taken when employees snoop on medical records.

The post Hospital Employee Fired for Accessing Medical Records Without Authorization appeared first on HIPAA Journal.

PHI of 28,000 Mental Health Patients Stolen by Healthcare Employee

Center for Health Care Services (CHCS) in San Antonio, a provider of mental health treatment and support services for individuals with intellectual and developmental disabilities, has discovered documents containing the protected health information of patients have been stolen by a former employee.

Breach notification letters have been sent to 28,434 patients who received services at CHCS before the summer of 2016 informing them of the breach.

The breach was only discovered on November 7, 2017, but the data theft occurred more than 17 months ago. The former employee was terminated on May 31, 2016, with the data downloaded onto a personal laptop after the individual was fired, according to a recent CHCS press release.

The breach came to light during discovery in a litigation case between the former employee and CHCS. No details have been released about the nature of the litigation.

The stolen documents contained a wide range of highly sensitive data on patients, including adults and children. The data included names, dates of birth, addresses, Social Security numbers, dates and types of services, medical record numbers, referral information, progress notes, medical diagnoses, medications prescribed, treatment plans, laboratory and toxicology reports, death certificates, autopsy reports, discharge dates, death summaries, and collateral hospital information.

The reason why the former employee took the data is unclear, although it does not appear that the information has been used for malicious purposes. CHCS believes the information has not been shared with any unauthorized individuals, other than the former employee’s attorneys. CHCS attorneys have also reportedly obtained a copy of the data.

According to the CHCS news release, patients are not believed to be at risk and there are no actions that need to be taken by patients as a result of the breach. Patients will be informed if the situation changes.

A spokesperson for CHCS said, “Attorneys for CHCS are seeking a protective order to prevent further disclosure of the information, and to verify deletion of the information as soon as the court permits.” CHCS is also taking steps to ensure security is improved to prevent future breaches of this nature from occurring.

The post PHI of 28,000 Mental Health Patients Stolen by Healthcare Employee appeared first on HIPAA Journal.

Medical Records from Pennsylvania Obs/Gyn Clinic Found at Public Recycling Center

Paper files containing names, Social Security numbers, and medical histories, including details of cancer diagnoses and sexually transmitted diseases, have been dumped at a recycling center in Allentown, Pennsylvania.

The files appear to have come from Women’s Health Consultants, an obstetrics and gynecology practice that had centers in South Whitehall Township and Hanover Township, PA. Women’s Health Consultants is no longer in business.

How the records came to be dumped at the recycling center is unknown as the container where the records were disposed of was not covered by surveillance cameras.

The center does have a locked recycling container where sensitive documents containing confidential information can be disposed of securely, but that container was not used. The records were dumped in a container where they could be accessed by unauthorized individuals.

The person who discovered the files left an anonymous tip on the non-emergency line of the Allentown communication center. According to The Morning Call, a city employee visited the recycling center and pushed the records further into the container, so they were no longer visible. The container has since been loaded onto a truck and is no longer accessible by the public. The container will be sent on to a recycling company.

The privacy breach has been reported to the Pennsylvania attorney general’s office, although it is unclear whether an investigation into the incident has been launched.

HIPAA requires all physical records containing patients’ protected health information to be disposed of securely, rendering all information unreadable and indecipherable, so that it cannot be reconstructed. For paper records, this typically involves shredding, pulping, or burning the files. If that process is to occur off-site, the records should be secured in transit to ensure they cannot be accessed by unauthorized individuals.

The failure to dispose of records securely can attract a significant financial penalty, ranging from $100 to $50,000 per instance, up to a maximum of $1,500,000.

The Department of Health and Human Services’ Office for Civil Rights has already punished healthcare organizations for improperly disposing of medical records. In 2015, Cornell Prescription Pharmacy settled an improper disposal case with OCR for $125,000.

The post Medical Records from Pennsylvania Obs/Gyn Clinic Found at Public Recycling Center appeared first on HIPAA Journal.

UAB Medicine Alerts 652 Patients of PHI Exposure

The UAB Medicine Viral Hepatitis Clinic in Birmingham, AL has experienced a breach of patients’ protected health information (PHI).

UAB Medicine uses flash drives to transfer data from its Fibroscan machine to a computer. On October 25, 2017, two flash drives were discovered to be missing. The portable storage devices contained a limited amount of PHI of 652 patients.

Information stored on the devices included first and last names, gender, birth dates, images and numbers relating to test results, medical diagnosis, names of referring physician, and the dates and times of the examination.

UAB Medicine has confirmed that no Social Security numbers, financial information, insurance details, addresses, or phone numbers were stored on the flash drives.

An extensive search of Viral Hepatitis Clinic was conducted, but the flash drives could not be located. The investigation into the breach is continuing. It is not known whether the flash drives were accidentally disposed of, lost within the facility, or if they were stolen. UAB Medicine therefore cannot say whether the PHI on the devices has been viewed by unauthorized individuals.

The breach of PHI has prompted UAB Medicine to review its policies and procedures and measures have been implemented to prevent similar incidents from occurring in the future. All patients affected by the incident were notified of the breach by mail this week.

Due to the limited nature of data that was exposed, patients are not believed to face a high risk of identity theft and fraud. As a precaution, patients have been advised to monitor their credit reports for any sign of fraudulent activity.

Since the possibility of unauthorized access of PHI cannot be ruled out, UAB Medicine is also offering patients impacted by the incident 12 months of credit monitoring and reporting services without charge.

The post UAB Medicine Alerts 652 Patients of PHI Exposure appeared first on HIPAA Journal.

Personal Information of New York Pharmacy Customers Exposed in Improper Disposal Incident

ShopRite Supermarkets, Inc., has announced that some of its pharmacy customers have been impacted by a security breach involving the improper disposal of a device used to capture customers’ signatures.

The device was used at the ShopRite, Kingston, NY location between 2005 and 2015 and stored personal and medical information. All customers who visited the pharmacy and had prescriptions filled between 2005 and 2015 have potentially been impacted by the incident. For those customers, the device stored information such as names, phone numbers, prescription numbers, dates and times of pickup or delivery, zip codes, medication names, and customers’ signatures.

The device was also used for customers who bought an over-the-counter product containing pseudoephedrine. Those customers have had their driver’s license number, zip code, details of the product purchased, and personal and medical information exposed.

In the substitute breach notice posted on the Wakefern Food Corp., website, customers have been advised that the device was disposed of by accident in February 2016, although ShopRite only confirmed that a data security incident had occurred on October 13, 2017.

ShopRight has not received any reports to suggest the information on the device has been accessed or misused in any way, although customers have been advised to monitor their Explanation of Benefits statements from their insurers for any sign of fraudulent use of their data. Customers have also been advised to monitor their financial accounts for any sign of fraud, although ShopRite does point out that their Social Security numbers and financial data were not exposed at any point.

ShopRite has responded to the incident by reviewing its security policies in relation to devices that store personal information and the removal and secure deletion of data from those devices prior to disposal. Privacy and security training has also been provided to all pharmacy staff to help prevent further security breaches of this nature.

All customers impacted by the security breach have now been notified by mail.

The post Personal Information of New York Pharmacy Customers Exposed in Improper Disposal Incident appeared first on HIPAA Journal.

7,000 Patients Impacted by Extortion Attempt on Sports Medicine Provider

Massachusetts-based Sports Medicine & Rehabilitation Therapy (SMART) has alerted 7,000 patients to a breach of their protected health information. Potentially, the breach impacted all patients whose information was recorded during a visit to a SMART center prior to December 31, 2016.

The breach, which occurred in September 2017, was an extortion attempt. Hackers gained access to SMART systems, allegedly stole data, and demanded a ransom payment to prevent the information from being released online.

No indication was provided in the breach notification letters to suggest the ransom was paid, although SMART has informed its patients that there is “no reason to believe that the data has been or will be used for further nefarious purposes.”

The matter has been investigated by the FBI and Homeland Security although the details of the investigations have not been released. An attempt was made by SMART to obtain a copy of the police report through the Freedom of Information Act, although at the time the notifications were sent, no copy had been received.

The information potentially stolen by the hackers did not include financial data or Social Security numbers, but insurance numbers and diagnostic codes were included in the stolen data set.

North Carolina DHHS Notifies 6,000 Patients of an Accidental Disclosure of PHI

The North Carolina Department of Health and Human Services has discovered a spreadsheet containing the protected health information of approximately 6,000 individuals was accidentally sent to a vendor in an unencrypted email. The breach was discovered on September 27, 2017.

The vendor in question was contacted and instructed to securely delete the spreadsheet attached to the email. NC DHHS has confirmed that the spreadsheet has been securely deleted, although affected individuals have been informed that potentially, the email could have been intercepted in transit by unauthorized individuals. The risk of interception of the email or the misuse of any information in the spreadsheet is believed to be low.

The spreadsheet contained information such as names, test results, and Social Security numbers of individuals who had undergone routine drug screening tests. The tests were conducted on individuals who had applied to NC DHHS for employment or intern and volunteer opportunities.

NC DHHS is conducting a review of policies and procedures to ensure similar incidents are prevented in the future.

The post 7,000 Patients Impacted by Extortion Attempt on Sports Medicine Provider appeared first on HIPAA Journal.

Cottage Health Fined $2 Million By California Attorney General’s Office

Santa Barbara-based Cottage Health has agreed to settle a data breach case with the California attorney general’s office. Cottage Health will pay $2 million to resolve multiple violations of state and federal laws.

Cottage Health was investigated by the California attorney general’s office over a breach of confidential patient data in 2013. The breach was discovered by Cottage Health on December 2, 2013, when someone contacted the healthcare network and left a message on its voicemail system warning that sensitive patient information had been indexed by the search engines and was freely available via Google.

The sensitive information of more than 50,000 patients was available online, without any need for authentication such as a password and the server on which the information was stored was not protected by a firewall. The types of information exposed included names, medical histories, diagnoses, prescriptions, and lab test results. In addition to the individual who alerted Cottage Health to the breach, the server had been accessed by other individuals during the time that it was unsecured.

As is required under state laws, the incident was reported to state attorney general Kamala D. Harris. Two years later, while the attorney general’s office was investigating the incident, Cottage Health experienced a second breach. The second breach involved the records of 4,596 patients, and similarly, were left exposed and accessible online without any need for authentication.

The information was accessible for almost two weeks before the error was identified and protections put in place to prevent unauthorised access. The information exposed in the second breach included personally identifiable information and protected health information such as names, addresses, medical record numbers, account numbers, employment information, Social Security numbers, and admission and discharge dates.

Cottage Health claims that while both incidents resulted in the exposure of patient data, there are no indications to suggest any patient information was used inappropriately. The breaches prompted Cottage Health to review its information security controls and strengthen its policies, procedures, and security protections to prevent similar breaches from occurring in the future. In each case, the health network’s security teams acted quickly to limit harm and secure the exposed information. New system monitoring tools have now been implemented, and advanced security solutions are in place that allow vulnerabilities to be identified and mitigated much more rapidly.

The response to the breach may have been reasonable and appropriate, and protections now far better, but it is the lack of protections leading up to the data breaches that warranted a financial penalty. The California state attorney general’s office alleges that Cottage Health breached California’s Confidentiality of Medical Information Act, its Unfair Competition Law, and HIPAA Rules were also violated. According to the complaint, “Cottage failed to employ basic security safeguards.” Cottage Health was running outdated software, patches were not applied promptly, default configurations had not been changed, strong passwords were not used, access to sensitive PII was not limited, and regular risk assessments were not conducted.

Announcing the settlement, California Attorney General Xavier Becerra said, “When patients go to a hospital to seek medical care, the last thing they should have to worry about is having their personal medical information exposed,” Becerra explained that “The law requires health care providers to protect patients’ privacy. On both of these counts, Cottage Health failed.”

In addition to the $2 million settlement, Cottage Health is required to update and maintain information security controls and ensure security practices and procedures match industry standards.

Specifically, the judgement requires Cottage Health to:

  • Assess hardware and software for vulnerabilities to the confidentiality, integrity, and availability of patients’ medical information.
  • Update access controls and security settings as appropriate
  • Evaluate the response to and protections from external threats, including firewall security
  • Encrypt patients’ medical information in transit to industry standards
  • Maintain reasonable policies and protocols for all information practices regarding data retention, internal audits, security incident tracking reports, risk assessments, incident management, and remediation plan
  • Conduct periodic vulnerability scans and penetration tests to identify and assess vulnerabilities, and remediate any vulnerabilities discovered
  • Conduct employee training on the correct use and storage of patients’ medical information.

The post Cottage Health Fined $2 Million By California Attorney General’s Office appeared first on HIPAA Journal.

Second Unencrypted Laptop Stolen from Rocky Mountain Health Care Services

Rocky Mountain Health Care Services of Colorado Springs has discovered an unencrypted laptop has been stolen from one of its employees. This is the second such incident to be discovered in the space of three months.

The latest incident was discovered on September 28. The laptop computer was discovered to contain the protected health information of a limited number of patients. The types of information stored on the device included first and last names, addresses, dates of birth, health insurance information, Medicare numbers, and limited treatment information.

The incident has been reported to law enforcement and patients impacted by the incident have been notified by mail.

Rocky Mountain Health Care Services, which also operates as Rocky Mountain PACE, BrainCare, HealthRide, and Rocky Mountain Options for Long Term Care, also discovered on June 18, 2017 that a mobile phone and laptop computer were stolen from a former employee. The devices contained names, dates of birth, addresses, limited treatment information, and health insurance details.

To date, only one of those incidents has appeared on the Department of Health and Human Services’ Office for Civil Rights breach portal. That incident, reported on November 16, indicates 909 patients were impacted. It is unclear whether this is the first or second laptop theft.

In response to the breaches, Rocky Mountain Health Care Services has been reviewing its policies and procedures with respect to the security of patient information and portable electronic devices, and is considering incorporating mobile device management technologies and data encryption for its portable electronic devices.

As the Office for Civil Rights breach portal shows, the loss and theft of unencrypted portable electronic devices is still a major cause of healthcare data breaches, and one that the use of data encryption technologies can easily prevent. So far in 2017, there have been 31 breaches reported by covered entities and business associates that have involved the loss or theft of unencrypted laptop computers and other portable electronic devices.

The post Second Unencrypted Laptop Stolen from Rocky Mountain Health Care Services appeared first on HIPAA Journal.

9,500 Patients Impacted by Medical College of Wisconsin Phishing Attack

A Medical College of Wisconsin phishing attack has resulted in the exposure of approximately 9,500 patients’ protected health information. The attackers managed to gain access to several employees’ email accounts, which contained a range of sensitive information of patients and some faculty staff.

The types of information in the compromised email accounts included names, addresses, medical record numbers, dates of birth, health insurance details, medical diagnoses, treatment information, surgical information, and dates of service. A very limited number of individuals also had their Social Security numbers and bank account information exposed.

The incident occurred over the space of a week in the summer between July 21 and July 28 when spear phishing emails were sent to specific individuals at the Medical College of Wisconsin. Responding to those emails resulted in the attackers gaining access to email login credentials.

Medical College of Wisconsin brought in a computer forensics firm to conduct an investigation into the phishing attack, and while that investigation established that access to the email accounts was gained by unauthorized individuals, it was not possible to determine whether emails containing protected health information had been accessed or viewed, or if any sensitive information was stolen. Since the attack occurred, no reports of misuse of patient information have been received.

To protect individuals against identity theft and fraud, credit monitoring and identity theft restoration services have been offered to breach victims free of charge, but only to those individuals whose Social Security numbers were compromised.

Medical College of Wisconsin reports that in addition to some faculty staff and Medical College of Wisconsin patients, some individuals who received treatment at Children’s Hospital of Wisconsin and Froedtert Health have also been impacted by the breach.

The latest Medical College of Wisconsin phishing attack comes just 10 months after a similar incident resulted in the exposure of 3,200 patients’ protected health information.

The post 9,500 Patients Impacted by Medical College of Wisconsin Phishing Attack appeared first on HIPAA Journal.