HIPAA Breach News

Aging Agency Reports Ransomware Attack: 8,750 Patients Impacted

The Ottawa-based East Central Kansas Area Agency on Aging (ECKAAA) has experienced a ransomware attack that has resulted in the encryption of files on one of the agency’s servers. Those files contained the protected health information (PHI) of 8,750 patients.

The attack occurred on September 5, 2017 and was immediately recognized by ECKAAA, which took prompt action to limit the spread of the infection. As a result, only parts of the server had files encrypted. Those files were discovered to contain names, telephone numbers, addresses, birthdates, Medicaid numbers, and Social Security numbers.

ECKAAA hired a cybersecurity firm to assist with the investigation and determine the true extent and nature of the attack. The investigation revealed the ransomware variant used was a variant of Crysis/Dharma – a ransomware variant known to encrypt files stored locally, on mapped network drives, and unmapped network shares. Crysis/Dharma ransomware also deletes shadow volume copies to hamper recovery.

While the investigation uncovered no evidence of exfiltration of data, the possibility of data access and data theft could not be ruled out. ECKAAA reports that while not all files on the server were encrypted, the attackers potentially had access to all files saved on the server.

Prior to the ransomware attack, ECKAAA had implemented safeguards to protect against malware attacks and to ensure files could be recovered in the event of disaster. Consequently, it was possible to recover all the encrypted files without paying the ransom.

Since the protections in place were not sufficient to block the ransomware attack on this occasion, ECKAAA has implemented a number of new measures to improve security. Those measures include the use of CrowdStrike advanced malware agents and subscription to Cisco Umbrella Insights to improve security monitoring.

Additional training has also been given to staff to improve awareness of the threat from ransomware, a full password reset has taken place, and staff have been reminded about the importance of selecting strong passwords. A review of policies and procedures is also taking place and they will be updated accordingly to reduce the risk of future attacks occurring.

ECKAAA conducted a fully HIPAA-compliant breach response. The incident was reported to the Department of Health and Human Services’ Office for Civil Rights, a substitute breach notice was placed prominently on the ECKAAA website, and media reports were submitted to prominent newspapers serving each of the five counties in which the agency operates. All individuals have now been notified of the potential breach of their PHI by mail.

The post Aging Agency Reports Ransomware Attack: 8,750 Patients Impacted appeared first on HIPAA Journal.

Healthcare Data Breach Statistics Questioned

Large healthcare providers experience more data breaches than smaller healthcare providers, at least that is what the healthcare data breach statistics from a spring Johns Hopkins University’s Care School of Business report show.

For the study, the researchers used breach reports submitted to the Department of Health and Human Services’ Office for Civil Rights. HIPAA-covered entities are required to submit breach reports to OCR, and under HITECT Act requirements, OCR publishes the breaches that impact more than 500 individuals.

The Ge Bai, PhD., led study, which was published in the journal JAMA Internal Medicine, indicates between 2009 and 2016, 216 hospitals had reported a data breach and 15% of hospitals reported more than one breach. The analysis of the breach reports suggest teaching hospitals are more likely to suffer data breaches – a third of breached hospitals were major teaching centers. The study also suggested larger hospitals were more likely to experience data breaches.

Now, a team of doctors from Vanderbilt University, in Nashville, TN have called the data breach statistics details in the Johns Hopkins study into question, pointing out a number of potential errors could have crept in due to the nature of the data available. Daniel Fabbri, PhD wrote to JAMA Internal Medicine pointing out that the claims made by Bai and his team may not be correct.

“Such a broad claim neglects inherent biases in data collection and reporting practices,” wrote Fabbri in the letter.  He explained that the data set available to the researchers only includes data breaches of 500 or more individuals, not smaller breaches which are not published. Larger hospitals have more patients, and could therefore be more likely to reach the 500-patient threshold for inclusion in the data set.

The researchers also argue, that in order for a breach to be reported, it must first be detected. Larger cybersecurity budgets mean more cybersecurity staff and better technology. Breaches are more likely to be detected by larger hospitals, whereas a breach at a smaller healthcare organization may remain undetected for longer. Regardless of size, hospitals are likely to be able to detect lost or stolen devices, but detecting insider breaches is likely to take much longer for smaller hospitals that lack technology and the resources to conduct internal audits of data access logs.

They also explain that there may be issues with the quality of the data. Just because it is a requirement of HIPAA to report data breaches, that does not necessarily mean that healthcare organizations will.

The Vanderbilt team explain “This nonuniform treatment of breaches based on size, instead of impact, offense, or rate-per-employee biases the results and can negatively impact perceived patient privacy and security risks. Small-scale violations are just as important and can be even more impactful.”

Bai and her team have responded to the letter and have agreed that there are issues with the 500-individual threshold for reporting, but explain that larger hospitals have more PHI and “combined with teaching hospitals’ need for broad data access, this creates significant targets for cyber criminals, compared with smaller institutions that might be the main reason for their relatively high risks of data breaches.”

It stands to reason that large healthcare organizations, with larger volumes of health data are an attractive target for cybercriminals. Large quantities of data mean a big payday for hackers. However, that does not necessarily mean they are targeted by cybercriminals much more than smaller organizations. Fort Knox holds significant gold reserves, but most bank robbers attack easier targets. TheDarkOverlord, a hacking group well known for targeting the healthcare industry, tends to attack smaller healthcare organizations – They are typically easier to attack as they do not have the resources or staff of their larger counterparts to devote to cybersecurity.

What is clear, is that based on the data available, obtaining meaningful healthcare data breach statistics is problematic. As the Vanderbilt researchers explained, it is difficult to conduct meaningful research based on the data set available, especially research that could be used as a basis to change hospital privacy practices.

The post Healthcare Data Breach Statistics Questioned appeared first on HIPAA Journal.

Former Employees of Virginia Medical Practice Inappropriately Used Patient Information

Two former employees of Valley Family Medicine in Staunton, VA have been discovered to have inappropriately used a patient list, in violation of the practice’s policies.

The list was used to inform patients of a new practice that was opening in the area. One of the employees used the list to send postcards to Valley Family Medicine patients to advise them that a new practice, unaffiliated to Valley Family Medicine, was being opened. Patients were invited to visit the new practice.

The mailing was sent in mid-July this year, although it was not discovered by Valley Family Medicine until September 15. The discovery prompted a full investigation of the breach, which confirmed that the only information used by the employees was the information contained on the list. That information was limited to names and addresses. No other protected health information was taken or used by the employees.

Those two individuals are no longer employed at the practice and the list has now been recovered. Valley Family Medicine is satisfied that there have been no further misuses or disclosures of the information, and that no other copies of the list exist.

In compliance with HIPAA Rules, the breach has been reported to appropriate authorities, including the Department of Health and Human Services’ Office for Civil Rights. All 8,450 patients on the list have been sent a breach notification letter explaining the nature of the incident and informed that there should be no further consequences for patients.

The post Former Employees of Virginia Medical Practice Inappropriately Used Patient Information appeared first on HIPAA Journal.

TJ Samson Community Hospital Discovers Inappropriate Accessing of 683 Patients’ PHI

An independent care provider who provides care for patients of TJ Samson Community Hospital in South Central Kentucky, has been discovered to have inappropriately accessed the protected health information (PHI) of 683 patients of TJ Samson Community Hospital in Glasgow, KY and the TJ Health Columbia Clinic.

The inappropriate access was discovered during a routine audit of PHI access logs on August 25, 2017. The subsequent investigation revealed two individuals from the healthcare provider’s office had accessed the protected health information of patients, without any legitimate work reason for doing so.

Access to patients PHI is necessary in order for independent health care providers to conduct their work duties, although in this case, the PHI of patients was accessed even though the patients were not being treated by the individuals.

TJ Samson interviewed both individuals about the alleged unauthorized access and is satisfied that no further uses or disclosures of PHI have occurred.

In response to the incident, TJ Samson has terminated access for the individuals in question. The breach notice posted to the TJ Samson website does not indicate any further action was taken against those individuals, although steps have been taken to prevent similar cases of unauthorized access, which included conducting a review of access procedures for independent health care providers. Individuals whose PHI was viewed have been notified of the breach of their confidential information by mail.

The types of information accessed included names, medical information, demographic information, and in some cases, Social Security numbers and insurance information. The access dated back to January 1, 2017. No financial information was accessed as the individuals’ login credentials did not permit them to access such information.

The post TJ Samson Community Hospital Discovers Inappropriate Accessing of 683 Patients’ PHI appeared first on HIPAA Journal.

Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) Introduced by NY AG

The Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) has been introduced into the legislature in New York by Attorney General Eric T. Schneiderman. The aim of the act is to protect New Yorkers from needless breaches of their personal information and to ensure they are notified when such breaches occur.

The program bill, which was sponsored by Senator David Carlucci (D-Clarkstown) and Assembly member Brian Kavanagh (D-Manhattan), is intended to improve protections for New York residents without placing an unnecessary burden on businesses.

The introduction of the SHIELD Act comes weeks after the announcement of the Equifax data breach which impacted more than 8 million New Yorkers. In 2016, more than 1,300 data breaches were reported to the New York attorney general’s office – a 60% increase in breaches from the previous year.

Attorney General Schneiderman explained that New York’s data security laws are “weak and outdated” and require an urgent update. While federal laws require some organizations to implement data security controls, in New York, there are no obligations for businesses to implement safeguards to secure the personal identifying information of New Yorkers if the data held on residents does not include a Social Security number.

The SHIELD Act will require all businesses, regardless of where they are based, to adopt reasonable administrative, physical, and technical safeguards for if they hold the sensitive data of New Yorkers. The laws will also apply if entities do not do business in the state of New York.

While many states have introduced data breach notification laws that require individuals impacted by breaches of information such as username/password combos and biometric data to be notified of the incidents, in New York, there are no such requirements. The Shield Act will change that and bring state laws in line with many other U.S. states.

Breach notification requirements will be updated to include breaches of username/password combos, biometric data, and protected health information covered by HIPAA laws. Breach notifications will be required if unauthorized individuals are discovered to have gained access to personal information as well as in cases of data theft.

Attorney General Schneiderman is encouraging businesses to go above and beyond the requirements of the SHIRLD Act and receive independent certification of their security controls to make sure they exceed the minimum required standards.

A flexible standard is being introduced for small businesses to ease the regulatory burden. Safeguards can be appropriate to the organization’s size for businesses employing fewer than 50 members of staff if gross revenue is under $3 million or they have less than $5 million in assets.

HIPAA-covered entities, organizations compliant with the Gramm-Leach-Bliley, and NYS DFS regulations will be deemed to already be compliant with the data security requirements of the SHIELD Act.

The failure to comply with the provisions of the SHIELD Act will be deemed to be a violation of General Business Law (GBL § 349) and will allow the state attorney general to bring suit and seek civil penalties under GBL § 350(d).

The post Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) Introduced by NY AG appeared first on HIPAA Journal.

Lawnmower Engine Manufacturer Reports HIPAA Breach

Briggs Stratton Corporation, a manufacturer of lawnmower engines, may not appear to be a HIPAA covered entity since the firm is not in the healthcare industry and does not provide services to healthcare organizations as a business associate. However, the company is required to comply with HIPAA Rules.

When the company experienced a potential breach of employee information, the incident was a reportable security breach, OCR required notification, and notification letters had to be issued to its employees. Just because a company does not operate in the healthcare industry does not mean that HIPAA does not apply.

Briggs Stratton was required to comply with HIPAA Rules due to its self-insured group health plan. Employers and health plan sponsors are required to ensure that HIPAA policies are put in place for their group health plans, that any ePHI created, accessed, stored, or transmitted is safeguarded to the standards required by the HIPAA Security Rule and all HIPAA Rules are followed. That includes entering into business associate agreements with any entity that has access to the ePHI of its employees, is provided with ePHI, or has access to systems containing ePHI.

When there is a breach of that information, the HIPAA Breach Notification Rule applies. In the case of Briggs Stratton, the breach was a hacking/IT incident resulting a potential unauthorized disclosure of ePHI. Malware was discovered on its systems which potentially gave unauthorized individuals access to the system where ePHI was stored. Access to the system was possible between July 25 and July 28, 2017. Briggs Stratton became aware of the incident on July 25, and took steps to contain the attack. Notifications were delayed until September 30, 2017 due to a law enforcement investigation into the malware attack.

The breach impacted 12,789 of its employees and potentially resulted in the exposure of names, addresses, dates of birth, driver’s license numbers, Social Security numbers, health plan IDs, insurance information, passport numbers, work-related evaluations, and login details to its work systems. No evidence of misuse of any health plan data has been uncovered, although employees impacted by the breach have been offered credit monitoring and identity theft protection services for 12 months without charge. Steps have also been taken to improve security to prevent similar incidents from occurring in the future.

The incident serves as a reminder that not all HIPAA covered entities fall under the standard classification of healthcare providers, health plans or business associates, and even firms not involved in healthcare may still be required to comply with HIPAA Rules and can face penalties for non-compliance with HIPAA Rules.

In the case of Briggs Stratton, the firm was well aware of its responsibilities, had implemented a HIPAA compliance program, and acted accordingly when a potential data breach occurred.

The post Lawnmower Engine Manufacturer Reports HIPAA Breach appeared first on HIPAA Journal.

Tips for Reducing Mobile Device Security Risks

An essential part of HIPAA compliance is reducing mobile device security risks to a reasonable and acceptable level.

As healthcare organizations turn to mobiles devices such as laptop computers, mobile phones, and tablets to improve efficiency and productivity, many are introducing risks that could all too easily result in a data breach and the exposure of protected health information (PHI).

As the breach reports submitted to the HHS’ Office for Civil Rights show, mobile devices are commonly involved in data breaches. Between January 2015 and the end of October 2017, 71 breaches have been reported to OCR that have involved mobile devices such as laptops, smartphones, tablets, and portable storage devices. Those breaches have resulted in the exposure of 1,303,760 patients and plan member records.

17 of those breaches have resulted in the exposure of more than 10,000 records, with the largest breach exposing 697,800 records. The majority of those breaches could have easily been avoided.
The Health Insurance Portability and Accountability Act (HIPAA) Security Rule does not demand encryption for mobile devices, yet such a security measure could have prevented a high percentage of the 71 data breaches reported to OCR.

When a mobile device containing ePHI is lost or stolen, the HIPAA Breach Notification Rule requires the breach to be reported and notifications to be sent to affected individuals. If PHI has been encrypted and a device containing ePHI is lost or stolen, notifications need not be sent as it would not be a HIPAA data breach. A breach report and patient notifications are only required for breaches of unencrypted PHI, unless the key to decrypt data is also obtained.

Even though HIPAA does not demand the use of encryption, it must be considered. If the decision is taken not to encrypt data, the decision must be documented and an alternative safeguard – or safeguards – must be employed to ensure the confidentiality, integrity, and availability of ePHI. That alternative safeguard(s) must provide a level of protection equivalent to encryption.

Before the decision about whether or not to encrypt data can be made, HIPAA covered entities must conduct an organization-wide risk analysis, which must include all mobile devices. All risks associated with the use of mobile devices must be assessed and mitigated – see 45 C.F.R. § 164.308(a)(1)(ii)(A)–(B).

OCR Reminds Covered Entities of Need to Address Risks Associated with Mobile Devices

In its October 2017 Cybersecurity Newsletter, OCR reminded covered entities of the risks associated with mobile devices that are used to create, receive, maintain, or transmit ePHI. HIPAA covered entities were reminded of the need to conduct an organization-wide risk assessment and develop a risk management plan to address all mobile device security risks identified during the risk analysis and reduce them to an appropriate and acceptable level.

While many covered entities allow the use of mobile devices, some prohibit the use of those devices to create, receive, maintain, or transmit ePHI. OCR reminds covered entities that if such a policy exists, it must be communicated to all staff and the policy must be enforced.

When mobile devices can be used to create, receive, maintain, or transmit ePHI, appropriate safeguards must be implemented to reduce risks to an appropriate and acceptable level. While loss or theft of mobile devices is an obvious risk, OCR draws attention to other risks associated with the devices, such as using them to access or send ePHI over unsecured Wi-Fi networks, viewing ePHI stored in the cloud, or accessing or sharing ePHI via file sharing services.

OCR also remined covered entities to ensure default settings on the devices are changed and how healthcare employees must be informed of mobile device security risks, taught best practices, and the correct way to uses the device to access, store, and transmit ePHI.

OCR offers the following advice to covered entities address mobile security risks and keep ePHI secure at all times.

To access OCR’s guidance – Click here.

OCR’s Tips for Reducing Mobile Device Security Risks

  • Implement policies and procedures regarding the use of mobile devices in the work place – especially when used to create, receive, maintain, or transmit ePHI.
  • Consider using Mobile Device Management (MDM) software to manage and secure mobile devices.
  • Install or enable automatic lock/logoff functionality.
  • Require authentication to use or unlock mobile devices.
  • Regularly install security patches and updates.
  • Install or enable encryption, anti-virus/anti-malware software, and remote wipe capabilities.
  • Use a privacy screen to prevent people close by from reading information on your screen.
  • Use only secure Wi-Fi connections.
  • Use a secure Virtual Private Network (VPN).
  • Reduce risks posed by third-party apps by prohibiting the downloading of third-party apps, using whitelisting to allow installation of only approved apps, securely separating ePHI from apps, and verifying that apps only have the minimum necessary permissions required.
  • Securely delete all PHI stored on a mobile device before discarding or reusing the mobile device.
  • Include training on how to securely use mobile devices in workforce training programs.

Penalties for Failing to Address Mobile Security Risks

The failure to address mobile device security risks could result in a data breach and a penalty for noncompliance with HIPAA Rules. Over the past few years there have been several settlements reached between OCR and HIPAA covered entities for the failure to address mobile device security risks.

These include:

Covered Entity HIPAA Violation Individuals Impacted Penalty
Children’s Medical Center of Dallas Theft of unencrypted devices 6,262 $3.2 million
Oregon Health & Science University Loss of unencrypted laptop / Storage on cloud server without BAA 4,361 $2,700,000
Cardionet Theft of an unencrypted laptop computer 1,391 $2.5 million
Catholic Health Care Services of the Archdiocese of Philadelphia Theft of mobile device 412 $650,000

Addressing Mobile Device Security Risks

Mobile device security risks must be reduced to a reasonable and appropriate level.  Some of the mobile device security risks, together with mitigations, have been summarized in the infographic below. (Click image to enlarge)

mobile device security risks

The post Tips for Reducing Mobile Device Security Risks appeared first on HIPAA Journal.

8,000 Patients Notified of PHI Exposure After Office Burglary

A limited amount of protected health information (PHI) of almost 8,000 patients of Brevard Physician Associates has been exposed after a desktop computer was stolen in a burglary.

The incident occurred on September 4, 2017 – Labor Day – when the offices were closed. In the early morning, thieves broke in and stole three desktop computers.

The burglary triggered the alarm system and police responded to the incident, although not in time to apprehend the criminals. A forensic analysis of the office was performed, although to date the individuals responsible have not been apprehended and the computers not recovered.

Two of the computers did not contain any protected health information, but the third computer had five audit files saved to the hard drive. The information in those audit files was limited, although there was sufficient information to warrant the issuing of breach notifications to patients.

Brevard Physician Associates acted quickly and dispatched breach notification letters to affected patients well within the timeframe allowed by the HIPAA Breach Notification Rule. In total, 7,976 patients were potentially impacted and had the following information exposed: Names, names of insurance providers, CPT codes for the services provided, and the amounts charged for services.

The HIPAA Security Rule does not demand the use of encryption, although if the decision is taken not to encrypt data, an alternative, equivalent control must be employed to safeguard the confidentiality, integrity, and availability of PHI. While the computers were not encrypted, they were protected with passwords and strong passwords had been used. Brevard Physician Associates also reports that the devices can be remotely wiped of all data, and that safeguard has been triggered. If the devices are connected to the Internet, data will be remotely wiped.

Brevard Physician Associates believes the risk – and future risk – of identity theft and fraud as a result of the incident is minimal. Even though addresses, dates of birth, telephone numbers, Social Security numbers, financial information and insurance ID numbers were not exposed and could not be accessed by the thieves, the decision has been taken to offer all affected patients 12 months of complimentary credit monitoring services.

Brevard Physician Associates should be commended for its rapid breach response, prompt issuing of notifications, and for the steps taken to mitigate risk.

The post 8,000 Patients Notified of PHI Exposure After Office Burglary appeared first on HIPAA Journal.

932 Texas Children’s Health Plan Members’ PHI Emailed to Personal Account by Employee

The protected health information (PHI) of 932 members of the Texas Children’s Health Plan has been discovered to have been emailed to the personal email account of a former employee.

The incident was discovered on September 21, 2017, although the former employee emailed the data late last year in November and December 2016. The emails were discovered during a routine review.

Texas Children’s Health Plan responded to the breach promptly and has taken action to mitigate risk. The health insurance plan has also implemented additional safeguards to prevent similar incidents from occurring in the future and employees have been re-trained on hospital policies and HIPAA Rules.

While the reason for the PHI being emailed to the personal email account has not been disclosed, the breach report uploaded to the insurance plan website explains no evidence has been uncovered to suggest any plan member information has been used inappropriately. However, the incident has been reported to law enforcement.

As is required by the HIPAA Breach Notification Rule, the incident has been reported to the Department of Health and Human Services’ Office for Civil Rights and all patients impacted by the incident have been notified by mail. Breach notification letters were dispatched to patients on Friday, October 27, well inside the maximum deadline allowed by the HIPAA Breach Notification Rule.

The types of data included in the emails varied for each patient, but typically included: Names, telephone numbers, addresses, dates of birth, Medicaid numbers, waiver type, STAR kids manager’s name and group, and information detailed in a budget worksheet. No financial information nor Social Security numbers were included in the emails, although for a small number of patients, the following information was also included: Medical record numbers, medical diagnoses, and clinical information.

This type of incident is relatively common. Several HIPAA-covered entities have discovered similar incidents in recent months. Oftentimes, PHI is taken to provide to a new employer to recruit patients to a new practice and some cases have seen PHI emailed to friends and relatives for assistance with data processing tasks. Some healthcare employees have stolen data with a view to committing identity theft and fraud.

HIPAA-covered entities should be monitoring for PHI theft via email. Ideally, restrictions should be put in place to prevent PHI from being emailed outside the organization.

The post 932 Texas Children’s Health Plan Members’ PHI Emailed to Personal Account by Employee appeared first on HIPAA Journal.