HIPAA Breach News

8,362 Patients Potentially Impacted by Advanced Spine & Pain Center Breach

The San Antonio, TX, Advanced Spine & Pain Center (ASPC) has notified patients of a potential breach and unauthorized use of their protected health information. Potentially, as many as 8,362 patients have been affected by the incident.

ASPC became aware of a potential breach of ePHI on July 31, 2017 when some patients reported receiving a telephone call claiming payment for an outstanding bill was required. An investigation was launched to determine whether ASPC systems had been breached.

That investigation revealed unauthorized individuals had gained access to an ASPC server. Unauthorized access occurred even though extensive protections had been put in place, including firewalls, network filtering, security monitoring, password protection, and antivirus software.

While unauthorized access was confirmed, it was unclear whether any sensitive information was accessed by those individuals. It was also not possible to determine whether the telephone calls received by some patients were linked to the security breach.

Since it is possible that patients’ ePHI was viewed or obtained by unauthorized individuals, ASPC has offered all affected patients identity theft protection services and coverage with a $1,000,000 insurance reimbursement policy. A full network scan has been conducted and steps have been taken to ensure the network is secured. Recent monitoring of the network has not uncovered any evidence of continued unauthorized access, and the breach is believed to have been contained.

An analysis of the compromised server has shown the following PHI may have been viewed: Names, addresses, telephone numbers, state and zip codes, Social Security numbers, birth dates, medical records, x-ray images and lab test results, scheduling notes, billing information, insurance information, CPT codes, ID numbers, group numbers, and patients’ gender. No payment information or credit/debit cards were compromised.

The incident has been reported to law enforcement and the Department of Health and Human Services’ Office for Civil Rights has been notified.

The post 8,362 Patients Potentially Impacted by Advanced Spine & Pain Center Breach appeared first on HIPAA Journal.

Q3, 2017 Healthcare Data Breach Report

In Q3, 2017, there were 99 breaches of more than 500 records reported to the Department of Health and Human Services’ Office for Civil Rights (OCR), bringing the total number of data breaches reported in 2017 up to 272 incidents. The 99 data breaches in Q3, 2017 resulted in the theft/exposure of 1,767,717 individuals’s PHI. Up until the end of September, the records of 4,601,097 Americans have been exposed or stolen as a result of healthcare data breaches.

Q3 Data Breaches by Covered Entity

Healthcare providers were the worst hit in Q3, reporting a total of 76 PHI breaches. Health plans reported 17 breaches and there were 6 data breaches experienced by business associates of covered entities.

There were 31 data breaches reported in July, 29 in August, and 39 in September. While September was the worst month for data breaches, August saw the most records exposed – 695,228.

The Ten Largest Healthcare Data Breaches in Q3, 2017

The ten largest healthcare data breaches reported to OCR in Q3, 2017 were all the result of hacking/IT incidents. In fact, 36 out of the 50 largest healthcare data breaches in Q3 were attributed to hacking/IT incidents.

Covered Entity Entity Type Number of Records Breached

Type of Breach

Women’s Health Care Group of PA, LLC Healthcare Provider 300,000 Hacking/IT Incident
Pacific Alliance Medical Center Healthcare Provider 266,123 Hacking/IT Incident
Peachtree Neurological Clinic, P.C. Healthcare Provider 176,295 Hacking/IT Incident
Arkansas Oral & Facial Surgery Center Healthcare Provider 128,000 Hacking/IT Incident
McLaren Medical Group, Mid-Michigan Physicians Imaging Center Healthcare Provider 106,008 Hacking/IT Incident
Salina Family Healthcare Center Healthcare Provider 77,337 Hacking/IT Incident
Morehead Memorial Hospital Healthcare Provider 66,000 Hacking/IT Incident
Network Health Health Plan 51,232 Hacking/IT Incident
St. Mark’s Surgical Center, LLC Healthcare Provider 33,877 Hacking/IT Incident
Sport and Spine Rehab Healthcare Provider 31,120 Hacking/IT Incident

Main Cause of Healthcare Data Breaches in Q3, 2017

For much of 2017, the main cause of healthcare data breaches was unauthorized disclosures by insiders, although in Q3, 2017, hacking was the biggest cause of healthcare data breaches. These incidents involve phishing attacks, malware and ransomware incidents, and the hacking of network servers and endpoints. These hacking incidents involved the exposure/theft of considerably more data than all of the other breach types combined. In Q3, 1,767,717 healthcare records were exposed/stolen, of which 1,578,666 – 89.3% – were exposed/stolen in hacking/IT incidents.

Location of Breached PHI

If vulnerabilities exist, it is only a matter of time before they will be discovered by hackers. It is therefore essential for HIPAA covered entities and their business associates conduct regular risk assessments to determine whether any vulnerabilities exist. Weekly checks should also be conducted to make sure the latest versions of operating systems and software are installed and no patches have been missed. Misconfigured servers, unsecured databases, and the failure to apply patches promptly resulted in 31 data breaches in Q3, 2017.

In Q3, 34 incidents were reported that involved email. While some of those incidents involved misdirected emails and the deliberate emailing of ePHI to personal email accounts, the majority of those breaches saw login details disclosed or ransomware/malware installed as a result of employees responding to phishing emails.  The high number of phishing attacks reported in Q3 shows just how important it is to train employees how to recognize phishing emails and how to report suspicious messages. Training should be an ongoing process, involving classroom-based training, CBT sessions, and phishing simulations, with email updates sent to alert employees to specific threats.

The post Q3, 2017 Healthcare Data Breach Report appeared first on HIPAA Journal.

Bill Introduced to Standardize State Data Breach Notification Laws

The HIPAA Breach Notification Rule explains how HIPAA covered entities and their business associates’ data breach response should include issuing notifications to patients, plan members and the HHS’ Office for Civil Rights. Healthcare organizations must also comply with state data breach notification laws, which in some U.S. states, requires notifications to be issued more rapidly. Those laws cover different types of information, have additional notification requirements, and in some states, require credit monitoring and identity theft protection services to be offered to breach victims.

Currently, there are 48 separate state data breach notification laws. For a small health system operating in one or two states, keeping up to date with relevant state data breach notification laws is straightforward. For large health systems and health plans that operate in multiple states, keeping up to date with changes to state laws, and ensuring compliance with those laws, can be a challenge.

Bill Proposes Standardization of State Data Breach Notification Laws

Congressman Jim Langevin (D-RI) has recently re-proposed a bill (H.R. 3806) – The Personal Data Breach Notification Act – that will standardize data breach protection laws and will ensure all consumers are notified of breaches promptly, regardless of where they live.

Rather than have separate state data breach notification laws, the Personal Data Breach Notification Act will introduce a national data breach notification standard that must be followed by all states. The Personal Data Breach Notification Act would apply to all organizations or entities that collect the data of more than 10,000 individuals over a 12-month period and the provisions of the Personal Data Breach Notification Act will supersede any provision of the law of any State.

Not only will the bill make it easier for businesses to understand what they are required to do following a data breach, Langevin explains it will “strengthen companies’ obligations to report intrusions that compromise consumers’ personal information.”

30 Day Time Limit for Issuing Breach Notifications

Currently, state data breach notification laws require notifications to be issued to consumers as soon as possible following the discovery of a breach, although the maximum timescale for issuing those notifications differs from state to state, and the speed of notification also depends on which entity experienced the breach.

The Personal Data Breach Notification Act will standardize notifications and will ensure consumers are informed of a breach of their personal information faster. The proposed maximum time limit to issue notifications is 30 days from the discovery of the breach, although the bill states there should be no unreasonable delay in issuing notifications.

Additional time may be granted to breached entities in certain circumstances, although a request for an extension would have to be made to the Federal Trade Commission, which would be responsible for enforcing the Personal Data Breach Notification Act.

As with HIPAA breach notifications, a request could be made by law enforcement to delay the issuing of notifications so as not to impede with an investigation. In such cases, the Director of the United States Secret Service or the Director of the Federal Bureau of Investigation would be permitted to authorize a delay of up to 30 days – meaning a maximum time frame of 60 days from the discovery of a breach.

Data Elements Covered by the Personal Data Breach Notification Act

The definition of a breach is defined as “a compromise of the security, confidentiality, or integrity of, or the loss of, computerized data that results in, or there is a reasonable basis to conclude has resulted in: i) the unauthorized acquisition of sensitive personally identifiable information; or (ii) access to sensitive personally identifiable information that is for an unauthorized purpose, or in excess of authorization.”

The exposure of the following information would require breach notifications to be issued.

Currently, state data breach laws require the breached entity to issue a notification to state attorneys general of any breach of personal information. If the Personal Data Breach Notification Act is passed, a government agency would be required to be designated to receive the breach notification reports.

Notifications could be made by mail, telephone, or email, with the latter only permissible if individuals consent to receiving electronic notifications.

As with HIPAA, a media notice must also be issued, although rather than the threshold being 500 individuals, the Personal Data Breach Notification Act would only require a media notice to be issued if the breach impacts 5,000 or more individuals.

The failure to comply with the Personal Data Breach Notification Act could result in financial penalties. The FTC would be able to issue financial penalties with the penalty structure the same as for Federal Trade Commission Act violations. State attorneys general would also be permitted to enforce compliance and take action against entities that breach the Personal Data Breach Notification Act.

The post Bill Introduced to Standardize State Data Breach Notification Laws appeared first on HIPAA Journal.

How Should You Respond to an Accidental HIPAA Violation?

The majority of HIPAA-covered entities, business associates, and healthcare employees take great care to ensure HIPAA Rules are followed, but what happens when there is accidental HIPAA

The majority of HIPAA-covered entities, business associates, and healthcare employees take great care to ensure HIPAA Rules are followed, but what happens when there is an accidental HIPAA violation? How should healthcare employees, covered entities, and business associates respond?

How Should Employees Report an Accidental HIPAA Violation?

Accidents happen. If a healthcare employee accidentally views the records of a patient, if a fax is sent to an incorrect recipient, if an email containing PHI is sent to the wrong person, or if any other accidental disclosure of PHI has occurred, it is essential that the incident is reported to your Privacy Officer.

The first thing a Privacy Officer should determine is whether the accidental HIPAA violation is indeed a HIPAA violation or a violation of the organization´s policies. For example, forgetting to document a patient´s agreement to be included in a hospital directory is not a violation of HIPAA but could be a violation of the hospital´s policies.

If the accidental violation is indeed a violation of HIPAA, the Privacy Office will need to determine whether or not the violation constitutes an impermissible use or disclosure which qualifies as a data breach.

If so, the Privacy Officer will need to determine what actions need to be taken to mitigate risk and reduce the potential for harm. The incident will need to be investigated, a HIPAA risk assessment may need to be performed, and a report of the breach may need to be sent to the Department of Health and Human Services’ Office for Civil Rights (OCR).

You should explain that a mistake was made and what has happened. You will need to explain which patient’s records were viewed or disclosed. The failure to report such a breach promptly can turn a simple error into a major incident, one that could result in disciplinary action and potentially, penalties for your employer.

How Should Covered Entities Respond to an Accidental HIPAA Violation?

Any accidental HIPAA violation that may qualify as a data breach must be treated seriously and warrants a risk assessment to determine the probability of PHI having been compromised, the level of risk to individuals whose PHI has potentially been compromised, and the risk of further disclosures of PHI.

The risk assessment should determine:

  • The nature of the breach
  • The person who viewed or acquired PHI
  • The types of information involved
  • The patients potentially impacted
  • To whom information has been disclosed
  • The potential for re-disclosure of information
  • Whether PHI was actually acquired or viewed
  • The extent to which risk has been mitigated

Following the risk assessment, risk must be managed and reduced to an appropriate and acceptable level. The HIPAA Breach Notification Rule (45 CFR §§ 164.400-414) also requires notifications to be issued. Not all breaches of PHI are reportable. There are three exceptions when there has been an accidental HIPAA violation.

1) An unintentional acquisition, access, or use of PHI by a workforce member or person acting under the authority of a covered entity or business associate, if such acquisition, access, or use was made in good faith and within the scope of authority. 

Example: A fax or email is sent to a member of staff in error. The information is accessed and viewed, but the mistake is realized and the fax is securely destroyed or the email is deleted and no further disclosure is made.

2) An inadvertent disclosure of PHI by a person authorized to access PHI at a covered entity or business associate to another person authorized to access PHI at the covered entity or business associate, or organized health care arrangement in which the covered entity participates.

Example: Providing the medical information of a patient to another individual authorized to receive it, but a mistake is made and the information of a different patient is disclosed.

3) If the covered entity or business associate has a good faith belief that the unauthorized person to whom the impermissible disclosure was made, would not have been able to retain the information.

Example: A physician gives X-ray films or a medical chart to a person not authorized to view the information but realizes that a mistake has been made and retrieves the information before it is likely that any PHI has been read and information retained.

In each case, while breach notifications are not required, any member of staff that finds themselves in one of the above situations should still report the incident to their Privacy Officer.

In all other cases when there has been a breach of unsecured PHI, the incident must be reported to OCR, and individuals impacted by the breach should be notified within 60 days of the discovery of the breach. HIPAA breach reporting requirements have been summarized here.

Examples of Unintentional HIPAA Violations

Lost or stolen USB flash drives could be considered by some to be examples of unintentional HIPAA violations as nobody intended for the USB flash drives to be lost or stolen. However, the loss or theft could have been reasonably foreseen and potential breaches of ePHI avoided by encryption. The following examples of unintentional HIPAA violations were less foreseeable.

In 2022, an investigation was conducted by The Markup into the use of third-party tracking technologies on hospital websites, namely a code snippet provided by Meta Platforms called Meta Pixel. The code snippet is used for tracking visitor activity on websites and provides insights into how the website users are accessing the sites. The data provided can be used to improve the website, services, and user experience. The analysis was conducted on the top 100 hospitals in the United States, and one-third were found to have used the code on their websites. The problem? The code was transmitting individually identifiable information to Meta, which could potentially be used to serve Facebook users with targeted advertisements related to their health conditions. No business associates were in place, no patient authorizations were obtained, and those disclosures were therefore impermissible under HIPAA. The code acted as it should. The problem was where it was added and how it was configured. Several hospitals and health systems accidentally violated HIPAA as a result, including Novant Health, WakeMed Health and Hospitals, and Advocate Aurora Health. Millions of patients of these and other healthcare providers have been affected.

In May 2017, Olivia O’Leary – a twenty-four-year-old medical technician – claims to have been dismissed from her job at the Onslow Memorial Hospital in Jacksonville, NC, after commenting on a Facebook post. Her warning that the victim of an auto accident should have worn a seat belt was not seen by her employer as a reminder to always wear a seatbelt – O´Leary alleges – but rather as a HIPAA violation.

In April 2016, the Raleigh Orthopedic Clinic in North Carolina was fined $750,000 for contracting an outside vendor to convert X-ray films to digital form and then allowing the vendor to harvest the silver from the films. The clinic´s error was not having a Business Associate Agreement in place; and, as well as the fine, the clinic had to implement a Corrective Action Plan overseen by OCR.

The Dallas, TX-based dental practice Elite Dental Associates responded to a post by a patient on the Yelp review website. The patient who posted on the site had identified herself as a patient of the practice, but when the practice responded, information was included in the post that revealed her health condition, treatment plan, insurance, and payment information. In October 2019 the practice was fined $10,000 for the HIPAA violation.

If an intern requires access to systems containing protected health information and a colleague allows their own credentials to be used, the intern can get the information they need to complete their work tasks. However, the sharing of login credentials is not permitted by HIPAA as it makes it impossible to track information system activity accurately. The sharing of login credentials contributed to a $202,400 financial penalty for the City of New Haven in Connecticut.

The HIPAA Right of Access provision of the HIPAA Privacy Rule gives patients the right to obtain a copy of their health information. There is an exception to this right concerning psychotherapy notes, which should not be provided. Riverside Psychiatric Medical Group received such a request from a patient and did not provide a copy of the requested records. Not providing psychotherapy notes doesn’t violate HIPAA but failing to respond to the request and notify the patient why the records are not being provided does. In such cases, records can be provided minus the psychotherapy notes. In November 2020, OCR fined the practice $25,000.

In a further example of an unintentional HIPAA violation listed on the OCR’s website, the staff was required to undergo HIPAA training when one member of staff discussed HIV testing procedures with a patient in a waiting room – disclosing the patient´s PHI to other patients in the waiting room. After the OCR investigation, computer monitors were also repositioned to prevent the accidental disclosure of PHI.

How Should Business Associates Respond to an Accidental HIPAA Violation?

The correct response to an accidental HIPAA violation should be detailed in your business associate agreement. The HIPAA Rules require all accidental HIPAA violations and security incidents that result in data breaches to be reported to the covered entity within 60 days of discovery, although the covered entity should be notified as soon as possible and notification should not be unnecessarily delayed. Business associates should provide their covered entity with as many details of the accidental HIPAA violation or breach as possible to allow the covered entity to make a determination on the best course of action to take.

HIPAA Compliance Infographics

Accidental HIPAA Violations: FAQs

Can I get fired for an accidental HIPAA violation?

Although it sounds unlikely that a member of the workforce is fired for an accidental HIPAA violation, this will depend on the nature of the violation, its consequences, and the content of your employer´s sanctions policy. It may also be the case that you have a history of accidental HIPAA violations and have received prior warnings about what might happen when you next violate HIPAA.

What happens if you accidentally violate HIPAA and nobody notices?

If you accidentally violate HIPAA, and nobody notices, it is still in your best interest to report it. Not only will your report indicate your willingness to be a compliant employee, but the circumstances that led to the accidental violation may have been overlooked in a risk assessment. Your report could help your employer fill a gap in their compliance efforts which – if left unfilled – may lead to further accidental violations with more serious consequences.

What happens if someone accidentally, or unknowingly, violates the Privacy Rule?

These are really two different questions. If somebody accidentally violates the Privacy Rule, it is better for them to admit the error so potential consequences can be preempted (i.e., a complaint to HHS´ Office for Civil Rights). If somebody unknowingly violates the Privacy Rule, how do they know they have violated it unless a colleague or supervisor tells them? If the person finds out later they have accidentally violated the Privacy Rule, the previous answer applies.

Why would a report of an accidental HIPAA violation need to be sent to OCR?

A report of an accidental HIPAA violation only needs to be sent to the Department of Health and Human Services´ Office for Civil Rights (OCR) if it results in the unauthorized disclosure of unsecured PHI – for example, an email containing PHI being sent to the wrong patient. An accidental violation of HIPAA that does not result in a data breach does not have to be reported to OCR.

What is an example of an accidental violation of HIPAA that does not need reporting?

Patients must be given the opportunity to object to their religious affiliation being disclosed to members of the clergy. If a patient is not given the opportunity to object, it is a violation of HIPAA. However, if the patient´s religious affiliation is not disclosed to a member of the clergy, no data breach of unsecured PHI has occurred, and it is not necessary to report the violation to OCR.

What is the difference between an accidental disclosure and an incidental disclosure?

An accidental disclosure of PHI is an unintended disclosure – such as sending an email containing PHI to the wrong patient. An incidental disclosure is a by-product of a permissible disclosure – such as a hospital visitor overhearing a discussion about a patient´s healthcare. An incidental disclosure is not considered to be a violation of HIPAA by OCR if the disclosure could not reasonably be prevented if it was limited in nature, and if it occurs as a result of a disclosure permitted by the Privacy Rule.

What is the “burden of proof” in the Breach Notification Rule?

Prior to the Final Omnibus Rule in 2013, OCR had to prove a data breach resulted in a “significant risk of financial, reputational or other harm for the individual” before taking enforcement action. Since 2013, the burden of proof has shifted to Covered Entities and Business Associates – who can only refrain from reporting a breach if it can be proven there is a low probability PHI has been compromised in the breach (like the three exceptions to accidental HIPAA violations above).

Can OCR issue financial penalties to Business Associates for accidental HIPAA violations?

In May 2019, OCR issued a notice clarifying the circumstances in which a Business Associate is considered to be directly liable for a HIPAA violation; and, although it is hard to conceive how a HIPAA violation by a Business Associate might be accidental in these circumstances, the potential exists for Business Associates to be issued a financial penalty or required to comply with a corrective action plan.

The post How Should You Respond to an Accidental HIPAA Violation? appeared first on HIPAA Journal.

PHI of 10,500 Patients of an Illinois Psychiatrist Exposed

The medical files of more than 10,000 patients of a Naperville, IL-based psychiatrist – Dr. Riaz Baber, M.D. – have been discovered in the basement of an Aurora property by the woman who rented the house from the psychiatrist. The files had been stored in the basement for at least 4 years.

The tenant, Barbara Jarvis-Neavins, was allegedly provided with a key to the basement by the psychiatrist’s wife as access was required when workmen had to visit the property. She was told that she was required to accompany workmen when they needed access.

Jarvis-Neavins said she wanted to report the presence of the files – and that she could access the storage area – but thought that by doing so she would be asked to vacate the property. When she was told that she had to move out as the house was being sold, she contacted law enforcement – including the FBI – and state regulators to report the unsecured files. The FBI referred her to the Department of Health and Human Services’ Office for Civil Rights and she filed a complaint. She also contacted NBC 5.

NBC 5 reporters followed up on the tip off and covered the story in March, 2017. She told reporters boxes of files were stored in the basement and that the files “has [patients] name, their address, their birthdate, their social security number, what’s wrong with them, what they’re being treated for, and what medication.”

NBC 5 reporters visited the property and contacted Dr. Baber. His attorney responded and issued a statement confirming the tenant should not have had access to the basement, that a key was never provided, and that the records were secured and the doors to the basement were locked. The files were allegedly removed from the property the day after NBC 5 contacted Dr. Baber.

On September 28, 2017, the Office for Civil Rights was informed of the breach of 10,500 records of Dr. Riaz Baber. It is unclear why it took 6 months for the breach to be reported, when HIPAA Rules require a breach report to be submitted within 60 days of discovery.

Covered entities and their business associates that decide to store physical records such as physicians’ notes, charts, x-ray films, or documents off site must implement administrative, technical, and physical controls to ensure the confidentiality, integrity, and availability of patients’ protected health information (PHI). Access to the facility must also be restricted to prevent unauthorized individuals from accessing PHI. In this case, some of the files were accessed by Jarvis-Neavins and the reporters, although no harm appears to have been caused to patients.

The post PHI of 10,500 Patients of an Illinois Psychiatrist Exposed appeared first on HIPAA Journal.

47GB of Medical Records and Test Results Found in Unsecured Amazon S3 Bucket

Researchers at Kromtech Security have identified another unsecured Amazon S3 bucket used by a HIPAA-covered entity. The unsecured Amazon S3 bucket contained 47.5GB of medical data relating to an estimated 150,000 patients.

The medical data in the files included blood test results, physician’s names, case management notes, and the personal information of patients, including their names, addresses, and contact telephone numbers. The researchers said many of the stored documents were PDF files, containing information on multiple patients that were having weekly blood tests performed.

In total, approximately 316,000 PDF files were freely accessible. The tests had been performed in patient’s homes, as requested by physicians, by Patient Home Monitoring Corporation. Kromtech researchers said the data could be accessed without a password. Anyone with an Internet connection, that knew where to look, could have accessed all 316,000 files. Whether any unauthorized individuals viewed or downloaded the files is not known. The researchers were also unable to tell how long the Amazon S3 bucket had remained unsecured.

The unsecured Amazon S3 bucket was found by Kromtech researchers on September 29. It took some time to identify the company concerned and find contact details. They were located on October 5 and a notification was sent. While no response was forthcoming, by the following day, all data were secured and files could no longer be accessed online without authentication.

The cloud offers healthcare organizations cost effective and convenient data storage. Provided HIPAA-compliant cloud platforms are used and a business associate agreement is obtained prior to the cloud being used to store ePHI, HIPAA permits use of the cloud. However, having a BAA does not guarantee HIPAA compliance. The actions of users can still result in HIPAA violations and the exposure of sensitive data.

The failure to implement controls to prevent cloud-stored data from being accessed by unauthorized individuals is an easy mistake to make, but one that can have serious consequences, not only for the patients whose PHI has been exposed, but also for the covered entity or business associate.

The failure to implement safeguards to ensure the confidentiality, integrity, and availability of ePHI can result in severe financial penalties from OCR and state attorneys general. A data breach can also result in lawsuits from patients seeking damages to cover the lifelong risk of harm from the exposure of their PHI.

Mistakes are inevitable, and oftentimes those mistakes will result in PHI being exposed, but in the case of unsecured Amazon S3 buckets, it is also easy to check for configuration errors. Kromtech, for example, offers a free software tool – S3 Inspector – that can be used by healthcare organizations to check whether their AWS S3 bucket permissions have been configured correctly to prevent access by the public.

The post 47GB of Medical Records and Test Results Found in Unsecured Amazon S3 Bucket appeared first on HIPAA Journal.

Summary of September 2017 Healthcare Data Breaches

There were 35 healthcare data breaches involving more than 500 records reported to the Department of Health and Human Services’ Office for Civil Rights in September 2017. Those breaches resulting in the theft/exposure of 435,202 patients’ protected health information.

September 2017 Healthcare Data Breaches

September 2017 healthcare data breaches followed a similar pattern to previous months. Healthcare providers suffered the most breaches with 25 reported incidents, followed by health plans with 8 breaches, and 2 breaches reported by business associates of covered entities.

There was a fairly even split between unauthorized access/disclosures (16 incidents) and hacking/IT incidents (15 incidents). There were three theft incidents and one lost device, all of which involved laptop computers. One incident also involved a desktop computer and another the theft of physical records. There were no reported cases of improper disposal of PHI.

 

September 2017 Healthcare Data Breaches - Breach Type

There were five attacks on network servers in September, but email attacks topped the list with 13 incidents. 6 were attributed to hacking, including two confirmed phishing attacks and one ransomware incident. The ransomware attack is also understood to have occurred as a result of an employee responding to a phishing email.

There were 7 cases of unauthorized access/disclosures via email. One of those incidents involved an employee emailing PHI to a personal email account. Another saw a healthcare employee email PHI to a relative to receive assistance with a work-related action.

September 2017 Healthcare Data Breaches - Breach Location

 

Healthcare organizations in 24 states reported data breaches in September. The worst affected states were California, Florida and Texas, with three breaches each. Arkansas, Minnesota, North Carolina, Pennsylvania, Washington and Wisconsin each had two reported incidents.

Largest Healthcare Data Breaches in September 2017

The largest healthcare data breaches in September 2017 have been detailed in the table below. Six of the top ten breaches in September were the result of hacking/IT incidents. Hacking/IT incidents resulted in the exposure of 355,084 records – 81.6% of the records exposed in all reported breaches in September. Unauthorized access/disclosures resulted in the exposure of 73,409 records – 16.87% of the total.

The largest reported data breach in September was a ransomware attack that potentially affected 128,000 patients. Data theft was not suspected, although it could not be ruled out with a high degree of certainty.

Covered Entity Entity Type Breached Records Breach Type Breach Information
Arkansas Oral & Facial Surgery Center Healthcare Provider 128,000 Hacking/IT Incident Ransomware attack
Morehead Memorial Hospital Healthcare Provider 66,000 Hacking/IT Incident Phishing attack
Network Health Health Plan 51,232 Hacking/IT Incident Phishing attack
ABB, Inc. Healthcare Provider 28,012 Hacking/IT Incident
Arkansas Department of Human Services Health Plan 26,000 Unauthorized Access/Disclosure Employee emailed PHI to a personal account
CBS Consolidated, Inc. Business Associate 21,856 Hacking/IT Incident Server hacked
MetroPlus Health Plan, Inc. Health Plan 15,212 Unauthorized Access/Disclosure Employee emailed PHI outside company
Mercy Health Love County Hospital and Clinic Healthcare Provider 13,004 Theft Paper records stolen from a storage unit
The Neurology Foundation, Inc. Healthcare Provider 12,861 Unauthorized Access/Disclosure Employee stole PHI
Hand & Upper Extremity Centers dba Hand Rehabilitation Specialists Healthcare Provider 12,806 Hacking/IT Incident Data theft and extortion attempt

The post Summary of September 2017 Healthcare Data Breaches appeared first on HIPAA Journal.

Network Health Phishing Attack Impacts 51,000 Plan Members

Wisconsin-based insurer Network Health has notified 51,232 of its plan members that some of their protected health information (PHI) has potentially been accessed by unauthorized individuals.

In August 2017, some Network Health employees received sophisticated phishing emails. Two of those employees responded to the scam email and divulged their login credentials to the attackers, who used the details to gain access to their email accounts.

The compromised email accounts contained a range of sensitive information including names, phone numbers, addresses, dates of birth, ID numbers, and provider information. No financial information or Social Security numbers were included in the compromised accounts, although certain individuals’ health insurance claim numbers and claim information was potentially accessed.

The breach was detected rapidly and the affected accounts were shut down to limit the harm caused. An external cybersecurity consultant was brought in to assess the extent of the attack and perform a forensic analysis to determine whether access to other parts of the network had been gained. The incident was also reported to law enforcement which is also investigating the breach.

Penny Ransom, Network Health’s Chief Administrative Officer said, “As a result of this attack, steps are underway to further improve the security of operations and prevent future incidents.”

Those measures include re-training the workforce to help employees recognize and report phishing emails. A full review of security processes and procedures is also being conducted. All individuals impacted by the attack have been offered one year of credit monitoring and identity theft protection services without charge.

Network Health was one of three healthcare organizations to report phishing attacks in September.  Morehead Memorial Hospital experienced a phishing attack that potentially resulted in the exposure of 66,000 patients’ PHI. Arkansas Oral & Facial Surgery Center also fell victim to a phishing attack that saw ransomware installed. That attack potentially impacted 128,000 individuals.

The post Network Health Phishing Attack Impacts 51,000 Plan Members appeared first on HIPAA Journal.

Resold Fax Machine Prints Documents Containing PHI

A fax machine used by a physician at Grand Rapids, MI, based Spectrum Health System was recently discovered to contain the PHI of around 20 patients. The fax machine was purchased from resale shop by a local resident, who discovered documents were still stored in the memory of the machine.

When attempting to print off a fax transmission report, the device started printing documents containing sensitive patient information such as names, addresses, dates of birth, details of dependents, diagnoses, test results, and insurance information.

The incident was brought to the attention of Wood TV’s Target 8 team, which investigated and traced the device to Spectrum Health’s Dr. Wendy Zink.

Spectrum Health was contacted about the breach and Chief Privacy Officer Leah Voigt confirmed that all electronic equipment containing ePHI is sent to a business associate that ensures ePHI on the devices is permanently erased in accordance with HIPAA Rules. Spectrum Health has certification to prove that was the case and that the vendor also confirmed data had been permanently destroyed. The fax machine has since been recovered by Spectrum Health and all copies of PHI have been permanently destroyed. The privacy violation is being viewed as an anomaly.

HIPAA and Electronic Media Containing ePHI

The HIPAA Security Rule – 45 CFR 164.310(d)(1) – requires HIPAA covered entities to implement policies governing the removal of hardware containing electronic protected health information from their facilities, and the movement of those devices within their facilities.

The standard naturally applies to portable storage devices such as zip drives, hard drives, and laptop computers, but it also applies to digital photocopiers, printers, scanners, and faxes. Digital photocopiers, printers, scanners, and faxes often store electronic copies of documents that have been copied or transmitted.

Movement of those devices must therefore be controlled and technical safeguards implemented to prevent any electronic protected health information in stored documents from being viewed by unauthorized individuals.

As well as controlling the movement and keeping track of those devices, covered entities must ensure that when the devices are no longer required, any data stored on hard drives, or in the memory, are permanently erased.

HIPAA Rules on Disposal of PHI

45 CFR 164.310(d)(2)(i) and (ii) cover the disposal of electronic equipment, which require policies and procedures to be developed and implemented to address the final disposition of ePHI, and the media on which it is stored. ePHI must be removed from electronic devices before they are re-used, scrapped, or recycled.

Prior to disposing of electronic media, all ePHI on the devices must be rendered unreadable, indecipherable, and incapable of being reconstructed. OCR suggests “clearing (using software or hardware products to overwrite media with non-sensitive data) or purging (degaussing or exposing the media to a strong magnetic field in order to disrupt the recorded magnetic domains) the information from the electronic media.”

If a covered entity is unable to perform these actions, a vendor can be used. That vendor would naturally be a business associate, and a HIPAA-compliant business associate agreement would need to be signed by both parties before any devices are handed over.

The failure to remove ePHI prior to disposal is a violation of HIPAA Rules, and one that could potentially result in an impermissible disclosure of protected health information. It could also lead to a financial penalty for noncompliance with HIPAA Rules.

The post Resold Fax Machine Prints Documents Containing PHI appeared first on HIPAA Journal.