HIPAA Breach News

Texas Patients Just Informed of 2015 CoPilot Data Breach

Patients of a Texas orthopedic clinic are just finding out that some of their protected health information was exposed in a 2015 CoPilot data breach.

In October 2015, a website maintained by CoPilot Provider Support Services was accessed by an unauthorized individual. That individual gained access to, and downloaded, the PHI of more than 220,000 patients. The website was used by providers to find out whether two drugs – ORTHOVISC® and MONOVISC® – were covered by the patients’ health insurance.

CoPilot discovered its website had been breached on December 23, 2015, and launched an investigation. The individual who accessed the data was identified and the matter was reported to law enforcement. No information was believed to have been accessible by the public.

While the incident was resolved, CoPilot delayed issuing breach notifications until January 2017. That delay resulted in a $130,000 fine from the New York Attorney General in June 2017.

It has been two years since the breach, and eight months from when notifications were issued, but some breach victims are only just discovering they have been impacted. 653 patients of Kraig R. Pepper, D.O., P.A. were only notified of the breach in late September.

Dr. Pepper did not become aware of the breach until July 31, 2017, when he found out some of his patients’ data had been exposed in the 2015 CoPilot data breach. The breached information did not include any medical records, X-rays, or test results held by Dr. Pepper, only information that was provided to DePuy Mitek, Inc., the company from which the drugs were purchased. The information disclosed to that company and was exposed included names, addresses, Social Security numbers, dates of birth, phone numbers, gender, ID numbers, Group numbers, medical insurance information, prescription information, and some clinical information.

While there has been a considerable delay in receiving notification, affected patients have been offered identity theft protection services without charge for 12 months.

The post Texas Patients Just Informed of 2015 CoPilot Data Breach appeared first on HIPAA Journal.

What are the HIPAA Breach Notification Requirements?

All HIPAA covered entities must familiarize themselves with the HIPAA breach notification requirements and develop a breach response plan that can be implemented as soon as a breach of unsecured protected health information (PHI) is discovered. HIPAA training for staff must also include the procedures for reporting breaches of unsecured PHI.

While most HIPAA covered entities should understand the HIPAA breach notification requirements, organizations that have yet to experience a data breach may not have a good working knowledge of the requirements of the Breach Notification Rule. Vendors that have only just started providing a service to Covered Entities may similarly be unsure of the reporting requirements and actions that must be taken following a breach.

The issuing of notifications following a breach of unencrypted PHI is an important element of HIPAA compliance. The failure to comply with HIPAA breach notification requirements can result in a significant financial penalty in additional to that impose for the data breach itself. With this in mind, we have compiled a summary of the HIPAA breach notification requirements for covered entities and their business associates.

Summary of the HIPAA Breach Notification Rule

The HIPAA Breach Notification Rule – 45 CFR §§ 164.400-414 – requires covered entities and their business associates to report breaches of unsecured electronic protected health information and physical copies of protected health information. A breach is defined as the acquisition, access, use, or disclosure of unsecured protected health information in a manner not permitted by HIPAA Rules.

According to the HHS´ guidance on the HIPAA Breach Notification Rule, an impermissible use or disclosure of unsecured protected health information is presumed to be a breach unless the covered entity or business associate demonstrates there is a low probability the protected health information has been compromised based on a risk assessment of at least the following factors:

  1. The nature and extent of the protected health information involved, including the types of identifiers and the likelihood of re-identification;
  2. The unauthorized person who used the protected health information or to whom the disclosure was made;
  3. Whether the protected health information was actually acquired or viewed; and
  4. The extent to which the risk to the protected health information has been mitigated.

HIPAA breaches include unauthorized access by employees as well as third parties, improper disclosures, the exposure of protected health information, and ransomware attacks. Exceptions include: Breaches of secured protected health information such as encrypted data when the key to unlock the encryption has not been obtained; “any unintentional acquisition, access, or use of protected health information by a workforce member or person acting under the authority of a covered entity or a business associate, if such acquisition, access, or use was made in good faith and within the scope of authority and does not result in further use or disclosure;” An inadvertent disclosure by a person who is authorized to access PHI, to another member of the workforce at the organization who is also authorized to access PHI; When the covered entity or business associate makes a disclosure and has a good faith belief that the information could not have been retained by the person to whom it was disclosed.

In the event of a reportable HIPAA breach being experienced, the HIPAA breach notification requirements are:

Notify Individuals Impacted – or Potentially Impacted – by the Breach

All individuals impacted by a data breach, who have had unsecured protected health information accessed, acquired, used, or disclosed, must be notified of the breach. Breach notifications are also required for any individual who is reasonably believed to have been affected by the breach.

Breach notification letters must be sent within 60 days of the discovery of a breach unless a request to delay notifications has been made by law enforcement. In such cases, notifications should be sent as soon as that request has expired. While it is permissible to delay reporting of a breach to the HHS for breaches impacting fewer than 500 individuals (see below), that delay does not apply to notifications to breach victims.

Breach notification letters should be sent by first class mail to the last known address of breach victims, or by email if individuals have given authorization to be contacted electronically.

The HIPAA breach notification requirements for letters include writing in plain language, explaining what has happened, what information has been exposed/stolen, providing a brief explanation of what the covered entity is doing/has done in response to the breach to mitigate harm, providing a summary of the actions that will be taken to prevent future breaches, and giving instructions on how breach victims can limit harm. Breach victims should also be provided with a toll-free number to contact the breached entity for further information, together with a postal address and an email address.

Notify the Department of Health and Human Services

Notifications must be issued to the Secretary of the Department of Health and Human Services, via the Office for Civil Rights breach reporting tool. The HIPAA breach notification requirements differ depending on how many individuals have been impacted by the breach.

When the breach has impacted more than 500 individuals, the maximum permitted time for issuing the notification to the HHS is 60 days from the discovery of the breach, although breach notices should be issued without unnecessary delay. In the case of breaches impacting fewer than 500 individuals, HIPAA breach notification requirements are for notifications to be issued to the HHS within 60 days of the end of the calendar year in which the breach was discovered.

Notify the Media

HIPAA breach notification requirements include issuing a notice to the media. Many covered entities that have experienced a breach of protected health information notify the HHS, relevant state attorneys general, and the patients and health plan members impacted by the breach, but fail to issue a media notice – a violation of the HIPAA Breach Notification Rule.

A breach of unsecured protected health information impacting more than 500 individuals must be reported to prominent media outlets in the states and jurisdictions where the breach victims reside – See 45 CFR §§ 164.406. This is an important requirement, as up-to-date contact information may not be held on all breach victims. By notifying the media, it will help to ensure that all breach victims are made aware of the potential exposure of their sensitive information. As with the notifications to the HHS and breach victims, the media notification must be issued within 60 days of the discovery of the breach.

Post a Substitute Breach Notice on the Home Page of the Breach Entity’s Website

In the event that up-to-date contact information is not held on 10 or more individuals that have been impacted by the breach, the covered entity is required to upload a substitute breach notice to their website and link to the notice from the home page. The link to the breach notice should be displayed prominently and should remain on the website for a period of 90 consecutive days. In cases where fewer than 10 individuals’ contact information is not up-to-date, alternative means can be used for the substitute notice, such as a written notice or notification by telephone.

Data Breaches Experienced by HIPAA Business Associates

Business associates of HIPAA-covered entities must also comply with the HIPAA breach notification requirements and can be fined directly by the HHS’ Office for Civil Rights and state attorney generals for a HIPAA Breach Notification Rule violation.

Any breach of unsecured protected health information must be reported to the covered entity within 60 days of the discovery of a breach. While this is the absolute deadline, business associates must not delay notification unnecessarily. Unnecessarily delaying notifications is a violation of the HIPAA Breach Notification Rule.

It is usually the covered entity that will issue breach notifications to affected individuals, so any breach notification will need to be accompanied with details of the individuals impacted. It is a good practice to issue a breach notification to a covered entity rapidly, and to provide further information on the individuals impacted once the investigation has been completed. Under the terms of a HIPAA-compliant Business Associate Agreement (BAA), a business associate may be required to issue breach notifications to affected individuals.

Timeline for Issuing Breach Notifications

Breach notifications should be issued as soon as possible and no later than 60 days after the discovery of the breach, except when a delay is requested by law enforcement. Investigating a breach of protected health information can take some time, but once all the necessary information has been obtained to allow breach notifications to be sent they should be mailed.

HIPAA-covered entities must not delay sending breach notification letters. It is possible to receive a HIPAA violation penalty for delaying notifications, even if they are sent within 60 days of the discovery of the breach. There have been several recent cases of HIPAA breach notification requirements not being followed within the appropriate time frame, which can potentially result in financial penalties.

State Breach Notification Laws May Be Stricter than HIPAA

U.S. states have their own breach notification laws. Typically, notifications must be issued to breach victims promptly and a notice also submitted to the state attorney general’s office. Some states require breach notifications to be issued well within the HIPAA deadline.

Delaying breach notifications until the 60-day limit of HIPAA could well see state laws violated, leading to financial penalties from state attorney generals. State laws frequently change so it is important to keep up to date on breach notification laws in the states in which you operate.

Penalties for Violations of HIPAA Breach Notification Requirements

HIPAA covered entities must ensure the HIPAA breach notification requirements are followed or they risk incurring financial penalties from state attorneys general and the HHS’ Office for Civil Rights.

In 2017, Presense Health became the first HIPAA-covered entity to settle a case with the Office for Civil Rights solely for a HIPAA Breach Notification Rule violation – after it exceeded the 60-day maximum time frame for issuing breach notifications. Presense Health took three months from the discovery of the breach to issue notifications – A delay that cost the health system $475,000. The maximum penalty for a HIPAA Breach Notification Rule violation is $1,500,000, or more if the delay is for more than 12 months.

Responding to a Healthcare Data Breach

how-to-respond-to-a-healthcare-data-breach

HIPAA Breach Notification Requirements FAQs

What is the difference between a HIPAA breach and a HIPAA violation?

A HIPAA breach is when unsecured PHI is acquired, accessed, used, or disclosed in a manner not permitted by the Privacy and Security Rules. A HIPAA violation occurs when a Covered Entity, Business Associate, or a member of the workforce fails to comply with any standard in the Privacy, Security, or Breach Notification Rules. It is not necessary for a breach to occur in order for there to be a HIPAA violation – for example, the failure to respond to a patient access request within 30 days is a HIPAA violation, but not a HIPAA breach.

Why must staff be trained on reporting HIPAA breaches?

Staff must be trained on reporting HIPAA violations to their supervisors, managers, or the Privacy Officer. It is not necessary for staff to know the mechanics of the HIPAA breach notification requirements beyond that point, but they must be aware of the consequences of delaying a report in terms of the impact it will have on patients impacted by the breach, the consequences for their employer if notifications are delayed longer than necessary, and on their own jobs if a breach comes to light weeks after it has happened.

What is the difference between secured PHI and unsecured PHI?

Secured PHI is generally defined as Protected Health Information that has been rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of technologies or methodologies specified in § 13402 of the HITECH Act. HIPAA is technology neutral, but the implementation specifications relating to Access Controls and Transmission Security state encryption is required unless an equivalent protection is implemented, or the use of encryption is unreasonable and inappropriate in the circumstances.

What is an example of a “good faith belief” that PHI has not been retained?

If, for example, a healthcare professional shows an X-ray image to a person not authorized to view the image but realizes a mistake has been made before it is likely any information relating to the image has been read, it is highly likely that PHI has not been retained and the Covered Entity can reasonably accept – in good faith – there has been no disclosure of unsecured PHI. In this scenario, it is important the healthcare professional reports the unauthorized disclosure to a higher authority, and that the report – along with the good faith determination – is documented.

Why do individuals have to give authorization before they receive email notifications?

Because email is not a secure communication channel, Covered Entities must obtain the authorization of an individual before sending an email that contains PHI. (If the email does not contain PHI, no authorization is necessary). Breach notifications have to inform individuals what PHI was accessed, so therefore Covered Entities can only communicate a breach by email if they have a prior authorization.

When must a HIPAA breach be reported?

A HIPAA breach must be reported whenever unsecured PHI or ePHI has been used or disclosed impermissibly unless there is a low probability that data has been comprised based on the risk assessment mentioned above. Also mentioned above was the timetable for reporting HIPAA breaches – within sixty days if the breach involves 500 or more records, and by the end of the calendar year if the breach involves fewer than 500 records.

The post What are the HIPAA Breach Notification Requirements? appeared first on HIPAA Journal.

13,000 Patients Potentially Impacted by Mercy Health Love County Hospital Breach

A Mercy Health Love County Hospital breach has potentially impacted more than 13,000 patients in Oklahoma.

On June 23, 2017, the hospital discovered an employee had stolen a laptop computer and paper records from a storage unit used by the hospital. According to the breach notice issued by Mercy Health, the records of 10 patients were taken from the storage unit along with the laptop.

The theft of PHI was initially investigated by the Love County Sheriff’s Office. That investigation revealed the former employee had used the stolen information to fraudulently obtain credit cards in the patients’ names. A second individual is also understood to have been involved.

While Mercy Health had up to 60 days to notify patients of the breach under HIPAA Rules, all ten patients were notified immediately. Mercy Health is working with the Love County Sherriff’s Office, the United States Postal Services, and the U.S. Secret Service which are all investigating the incident.

Mercy Health said in its breach notice, “Although there is no evidence that files belonging to patients aside from the ten patients originally identified were accessed or acquired without authorization, Mercy is nonetheless informing the public of the incident.” All affected patients have been offered 12 months of credit monitoring and identity theft repair services without charge.

Mercy Health Love County Hospital and Clinic Administrator Richard Barker said, “We are taking steps to secure all patient information to prevent anything similar from happening.”

While it would appear that the records of only 10 patients were stolen, a report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates a breach has been experienced involving 13,004 paper/film records.

It is currently unclear whether the storage unit contained the records of 13,004 patients, but only 10 patients’ files were taken, or if this is a separate incident. HIPAA Journal contacted Mercy Health for clarification but has yet to receive a response.

This post will be updated with further information as it becomes available.

The post 13,000 Patients Potentially Impacted by Mercy Health Love County Hospital Breach appeared first on HIPAA Journal.

Our Lady of the Angels Hospital Breach Impacts 1,140 Patients

Our Lady of the Angels Hospital has discovered a former employee accessed the medical records of 1,140 patients without authorization.

The employee had been granted access to the protected health information in order to conduct work duties; however, hospital staff became aware the employee was accessing medical records without any legitimate work reason for doing so.

The improper access was discovered on July 25, 2017, and the employee’s access to the medical record system was immediately terminated, as was the employee.

Rene Ragas, President and CEO, Our Lady of the Angels Hospital, said, “Patient privacy is a top priority and we have a zero-tolerance policy for employees who improperly access patient data.”

A thorough investigation was conducted to determine which patients had been impacted, which revealed the former employee had been inappropriately accessing the medical records of patients for more than three years.

The Bogalusa, LA hospital was acquired by the Franciscan Missionaries of Our Lady Health System on March 17, 2014, which is the date given for when the improper access first started. It is currently unclear whether the employee had been accessing medical records without authorization before that date, when the hospital was managed by LSU Health under the name LSU Bogalusa Medical Center.

The employee was questioned about the improper access and it does not appear that any patient health information was shared with any other individuals or was used improperly. This appears to be another case of a healthcare employee accessing medical records out of curiosity.

Even though data theft and misuse is not suspected, out of an abundance of caution, all patients whose privacy was violated have been offered 12 months of credit monitoring services without charge.

The types of information accessed by the former employee includes names, addresses, phone numbers, dates of birth, gender, insurance information, social security numbers, diagnoses, dates of services, places of services, and clinical information such as orders, test results, medications, and clinical abstracts.

Our Lady of the Angels Hospital is reviewing policies and procedures and will be revising its audit processes to ensure any future privacy breaches of this nature are identified more rapidly. Additional training is also being provided to employees regarding the privacy and security of PHI.

The post Our Lady of the Angels Hospital Breach Impacts 1,140 Patients appeared first on HIPAA Journal.

PeaceHealth Employee Accessed Medical Records Without Authorization for Almost 6 Years

PeaceHealth, a not-for-profit Catholic health system based in Vancouver, WA, has discovered one of its former employees had accessed the medical records of almost 2,000 of its patients without any legitimate work reason for doing so.

The unauthorized access was discovered by PeaceHealth on August 9, 2017, triggering an investigation. PeaceHealth determined the improper access started in November 2011 and continued until July 2017.

The investigation confirmed Social Security numbers and financial information were not accessed by the employee, although patient names, medical record numbers, admission and discharge dates, medical diagnoses, and progress notes were all viewed.

Due to the nature of information that was accessed, and the results of the internal investigation, PeaceHealth does not believe any patients impacted by the breach are at risk of identity theft. However, all impacted individuals have been advised to remain vigilant and review their credit reports and account statements for any sign of fraudulent activity.

Patients impacted by the breach had visited either the PeaceHealth St. Joseph Medical Center or its Southwest Medical Center between November 2011 and July 2017. All individuals affected by the incident have now been notified of the breach by mail.

PeaceHealth issued a statement saying, “Patient privacy is among our highest priorities, and we take this [incident] very seriously.” The employee no longer works for PeaceHealth.

PeaceHealth already invests in technology to prevent data breaches, follows industry best practices for monitoring and safeguarding PHI, and provides training to staff on privacy and security. The incident has prompted PeaceHealth to reinforce education of its staff with respect to appropriate accessing of PHI.

The incident has now been reported to the Department of Health and Human Services’ Office for Civil Rights. The breach report indicates the PHI of 1,969 patients was improperly accessed.

The post PeaceHealth Employee Accessed Medical Records Without Authorization for Almost 6 Years appeared first on HIPAA Journal.

Ransomware Attack Potentially Impacts 128,000 Arkansas Patients

Arkansas Oral Facial Surgery Center in Fayetteville has experienced a ransomware attack that has potentially impacted up to 128,000 of its patients.

Ransomware was believed to have been installed on its network between July 25 and 26, 2017. The attack was detected rapidly, although not before files, x-ray images, and documents had been encrypted. The incident did not result in the encryption of its patient database, except for a ‘relatively limited’ set of patients who data related to their recent visits encrypted. Those patients had visited the center for medical services in the three weeks prior to the ransomware attack.

The ransomware attack is still under investigation, although to date, no evidence of data theft has been found. Arkansas Oral Facial Surgery Center believes the sole purpose of the attack was to extort money, and not to steal data; however, it has not been possible to rule out data access or data theft with a high degree of certainty.

The files and images that were potentially accessed included information such as names, addresses, dates of birth, Social Security numbers, health insurance details, medical diagnoses, health conditions, treatment information and other clinical information. The ransomware attack has also rendered files, medical images and details of visits unavailable.

Since sensitive protected health information has potentially been accessed, patients are now being notified of the breach by mail. All impacted individuals have been offered identity repair and credit monitoring services through AllClear ID for 12 months without charge.

Arkansas Oral Facial Surgery Center has warned patients to be alert for phishing attacks in the wake of the breach and has confirmed it would not request any personal information via the telephone or email in relation to the breach. If any calls or emails are received, patients should exercise caution and treat them as potential phishing scams.

The post Ransomware Attack Potentially Impacts 128,000 Arkansas Patients appeared first on HIPAA Journal.

Another Healthcare Organization Attacked by The Dark Overlord

Following a couple of months of relative quiet, the hacking group TheDarkOverlord has announced another successful attack on a U.S. healthcare provider, Mass-based SMART Physical Therapy (SMART PT).

The hack reportedly occurred on September 13, 2017, with the announcement of the data theft disclosed by TDO on Twitter on Friday 22, 2017.  No mention was made about how access to the data was gained, although it was confirmed to databreaches.net that the attack took advantage of the use of weak passwords. The entire database of patients was reportedly stolen.

Databreaches.net was provided with the patient database and has confirmed the authenticity of the attack. The database contained a wide range of information on 16,428 patients, including contact information, dates of birth and Social Security numbers.

This was an extortion attempt and a demand for payment in Bitcoin was reportedly sent to SMART PT, although no payment has been made, nor will it be. SMART PT spokesperson Joanne Ponte confirmed to databreaches.net that they refuse to communicate with criminals and give into extortion demands.

TDO was responsible for several hacks of healthcare organizations over the past two years, including Ca-based Dougherty Laser Vision, Little Red Door Cancer Services of East Central Indiana, Hand Rehabilitation Specialists, Tampa Bay Surgery Center, OC GastroCare, Aesthetic Dentistry and Athens Orthopedic Clinic, to mention but a few. In several cases, the failure to respond to emails and the refusal to give in to the extortion demands has resulted in patient data being dumped online.

Since the attack only occurred in the past few days, the incident has yet to be reported to the Department of Health and Human Services’ Office for Civil Rights and patients have not yet been notified of the breach. SMART PT is currently investigating the breach and is implementing its breach response protocol. Further information on the incident can be read here.

The post Another Healthcare Organization Attacked by The Dark Overlord appeared first on HIPAA Journal.

Lost Laptop Sees PHI of 3,725 Veterans Exposed

A decommissioned laptop computer previously used by the Mann-Grandstaff VA Medical Center (MGVAMC) in Spokane, WA, has been discovered to be missing, potentially resulting in the exposure of sensitive patient data.

The laptop was paired with a hematology analyzer and stored data related to hematology tests. The laptop was in use between April 2013 and May 2016, but was decommissioned when the device became unusable. The laptop, which had been supplied by a vendor, was replaced; however, an equipment inventory revealed the device to be missing.

The device should have been returned to the vendor, although the vendor has no record of the laptop ever being recalled from MGVAMC. An inventory of equipment at the MGVAMC lab determined the device was missing. A full search of the medical center was conducted but the laptop could not be located.

It was not possible to tell exactly what information had been stored on the device, or the exact number of patients whose protected health information may have been exposed. MGVAMC concluded all patients who submitted samples for hematology tests during the dates that the laptop was in use potentially had data exposed.

The types of information stored on the device would have included names, dates of birth, and Social Security numbers according to a statement issued by MGVAMC. 3,275 patients have potentially been impacted and have been notified of the possible breach. Where applicable, patients will be offered credit monitoring and identity theft protection services.

Whenever equipment containing electronic protected health information is decommissioned, HIPAA-covered entities must ensure all data is rendered unreadable, indecipherable, and otherwise cannot be reconstructed.

The physical safeguards stipulated in the HIPAA Security Rule – 45 CFR 164.310(d)(2)(i) – require covered entities to implement policies and procedures to address the final disposition of ePHI and/or the hardware on which it is stored, while 45 CFR 164.310(d)(2)(ii) requires covered entities to implement procedures for the removal of ePHI from electronic media before the media are made available for re-use.

OCR recommends “clearing (using software or hardware products to overwrite media with non-sensitive data), purging (degaussing or exposing the media to a strong magnetic field in order to disrupt the recorded magnetic domains), or destroying the media (disintegration, pulverization, melting, incinerating, or shredding). If devices are supplied by vendors, the method for clearing the devices prior to decommissioning should be discussed with the vendor and policies developed accordingly.

In response to this incident, the Mann-Grandstaff VA has developed a new policy for sanitizing electronic media prior to disposal, decommissioning, or returning devices to suppliers to prevent further potential breaches of ePHI.

The post Lost Laptop Sees PHI of 3,725 Veterans Exposed appeared first on HIPAA Journal.

HIPAA Business Associate Data Breach Impacts 21,856 Individuals

The importance of reviewing system activity logs has been underscored by recent HIPAA business associate data breach.

Nebraska-based CBS Consolidated Inc., doing business as Cornerstone Business & Management Solutions, conducted a routine review of system logs on July 10, 2017 and discovered an unfamiliar account on the server. Closer examination of that account revealed it was being used to download sensitive data from the server, including the protected health information of patients that used its medical supplies.

21,856 patients who received durable medical supplies from the company through their Medicare coverage have potentially been affected. The types of data obtained by the hacker included names, addresses, dates of birth, insurance details, and Social Security numbers. While personal information was exposed, the hacker was not able to obtain details of any medical conditions suffered by patients, nor details of any items purchased or financial information.

It is currently unclear how the account was created, although an investigation into the incident is ongoing. CBS says following the discovery of unauthorized access, the server was isolated and access to data was blocked. Since the incident was discovered, CBS has been carefully monitoring its systems and has uncovered no further evidence of unauthorized access or data theft.

Due to the sensitive nature of data stolen by the hacker, all individuals impacted by the breach have been offered 12 months of credit monitoring and identity theft protection services without charge. CBS is also reviewing its security protections and will be introducing new administrative safeguards, providing additional training to staff members on security, as well as improving technical safeguards to prevent future incidents from occurring.

This is the second worst data breach reported by a HIPAA business associate so far in 2017, behind the 56,000-record breach reported by Enterprise Services LLC in June.

The post HIPAA Business Associate Data Breach Impacts 21,856 Individuals appeared first on HIPAA Journal.