HIPAA Breach News

Protected Health Information Stolen in Vision Care Specialists Burglary

The price of medical information on the black market may be high, but it is relatively rare for paper records to be stolen during break-ins. However, a burglary at Vision Care Specialists’ administrative offices in Denver, CO saw paperwork containing the PHI of patients taken by thieves.

The burglary was discovered on May 22, 2017 and law enforcement was called in to investigate. An inventory was conducted to determine what items were taken by the thieves and third party forensic investigators were called in to ascertain whether its systems had been accessed. That investigation did not uncover any evidence to suggest electronic medical information had been accessed, although on July 5, Vision Care Specialists discovered that paperwork containing the protected health information of some of its patients had been removed from its offices.

The documents contained a range of sensitive information including names, dates of birth, Social Security numbers, medical information, health conditions/diagnoses, financial information and health insurance details. While no reports have been received to suggest any of the information has been used inappropriately, it can be safely assumed that the information was taken for nefarious purposes.

Vision Care Specialists has now contacted all individuals whose information was obtained by the thieves and all affected patients have been offered complimentary credit monitoring services for 12 months.

Patients affected by the incident have been advised to exercise caution and to monitor their accounts, credit reports and Explanation of Benefits statements and to be alert for identity theft and fraud.

Vision Care Specialists has responded to the incident by enhancing security at its office to prevent any further incidents of this nature from occurring.

The post Protected Health Information Stolen in Vision Care Specialists Burglary appeared first on HIPAA Journal.

Hospital Employee Discovered to Have Accessed Medical Records Without Authorization for 14 Years

Cases of employees snooping on medical records are relatively common, although an incident at Tewksbury Hospital in Massachusetts stands out due to the length of time that an employee was accessing medical records without authorization before being caught.

The hospital was tipped off about the employee in April after a former patient made a complaint about their medical record being accessed inappropriately. In response to the complaint, the hospital conducted a full review which revealed the former patient’s medical records had been accessed by an employee without any legitimate reason for doing so.

Further investigation revealed it was far from a one off.  The employee had been accessing the records of patients without authorization for a period of 14 years. The first instance dated back to 2003 and the inappropriate access continued until May 2017. During that time, the employee accessed the records of more than 1,000 patients.

Tewksbury Hospital, which is run by the Department of Public Health, has now written to all patients whose medical records were inappropriately accessed, although many of those individuals are now former patients and the hospital no longer holds valid contact information. In an attempt to contact those individuals, a substitute data breach notice has been placed on the Mass.gov website.

The employee was a clerk at the hospital and was required to have access to medical records in order to complete work duties. Those access rights were abused and as a result, the employee was terminated and no longer has access to the EMR system.

The types of information that were potentially accessed includes names, phone numbers, addresses, gender, dates of birth, medical diagnoses, details of medical treatment provided at the hospital and in some cases, Social Security numbers.

Tewksbury Hospitals says steps have now been taken to reduce the probability of similar incidents occurring in the future and to make sure that if records are accessed inappropriately, incidents are detected promptly. Those steps included conducting a review of policies and procedures regarding access to its EMR system and a reassessment of how access logs to medical records are reviewed. Staff will also be provided with additional training on the privacy and security of protected health information.

Tewksbury Hospital says the investigation did not uncover any evidence to suggest protected health information was misused in any way.

The incident has been reported to the Department of Health and Human Services’ Office for Civil Rights, which investigates all data breaches that have impacted more than 500 individuals. If the investigation reveals HIPAA Rules have been violated by the hospital, the penalty is likely to be severe for a breach of this duration.

The post Hospital Employee Discovered to Have Accessed Medical Records Without Authorization for 14 Years appeared first on HIPAA Journal.

NotPetya Attack Continues to Disrupt Nuance Communications’ Services

In late June, Nuance Communications, a provider of healthcare solutions and transcription services, was one of many organizations around the globe to have systems taken out of action by NotPetya ransomware.

While most ransomware attacks are conducted with the intention of obtaining ransom payments in exchange for the keys to unlock data, NotPetya was different. The aim was sabotage. Infection resulted in permanent encryption of master file tables, preventing infected computers from locating stored data. Data recovery was not possible even if the ransom demand was paid.

The attacks caused permanent damage at many organizations requiring the replacement of hardware and substantial portions of affected networks. Nuance Communications was no different.

Following the attack, Nuance Communications brought in external security experts to contain the infection and determine the extent of the attack. However, not in time to prevent widespread damage. Systems were taken out of action preventing hundreds of hospitals from using its services.

Premier Health was one of many hospital systems forced to switch transcription service providers. Boston’s Beth Israel Deaconess Medical Center was also impacted and has been prevented from using Nuance’s eScription service. University of Pittsburgh Medical Center was similarly affected and still cannot use the company’s transcription service.

It took Nuance Communications until July 3 to bring its eScription RH and Clinic 360 clients back online on the Emdat platform, and until July 5 to bring its eScription LH platform back online.  By July 11, almost 200 hospitals had started using its eScription LH platform again, although some company services continue to be disrupted.

Nuance Communications spokesperson Richard Mack announced yesterday that “We are doing everything within our power to support our health-care customers and provide them with the information and resources they need to provide quality patient care, including offering an alternative system and solutions.”

In addition to fixing its systems and working hard to bring customers back online, the company has been improving its security to prevent future attacks.

Even though most systems are now back online, it may be difficult to convince hospitals to return. Many have since switched to other service providers as a result of the attack and loss of its services. Many are unlikely to return. That is likely to make a serious dent in its Q3 profits at the very least. At present, the company’s share price has fallen 6% since the attack.

The post NotPetya Attack Continues to Disrupt Nuance Communications’ Services appeared first on HIPAA Journal.

U.S. Data Breaches Hit Record High

Hacking still the biggest cause of data breaches and the breach count has risen once again in 2017, according to a new report released by the Identity Theft Resource Center (ITRC) and CyberScout.

In its half yearly report, ITRC says 791 data breaches have already been reported in the year to June 30, 2017 marking a 29% increase year on year. At the current rate, the annual total is likely to reach 1,500 reported data breaches. If that total is reached it would represent a 37% increase from last year’s record-breaking total of 1,093 breaches.

Following the passing of the HITECH Act in 2009, the Department of Health and Human Services’ Office for Civil Rights (OCR) has been publishing healthcare data breach summaries on its website. Healthcare organizations are required by HIPAA/HITECH to detail the extent of those breaches and how many records have been exposed or stolen. The healthcare industry leads the way when it comes to transparency over data breaches, with many businesses failing to submit details of the extent of their breaches.

ITRC says it is becoming much more common to withhold this information. In the first 6 months of 2017, 67% of data breach notifications and public notices did not include the number of records exposed, which is a 13% increase year on year and a substantial increase from the 10-year average of 43%. The lack of full information about data breaches makes it harder to produce meaningful statistics and assess the impact of breaches.

81.5% of healthcare industry data breach reports included the number of people impacted – a similar level to 2016. ITRC points out that does not mean healthcare organizations are failing to provide full reports, only that HITECH/HIPAA regulations do not require details of breaches of employee information to be reported.

The OCR breach portal shows healthcare industry data breaches in the year to June 30, 2017 increased by 14% year on year. 169 breaches were reported in the first six months of 2017 compared to 148 in the same period in 2016.

Hacking is Still the Biggest Cause of U.S Data Breaches

The biggest cause of U.S data breaches is still hacking according to the report, accounting for 63% of data breaches reported in the first half of the year across all industries – and increase of 5% year on year. Phishing, ransomware, malware and skimming were also included in the totals for hacking. 47.7% of those breaches involved phishing and 18.5% involved ransomware or malware.

The second biggest causes of U.S. data breaches were employee error, negligence and improper disposal, accounting for 9% of the total, followed by accidental exposure on the Internet – 7% of breaches.

The OCR breach portal shows 63 healthcare data breaches were attributed to hacking/IT incidents – 37% of the half yearly total. That represents a rise of 19% from last year.

In close second place is unauthorized access/disclosure – 58 incidents or 35% of the total. A 14% decrease year on year. In third place is loss/theft of devices – 40 incidents or 24% of all healthcare data breaches. A 4% fall year on year. The remaining 4% of healthcare data breaches – 7 incidents – were caused by improper disposal of PHI/ePHI.

Matt Cullina, CEO of CyberScout, said “All these trends point to the need for businesses to take steps to manage their risk, prepare for common data breach scenarios, and get cyber insurance protection.”

The post U.S. Data Breaches Hit Record High appeared first on HIPAA Journal.

Ransomware Attack Investigation Reveals 15-Month Security Breach

A ransomware attack on Peachtree Neurological Clinic (PNC) in Atlanta, GA resulted in the encryption of sensitive data. Since PNC had backed up its data, it was possible to restore the affected files without paying the ransom.

Following any ransomware attack it is important to conduct a forensic analysis of systems to ensure all traces of the ransomware have been removed and no backdoors have been installed. PNC performed scans of its system and confirmed that the malware had been removed; however, the scans revealed that its systems had been accessed by unauthorized individuals between February 2016 and May 2017.

Cybercriminals have been known to gain access to organizations’ systems and install ransomware when there is no further need for access, but it is unclear whether the same individuals were responsible for both security breaches.

PNC found no evidence to suggest that the ransomware attack involved the exfiltration of data, but it was not possible to determine with any degree of certainty whether access to protected health information was gained in the initial attack. PNC was only able to confirm that its systems had been accessed.

The types of protected health information stored on the compromised system included names, telephone numbers, addresses, dates of birth, Social Security numbers, driver’s license numbers, prescription information, details of treatments/procedures and health insurance information.

Due to the sensitive nature of the data that were potentially accessed, PNC has offered all affected individuals complimentary identity theft protection services. The attacks have been reported to law enforcement and all affected individuals have been notified of the incidents by mail.

Dr. Lawrence Seiden, M.D., managing partner of PNC, said, “We take patient privacy seriously, and are very sorry for any concern or inconvenience this incident has caused or may cause to anyone who has been affected.”

The security breaches have yet to appear on the Department of Health and Human Services’ Office for Civil Rights Breach portal so it is unclear how many individuals have been impacted.

The post Ransomware Attack Investigation Reveals 15-Month Security Breach appeared first on HIPAA Journal.

Rosalind Franklin University of Medicine and Science Phishing Attack Sees PHI Compromised

The protected health information of 859 patients of Rosalind Franklin University of Medicine and Science (RFU) has been compromised and potentially been viewed/stolen. The information was stored in two email accounts that were accessed by unauthorized individuals in May.

Access to the email accounts was gained after employees responded to phishing emails. The phishing attack occurred on May 10, 2017 prompting a full investigation. The malicious actors behind the phishing scam gained access to one email account for less than a day and the second email account for a period of 9 days. Access to the second email account was blocked on May 19.

Third party security experts were brought in to assist with the investigation to help determine the full extent of the security breach. RFU is now certain that unauthorized access to sensitive data has been blocked. Part of the investigation involved checking all messages in the compromised email accounts for protected health information.

The investigation confirmed that the compromised PHI was limited to patients’ names, addresses, dates of birth, telephone numbers, medical record numbers, diagnostic information and lab test results. No social security numbers or financial information were compromised.

RFU says it has received no reports of any misuse of information in the accounts, although affected individuals have been advised to remain vigilant and to check their credit reports, account statements and Explanation of Benefits statements for any sign of fraudulent activity.

RFU has reassured patients that security measures had been introduced prior to the attack to protect data stored in its systems and proactive steps have now been taken to address the incident and strengthen security to prevent further successful phishing attacks. RFU has reported the incident to the FBI which is investigating.

An RFU spokesperson said, “The confidentiality, privacy, and security of information within our care is one of our highest priorities.”

The post Rosalind Franklin University of Medicine and Science Phishing Attack Sees PHI Compromised appeared first on HIPAA Journal.

Detroit Medical Center Discovers Agency Employee Disclosed Patients’ PHI

Detroit Medical Center has discovered an employee has stolen the protected health information of as many as 1,529 patients and impermissibly disclosed that information to a third party.

Detroit Medical Center became aware of the security breach when the staffing agency that supplied the employee contacted DMC to report that it had discovered protected health information had been obtained and provided to an third party.

DMC is part of the Tenet Healthcare system and runs eight hospitals and institutions in Detroit and southeast Michigan. DMC has not released information on the specific medical center where the employee worked or that individual’s role.

The types of information that were stolen and disclosed were also not made public. However, DMC has issued a statement confirming the data theft and disclosure have been reported to law enforcement and that the hospital is cooperating fully with the police investigation.

Upon hearing of the unauthorized disclosure, Detroit Medical Center conducted a thorough internal investigation, which included a review of all medical records that could potentially have been accessed by the employee. The employee’s login to systems containing PHI has been blocked and the employee has been terminated.

Detroit Medical Center determined that patients impacted by the security breach had visited a DMC facility for treatment between March 2015 and May 2016. Those individuals have now been notified by mail that their PHI has been compromised and have been offered credit monitoring services for 12 months without charge through AllClear.

If employees are given access to PHI in order to complete work duties there is always a risk that data access rights will be abused. It is therefore important for healthcare organizations to monitor PHI access logs regularly to check for inappropriate access. Detroit Medical Center did have monitoring systems in place, although the security breach has prompted DMC to modify monitoring programs to ensure any future incidents are detected rapidly.

The post Detroit Medical Center Discovers Agency Employee Disclosed Patients’ PHI appeared first on HIPAA Journal.

Ivinson Memorial Hospital Affected by FastHealth Security Breach

A data breach experienced by FastHealth, a vendor of website services, has impacted more than 500 patients of Ivinson Memorial Hospital in Laramie, WY.

Access was gained to a web server used by FastHealth and the attackers altered code on the website to capture billing and health information submitted by patients in online forms.

The breach does not affect all patients, only those that used the online bill-pay platform or completed new patient intake forms between January 14, 2016 and December 20, 2016. The security breach was discovered by FastHealth on December 21, 2016 and a third-party security firm was contracted to conduct an investigation. Forensic investigations can take some time to conduct, although it is unclear why it took almost 5 months for FastHealth to notify organizations about the breach.

The Laramie Boomerang reports that Ivinson Memorial Hospital was informed about the security breach on May 15, 2017. Patients are just being notified of the breach as it took time for Ivinson Memorial Hospital to verify the information sent by FastHealth. Ivinson Memorial Hospital says it wanted to make sure that the information it received about the breach was correct before making an announcement and notifying its patients.

The breach has prompted Ivinson Memorial Hospital to look for a new website vendor and will be terminating the contract with FastHealth as soon as possible.

The Fast Health data breach does not only impact individuals from Ivinson Memorial Hospital. Fast Health provides website services to many healthcare organizations with more than 100 hospitals across the United States understood to have been affected by the security breach, according to the Laramie Boomerang.

Heart of the Rockies Regional Medical Center in Salida, CO was also impacted by the breach and was recently notified by FastHealth. Its patients have been informed that their names, dates of birth, email addresses, billing addresses, phone numbers, account numbers, payment card numbers, expiration dates and CVV security codes were compromised as a result of the breach.   Heart of the Rockies Regional Medical Center has now found an alternate vendor to provide its online payment and registration platform.

The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates 9,289 individuals were impacted by the security breach at FastHealth.

The post Ivinson Memorial Hospital Affected by FastHealth Security Breach appeared first on HIPAA Journal.

PHI of 15,000 UC Davis Health Patients Compromised in Phishing Attack

University of California Davis Health is alerting almost 15,000 patients that their PHI may have been viewed as a result of an employee falling for a phishing scam.

The incident occurred on May 15, 2017. A phishing email was sent to a UC Davis Health employee who responded and unwittingly gave the attacker login credentials to his/her email account. That email account was accessed by the attacker on May 17.

It is possible that the attacker accessed the employee’s email messages and viewed and/or obtained patients’ PHI. The investigation did not uncover any evidence to suggest that any patients’ PHI was viewed, although it was not possible to rule out the possibility with a high degree of confidence.

On May 17, the attacker used the email account to send emails to other staff members requesting bank transfers for large sums of money. The emails were recognized as fraudulent and were reported to the data security team which secured the email account to prevent further access. Since access to the email account was rapidly blocked it is possible that PHI was not viewed or copied by the attacker. However, out of an abundance of caution, affected individuals have been notified of the breach.

The employee had previously conducted various informational mailings and was required to perform other actions that required a limited amount of patients’ PHI. Consequently, the email account contained some PHI.

In most cases, the PHI in the email account was limited to patients’ names’ addresses, and phone numbers, although some patients’ Social Security numbers, medical record numbers and diagnoses were also potentially compromised.

Individuals whose sensitive information was exposed have been offered credit monitoring and identity theft protection services without charge for 12 months.

UC Davis Health says the phishing email was delivered to the employee’s inbox even though security measures had been introduced to block spam and phishing emails. An intrusion detection solution had been installed, but failed to detect fraudulent use of the email account. Staff at UC Davis Health are also provided with security awareness training to raise awareness of phishing and other threats.

UC Davis Health is now evaluating its security controls and training program and is considering augmenting its security protections to improve resilience against phishing attacks.

The incident has been reported to the Department of Health and Human Services’ Office for Civil Rights. The breach report indicates 14,900 individuals were impacted by the security breach.

The post PHI of 15,000 UC Davis Health Patients Compromised in Phishing Attack appeared first on HIPAA Journal.