HIPAA Breach News

OCR’s Wall of Shame Under Review by HHS

Since 2009, the Department of Health and Human Services’ Office for Civil Rights has been publishing summaries of healthcare data breaches on its website. The data breach list is commonly referred to as OCR’s ‘Wall of Shame’.

The data breach list only provides a brief summary of data breaches, including the name of the covered entity, the state in which the covered entity is based, covered entity type, date of notification, type of breach, location of breach information, whether a business associate was involved and the number of individuals affected.

The list includes all reported data breaches, including those which occurred due to no fault of the healthcare organization. The list is not a record of HIPAA violations. Those are determined during OCR investigations of breaches.

Making brief details of the data breaches available to the public is an ‘unnecessarily punitive’ measure, according to Rep. Michael Burgess (R-Texas), who recently criticized OCR about its data breach list.

Burgess was informed at a cybersecurity hearing last week that HHS secretary Tom Price is currently reassessing the website and how the information is made public.

While the publication of information is under review, the publication of breach summaries is a requirement of the HITECH Act of 2009. Any decision to stop publishing breach summaries on the website would require assistance from Congress. However, it is possible for changes be made to how the information displayed and for how long the information is made available. HITECH Act only requires the information to be published. It does not stipulate the length of time that the covered entity remains on the list.

The reason behind the publication of breach information is to inform the public of data breaches and to provide some information on what has occurred. If there was a time limit placed on the length of time a covered entity remained on the list, it would not be possible for a member of the public to determine whether a breach was an isolated event or one of several suffered by a covered entity.

OCR Director Roger Severino issued a statement confirming the usefulness of the website saying, “The website provides an important source of information to the public, but we recognize that the format has become stale and can and should be improved,” explaining “OCR will continue to evaluate the best options for communicating this information as we meet statutory obligations, educate the regulated community (and the public) on lessons learned, and highlight actions taken in response.”

Burgess told Fierce Healthcare, “I am interested in pursuing solutions that hold hospital systems accountable for maintaining patient privacy without defaming systems that may fall victim to large-scale ransomware attacks, such as WannaCry.”

Of course, in the case of the WannaCry attacks, healthcare organizations may not be blameless. The attacks were only possible as a result of the failure to apply patches promptly. However, in its current form, there would be no indication on the website that a covered entity had experienced a ransomware attack as the breach list does not go into that much detail.

While options are being considered, some privacy advocates argue that the breach portal does not go into nearly enough detail and suggest even more information should be uploaded to the site to better inform the public on exactly what has occurred.

The post OCR’s Wall of Shame Under Review by HHS appeared first on HIPAA Journal.

Sound Community Services Discovers Email Account Breach

New London, CT-based Sound Community Services Inc., a not-for-profit provider of education, support and assistance for individuals with persistent mental illness and/or substance abuse disorders has discovered an unauthorized individual has gained access to an employee’s email account.

Suspicious activity was detected on the email account on January 13, 2017. An investigation was immediately launched and access to the email account was blocked. The investigators determined access to the email account had been gained the previous day.

A forensic investigation into the security breach was conducted, although the identity of the unauthorized individual could not be determined. The email account was discovered to contained the protected health information of 1,278 individuals.

No information has been released detailing how the unauthorized individual gained access to the email account, although this type of security breach is commonly caused as a result of employees responding to phishing emails and disclosing their email credentials.

While it is possible that patient information was accessed by the unauthorized individual, no evidence has been uncovered to suggest emails in the account were opened and viewed and no reports have been received to suggest any exposed information has been obtained and misused. Fortunately, the information in the emails was limited, with only names and client numbers exposed. One individual also had details of referring information exposed.

The review of the email accounts was only completed on April 18, hence the delay in issuing notifications. The Department of Health and Human Services’ Office for Civil Rights was notified of the breach on May 26.

Even though the information exposed was limited, all affected individuals have been offered 24 months of identity protection services without charge. Those individuals are being notified of the breach by mail and are being provided with background information on the incident.

Sound Community Services will be implementing new controls to ensure similar incidents are prevented in the future.

The post Sound Community Services Discovers Email Account Breach appeared first on HIPAA Journal.

Double Burglary Sees Connecticut Patients’ PHI Exposed

SouthWest Community Health Center, a Bridgeport, CT network of health centers, has alerted patients that some of their protected health information has been exposed after burglars targeted two of its facilities.

Several computers were stolen in a double burglary at its 1046 Fairfield Avenue and 10 Clinton Avenue sites. Thieves first broke into the Fairfield Avenue facility on Saturday 8, April and stole four desktop computers and a laptop. The following weekend, the Clinton Avenue health center was broken into and two laptop computers were stolen.

Both facilities had security alarms which were triggered when the offices were entered. Law enforcement responded immediately in both cases, but the perpetrators had fled the scene.

The burglaries were not believed to have been conducted in order to gain access to patients’ protected health information, only for the value of the computer hardware that was stolen. However, it is possible that the thieves or other unauthorized individuals were able to view the information stored on the devices. The data stored locally on the devices were not encrypted.

SouthWest Community Health Center reconstructed the data stored on the computers to determine which patients’ protected health information had been exposed. The investigation revealed patients’ names, dates of birth, bank account numbers, Social Security numbers, insurance information and medical information, including diagnoses, treatment and admission information had been saved on the hard drives.

Due to the sensitive nature of exposed information, all affected patients have been offered identity theft monitoring and restoration services without charge for a period of 12 months. SouthWest Community Health Center is also reviewing security at its health centers to prevent future burglaries and is working closely with law enforcement and other third parties in this regard.

The incident has been reported to the Department of Health and Human Services’ Office for Civil Rights, although since the incident has yet to appear on the OCR breach portal it is unclear exactly how many patients have been impacted.

The post Double Burglary Sees Connecticut Patients’ PHI Exposed appeared first on HIPAA Journal.

Austin Medical Center Discovers Patient Data Was Accessible Via Internet

An Austin, TX medical center has discovered patient data has been stolen and uploaded to the Internet and was accessible for 4 years. The information, which related to approximately 2,000 patients, could freely be found via search engines.

Victory Medical Center was alerted to the data leak on April 5, 2017 by a patient who had found his or her personal information online while browsing the Internet.

An investigation was launched by Victory Medical which revealed a paper based report containing patient information had been uploaded to Github by an unauthorized individual. The data was taken and uploaded without the knowledge or authorization by Victory Medical. The company says the breach was likely the work of a ‘lone bad actor’.

The date of the breach is not known, although it is likely the incident occurred on or after June 10, 2013 according to the substitute breach notice uploaded to the Victory Medical website. The report had been generated from Victory Medical’s secure patient record system, although it did not include any medical information.

The types of information exposed and likely viewed by unauthorized individuals was restricted to patients’ names, phone numbers, addresses, email addresses, preferred language, race and ethnicity and internal medical account numbers. Victory Medical contacted Github and arranged for the information to be removed. The information was taken offline five days later.

Since only demographic information has been exposed, Victory Medical believes the risk of improper use of the information is low.

The breach investigation involved interviews with all members of staff who were working at or around the time of the suspected breach, although the person responsible for the breach could not be identified.

The breach has prompted a review of privacy practices, policies and security procedures that could potentially have contributed to the breach, although no systemic weaknesses have been identified. Physical security standards are also being reviewed at the organization’s offices and feasible changes will be implemented to improve security and prevent future breaches of PHI.

The post Austin Medical Center Discovers Patient Data Was Accessible Via Internet appeared first on HIPAA Journal.

WannaCry Ransomware Continues to Cause Problems for U.S. Hospitals

The Department of Health and Human Services (HHS) has issued a cyber notice to alert healthcare organizations of the continuing problems caused by the WannaCry ransomware attacks on May 12, 2017.

Following the attacks, the United States Department of Homeland Security (DHS) issued a statement saying the U.S. had suffered ‘limited attacks’ with only a small number of companies affected. However, the problems caused by those attacks have been considerable. The HHS says two large, multi-state hospital systems are still facing significant challenges to operations as a result of the May 12 attacks.

The Windows SMB vulnerability (MS17-010) exploited by the threat actors was addressed by Microsoft in a March 14, 2017 update, with an emergency patch released for unsupported Windows versions shortly after the attacks took place. The patches will prevent the MS17-010 vulnerability from being exploited and thus prevent WannaCry from being downloaded.

The encryption routine used by the WannaCry malware was deactivated quickly following the discovery of a kill switch. While the encryption process has been blocked, that does not stop infection. Vulnerable devices could still be infected if the patch has not been applied.

Further, if a device has already been infected prior to the patch being applied, the malware will still be present on the infected system. The HHS likens the patch to quarantining a patient. While that action will prevent the spread of the infection to other individuals, simply placing a patient in quarantine will not remove the infection in that patient.

While the ransomware component of the malware is not active, the presence of the malware on computer systems will have some effects. Those are dependent on the Windows version installed.

If the malware is present, it will be capable of scanning the network for other vulnerable devices and spreading to those devices.

The HHS says that if a device has been infected with WannaCry, reimaging and applying the patch will remove the virus and prevent it from being installed again. However, HHS explains that while the patch addresses a vulnerability in the Windows Server Message Block version 1 (SMBv1) protocol, that may not be the only vulnerability that is exploited to download WannaCry. Even patched systems may still be infected if the threat actors exploit a different vulnerability to introduce the malware. Patches must therefore be applied promptly after they have been issued to prevent future WannaCry – and other – malware attacks.

If you have been affected by WannaCry, the HHS recommends contacting your FBI Field Office Cyber Task Force or the US Secret Service Electronic Crimes Task Force to report the incident and request assistance.

The HHS also recommends contacting the FDA’s 24/7 emergency line at 1-866-300-4374 if a suspected cyberattack affects medical devices.

HHS has issued the following advice to healthcare organizations on mitigating the risk of WannaCry infection:

The post WannaCry Ransomware Continues to Cause Problems for U.S. Hospitals appeared first on HIPAA Journal.

North Dakota Department of Human Services Notifies 2,452 Medicaid Recipients of PHI Exposure

The North Dakota Department of Human Services (NDDHS) is alerting 2,452 Medicaid recipients that some of their protected health information has been exposed when documents were improperly disposed of in a Bismarck dumpster.

The HIPAA breach was discovered on May 19, 2017 when a member of the public saw documents containing sensitive information in a dumpster. The citizen contacted NDDHS about the discovery and an investigation was immediately launched. NDDHS arranged to collect the documents the same day.

The documents were Medicaid worksheets dated 2015. The worksheets did not contain Social Security numbers, financial information or Medicaid recipients’ addresses; however, detailed on the sheets were Medicaid recipients’ first and last names, the first two characters of their Medicaid provider name, Medicaid provider numbers, Medicaid ID numbers, a two-digit code representing the county of residence, an internal NDDHS ID number, dates of service, amounts covered by insurance, amounts billed and allowed, diagnosis codes, coding modifiers and quantity and tooth and surface detail relating to dental work. The information exposed varied for each patient.

The internal investigation into the privacy breach revealed one individual was responsible for dumping the documents and the improper disposal involved no malicious intent. The records were dumped on May 8, 2017, two days prior to them being found by a member of the public.

Since there is a possibility that the documents have been viewed by others, individuals affected by the incident have been offered complimentary credit monitoring and identity theft protection services. However, the potential for re-disclosure of information is believed to be low as all documents have now been recovered and secured. NDDHS said in its press release that no evidence has been uncovered to suggest any information in the documents has been used improperly or further disclosed and that “appropriate disciplinary action has been taken.”

Training had already been provided to staff members on information security and HIPAA Rules. NDDHS is now working with its staff to prevent future incidents of this nature from occurring. The incident has also prompted NDDHS to conduct a review of its policies and procedures for safeguarding the protected health information of Medicaid recipients.

The post North Dakota Department of Human Services Notifies 2,452 Medicaid Recipients of PHI Exposure appeared first on HIPAA Journal.

Plastic Surgery Clinic Employee Suspected of Stealing 15,000 Patient Records

A former employee of a Californian plastic surgery clinic is suspected of stealing the medical records of around 15,000 patients.

The employee worked at the Rodeo Drive clinic in Beverly Hills run by Dr. Zain Kadri. The employee had been employed as a driver and translator since September 2016, but had subsequently been given other duties such as data entry. Allegedly, she quit the practice on May 13 after being accused of embezzlement.

The employee was later discovered to have taken photographs of patients before and during surgical procedures and uploaded those pictures to the image sharing site Snapchat.

Further data theft was uncovered in May while the clinic was transferring paper records to digital files. As part of that process, the clinic checked a company phone used by the former employee. Images were discovered on the device including photographs of patients, but also photographs of patient IDs, usernames and passwords, copies of checks and credit and debit card information. Conversations were also reportedly recorded by the employee. It is unclear how much of that information was shared on social media or was stolen.

The clinic has performed surgeries on several celebrities, many of whom have had their privacy violated. The patients affected by the incident come from 16 U.S. states and four countries. The potential harm from misuse of the information is considerable.

The data theft has been reported to the Los Angeles County Sheriff’s Department and the incident is being investigated. All patients affected by the breach are now being notified that their information may have been stolen. At this stage, it is unclear whether charges will be filed against the former employee.

The post Plastic Surgery Clinic Employee Suspected of Stealing 15,000 Patient Records appeared first on HIPAA Journal.

Trios Health Discovers Employee Accessed EHR Without Authorization for 41 Months

The medical records of 570 Trios Health patients have been accessed by an employee, without authorization, over a period of 41 months.

In March, Trios Health noticed some irregularities in its EHR logs which suggested patient records were being accessed without any legitimate work purpose for doing so. An investigation was launched to investigate and the employee was placed on leave. The investigation revealed the employee had accessed hospital patient records without authorization between October 2013 and March 2017.

The types of information that was viewed included names, contact information, driver’s license numbers, Social Security numbers, dates of service, demographic information and limited medical information such as diagnoses.

Interviews were conducted, although a spokesperson for Trios Health said, “We don’t know the motivation,” although it would appear that no harm was intended by the employee. Trios Health says the risk of information being used inappropriately is low, although credit monitoring and identity theft protection services are being offered to affected patients for 12 months without charge as a precautionary measure.

Trios Health interim CEO said, “We cannot succeed as an organization without holding ourselves and others responsible for mistakes and taking decisive action to address them.”

The employee has now been terminated for violating hospital policies and HIPAA Rules and Trios Health is implementing software that will alert staff to improper ePHI access. EHR restrictions have also been put in place to limit ePHI access, with staff only able to access the records of patients in their own department.

If a member of staff attempts to access the medical records of a patient that they are unauthorized to view, access will be prevented, a popup warning will appear on screen and an alert of attempted ePHI access will be sent to a supervisor. Staff have also received additional privacy training and a new PHI auditing process will be implemented.

The incident has now been reported to the state Attorney General and the Department of Health and Human Services’ Office for Civil Rights. Patients impacted by the breach are being notified by mail.

The post Trios Health Discovers Employee Accessed EHR Without Authorization for 41 Months appeared first on HIPAA Journal.

Molina Healthcare Patient Portal Discovered to Have Exposed Patient Data

Earlier this month, security researcher Brian Krebs was alerted to a flaw in a patient portal used by True Health Group that allowed patients’ test results to be viewed by other patients. While patients were required to login to the patient portal before viewing their test results, a security flaw allowed then to also view other patients’ results.

Now, the Medicaid and Affordable Care Act Insurer Molina Healthcare is investigating a similar flaw in its patient portal that has allowed the sensitive medical information of patients to be accessed by unauthorized individuals. In the case of Molina Healthcare, patients’ medical claims could be accessed without authentication.

Brian Krebs contacted Molina Healthcare to alert the company to the flaw. An investigation was conducted and its patient portal was shut down while the issue was resolved.

It is unclear for how long the flaw existed, whether medical claims had been viewed by unauthorized individuals, and if so, how many patients had their privacy violated. Potentially, the flaw resulted in the exposure of all customers’ medical claims. Molina Healthcare serves 4.8 million individuals in 12 states and Puerto Rico.

The individuals who identified the flaw and reported the issue to Brian Krebs was able to demonstrate it was possible to access other patients’ names, addresses, birthdates, medical procedure codes, prescribed medications and other sensitive data related to health complaints. Anyone with a link to a medical claim could change a digit in the URL and view other individuals’ medical claims.

In contrast to the security flaw at True Health, Brian Krebs said anyone with a link to a medical claim would be able to access the URL without any authentication required. The link could be clicked and the medical claim could be viewed.

On Friday last week, Molina Healthcare issued a statement saying “We are in the process of conducting an internal investigation to determine the impact, if any, to our customers’ information and will provide any applicable notifications to customers and/or regulatory authorities.”

Molina Healthcare has also engaged the services of Mandiant to improve its system security. Molina Healthcare says the security vulnerability in the patient portal has now been remediated.

The post Molina Healthcare Patient Portal Discovered to Have Exposed Patient Data appeared first on HIPAA Journal.