HIPAA Breach News

Email Error Impacts 6,500 Saliba’s Extended Care Pharmacy Patients

Saliba’s Extended Care Pharmacy in Phoenix, Arizona is alerting more than 6,500 patients to an accidental disclosure of some of their protected health information (PHI).

A copy of invoices for December 2016 was sent via Saliba’s Pharmacy’s encrypted email platform to the wrong patients in January. While there is no chance that the emails could have been intercepted by unauthorized individuals, the emails were opened by three patients or their representatives. The incident occurred on January 12, 2017, and Saliba’s Pharmacy discovered the error four days later on January 16.

Since HIPAA Rules and patient privacy were accidentally violated, breach notification letters were sent to patients on March 3 to alert them to the incident. Patients have been advised to exercise caution and check their explanation of benefits statements and Saliba’s Pharmacy statements for signs of misuse. However, no reports of any misuse of the information have been received by Saliba’s Pharmacy and the risk of PHI misuse as a result of this impermissible disclosure is believed to be very low.

Patients affected by the incident have been told that the information disclosed was limited to names, addresses, and account balances. Some patients also had descriptions and amounts of over-the-counter medications and other pharmacy items detailed in the invoices. The invoices did not contain highly sensitive PHI such as Social Security numbers, health insurance information or financial information.

President of Saliba’s Pharmacy, John Saliba, issued a statement saying privacy breaches such as this are treated very seriously. The employee who made the error has been terminated and additional training has been provided to staff members. Policies and procedures at the pharmacy have also been updated to prevent similar incidents from occurring in the future and to ensure the protected health information of patients is better protected.

According to the breach report submitted to the Department of Health and Human Services’ Office for Civil Rights, 6,599 patients were impacted by this incident.

The post Email Error Impacts 6,500 Saliba’s Extended Care Pharmacy Patients appeared first on HIPAA Journal.

Sharp Healthcare Says Stolen Devices Contained PHI of Patients

A computer and an external storage drive have been discovered to have been stolen from San Diego-based healthcare provider Sharp Healthcare.

The devices were taken from a locked cabinet in an access-controlled patient treatment area of the Sharp Memorial Outpatient Pavilion in Kearny Mesa in San Diego, CA. It is not known when the devices were taken, although they were discovered to be missing on February 6, 2017.

The devices were used to store the data of patients who had undergone wellness screening as part of blood pressure and cardiac health studies performed at the outpatient center. The types of data stored on the devices includes patients’ full names, ages, dates of birth, medications currently being taken, a summary of the studies that were being performed and family health histories. The devices were not encrypted, so it is possible that the patient health information stored on both devices could be accessed by unauthorized individuals.

An internal investigation was conducted when the devices were discovered to be missing and efforts were made to locate the devices, although the investigation suggested the devices had been stolen. Law enforcement has been notified of the theft, although the equipment has not yet been discovered.

In response to the incident, Sharp Healthcare is reviewing its security practices and will be implementing a number of additional safeguards to prevent further incidents of this nature from occurring.

The Department of Health and Human Services’ Office for Civil Rights and the California Department of Public Health have been notified of the breach. 750 current and former patients are understood to have been impacted by the incident. All patients have already been notified by mail in accordance with Health Insurance Portability and Accountability Act Rules.

The post Sharp Healthcare Says Stolen Devices Contained PHI of Patients appeared first on HIPAA Journal.

Improper Disposal of PHI Discovered by Minneapolis Heart Institute

A member of a cleaning crew at the Minneapolis Heart Institute at Abbott Northwestern Hospital accidentally disposed of documents containing PHI with regular trash.

Minneapolis Heart Institute has policies and procedures in place that require all documents containing sensitive patient health information to be securely destroyed in accordance with HIPAA Rules. However, a member of the cleaning team was discovered to have emptied a trash container from a physician’s private office before documents could be securely shredded.

The incident was discovered on January 20, 2017, although not in time for the documents to be recovered and securely destroyed. The documents had been emptied into a bin bag which was placed in a regular recycling dumpster at the hospital.

It is unclear at this stage how many individuals have been impacted, although as a precaution, the Minneapolis Heart Institute is notifying all patients who were part of the physician’s service group between April 17, 2016 and January 17, 2017. Those individuals have been offered credit monitoring and identity theft protection services without charge for a period of 12 months, even though the risk of any PHI being accessed by unauthorized individuals is believed to be very low.

The documents contained PHI including names, addresses, birth dates, medical record numbers, clinical data, and health insurance information. Some health insurers use Social Security numbers as health plan identifiers; therefore, some Social Security numbers may also have been on the documents.

The incident shows that policies and procedures alone will not always prevent breaches of this nature from occurring. However, the action taken following the incident by Allina Health, which operates Abbott Northwestern Hospital, should prevent any further such incidents from occurring in the future.

Allina Health has removed all desk-side recycling bins and has replaced them with locked shredding bins. Now, all documents will be sent for shredding, irrespective of whether they contain sensitive data. An employee education program has also been conducted to advise employees of the need to shred all paperwork and Allina Health’s safeguards policy has also been reinforced, highlighting the importance of the correct disposal of documents.

The post Improper Disposal of PHI Discovered by Minneapolis Heart Institute appeared first on HIPAA Journal.

Healthcare Employee Accessed ePHI Without Authorization for 5 Years

Healthcare professionals must have access to the protected health information of patients in order to provide medical care and perform healthcare operations.

Since access to data can be abused by rogue employees, it is essential that controls are put in place to alert healthcare organizations rapidly when improper access occurs. Rapid identification of improper access can greatly reduce the harm caused.

In many cases, improper access is discovered during routine audits of access and application logs. When those audits are conducted on an annual basis, employees may be found to have been improperly accessing patient data for many months.

Last month, Chadron Community Hospital and Health Services in Nevada discovered that a rogue employee had been accessing ePHI without any legitimate work reason for doing so. What makes this incident stand out, is how long access had been allowed to continue before it was discovered.

An investigation conducted by the healthcare provider revealed that the improper access had gone unnoticed for more than 5 years. During that time, the records of more than 700 patients had been accessed by the employee. The report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates 702 individuals had their privacy violated by the employee.

Chadron Community Hospital and Health Services first learned of the privacy breach on January 3, 2017. The investigation into the employee’s activities showed medical records were first improperly accessed in September 2011 and that HIPAA-violating activity had continued until November 2016. The types of information accessed included names, addresses, dates of birth, demographic information, clinical information such as medical diagnoses, orders and physicians’ notes, some financial data and insurance information. No Social Security numbers are believed to have been viewed.

It is not clear why the employee accessed the information out of curiosity or if data were viewed with malicious intent. The individual is no longer employed by Chadron Community Hospital and Health Services. The dates of access suggest the employee had left the healthcare organization prior to the improper access being discovered.

Insider threats are a major concern for healthcare security staff. A recent Dimensional Research/Preempt survey showed that almost half of IT security professionals are more concerned about internal attacks than external threats. The network perimeter can be secured, although monitoring for improper access by employees can be a challenge.

HIPAA Rules require covered entities to maintain access logs and conduct periodic reviews of those logs to monitor for improper access. HIPAA does not state how often those logs must be checked, although it would be difficult to argue that regular, thorough checks were conducted if an employee was able to evade detection for more than 5 years. Such a long period of improper access is certain to attract the attention of Office for Civil Rights’ investigators.

The post Healthcare Employee Accessed ePHI Without Authorization for 5 Years appeared first on HIPAA Journal.

Vendor Configuration Error Results in Exposure of 14,000 Individuals’ ePHI

A major breach of electronic protected health information has been discovered by Universal Care, dba, Brand New Day – A Medicare approved Health Plan.

The incident occurred on December 22, 2016 and was discovered six days later on December 28, 2016. Brand New Day became aware that an unauthorized individual had gained access to the ePHI provided to one of its HIPAA business associates. Access to ePHI was gained via a third-party vendor system used by Brand New Day’s contracting provider.

The breach notification submitted to the California Attorney General does not indicate whether the ePHI of plan members was stolen, although the data were accessed and a criminal investigation into the breach has been launched by law enforcement. The types of data accessed include plan members’ names, addresses, phone numbers, dates of birth and Medicare ID numbers.

Upon discovery of the incident, Brand New Day immediately launched an investigation and contacted its vendor to ensure that access to ePHI was immediately terminated. The vendor was informed that someone had improperly accessed plan members’ data and rapid action was taken to block access. Brand New Day says the error that allowed ePHI to be accessed was eliminated ‘within hours’ of the vendor being notified of the breach.

While no specific mention of the exact nature of improper access was made, Brand New Day says “We changed our practices regarding access requiring monthly verification of each user.” Brand New Day is also performing a thorough ‘self audit’ to determine whether any other errors have occurred that jeopardize the confidentiality, integrity and availability of ePHI.

As a precaution against identity theft, all affected individuals have been offered 12 months’ complimentary identity theft mitigation services via Experian.

The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates 14,005 individuals were impacted by the incident. Brand New Day says it delayed the issuing of breach notification letters so as not to interfere with the criminal investigation of the breach.

HIPAA and Business Associates

Before any electronic protected health information is provided to a business associate, a signed copy of a business associate agreement must be obtained. The business associate agreement should explain the need to comply with the HIPAA Privacy, Security, and Breach Notification Rules and the need to implement safeguards to ensure the confidentiality, integrity, and availability of ePHI is not put at risk. The BAA should also explain the procedures for notifying the covered entity in the event of a breach of ePHI.

A BAA will not necessarily prevent breaches of ePHI, although it will ensure that business associates are aware of their responsibilities to safeguard ePHI and issue notifications in the event of a breach. Should any violation of HIPAA Rules occur, it would likely be the business associate that is liable, rather than the covered entity. Since the introduction of the HIPAA Omnibus Rule, business associates of HIPAA covered entities can be fined directly by OCR and state attorneys general if HIPAA Rules are discovered to have been violated.

The post Vendor Configuration Error Results in Exposure of 14,000 Individuals’ ePHI appeared first on HIPAA Journal.

North Carolina Department of Health and Human Services Email Breach Impacts 12,700

The North Carolina Department of Health and Human Services has announced that the names, addresses, and Medicaid numbers of 12,731 patients were exposed as a result of an email error. The data were sent via email to adult care homes last year, but the emails were not encrypted. Potentially, the emails could have been intercepted and the data obtained by individuals unauthorized to view the information.

The emails were sent on November 30, 2016 and the Department of Health and Human Services’ Office for Civil Rights has now been notified of the incident. No mention has been made of when the incident was discovered.

This is the third such incident of this nature to have affected the NC Department of Health and Human Services in the past 38 months.

On December 30, 2013, 49,000 Medicaid cards of minors were accidentally mailed to incorrect recipients, exposing Medicaid numbers, names and birth dates. The privacy breach was attributed to human error. Two years later, 1,615 patients were impacted when an unencrypted email containing was sent to the Granville County Health Department. The email contained a spreadsheet containing names, Medicaid ID numbers, provider’s name and ID number, and other Medicaid related information.

The two email incidents are not believed to have resulted in any individual’s data being compromised. No indications that the emails were intercepted has been found by the NC Department of Health and Human Services, although the possibility cannot be ruled out. Individuals affected by the latest incident have been advised to monitor their accounts for any signs of fraud as a precaution.

In order to prevent similar security breaches from occurring in the future, policies and procedures have now been changed. Rather than emailing Medicaid numbers and names, identification numbers will be used in future. Should any email messages be intercepted, it would not be possible for patients to be identified.

The post North Carolina Department of Health and Human Services Email Breach Impacts 12,700 appeared first on HIPAA Journal.

Vanderbilt University Medical Center Employees Inappropriately Accessed 3,000 Patients’ PHI

Two employees of Vanderbilt University Medical Center have been discovered to have inappropriately accessed the medical records of more than 3,000 patients.

The inappropriate ePHI access was discovered during a routine audit of access logs: A requirement of the Health Insurance Portability and Accountability Act (HIPAA).

While the HIPAA Security Rule requires audit logs to be regularly reviewed by HIPAA-covered entities, in this case the inappropriate accessing of ePHI continued for 19 months before it was detected.

Vanderbilt University Medical Center first became aware of inappropriate ePHI access on December 27, 2016, prompting a full audit of access logs.

That audit revealed that two patient transporters at the medical center had viewed more information than was necessary in order for them to perform their work duties. The employees were required to move patients between treatment rooms and hospital floors. The pair were discovered to have first started viewing patients protected health information in May 2015. Medical records of patients continued to be accessed until December 2016.

The types of information accessed included patients’ names, medical record IDs, and birth dates. According to a press release from VUMC, one individual was also able to view some patients’ Social Security numbers. While patients’ electronic medical records were accessed, VUMC does not believe that any information has been copied or misused. VUMC has not said why patients’ health information was viewed by the employees, although the individuals concerned have been disciplined for their actions.

Patients are not believed to be at any elevated risk of suffering identity theft or fraud as a result of the privacy breaches. However, as a precaution, VUMC said “we are contacting each of them by letter to recommend that they vigilantly review account statements and their credit status.” Any patient whose Social Security number has been viewed is being provided with credit monitoring services via Experian Family Secure “out of an abundance of caution.”

In response to the breach, Vanderbilt University Medical Center has changed policies and procedures relating to how patient transporters are provided with patients’ health information. Any PHI needed for patient transporters to conduct their work duties will now be provided on paper. Access to its medical record system will no longer be provided. Patient transporters have also received further training relating to the accessing of patient health information.

The post Vanderbilt University Medical Center Employees Inappropriately Accessed 3,000 Patients’ PHI appeared first on HIPAA Journal.

Berkeley Medical Center Employee Inappropriately Accessed 7,445 Patients’ Records

A Berkeley Medical Center employee has been discovered to have inappropriately accessed the electronic protected health information of more than 7,400 patients over a period of 10 months.

WVU Medicine University Healthcare discovered the inappropriate accessing of ePHI by an employee of the Berkeley Medical Center on January 17, 2017 after being alerted to potential data theft by law enforcement. A joint investigation into the employee had been conducted by the FBI and the Berkeley County Sheriff’s Department.

As soon as WVU Medicine University Healthcare became aware of the incident, an internal investigation was launched. Two days later, the employee was suspended pending the outcome of the investigation. Information provided to the healthcare provider from law enforcement linked the employee with 113 former patients who had suffered identity theft.

The healthcare worker had been employed by WVU Medicine University Healthcare since March 2004 and was required to schedule appointments for patients at both the Berkeley Medical Center in Martinsburg, WV and Jefferson Medical Center in Ranson, WV. The investigation revealed that the inappropriate accessing of medical records first occurred on March 1, 2016. Inappropriate access continued until the notification was received by law enforcement.

No evidence was uncovered to suggest that the employee copied ePHI onto a portable device, although Teresa McCabe, vice president of marketing and development, said the employee manually copied data from computer screens and removed that information from the premises. A link between 113 patients and the employee was found, although in total, 7,445 breach notification letters were sent to patients informing them of unauthorized ePHI access.

After the investigation confirmed that hospital and HIPAA Rules had been violated, WVU Medicine University Healthcare terminated the employee. A criminal investigation is ongoing and the woman is being prosecuted.

The female employee was found to be in possession of driver’s licenses with photos and insurance and Social Security cards, suggesting the stolen information had already been used for identity theft. It is unclear whether those identification documents have been used to fraudulently obtain credit or medical services.

All individuals impacted by the incident have been offered credit monitoring and identity theft protection services for a period of one year via Kroll. Patients have been encouraged to check their accounts, credit histories, and EoB statements and to alert their financial organizations to the possibility of fraudulent use of their information.

HIPAA Requires Regular Reviews of ePHI Access Logs

Inappropriate accessing of patients’ medical records by healthcare employees occurs frequently, although this incident stands out due to the number of patients potentially impacted and how long it took for the HIPAA violation to be discovered – almost 10 months.

According to a statement released by WVU Medicine University Healthcare, “Because the former employee had access to this information as part of her employment as an authorization/prescheduling coordinator, her criminal conduct could not be detected as part of University Healthcare’s routine IT/privacy security checks.”

The HIPAA Security Rule (Security Management Process) requires healthcare originations to maintain ePHI access logs and to regularly check those logs for signs of inappropriate access. An Information System Activity Review should be conducted regularly. Audit logs, access reports and security incident tracking reports should be reviewed – § 164.308(a)(1)(ii)(D).

When healthcare employees are found to have accessed information without a legitimate work reason for doing so, it sends a message to other employees that their actions are being carefully monitored. This helps to establish a culture of responsibility and accountability. Prompt identification of inappropriate ePHI access will also ensure that patients can be notified in time to prevent their stolen information from being used to steal identities and commit medical fraud.

The post Berkeley Medical Center Employee Inappropriately Accessed 7,445 Patients’ Records appeared first on HIPAA Journal.

Theft, Hacking, Ransomware and Improper Accessing of ePHI – Attacks Coming from All Angles

Theft, hacking, ransomware, and improper ePHI access by employees – The past few days have seen a diverse range of healthcare data breaches reported.

St. Joseph’s Hospital and Medical Center in Arizona, Family Service Rochester of Minnesota, and the University of North Carolina have all reported potential breaches of patients’ ePHI, while Lexington Medical Center in South Carolina has announced that the sensitive data of its employees have been viewed.

University of North Carolina Reports Theft of Dental Patients’ ePHI

A laptop computer and a SD memory card from a digital camera have been stolen from the car of a postgrad dental resident of the University of North Carolina School of Dentistry. While the devices should have had a number of security measures installed to prevent improper data access, UNC has been unable to confirm whether that was the case. The breach may have resulted in the exposure of around 200 patients’ personal information including full face photographs (without any other PHI), names, dates of birth, dental record numbers, treatment plans, dental and health histories, and referral letters including contact information.

Affected patients have been offered one year of credit monitoring services, staff have been retrained on the proper procedures for storing patient health information and disciplinary sanctions have been imposed on the individual who had been issued with the devices.

Family Services Rochester: Systems Hacked; ePHI Potentially Viewed; Data Encrypted

Family Services Rochester in Minnesota has discovered that some of its systems were compromised by a hacker. The accessed part of its computer system contained a range of sensitive electronic information including names, addresses, dates of birth, Social Security numbers, driver’s license numbers, medical insurance numbers and medical information.

Access to the computer system was first gained on December 26, 2016 and continued until January 25, 2017, when the attacker installed ransomware that encrypted a range of sensitive data. The incident is being investigated internally and by law enforcement and affected individuals have been offered credit monitoring services to protect them against identity theft.

St. Joseph’s Hospital and Medical Center Breach: Improper Access by Employee

The electronic protected health information of 623 patients of Dignity Health’s St. Joseph Hospital and Medical Center in Phoenix, AZ., has been improperly accessed by one of the center’s employees. The part-time employee was discovered to have accessed the records of patients without any legitimate work purpose for doing so between October 1, 2016 and November 22, 2016. The types of data accessed include patients’ names, demographic data, diagnostic information, clinical information (including doctor’s orders) and medication records. No Social Security numbers or financial data were accessed. The employee in question is not believed to have accessed the records with malicious intent and patients are not believed to be at risk of identity theft.  Dignity Health says “appropriate action has been taken in response to the event.”

Lexington Medical Center – Employee Information Accessed by an Unauthorized Individual

Lexington Medical Center, in Lexington, SC., has discovered that a database – eConnect/Peoplesoft – containing the sensitive information of employees has been accessed by an unauthorized individual. The database contained the types of information criminals seek when sending W-2 Form phishing emails. In this case, the database does not appear to have been accessed as a result of an employee falling for such a scam. The data accessed includes the names and Social Security numbers of employees, but no patient information. Action has been taken to secure the database to prevent further access by unauthorized individuals.

Healthcare Data Breaches Reported to Office for Civil Rights in February 2017

Other recent healthcare data breaches reported to the Department of Health and Human Services Office for Civil Rights in February include:

 

Covered Entity Location Entity Type Records Breached Cause of Breach
Universal Care, Inc. DBA Brand New Day CA Health Plan 14,005 Unauthorized Access/Disclosure
Family Medicine East, Chartered KS Healthcare Provider 6,800 Theft
Walgreen Co IL Healthcare Provider 4,500 Unauthorized Access/Disclosure
Catalina Post-Acute Care and Rehabilitation AZ Healthcare Provider 2,953 Improper Disposal
Jeffrey D. Rice, O.D., L.L.C. OH Healthcare Provider 1,586 Theft
Benesch, Friedlander, Coplan & Aronoff LLP OH Business Associate 1,134 Unauthorized Access/Disclosure
Bloom Physical Therapy, LLC dba Physicians Physical Therapy Service AZ Healthcare Provider 500 Unauthorized Access/Disclosure

The post Theft, Hacking, Ransomware and Improper Accessing of ePHI – Attacks Coming from All Angles appeared first on HIPAA Journal.