HIPAA Breach News

Horizon BCBS of New Jersey Pays $1.1 Million for HIPAA Violation

The New Jersey Division of Consumer Affairs recently announced that Horizon Blue Cross Blue Shield of New Jersey (Horizon BCBSNJ) has agreed to pay a $1.1 million fine for failing to protect the electronic protected health information of almost 690,000 plan members.

The Health Insurance Portability and Accountability Act (HIPAA) requires covered entities to implement administrative, technical and physical safeguard to protect the ePHI of patients and health plan members. While data encryption is not mandatory technical safeguard, it is an addressable issue. Covered entities must therefore consider the use of encryption technologies to protect ePHI at rest and in motion. If data encryption is not chosen, alternative, security measures must be implemented that offer an equivalent level of protection.

Covered entities are required to conduct a comprehensive risk analysis to identify potential risks to the confidentiality, integrity and availability of PHI. If laptop computers are used to store the ePHI of patients or plan members, a risk assessment should show that there is a risk of ePHI exposure. Appropriate security controls should therefore be put in place to prevent ePHI exposure in the event that the devices are lost or stolen. Data encryption is one method of securing data, although other controls could equally be used. However, the use of a password on its own is insufficient. Passwords do not offer an equivalent level of protection as data encryption.

In November 2013, two laptop computers were stolen from Horizon BCBSNJ offices. The laptops were password protected but ePHI on the devices was not encrypted and no other technical security controls were used to safeguard the data. The laptop computers were secured to desks with security cables, although the thieves cut through those cables and took the laptops.

Data stored on the devices included names and addresses of policy holders, along with insurance identifiers, birth dates, Some Social Security numbers, and a limited amount of clinical data.

The theft occurred over the course of a weekend when work was being conducted on Horizon BCBSNJ offices. A number of external vendors were provided with unsupervised access to the offices, including the area where the laptops were stored.

This was not the first time that an unencrypted laptop computer containing the ePHI of policyholders was stolen from Horizon BCBSNJ. A laptop computer was stolen from the vehicle of an employee in January 2008. Following that incident, Horizon BCBSNJ changed its policies and started using encryption on all laptop computers used to store ePHI. By May 2008, Horizon BCBSNJ announced that the encryption process had been completed. Training on the use of encryption was also provided to company employees to ensure they were aware of the new security controls.

However, during the course of the Division of Consumer Affairs investigation, it was discovered that more than 100 laptop computers used by Horizon BCBSNJ had no encryption, potentially placing ePHI at risk of exposure. The reason provided for the lack of encryption was the laptops computers were obtained via a non-standard procurement process. As a result, the IT department was unaware that the devices had not been encrypted. The devices were also not subjected to monitoring or servicing, as per corporate policies.

Additionally, the Division of Consumer Affairs investigators determined that the employees who had been issued the two laptop computers were not required to store ePHI, and that doing so violated corporate policies.

The investigators concluded that in addition to violations of HIPAA Privacy and Security Rules, Horizon BCBSNJ had also violated the New Jersey Consumer Fraud Act.

In addition to the $1.1 million fine, Horizon BCBSNJ is required to adopt a robust corrective action plan to ensure compliance with HIPAA/HITECH and the New Jersey Consumer Fraud Act. An external professional must be hired to conduct a comprehensive, organization-wide risk analysis covering all devices and systems used to store or transmit ePHI. That risk analysis must be conducted within 180 days of the settlement date, and annually for the next two years. Reports of the findings of the analysis must be submitted to the Division of Consumer Affairs.

Steve Lee, Director of the Division of Consumer Affairs, said “Protecting the personal information of policyholders must be a top priority of every company. Customers deserve it and the law demands it,” He also explained that “Horizon Blue Cross Blue Shield of New Jersey’s alleged security lapses risked exposing policyholders’ most private information to the public, leaving them vulnerable to identity theft.  This settlement ensures that Horizon BCBSNJ will maintain appropriate data privacy and security protocols to prevent future data breaches.”

The post Horizon BCBS of New Jersey Pays $1.1 Million for HIPAA Violation appeared first on HIPAA Journal.

Three Breaches of Physical Medical Records Impact at Least 4,100 Individuals

Three healthcare organizations have recently reported security breaches involving the theft/exposure of physical protected health information. While it is currently unclear exactly how many healthcare patients have been impacted, at least 4,100 individuals are known to have been affected. According to police reports, the total could be as high as 8,000 individuals.

The largest confirmed breach has impacted 2,953 employees and residents of Catalina Post-Acute and Rehabilitation of Tucson, AZ.

The nursing home and rehabilitation center discovered that documents containing the sensitive information of residents and employees had been left unattended and unprotected in a location accessible by the public. A range of sensitive information was detailed in the documents including names, demographic information, Social Security numbers and medical diagnoses.

An internal investigation of the incident was conducted to determine how the information was exposed and the potential for that information to have been inappropriately accessed. No evidence was uncovered to suggest any information had been used inappropriately, although the possibility that PHI was disclosed to unauthorized individuals could not be ruled out.

As a result of the potential privacy breach, Catalina Post-Acute and Rehabilitation has reviewed and reinforced its protocols relating to the storage of physical PHI of residents and employee data to prevent future breaches of this nature from occurring. All affected individuals have now been contacted in accordance with HIPAA Rules.

Storage Unit Break in Impacts Patients of Two Healthcare Organizations

A break-in at a Zanesville, OH storage facility used by multiple healthcare organizations has resulted in the theft of highly sensitive patient health information.

Thieves targeted the Brandywine Lock-N-Stock in Zanesville on December 12, 2016 and broke into 9 storage units. The units were used to keep old patient records, many boxes of which were taken by the thieves.

The units raided by the thieves were rented by Genesis HealthCare/Genesis Credit Union, Dr. Rice of Vision Source, and Capital Prosthetic & Orthotic Center, Inc. Genesis HealthCare and Genesis Credit Union have said that no patients were impacted by the break-in, although several boxes of files were taken from the Vision Care and Capital Prosthetic-rented units.

Capital Prosthetic & Orthotic Center, Inc., said 15 boxes of files were taken from its storage unit, and Vision Care said seven boxes of files were taken.

According to a breach notice issued by Capital Prosthetic, the stored documents contained a range of sensitive information of former patients, including names, addresses, birth dates, medical diagnoses, treatment information, health insurance information and Social Security numbers. Individual impacted by the incident had received medical services at Capital Prosthetic between 2008 and 2012. A statement released by Capital Prosthetic indicates 1,134 former patients had their medical records stolen.

The files taken from the Vision Care unit contained names, Social Security numbers and limited health information. While a substitute breach notice has been uploaded to the Vision Care website, no mention has been made about the number of individuals impacted.

The Zanesville Police Department was notified of the break-in and nine days later some boxes of medical files were recovered. Zanesville Police Department has also identified suspects believed to be responsible for the theft, although no charges against those individuals have been filed as of yet.

According to the Zanesville Times Recorder, detectives estimate that around 3,000 to 5,000 medical files have been recovered. All files relating to Capital Prosthetic patients are believed to have been recovered, according the company’s attorney Cliff Mull. Vision Care also claims that all seven boxes of stolen records have now been recovered and secured.

Both companies say no evidence has been uncovered to suggest that any of the data in the files have been used inappropriately.

The post Three Breaches of Physical Medical Records Impact at Least 4,100 Individuals appeared first on HIPAA Journal.

Faxing Error Sees PHI Sent to Local Media Outlet

Seven doctors’ offices in the Fort Worth area of Texas accidentally faxed patients’ protected health information to the wrong fax number. The faxes contained a range of highly sensitive patient information including names, dates of birth, Social Security numbers, medical histories and much more.

While such a mistake could potentially see patients’ health information fall into the hands of criminals, in this case the errors saw the faxes sent to local media outlet, WFAA.

The faxes received by WFAA related to at least 28 separate patients and should have been sent to Baylor Surgicare of Oakmont. The fax number used by the Fort Worth medical facility was identical to WFAA’s except for a single digit.

In this case, the seven doctors’ offices were contacted and informed of the error and the faxes were securely destroyed, although the incident shows how easy it is for sensitive patient data to be sent to incorrect recipients by fax.

While an incident such as this is unlikely to result in a HIPAA violation penalty from the Department of Health and Human Services’ Office for Civil Rights, such a mistake could potentially cause patients to come to harm. Medical data can be used for a multitude of criminal activities such as extortion, blackmail, and fraud.

The use of faxes to communicate patient health information is commonplace in the United States. Doctors need to communicate information about patients to other healthcare providers, and faxes have long been used to rapidly communicate essential information. The communication method is fast and convenient, although not particularly secure.

Faxes may be misdirected and sensitive health information could be left on fax machines where it can be accessed by unauthorized individuals. The potential for patient privacy violations are considerable.

In certain circumstances, faxes have their uses, although healthcare providers can easily send data more securely. Encrypted email is a much more secure method of communication, while electronic protected health information can be sent safely using a HIPAA-compliant, secure text messaging platform. The latter incorporates authentication controls to ensure information can only be accessed by the intended recipient.

Faxes and pagers have served the healthcare industry well over the years, although more secure methods of communication are now ubiquitous and cost-effective. They also ensure that privacy violations such as this do not occur.

The post Faxing Error Sees PHI Sent to Local Media Outlet appeared first on HIPAA Journal.

South Fulton Mental Heath Center Discovers Dumped Medical Records

Late last week, South Fulton Mental Health Center in Georgia discovered highly sensitive patient health records had been improperly disposed of in a dumpster that was accessible by the public.

A statement released by the clinic shortly after the records were discovered confirmed that an investigation had been launched into the HIPAA breach. “A preliminary review suggests that a staff member did not secure the files properly” during the move from the South Fulton Mental Health Center.

The files have now been retrieved and secured, although they were accessed by at least one individual. CBS46 was tipped off about the dumped records and a reporter was able to retrieve some documents from the dumpster before they were secured. The documents viewed by the CBS46 reporter contained patients’ names, Social Security numbers and other sensitive information.

An internal investigation into the incident is ongoing. While it is possible that an employee made an error and either left the records unsecured or accidentally dumped the records, this is now being viewed as a deliberate act.

Fulton County Commission Chairman John Eaves told CBS46 that “There’s at least one disgruntled employee who’s responsible for this.” Fulton County officials have confirmed they have identified the employee they believe is responsible. That individual has not been named although he/she had worked at the clinic for a number of years.

The employee is believed to have dumped the records in an act of retaliation to the decision by the clinic to start outsourcing its mental health services.

Fulton County is now checking all of the dumped records to find out which patients have been affected. Breach notification letters will be sent to all affected patients once that process is complete. At this stage, it is unclear how many of the clinic’s current and former patients have been impacted, although initial reports suggest that hundreds of patients have been impacted.

The post South Fulton Mental Heath Center Discovers Dumped Medical Records appeared first on HIPAA Journal.

Covered Entities Flirting with Fines for Late Data Breach Reports

Last month, the Department of Health and Human Services’ Office for Civil Rights sent a message to covered entities regarding the late reporting of data breaches with the announcement of a settlement with Chicago-based healthcare network Presense Health.

The settlement was the first reached with a covered entity purely to resolve HIPAA Breach Notification Rule violations. Presense Health had delayed the issuing of breach notification letters to patients. Presense Health agreed to settle with OCR for $475,000 to resolve the potential HIPAA violations.

However, since the announcement was made, there have been a number of instances where covered entities have unnecessarily delayed the issuing of breach notification letters to patients and data breach reports to OCR.

The January Breach Barometer – released by Protenus yesterday – indicates 40% of data breaches reported in January 2017 had notifications sent outside of the timescale required by the Health Insurance Portability and Accountability Act’s Breach Notification Rule.

The loss, theft, or exposure of patients’ electronic protected health information potentially places them at an elevated risk of suffering identity theft and fraud. When data breaches are reported promptly, patients can take rapid action to protect their identities, secure their accounts, and mitigate risk. However, when breach notification letters are delayed unnecessarily patients face a higher risk of suffering financial losses since mitigations will not be in place.

Summary of the HIPAA Breach Notification Rule

The HIPAA Breach Notification Rule was introduced to ensure that patients are made aware of any ePHI breach promptly. Any breach of unsecured protected health information requires individual notices to be sent to all affected patients by first class mail (or email if patients have elected to receive electronic communications) “in no case later than 60 days following the discovery of a breach.” However, breach notification letters should be sent without unreasonable delay.

Notification letters should include a summary of the nature of the breach, details of the information that was exposed or stolen, information about the steps that are being taken by the covered entity/business associate to prevent future data breaches, and steps that can be taken by the individual to protect themselves from potential harm. A toll-free number should also be provided to allow affected individuals to make contact for further information.  That toll-free number must remain active for 90 days from the date of the notification letters.

Additionally, a substitute breach notice must be placed on a prominent part of the covered entity’s website notifying individuals of the breach if contact information is not held for 10 or more individuals, or if that contact information is out of date and incorrect.

A media notice must be issued if a breach affects more than 500 residents of a state or jurisdiction. That breach notice must be issued to a prominent media outlet serving the state or jurisdiction. The media notice must also be issued within 60 days of the discovery of the breach.

The Secretary of the Department of Health and Human Services must be notified of a breach of more than 500 individuals’ ePHI via the Office for Civil Rights’ breach reporting tool. That notification should be provided without unreasonable delay and no later than 60 days following the discovery of the breach. Notifications about smaller breaches – those impacting fewer than 500 individuals – can be made up until 60 days following the end of the calendar year when the breach was discovered. However, notifications to affected individuals must still be issued within 60 days of the discovery of the breach.

The Breach Notification Rule and Business Associate Data Breaches

The 60-day window for issuing breach notification letters applies to both covered entities and business associates of covered entities. In the case of the latter, the covered entity may delegate responsibility for the issuing of breach notification letters to its business associate.

Covered entities should consider whether the business associate is in the best position to issue breach notification letters before the responsibility is delegated.

Recently, a breach at a business associate of a covered entity saw the business entity issue breach notification letters to affected individuals. However, since the affected individuals were unaware that the business associate was contracted to their insurance provider, the letters caused some confusion. The letters provided the necessary information to allow patients to take steps to protect their identities, but with no mention of the covered entity, some patients thought the letters were some sort of scam.

While not stated in the Breach Notification Rule, it would be of benefit in such situations to include the name of the covered entity in the letters or for the covered entity – and not the business associate – to issue notifications to patients.

Penalties for Late Breach Notifications

Office for Civil Rights has shown that breach notification delays do warrant the issuing of financial penalties in certain situations, and the penalties can be severe. While Presense Health was only fined $475,000 for delaying the issuing of breach notification letters for one month, considerably higher fines are possible.

OCR is permitted to fine covered entities, or their business associates, a maximum of $1,500,000 for each violation of HIPAA Rules. The HIPAA violation penalties are determined based four categories of violations, with the penalties ranging from $100 per violation up to a maximum of $50,000 per violation.

Given the willingness of OCR to penalize covered entities for HIPAA Breach Notification Rule violations, covered entities should make sure that their data breach policies and procedures include the timescales for issuing breach notifications to patients/OCR, and to ensure that those notifications are issued within the allowed timeframe.

The post Covered Entities Flirting with Fines for Late Data Breach Reports appeared first on HIPAA Journal.

Summary of January 2017 Healthcare Data Breaches Released

Protenus, in conjunction with databreaches.net, has released a summary of January 2017 healthcare data breaches. The report shows that 2017 started where 2016 left off, with similarly high numbers of healthcare data breach reported.

January 2016 saw the lowest number of data breaches of any month in 2016 (21) and also the lowest number of records exposed of any month in the year (104,056 records). 2017 did not start nearly as well. While lower than the average monthly breaches for 2016 (37.5), January saw 31 healthcare data breaches disclosed. Those breaches resulted in the exposure of 388,307 patient and health plan member records.

The largest healthcare data breach of January 2017 affected CoPilot Provider Support Services, Inc. The breach impacted 220,000 individuals. However, the breach actually occurred in October 2015, with CoPilot discovering the incident two months later in December 2015. The Department of Health and Human Services’ Office for Civil Rights was only notified of the incident last month, well outside the 60-day deadline for reporting breaches.

That was a recurrent theme in January. According to the Breach Barometer report, 40% of HIPAA-covered entities that disclosed in January 2017 reported the incident outside of the 60-day reporting window of the HIPAA Breach Notification Rule. January also saw the first settlement with a covered entity based solely on delayed breach notifications. Presense Health paid OCR $475,000 after breach notifications were delayed by a month.

In January, 12 hacking and IT incidents were disclosed which resulted in the theft of 145,636 records. Those incidents also included phishing attacks on covered entities. However, the biggest cause of healthcare data breaches by far was insider incidents. 58.4% of breaches, where the cause was known, and 59.2% of breached records (230,044) were the result of insiders.

Protenus reports that four incidents were the result of insider wrongdoing and 4 incidents were the result of insider errors.

Healthcare providers were the worst affected with 25 incidents in January, four health plans disclosed data breaches, and two business associates of covered entities reported breaches.

The average number of days between the breach occurring and the incident being reported to OCR was 174 days. It took an average of 123.5 days for healthcare organizations to discover a breach had occurred.

Healthcare data breaches in January 2017 were spread across 21 states, with California accounting for the highest number (6) followed by Maryland (3).

The post Summary of January 2017 Healthcare Data Breaches Released appeared first on HIPAA Journal.

Automatic Email Forwarding Rule Sent 1,700 Patients’ PHI to Employee’s Personal Email Account

Health Department officials in Multnomah County, OR, have discovered that an employee set up an automatic mail forwarder on an email account that sent all email correspondence to a personal Google email account for a period of around three months.

The emails were forwarded to an account outside the control of Multnomah County, in violation of the Health Insurance Portability and Accountability Act. Since the employee works in the Health Department, emails sent to that individual’s official email account contained a range of patients’ electronic protected health information (ePHI). The ePHI included first and last names, ages, medical record numbers, medical diagnoses, dates of service, medication names and prescription numbers.

The email forwarder was discovered during a random audit that was conducted on November, 22, 2016. An internal investigation into the incident revealed that the ePHI of 1,700 patients was exposed. The investigation did not uncover any evidence to suggest that any of the forwarded emails had been opened or read, but the possibility that ePHI was inappropriately accessed could not be ruled out.

Multnomah County has now confirmed that the email account has been deleted and none of the forwarded emails can be accessed by the employee. Multnomah County believes the risk of ePHI being used inappropriately is low and no reports have been received to suggest any ePHI has been used inappropriately. Multnomah County has also confirmed that no Social Security numbers, home addresses, or phone numbers were present in the emails or email attachments forwarded to the personal account.

The incident has prompted Multnomah County to conduct a review of policies and procedures with the member of staff concerned. Policies, controls, business practices, and data protection solutions are also being reviewed in direct response to this incident.

It is unclear why the emails were being forwarded to the personal account and it would appear from the substitute breach notice issued by Multnomah County that the matter has been dealt with internally and the employee in question has not been terminated.

The post Automatic Email Forwarding Rule Sent 1,700 Patients’ PHI to Employee’s Personal Email Account appeared first on HIPAA Journal.

Singh and Arora Oncology Hematology Breach Notifications Sent After 5 Months

A Singh and Arora Oncology Hematology breach is finally being communicated to individuals who had their electronic protected health information exposed, although it has taken 5 months for those letters to be sent.

The Health Insurance Portability and Accountability Act’s (HIPAA) Breach Notification Rule requires covered entities – healthcare providers, health plans, healthcare clearinghouses, and business associates of covered entities – to send breach notification letters to patients within 60 days of the discovery of an ePHI breach. The Department of Health and Human Services’ Office for Civil Rights (OCR) must also be notified of a breach in the same timeframe.

However, in the case of the Singh and Arora Oncology Hematology breach, the Flint, MI-based cancer treatment center discovered that its systems had been breached on August 22, 2016. While OCR was notified of the breach on October 21, 2016, patients have only just started receiving their letters.

The Singh and Arora Oncology Hematology breach actually occurred between February 27, 2016 and July 14, 2016. An unauthorized individual gained access to a server containing ePHI. It took around a year from when access to ePHI was first gained for patients to be informed that their sensitive data had potentially been accessed.

According to the OCR breach notice, the incident resulted in the exposure of 16,000 patients’ ePHI. ABC12, which was contacted by some of the affected patients, were told that the breach included patients’ names, addresses, phone numbers, dates of birth, Social Security numbers, current procedural terminology codes and health insurance details.

While the delay in the discovery of the breach is perhaps understandable – it is rarely a simple task to determine a cyberattack has occurred – the delay in the issuing of notification letters is not, especially when OCR was informed of the cyberattack and potential ePHI exposure within 2 months.

In some situations, patient breach notification letters are delayed so as not to interfere with a criminal investigation. There have been numerous instances where law enforcement has requested that HIPAA-covered entities delay the issuing of notifications to patients. However, in this case, no mention has been made of any law enforcement-requested delay.

The delay in issuing breach notification letters to patients was allegedly due to the healthcare provider being unable to determine whether data had actually been compromised. The letters explain to patients that the attacker was not believed to have been looking for ePHI and no indications that ePHI was accessed or used inappropriately have been discovered. However, it has not been possible to rule out the possibility that ePHI was accessed.

To protect patients, all affected individuals have been offered a year of credit monitoring services without charge. Given the delay in notification, patients should obtain credit reports and check back for any sign of suspicious activity over the past 12 months. EoB statements should also be carefully checked.

As with all breaches of more than 500-records, OCR will conduct an investigation. Given that OCR has recently penalized a healthcare organization solely for delaying the issuing of breach notification letters to patients, it doesn’t bode well for Singh and Arora Oncology Hematology.

The post Singh and Arora Oncology Hematology Breach Notifications Sent After 5 Months appeared first on HIPAA Journal.

Hacker Gains Access to Records of 4,668 Princeton Pain Management Patients

Princeton Pain Management, a healthcare provider specializing in the management of chronic pain, has reported a hacking incident has impacted 4,668 of its patients.

The breach affects individuals who visited its medical centers in New Jersey, Pennsylvania, and New York for treatment.

It is not known for how long the hacker had access to Princeton Pain Management’s systems, although the breach was discovered on November 28, 2016. Upon discovery of the breach, a cybersecurity firm was retained to conduct a thorough forensic investigation to determine how access to its systems had been gained, the types of information that were potentially accessed, and which patients were impacted. An internal investigation into the breach was also launched.

The investigation revealed that a wide range of sensitive electronic protected health information (ePHI) had potentially been accessed, including names, telephone numbers, addresses, birth dates, Social Security numbers, driver’s license numbers, Medicare numbers, government identification numbers, diagnostic information, treatment information, and medical and health insurance identifiers.

Princeton Pain Management responded to the breach by conducting a review of its security processes and systems. The security review identified a number of areas where protections could be improved. System security has now been enhanced to prevent similar data breaches from occurring in the future.

The incident has now been reported to the Department of Health and Human Services’ Office for Civil Rights and affected patients have been notified of the breach.

So far in 2017, seven healthcare hacking/IT incidents have been reported to OCR. Hacking/IT incidents account for 29% of all healthcare breaches reported so far this year.

The main cause of healthcare data security incidents in 2017 is unauthorized access/disclosure. 10 incidents have been reported: 42% of the year-to-date total.

The year may be young, but 24 incidents have already been reported to OCR in 2017. Those incidents have impacted 151,970 healthcare patients and health plan members.

The post Hacker Gains Access to Records of 4,668 Princeton Pain Management Patients appeared first on HIPAA Journal.