HIPAA Breach News

WellCare Health Reports Security Breach Affecting 24,800 Patients

In August 2016, Summit Reinsurance Services experienced a data breach affecting a number of its healthcare clients. Highmark Blue Cross Blue Shield of Delaware was informed in early January that 19,000 of its members were impacted by the breach. Now, WellCare Health Plans has announced that 24,809 of its members have also been impacted by that security incident.

Summit Reinsurance Services had previously been contracted by WellCare to provide reinsurance services. WellCare no longer uses SummitRe as its reinsurance service provider, although the breach dates back to before WellCare’s association with the company was terminated.

WellCare was informed on December 27, 2016 that a ransomware infection had occurred at SummitRe on August 8, 2016 and that its members’ electronic protected health information had potentially been accessed by the attacker.

The ransomware encrypted a range of sensitive data including names, member IDs, home addresses, dates of birth, Social Security numbers, medical diagnoses and provider names and locations.

While many ransomware infections occur randomly as a result of employees opening malicious email attachments or from visiting malware-infected websites, in this case the investigation into the breach revealed that access to SummitRe’s system was first gained on March 12, 2016, approximately 5 months prior to ransomware being installed. That suggests the attacker had time to view sensitive information stored on its system and installed ransomware when there was no further need for system access.

While data were potentially accessed and viewed, neither Summit Reinsurance Services nor WellCare has uncovered any evidence to suggest that PHI was stolen by the attackers, nor that any ePHI has been misused.

75,000-Record Breach Discovered at Texas Medical Clinic

The breach would take the title of the worst healthcare data breach of 2017 to date, having resulted in the exposure of more than twice the number of records as the Verity Health System breach; however, yesterday, a new report appeared on the Department of Health and Human Services’ Office for Civil Rights breach portal.

Stephenville Medical & Surgical Clinic in Stephenville, Texas, reported a security breach has impacted 75,000 individuals. The incident involved the unauthorized accessing of a desktop computer, although at present few details of the incident have been released. An incident report will be posted on this site when further information becomes available.

The post WellCare Health Reports Security Breach Affecting 24,800 Patients appeared first on HIPAA Journal.

Verity Health System Announces Details of 10K-Record Data Breach

Verity Health System – A Redwood City-based Californian health system comprising six hospitals, the Verity Medical Foundation, and the Verity Physician Network – has discovered that one of its websites was breached by a hacker who gained access to the electronic protected health information (ePHI) of thousands of its former patients.

The unauthorized individual accessed a Verity Medical Foundation (San Jose) Medical Group website that contained a wide range of protected health information on “more than 9,000 patients”.

Verity Health System discovered that its systems had been breached on January 6, 2017. An investigation into the breach was immediately launched and a third-party cybersecurity firm was brought in to conduct a full forensic analysis.

That analysis determined that access to the website was first gained in October 2015 and continued until early January 2017.

Verity Health System reports that Social Security numbers were not stored on the website and financial information was not viewed, apart from the last four digits of credit/debit card numbers. The website that was accessed was no longer in use and upon discovery of the breach, access to the website was immediately terminated and the site was secured.

No medical records were viewed and the breach was limited to ID numbers and patients’ personal information. That information included patients’ names, addresses, email addresses, phone numbers, dates of birth, and medical record numbers.

The incident was reported to the Department of Health and Human Services’ Office for Civil Rights on January 11. The OCR breach notification shows that 10,164 patients were impacted.

According to a statement from Verity Health System, “We are working with a leading cyber-security firm to further evaluate the integrity of our information systems.”

Given the length of time that the system remained accessible, it is fair to assume that patient information has been accessed. However, Verity Health System has not received any reports to suggest that ePHI has been used in an “unauthorized fashion.”

Patients affected by the incident had visited Verity Health System facilities for treatment between 2010 and 2014. All patients affected have been notified of the data breach by mail and have been offered 12 months of credit monitoring services without charge.

The post Verity Health System Announces Details of 10K-Record Data Breach appeared first on HIPAA Journal.

Family Medicine East, Chartered Alerts 6,800 Patients to ePHI Exposure

Family Medicine East, Chartered of Wichita, KS, has reported the theft of a computer from its Rock Road facilities. Thieves broke into the locked clinic on December 8, 2016 and stole a desktop computer and a printer. The computer, which was unencrypted, contained the protected health information of almost 7,000 patients.

Law enforcement was notified of the break-in and theft, although the individual(s) responsible have not been apprehended and the stolen computer has not been recovered.

The data on the computer were backed up so the theft has not resulted in the loss of any ePHI although an investigation of data backups did reveal that a considerable number of images and office notes were stored on the device.

The medical notes were mostly transcriptions of dictated physicians’ notes and related to patients that had visited Family Medicine East, Chartered for medical services between 2003 and 2004. The notes contain details of what was discussed during patients’ appointments and included patients’ names, birth dates, appointment dates, physician’s names, symptoms, details of examinations, diagnoses and orders. In additions to the physicians’ notes, some letters were stored on the stolen device which detailed patients’ names and medical conditions. The letters related to referrals of patients to other physicians.

Family Medicine East, Chartered has now notified all affected patients of the breach and has reassured them that no financial information, Social Security numbers, or addresses were stored on the computer. Only images and notes typed by transcriptionists were exposed as a result of the theft.

Family Medicine East, Chartered pointed out in its notification letters that files should not have been stored on the computer and therefore were not flagged during risk analyses conducted prior to the theft. The files had been stored on the stolen device “as a result of an employee’s oversight” according to the clinic’s substitute breach notification letter.

Due to the nature of data stored on the device, Family Medicine East, Chartered says “it is hoped that the risk of information being misused is low,” although the clinic has agreed to make credit reports available to affected patients free of charge.

Prior to the theft, Family Medicine East, Chartered had already started the process of encrypting all devices that contained patients’ protected health information and the clinic reports that that process has now been completed.  Security at its facilities has also been augmented to reduce the risk of further burglaries.

The post Family Medicine East, Chartered Alerts 6,800 Patients to ePHI Exposure appeared first on HIPAA Journal.

$3.2 Million HIPAA Civil Monetary Penalty for Children’s Medical Center of Dallas

The Department of Health and Human Services’ Office for Civil Rights (OCR) has announced that Children’s Medical Center of Dallas has paid a civil monetary penalty of $3.2 million to resolve multiple HIPAA violations spanning several years.

It is relatively rare for OCR a HIPAA Civil Monetary Penalty to be paid by a HIPAA-covered entity to resolve HIPAA violations discovered during OCR data breach investigations. In the vast majority of cases when serious violations of the Health Insurance Portability and Accountability Act are discovered by OCR investigators, the covered entity in question enters into a voluntary settlement with OCR.

Typically, this sees the covered entity pay a lower amount to OCR to resolve the HIPAA violations. OCR attempted to resolve the matter via informal means between November 6, 2015, to August 30,2016, before issuing a Notice of Proposed Determination on September 30, 2016. In the Notice of Proposed Determination, OCR explained that Children’s Medical Center of Dallas could file a request for a hearing, although no request was received. Consequently, Children’s Medical Center of Dallas was required to pay the full civil monetary penalty of $3,217,000, making this the biggest HIPAA violation penalty of 2017, eclipsing the payments made by Presense Health ($475,000) and MAPFRE Life Insurance Company of Puerto Rico ($2.2 million).

Children’s Medical Center of Dallas is run by Children’s Health, a Dallas-based healthcare system comprising three hospitals and numerous clinics in North Texas. On January 18, 2010, OCR was notified by Children’s Medical Center that a breach of patients’ electronic protected health information (ePHI) had occurred. The breach involved the loss of a Blackberry device containing the ePHI of 3,800 patients. The device had not been encrypted and was not protected with a password, allowing any individual who found the device to access the ePHI of patients.

An investigation into the breach was launched on or around June 14, 2010. As part of the investigation, Children’s Medical Center provided OCR with a Security Gap Analysis conducted by Strategic Management Systems, Inc., (SMS) between December 2006 and February 2007. That analysis revealed a lack of risk management at Children’s Medical Center. In the report, SMS recommended that Children’s Medical Center implement encryption on portable devices such as laptop computers to prevent the exposure of ePHI in the event that a device be lost or stolen. Children’s Medical Center failed to act on that recommendation.

PricewaterhouseCoopers (PwC) conducted an analysis of threats and vulnerabilities to ePHI in August 2008. In the PwC report, it was also recommended that Children’s Medical Center implement encryption on laptop computers, workstations, mobile devices, and portable storage devices such as USB thumb drives. PwC determined that the use of encryption was “necessary and appropriate.” Children’s Medical Center failed to act on PwC’s recommendations, even though encryption was rated as a “high priority” item.

To OCR it was clear that Children’s Medical Center was aware of the risks to the confidentiality, integrity, and availability of ePHI and that were was a lack of appropriate safeguards for ePHI at rest. Children’s Medical Center was aware of the risks as early as March 2007, more than a year before the security incident occurred and ePHI was exposed. Had Children’s Medical Center acted on the recommendations of SMS or PwC the breach could have been avoided.

In addition to the lost Blackberry in 2010, Children’s Medical Center reported the loss of an unencrypted iPod containing the ePHI of 22 patients. The loss occurred in December 2010. On July 5, 2013, Children’s Medical Center notified OCR of another breach involving an unencrypted device. In this case, the laptop theft resulted in the exposure of 2,462 individuals’ ePHI.

Even after the data breaches were experienced, Children’s Medical Center failed to act; only implementing encryption on portable devices in April, 2013. From 2007 to April 9, 2013, nurses were using unprotected Blackberry devices that contained ePHI, while other workers were using unencrypted laptop computers and mobile devices until April 9, 2013.

Encryption of ePHI is not mandatory for HIPAA-covered entities. The use of encryption to safeguard the confidentiality, integrity, and availability of ePHI is an ‘addressable’ issue.

HIPAA-covered entities are required to conduct a comprehensive, organization-wide risk assessment to determine vulnerabilities that could potentially result in the exposure of ePHI. If, after performing the risk assessment, the covered entity determines that encryption is not ‘reasonable and appropriate’, the reasons why encryption is not deemed necessary must be documented and an equivalent measure must still be implemented to ensure ePHI is appropriately secured. Children’s Medical Center failed to document why encryption had not been used and also failed to implement an equivalent security measure.

Furthermore, OCR determined that prior to November 9, 2012, Children’s Medical Center did not have sufficient policies and procedures governing the removal of hardware and electronic equipment from its facilities or movement of the devices within its facilities. Until November 9, 2012, Children’s Medical Center could not tell how many devices those policies and procedures should apply to: A full inventory was only completed on November 9, 2012. While devices had been inventoried prior to November 9, 2012, devices managed by the Biomedical department were not included in that inventory, breaching the HIPAA Security Rule (45 C.P.R. § 164.310(d)(l)).

While efforts were made to resolve the HIPAA violations informally, Children’s Medical Center was unable to ‘provide written evidence of mitigating factors or affirmative defenses and/or its written evidence in support of a waiver of a CMP.’

OCR determined that the violations were due to reasonable cause and not willful neglect of HIPAA Rules. Had that not been the case, the penalty would have been considerably higher. OCR considered the fact that there had been no apparent harm caused to patients as a result of the lost devices, and chose the minimum penalty amount of $1,000 per day that the violations were allowed to persist.

OCR’s Final Notice of Determination can be viewed on this link.

According to OCR Acting Director Robinsue Frohboese, “Ensuring adequate security precautions to protect health information, including identifying any security risks and immediately correcting them, is essential.” Frohboese also explained that the lack of risk management can be costly for covered entities, “Although OCR prefers to settle cases and assist entities in implementing corrective action plans, a lack of risk management not only costs individuals the security of their data, but it can also cost covered entities a sizable fine.”

The post $3.2 Million HIPAA Civil Monetary Penalty for Children’s Medical Center of Dallas appeared first on HIPAA Journal.

Email Account Compromised: 1,200 MultiCare Patients’ ePHI Exposed

The Tacoma, WA-based MultiCare Health System has announced that the email account of one of its employees has been compromised by a hacker following a successful phishing attack.

The five-hospital health system issued a statement yesterday about the email security breach confirming patients’ protected health information had been compromised. It is unclear when access to the email account was first gained, although the email security breach was discovered by MultiCare Health on November 27, 2016.

An investigation into the breach was immediately launched and rapid action was taken to secure the health system’s email accounts, including resetting passwords on all email accounts. However, the investigation revealed that only one email account had been compromised.

An analysis of the email account revealed that emails contained the ePHI of 1,200 former and current patients. Data potentially accessed by the attacker included patients’ names, addresses, dates of birth, genders, dates of service, account balances, and diagnosis and treatment information. MultiCare has confirmed that the compromised email account contained no Social Security numbers or financial information.

Patients are in the process of being notified of the security breach by mail and have been advised to check their Explanation of Benefits statements and to report any irregularities. To date, MultiCare has not received any reports of misuse of patients’ information.

Phishing attacks on healthcare organizations are to be expected. It is therefore essential for healthcare organizations to make employees aware of the risk of phishing and how to identify potential phishing attacks. Phishing simulation exercises are highly effective at reinforcing training and can greatly improve detection of phishing emails. Healthcare organizations should also set up a system of reporting potential phishing emails. Fast detection can help to prevent other employees from falling for the scams.

To counter the threat and prevent similar incidents from occurring in the future, MultiCare Health is reinforcing the education and training of its employees and will be providing staff members with additional training on phishing email detection. A review of security practices and procedures and ePHI safeguards has also been scheduled.

The post Email Account Compromised: 1,200 MultiCare Patients’ ePHI Exposed appeared first on HIPAA Journal.

Hospital Employee Discovered to Have Improperly Accessed 6,200 Patient Records

Covenant HealthCare has notified more than 6,000 patients that their electronic medical records were inappropriately accessed by one of its employees. Individuals affected by the privacy breach had previously received medical services at a Covenant HealthCare facility in Saginaw, Michigan.

The improper access was discovered during a November 2016 audit of EMR access logs. The audit revealed an unusual pattern of medical record access by a single employee. Covenant HealthCare immediately ordered a full review of ePHI access by the employee to determine which medical records had been accessed and whether there was any legitimate reason for those records to have been viewed.

The review revealed that the Covenant HealthCare employee first started improperly accessing its electronic medical record system on February 1, 2016. The improper access continued for nine months until November 21, 2016 and involved 6,197 patients. A range of data were potentially viewed including patient’s names, dates of birth, home addresses, health insurance information, diagnostic and treatment information, medical record numbers, Social Security numbers and driver’s license numbers.

Covenant HealthCare spokesperson Kristin Knoll said in a statement that an investigation into the HIPAA breach was immediately launched and resulted in termination of the employee. Knoll also confirmed that the breach has been reported to all appropriate agencies.

Affected patients have now been notified of the breach by mail, although the delay in issuing notifications was because Covenant required two months to complete its investigation.

No reports of misuse of patients’ information have been received to date by Covenant HealthCare. All patients who have had their Social Security numbers viewed will be offered free credit monitoring and protection services to mitigate risk.

To prevent future breaches of this nature, Covenant HealthCare has increased ongoing training on patient privacy. Audits of ePHI access logs will also be conducted more frequently to ensure that any future inappropriate access is identified promptly.

The post Hospital Employee Discovered to Have Improperly Accessed 6,200 Patient Records appeared first on HIPAA Journal.

Mailing Error Sees 1,126 Letters Sent to Patients’ Previous Addresses

A ‘software glitch’ has resulted in billing statements and other communications sent by TriHealth of Cincinnati being sent to patients’ former addresses. The privacy breach was discovered in November 2016, and impacts 1,126 TriHealth patients.

The glitch caused current addresses to be substituted with former addresses. In some cases, mail may have been forwarded on to the correct address, although TriHealth was unable to determine whether this was the case.  Letters have now been mailed to the correct addresses and affected patients have been notified of the error by mail.

The error affected mailings of billing statements, appointment reminder letters, and other correspondence between November 15, 2015 and January 12, 2017 when the error was discovered. Individuals affected by the error had all mailings directed to wrong addresses between those dates.

The types of protected health information contained in the mailings varied from patient to patient. PHI that was potentially exposed was limited to patients’ names, visit dates, descriptions of medical service provided, places of service, financial charges, details of payments and adjustments, account balances, due payments, and details of appointments.

No insurance numbers, Social Security numbers, credit/debit card information or financial institution information was printed in any of the misdirected letters.

TriHealth has not received any reports to suggest any of the information contained in the letters has been misused in any way. Since the privacy breach only involved a limited amount of data, and the risk of misuse is believed to be low, affected individuals have not been offered credit monitoring or identity theft protection services. They have been advised that they are entitled to obtain a free annual credit report from credit reporting companies and can check for suspicious credit activity.

The software error has now been fixed and affected patients have had their addresses corrected in TriHealth’s computer system.

The post Mailing Error Sees 1,126 Letters Sent to Patients’ Previous Addresses appeared first on HIPAA Journal.

South Carolina Hospital Reports Loss of Camera Containing Babies’ PHI

Roper St. Francis Mount Pleasant Hospital in South Carolina has discovered that a digital camera used to take photographs of new born babies has been lost and potentially stolen.

As is recommended by the National Center for Missing and Exploited Children, photographs of new born babies are taken by hospital staff for security reasons. In the event that a baby goes missing, the digital images can be used for identification purposes. According to hospital spokesperson Andy Lyons, the camera was stored in a secure location in the hospital not accessible by the general public.

Following the discovery that the camera was missing, an extensive search of the hospital was conducted, although the missing camera has not yet been located.

The camera stored images on a memory card which was in the device when it went missing. The memory card is believed to contain the images of approximately 500 babies born at the hospital between November 2015 and November 2016. The photos also contained physicians’ names, the birthdate of each baby, and the babies’ names.

Parents of the babies are being notified of the privacy breach in accordance with Health Insurance Portability and Accountability Act Rules and a HIPAA breach notice has been sent to the Department of Health and Human Services’ Office for Civil Rights. Roper St. Francis Mount Pleasant Hospital has not received any reports to suggest any of the data stored on the device have been used inappropriately.

According to a statement released by the hospital, action has been taken to prevent similar incidents from occurring in the future. Staff members have been provided with additional training on the importance of safeguarding patient information and additional measures have been implemented to protect cameras used by the hospital. The hospital has also strengthened its policies and procedures covering the use, disclosure, and storage of patient information.

The post South Carolina Hospital Reports Loss of Camera Containing Babies’ PHI appeared first on HIPAA Journal.

ePHI Improperly Accessed, Copied, and Lost by Employee

The protected health information of 600 individuals who received treatment for mental health disorders and/or substance abuse at a Baltimore treatment center has potentially been compromised.

On November 28, 2016, Complete Wellness discovered that highly confidential information had been accessed and copied onto a flash drive without authorization. Even though the treatment center was able to identify the individual responsible, it was not possible to recover the drive as the device was allegedly lost by the employee.

While no reports of misuse of the information contained on the device have been received by Complete Wellness, the possibility remains that the drive has been found and patient data accessed.

Data stored on the device included patients’ names, phone numbers. home addresses, email addresses, ages and dates of birth, languages spoken, ethnicity, race, marital statuses, the names of primary care physicians, emergency contact information, level of education, employer information, hurricane victim status, living situation, arrest history, military service information, and whether individuals had any hearing or vision difficulties. Social Security numbers of patients were also downloaded to the device. Patients affected by the breach had previously received treatment from Leslie Duff CRNP or Durwood Whitten, PhD.

Complete Wellness has since implemented a number of security measure to prevent future privacy breaches from occurring. Those measures included adopting technology to enable sensitive data to be sent securely rather than being transported on portable devices. Encryption technology has been implemented and additional privacy training provided to all administration and clinical staff members. A review of policies and procedures has been conducted and updates made to prevent similar incidents from occurring in the future.

Ongoing discussions have taken place with company leadership to address the security incident and prevent a recurrence. Complete Wellness has also confirmed that the employee was terminated as a result of the incident.

The post ePHI Improperly Accessed, Copied, and Lost by Employee appeared first on HIPAA Journal.