HIPAA Breach News

Theft of Unencrypted Laptop Exposes Wonderful Health & Wellness Patients’ ePHI

Los Angeles-based Wonderful Health and Wellness has notified patents that their electronic protected health information (ePHI) was exposed in early December, 2016 when an unencrypted laptop computer was stolen from the company’s Wonderful Center for Health Innovation.

Staff at the Center discovered the laptop computer was missing on December 12 when they returned to work after the weekend, with the theft having occurred at some point between December 9 and 12. The theft was immediately reported to law enforcement, although the device has not been recovered.

The laptop contained a range of protected health information including patients’ names along with their home addresses, telephone numbers, dates of birth, email addresses, clinical account numbers, medical conditions, treatment information, treatment dates, and test results. No Social Security numbers or financial information were stored on the device.

While the laptop computer was not encrypted, software had been installed which allows data on the device to be remotely deleted, although only if the laptop is used to connect to the Internet. Wonderful Health and Wellness has programmed the software to delete all sensitive data on the device the next time the device connects.

Patients were notified of the potential ePHI breach on January 18, 2017. At that point, there was no indication that any of the data on the device had been accessed or used inappropriately.

Wonderful Health and Wellness has conducted a review of its strategy for storing and transmitting medical information and additional safeguards have already been implemented to better secure patients’ medical information and prevent future breaches of this nature from occurring.

The incident has yet to appear on the Department of Health and Human Services’ Office for Civil Rights breach portal, so it is currently unclear how many patients have been impacted by the incident.

The post Theft of Unencrypted Laptop Exposes Wonderful Health & Wellness Patients’ ePHI appeared first on HIPAA Journal.

Court of Appeal Rules Horizon BCBS Class Action Has Standing Without Evidence of ID Theft

The United States Court of Appeals for the Third Circuit has ruled that a class action lawsuit filed by customers of Horizon Blue Cross Blue Shield whose protected health information was exposed when two laptop computers were stolen from its New Jersey offices does have standing, even without proof of harm. The case had previously been dismissed by U.S. District Judge Claire Cecchi.

The incident which led to the lawsuit occurred between November 1 and 3, 2013. Two unencrypted laptop computers containing the personal information of 839,000 plan members were stolen from Horizon BCBS’s headquarters in Newark, NJ. Stored on the laptops were names, addresses, birth dates, Social Security numbers, medical histories, demographic data, lab test results, insurance information, and other care-related data.

Four plaintiffs – Courtney Diana, Karen Pekelney, Mark Meisel, and Mitchell Rindner – are named on the lawsuit, which was filed on behalf of themselves and other customers whose personal information was exposed.

The complainants maintain that the laptop computers were targeted by thieves who realized the value of data contained on the devices, rather than the computers being stolen for resale for their hardware value.

The plaintiffs claim that the disclosure, although accidental, placed them at “imminent, immediate, and continuing increased risk of harm from identity theft, identity fraud, and medical fraud, requiring them to take the time and effort to mitigate the actual and potential impact of the Data Breach on their lives.”

The plaintiffs allege Horizon BCBS wilfully and negligently violated the Fair Credit Reporting Act (FCRA) – in addition to a number of state laws – by failing to adequately protect their personal information. The plaintiffs claim that the unauthorized transfer of personal information was a violation of FCRA and that the transfer, in itself, constitutes a cognizable injury.

The District Court dismissed the lawsuit under Federal Rule of Civil Procedure 12(b)(1) claiming a lack of Article III standing. However, the court of appeals judges ruled that even without evidence of misuse of the plaintiffs’ personal information, the case has standing.

According to U.S. Circuit Judge Kent Jordan , who wrote for the three-judge panel, “In light of the congressional decision to create a remedy for the unauthorized transfer of personal information, a violation of FCRA gives rise to an injury sufficient for Article III standing purposes.” Judge Jordan explained, “the alleged disclosure of their personal information created a de facto injury. Accordingly, all of the Plaintiffs suffered a cognizable injury, and the Complaint should not have been dismissed under Rule 12(b)(1).”

The post Court of Appeal Rules Horizon BCBS Class Action Has Standing Without Evidence of ID Theft appeared first on HIPAA Journal.

CoPilot Provider Support Services Alerts 220,000 Patients to Historic ePHI Incident

An unauthorized individual has accessed and downloaded the highly sensitive information of approximately 220,000 osteoarthritis patients from a website database maintained by CoPilot Provider Support Services.

The website is used by physicians to determine whether ORTHOVISC® and MONOVISC® injections are covered by patients’ health insurance. The information entered via the website is added to a database maintained by CoPilot. That database was downloaded by an unauthorized individual, although according to a breach notice issued by CoPilot, the database was not accessible to the general public at any point.

While not explicitly stated in the breach notice, the wording suggests that the individual responsible for the breach was a former employee. CoPilot believes it identified the person responsible and details of its investigation were passed to law enforcement.  CoPilot reports that the law enforcement investigation confirmed CoPilot’s conclusions to be correct.

While it is possible that data were accessed and downloaded with malicious intent, CoPilot does not believe the information was downloaded in order to commit fraud. This also points to an employee rather than a hacker.

The data downloaded was limited to names, genders, addresses, phone numbers, and medical insurance card information, although some individuals’ Social Security numbers were also copied.

Individuals impacted by the breach have been offered credit and identity monitoring services via Kroll for 12 months to protect them against fraudulent use of their information, although CoPilot has told patients it has no reason to believe that any of the downloaded information was misused, nor that it will be disclosed to other individuals.

The security incident came to light when CoPilot started to receive complaints claiming information uploaded to the website could be downloaded. An investigation was immediately initiated and a cybersecurity firm was retained to conduct a forensic investigation.

CoPilot issued a press release on January 18, 2017 announcing the security incident, notified the California Department of Justice on January 19, 2017, and started informing patients on or around the same date.

However, the timing of the breach notices is peculiar. CoPilot discovered the potential breach on December 23, 2015, yet it has taken over a year from discovery of the breach for breach notifications to be issued. CoPilot’s investigation revealed patient data were improperly downloaded in October 2015.

Under Health Insurance Portability and Accountability Act’s Breach Notification Rule, HIPAA-covered entities are required to issue data breach notifications to patients, Office for Civil Rights and the media within 60 days of the discovery of a breach.

The failure to comply with the Breach Notification Rule can result in financial penalties. OCR has recently agreed to settle potential HIPAA Breach Notification Rule violations with Presense Health after breach notifications to patients were delayed. Presense Health was required to pay OCR $475,000 for exceeding the Breach Notification Rule time limit by a month.

Office for Civil Rights investigates all breaches that impact more than 500 individuals to determine whether HIPAA Rules have been violated. Given the recent enforcement activity, action may well be taken against CoPilot for the delayed notifications.

While patients impacted by the incident have only just been notified, prompt action was taken by CoPilot to improve security after the breach was discovered. Those measures included “enhanced verification, enhanced encryption and implementing increased security audit activity.”

The post CoPilot Provider Support Services Alerts 220,000 Patients to Historic ePHI Incident appeared first on HIPAA Journal.

Hacking Group Attempts to Extort Funds from Cancer Services Provider

TheDarkOverlord has struck again, this time the victim was a small Indiana cancer charity. The attack occurred on January 11 and was accompanied with a 50 Bitcoin ($43,000) ransom demand. Little Red Door Cancer Services of East Central Indiana was threatened with the publication of confidential data if the ransom was not paid.

The charitable organization provides a range of services to help victims of cancer live normal lives during treatment, recovery, and at end of life. Little Red Door provides an invaluable service to cancer patients in East Central Indiana, with its limited funds carefully spent to provide the maximum benefit to cancer patients and their families.

The payment of a $43,000 ransom would have had a significant impact on the good work the organization does, and would have taken funding away from the people who need it most. Little Red Door followed the advice of the FBI and refused to pay.

Little Red Door spokesperson, Aimee Fant, issued a statement saying the organization “will not pay a ransom when all funds raised must instead go to serving families, all stage cancer clients, late stage care/hospice support and preventative screenings.”

The ransom demand was first sent to company executives, its vice president and president by text message. Messages were sent to their personal cell phones. The ransom demand and threats were also followed with email demands. The ransom demand was later reduced to around $12,000, although payment will still not be made. The stolen data included documents pertaining to grants, donors, employees, and the organization’s operations.

In addition to threatening to publish the data, TheDarkOverlord allegedly also issued a threat to contact the families of cancer patients, as well as the organization’s partners and donors.

Previous attacks by TheDarkOverlord have involved data theft. This time around, data were stolen and the company’s database and physical backups were wiped. Fortunately, patient diagnoses and other client information were on paper files.

Little Red Door has a cloud storage backup containing most of its data. Systems and databases will be rebuilt and data reconstructed. The cancer agency expects its IT systems to be back up and running by the end of this week. After recovery, Little Red Door will fully transition to a cloud-based system.

Little Red Door has received assistance from a number of organizations. A spokesperson for the organization said it “extends its immense gratitude to all who have helped in its efforts to gain control of the ransom attack and sincerely apologizes for any inconvenience and distress experienced on account of this act of cyberterrorism.”

The post Hacking Group Attempts to Extort Funds from Cancer Services Provider appeared first on HIPAA Journal.

Protenus Releases 2016 Healthcare Data Breach Report

Protenus, in conjunction with Databreaches.net, has published its 2016 healthcare data breach report, summarizing the hacks and mishaps that have resulted in patient and health plan members’ protected health information being exposed or stolen.

Fortunately, 2016 has not seen the mega data breaches of 2015, although it has been far from a good year. More than 27 million healthcare records were stolen in 2016 across 450 reported data breaches. The total number of breached records may be down year on year, but the total number of incidents has increased. 2016 has been the worst year for healthcare industry breaches since records first started being kept.

The Protenus 2016 healthcare data breach report includes data breaches that have already been reported to the Department of Health and Human Services’ Office for Civil Rights, in addition to those that have been disclosed to the media but not yet uploaded to the OCR breach portal.

In total, there were 27,314,647 individuals affected by healthcare data breaches in 2016, with detailed information available for 380 of the 450 incidents. More than one healthcare data breach was reported every single day, on average, in 2016.

Data breaches fluctuated throughout 2016, with no clear trend emerging. The worst months of the year – in terms of the number of records breached – were June and August. In June, 10,880,605 healthcare records were exposed or stolen. 9,096,515 records were breached in August.

The worst months of 2016 for reported data breaches were November (58 incidents) April (946 incidents) and August (45 incidents). January saw the fewest breaches with 21 incidents reported. January also saw the lowest number of healthcare records exposed, with 104,056 individuals impacted.

Million-record plus data breaches were relatively rare. The largest breach of the year – at Banner Health – saw 3.62 million records exposed.

The 2016 healthcare data breach report shows the majority of security breaches in 2016 involved insiders. Protenus classified insider breaches as those involving accidents caused by human error, data theft by healthcare workers, and snooping on medical records. 43% of the data breaches in 2016 involved insiders, compared to 26.8% of incidents which involved hacking, malware or ransomware.

There were 99 accidental data breaches and 91 breaches caused by insider wrongdoing. Breaches that were the result of insider wrongdoing tended to result in the theft of less data than accidental data breaches. Accidental data breaches exposed three times as many records, on average.

2016 saw an explosion in ransomware attacks with the healthcare industry heavily targeted. The healthcare data breach report indicates only 30 ransomware attacks were reported in 2016. The true figure may be considerably higher. Healthcare organizations are only required to report ransomware attacks if there was a reasonable probability that ePHI was compromised. Covered entities also have up to 60 days to report healthcare data breaches, so a final total for the year will not be available until March 1, 2017. 2016 also saw a rise in other extortion attempts, with hackers gaining access to healthcare data and demanding ransoms not to publish the information.

Hacking may not have been the biggest cause of healthcare data breaches in 2016, but hackers certainly obtained the most records. 120 hacking incidents were included in the report, although the number of records stolen in those attacks was only known for 99 incidents. Even so, the total number of records obtained by hackers was 87% of the annual total – 23,695,069 records.

Healthcare providers were the worst hit in 2016 accounting for 80% of the total breach count. Health plans were second with 10% of attacks, followed by business associate breaches which accounted for 6.3% of the total. 4% of breaches affected other entities.

The report shows healthcare organizations are slow to detect breaches. The report indicates the average time to discover data breaches was 233 days, although insider breaches took considerably longer. Cases of insider wrongdoing took an average of 607 days to discover that ePHI had been breached. Protenus reports the average time from the breach to reporting the incident to HHS was 344 days.

The post Protenus Releases 2016 Healthcare Data Breach Report appeared first on HIPAA Journal.

$2.2 Million Settlement for Impermissible Disclosure of ePHI

The U.S. Department of Health and Human Services’ Office for Civil Rights has agreed to a $2.2 million settlement with MAPFRE Life Assurance Company of Puerto Rico – A subsidiary of MAPFRE S.A., of Spain – to resolve potential noncompliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

The settlement relates to the impermissible disclosure of the electronic protected health information of 2,209 patients in 2011. On September 29, 2011, a portable USB storage device (pen drive) was left overnight in the IT Department from where it was stolen. The device contained a range of patients’ ePHI, including full names, Social Security numbers and dates of birth. The device was not protected by a password and data on the device were not encrypted.

MAPFRE reported the device theft to OCR, which launched an investigation to determine whether HIPAA Rules had been violated, as is customary with all breaches of ePHI that impact more than 500 individuals.

Multiple Areas of Noncompliance with HIPAA Rules Discovered

During the course of the investigation, OCR discovered numerous HIPAA noncompliance issues:

45 C.F.R. 164.502(a) – Impermissible disclosure of the ePHI of 2,209 individuals.

5 C.F.R. 164.308(a)(1)(i) – A failure to conduct a comprehensive risk assessment to evaluate risks and vulnerabilities to the confidentiality, integrity and availability of ePHI and a failure to implement measures to reduce risks to an appropriate level.

45 C.F.R. 164.308(a)(5)(i) – A failure to implement a security awareness training program for all members of the workforce.

45 C.F.R. 164.312(a)(2)(iv) – A failure to implement data encryption or an equivalent measure to safeguard the ePHI stored on portable storage devices.

45 C.F.R. 164.316 (a) – A failure to implement reasonable and appropriate policies and procedures to safeguard ePHI to comply with HIPAA standards implementation specifications.

Additionally, the corrective measures MAPFRE said it would undertake following the submission of a breach report to OCR on August 5, 2011 were delayed. MAPFRE did not start encrypting data on laptop computers and portable storage devices until September 1, 2014.

OCR considered the financial position of MAPFRE along with the number and severity of HIPAA violations when determining the resolution amount. In addition to paying OCR $2,204,182, MAPFRE is required to adopt a corrective action plan to address all areas of noncompliance.

HIPAA and Data Encryption

HIPAA does not require covered entities to implement encryption on portable devices used to store ePHI. Data encryption is only an addressable issue. However, covered entities must conduct a thorough risk assessment to identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. If, after assessing risks, covered entities determine that other controls are in place to safeguard ePHI and data encryption is not appropriate, the reasons for not implementing encryption must be documented.

Recent HIPAA Settlements

OCR has stepped up its enforcement of HIPAA Rules in recent years, with more settlements agreed in 2016 than in any other year to date. Last year, 12 healthcare organizations settled potential HIPAA violations with OCR, and one civil monetary penalty (CMP) was imposed.

MAPFRE is the second HIPAA-covered entity to settle potential HIPAA violations with OCR in 2017. Last week, OCR announced a settlement of $475,000 had been agreed with Presense Health for violations of the HIPAA Breach Notification Rule.

The post $2.2 Million Settlement for Impermissible Disclosure of ePHI appeared first on HIPAA Journal.

Potential ePHI Breach Impacts 3,600 Children’s Hospital Los Angeles Patients

3,600 patients of Children’s Hospital Los Angeles (CHLA) and Children’s Hospital Los Angeles Medical Group (CHLAMG) are being notified of a potential breach of their electronic protected health information following the theft of an unencrypted, password-protected laptop computer.

The laptop was stolen from the locked vehicle of a CHLAMG employee who practices at CHLA. The theft is understood to have occurred on October 18, 2016.

CHLAMG encrypts its laptop computers, and while the investigation into the breach initially indicated the laptop had been encrypted to institutional standards, on December 21, 2016, CHLA determined that there was a possibility that the device had not been encrypted.

Typically, laptops are stolen by thieves for the value of the device, not for data stored on the devices. Laptops are wiped, have software reinstalled, and are sold on.

While it cannot be confirmed that this was the case in this instance, CHLA investigators were able to determine that the laptop computer has not been used to connect to the Internet since it was stolen, suggesting the device was wiped and ePHI is no longer accessible.

A CHLA spokesperson said their IT security systems allow data on laptop computers to be remotely and securely erased. The protocol for doing this has been activated and data on the device will be wiped should the device be used to connect to the Internet.  No evidence has been uncovered to suggest data have been accessed or used inappropriately. CHLA is continuing to work with law enforcement, although to date, the laptop computer has not been recovered.

The data stored on the device included children’s names, addresses, medical record numbers, birthdates, and limited clinical information.

Parents of affected children have been notified of the potential ePHI breach out of an abundance of caution. They have been advised to check Explanation of Benefits statements for medical services that have not been received.

CHLA will be enhancing its encryption levels on all laptop computers used by its physicians to prevent future data breaches of this nature from occurring.

The post Potential ePHI Breach Impacts 3,600 Children’s Hospital Los Angeles Patients appeared first on HIPAA Journal.

Sentara Healthcare Informs 5,454 Patients of ePHI Breach

Sentara Healthcare is notifying 5,454 patients that some of their electronic protected health information has been accessed by an unauthorized individual.

It is unclear when the cybersecurity incident occurred, although law enforcement informed Sentara Healthcare of the security breach on November 17, 2016.

Sentara Healthcare launched an investigation into the potential data breach in November and determined that the cybersecurity incident was experienced by one of its third party vendors.

Sentara has not disclosed which vendor was attacked, nor whether the incident was an internal breach involving one of the vendor’s employees or if patient data were accessed by a hacker.

The data breach affects vascular and thoracic patients who received medical services at Sentara Healthcare’s Virginia hospitals between 2012 and 2015.

Patients have been notified of the data breach by mail and have been told that highly sensitive protected health information was inappropriately accessed. The information viewed – and potentially copied – by an unauthorized third party includes patients’ names, Social Security numbers, dates of birth, medical record numbers, demographic information, medications prescribed, and details of procedures that were performed at Sentara Healthcare hospitals.

Sentara Healthcare’s Information Security Team is working closely with its vendor and is assisting law enforcement with its criminal investigation. The data breach investigation is ongoing.

Sentara Healthcare has told patients that it continually assesses and strengthens its policies, procedures, and cybersecurity defenses to ensure that patient data is appropriately protected at all times. Patients have been told that those processes will continue and that the third party vendor concerned will be implementing additional controls to enhance its security defenses to prevent similar incidents from occurring in the future.

All patients impacted by the data breach have been offered 12 months of complementary credit monitoring and identity theft protection services through Experian’s ConsumerInfo.com, Inc., and will receive in-depth assistance if their ePHI are discovered to have been used inappropriately.

The post Sentara Healthcare Informs 5,454 Patients of ePHI Breach appeared first on HIPAA Journal.

Highmark BCBS of Delaware Investigates Data Breach Affecting 19,000 Individuals

Highmark BlueCross BlueShield of Delaware is investigating a breach of 19,000 beneficiaries of employer-paid health plans. The data breach involves two subcontractors of Highmark BCBS – Summit Reinsurance Services and BCS Financial Corporation.

Karen Kane, Highmark BSBC director of privacy and information management, issued a statement saying 16 current and former Highmark self-insured customers have been impacted.

Affected individuals have now been notified of the breach by mail. The breach notification letters were sent by Summit Reinsurance Services (SummitRe). In the letters, consumers were informed that some of their highly sensitive protected health information had potentially been accessed by unauthorized individuals.

A ransomware infection was discovered by SummitRe on August 5, 2016, although a forensic analysis of the cyberattack revealed that access to Summit’s systems was first gained on March 12, 2016. SummitRe stated in the letters that the forensic investigation into the breach is ongoing, although no direct evidence has been uncovered to suggest that any ePHI stored on the affected server has been used inappropriately.

The types of data that could potentially have been accessed include names, Social Security numbers, details of health insurance, providers’ names, medical records relating to insurance claims – including medical diagnoses, and some clinical information.

Patients affected by the breach have been offered a year of credit monitoring and identity restoration services to protect them against identity theft and fraud.

Details of the nature of the cyberattack are being kept under wraps for the time being while the investigation continues. One of the questions that is likely to be asked is what happened during the five months between the initial intrusion and the ransomware infection.

Hackers are known to install ransomware after they no longer require access to infiltrated systems. Often after all valuable information has been obtained. In this case, it is unclear whether any data were exfiltrated during those five months.

SummitRe has been criticized for the letter sent to affected individuals, as it was not abundantly clear who the company was. Affected individuals would have been unlikely to have any dealings with the company in the past as insurance plans were provided through their employers.

Trinidad Navarro, Insurance Commissioner for the State of Delaware, said the letter “appears as if it is A) and Ad, or B) a scam.” Navarro also said, “Unfortunately, we fear that many may have misinterpreted or inadvertently discarded the letter.”

One of the data breach notification letters was provided to NBC 10 reporters by an affected patient. The letter was dated January 4, 2016. It is unclear why it took five months for patients to be notified of the breach – almost 10 months after the server was inappropriately accessed.

HIPAA Breach Notification Rule Requirements for Notifying Individuals of Data Breaches

The HIPAA Breach Notification Rule requires covered entities to notify individuals of a suspected ePHI breach within 60 days of discovery of the breach. Last week, the Department of Health and Human Services’ Office for Civil Rights sent a strong message to covered entities about the importance of issuing timely breach notifications. Presence Health of Illinois agreed to settle potential violations of the HIPAA Breach Notification Rule after OCR investigators became aware that it had delayed breach notifications for 3 months following a 2013 security incident affecting 836 individuals. Presense Health will pay OCR $475,000 as part of the settlement deal.

The post Highmark BCBS of Delaware Investigates Data Breach Affecting 19,000 Individuals appeared first on HIPAA Journal.