HIPAA Breach News

108 L.A. County Employees Fall for Phishing Attack: 756,000 Impacted

It has taken some time for the County of Los Angeles to announce it was the victim of a major phishing attack, especially considering the attack was discovered within 24 hours of the May, 2016 breach. However, notification had to be delayed so as not to interfere with an “extensive” criminal investigation.

The investigation into the phishing attack was conducted by county district attorney Jackie Lacey’s cyber investigation response team. In many cases, cybercriminals are able to effectively mask their identities and it is relatively rare for the individuals responsible for phishing attacks to be identified. Bringing individuals to justice is harder still. All too often the perpetrators are based overseas.

In this case, the investigation has resulted in the identification of a suspect: Austin Kelvin Onaghinor, 37, of Nigeria. On December 15, 2016, a criminal arrest warrant for Onaghinor was issued. Onaghinor faces nine charges related to the phishing attack, including theft and misuse of L.A. County confidential information, unauthorized computer access, and identity theft.

At the time of writing, Onaghinor has yet to be arrested and his whereabouts is unknown. He is considered to be a fugitive of the law and Lacey said “My office will work aggressively to bring this criminal hacker and others to Los Angeles County where they will be prosecuted to the fullest extent of the law.”

The phishing attack occurred on May 13, 2016. A large number of expertly crafted phishing emails were sent to Los Angeles County employees. The emails appeared to be legitimate; however, responding to the emails resulted in employees disclosing their usernames and passwords to the attacker. In total, 108 L.A. County employees responded, and by doing so, compromised their email accounts.

The email accounts contained a wide range of sensitive data including financial and health information. Investigators were required to individually check each email in the 108 compromised accounts to determine which individuals had been impacted and what information had been exposed.

The extensive investigation determined that 756,000 individuals had been impacted by the breach. Those individuals had previously had contact via email with the following Los Angeles County departments: Assessor, Chief Executive Office, Children and Family Services, Child Support Services, Health Services, Human Resources, Internal Services, Mental Health, Probation, Public Health, Public Library, Public Social Services and Public Works.”

According to the breach notice recently uploaded to the Department of Health and Human Services’ Office for Civil Rights breach portal, 749,017 patients of the County of Los Angeles Departments of Health and Mental Health were impacted.

The information contained in the email accounts included full names, home addresses, phone numbers, birth dates, Social Security numbers, state ID numbers, driver’s license numbers, Medi-Cal and insurance carrier IDs, medical record numbers, payment card numbers, bank account information, and medical information, including diagnoses and treatment information.

While the information was potentially accessed 7 months previously, Los Angeles County has uncovered no evidence to suggest that any information has been misused. As a precaution against identity theft and fraud, all individuals impacted by the breach have been offered a year of credit monitoring, identity consultation, and identity restoration services without charge.

Phishing emails are regularly sent to government employees and many make it past spam filters to employees’ inboxes. However, for the emails to result in the disclosure of 108 email account credentials is concerning.

Preventing employees from responding to phishing emails is a challenge, but a successful attack of this scale suggests a spectacular failure of systems and training, although the attack was detected the following day and L.A. County “immediately implemented strict security measures” to reduce the impact of the breach.

Phishing emails are a difficult threat to mitigate, although there are proven technologies and tactics that can be employed to reduce risk and at least limit the harm caused. Anti-phishing training has been demonstrated to greatly improve employees’ phishing email identification skills, in particular when anti-phishing exercises are conducted.

A study of 40 million phishing simulation emails by PhishMe (between January 2015 and July 2016) showed that susceptibility to phishing attacks falls to around 20% after just one failed phishing email simulation, while the implementation of a reporting tool can dramatically reduce the time to detect phishing threats. The sooner the threat is detected, the easier it is to alert employees and mitigate risk.

Solutions such as advanced spam filters can reduce the volume of phishing emails that are delivered to end users, while web filtering gateways can block users’ attempts to respond to phishing emails. Preventing end users from visiting websites based in foreign countries can reduce risk, although foreign-based phishers often host their phishing sites in the United States.

Along with next generation firewalls and intrusion detection systems it is possible to mount a reasonable defense against phishing attacks and reduce the damaged caused when those attacks succeed.

The attack should serve as a reminder of how serious the threat of phishing is, and how important it is for organizations – government and private sector – to enhance the controls they have in place to mitigate the threat.

The post 108 L.A. County Employees Fall for Phishing Attack: 756,000 Impacted appeared first on HIPAA Journal.

Healthcare Pages Intercepted and Posted Online

Providence Health & Services, a not-for-profit health system operating in Alaska, California, Montana, Oregon, and Washington, has discovered its paging system has been breached by an unauthorized individual.

Pages were intercepted and posted online exposing a limited amount of patients’ protected health information. The individual responsible for the pager attack posted pager transmissions that included patients’ names, room numbers, medication data, birth dates, medical record numbers, symptoms, diagnoses, and details of medical procedures.

Providence Health & Services reports that the information sent via its pager network was limited to the minimum necessary information, in accordance with HIPAA Rules.

Pages were accessed and disclosed publicly between October 25 and October 28, 2016. The breach was discovered on October 27. The breach notification letters sent to patients explain that PHI was only accessible on the website for a “couple of minutes at most.”

The incident was not limited to Providence Health & Services. Other healthcare organizations were also targeted, as were other users of non-secured pagers such as public safety departments and businesses. At this stage, it is unclear how many healthcare organizations were affected and how many patients had their privacy breached.

In a healthcare environment, pagers are primarily used to communicate urgent patient information to physicians and other healthcare professionals. The information sent via pagers is brief and usually limited to PHI required to provide treatment to patients.

Pager technology has served healthcare organizations well for more than 60 years with the first healthcare pagers used in New York City’s Jewish Hospital in 1950. The appeal of pagers is clear. The technology is reliable and vital information can be rapidly communicated. However, pagers are not secure.

Previous studies have highlighted the privacy risks from using unsecured pages in a healthcare setting. This incident highlights just how easy PHI breaches can occur if unencrypted messages containing PHI are transmitted.

Fortunately, 100% secure communication systems such as HIPAA-compliant text messaging platforms are becoming more commonplace and pager technology is compatible with data encryption. However, organizations that still use unsecured channels for communicating health information run the risk of experiencing HIPAA breaches such as this.

The post Healthcare Pages Intercepted and Posted Online appeared first on HIPAA Journal.

Regular PHI Access Log Audits Can Prevent Major PHI Breaches

Infirmary Health has announced that an employee has been fired after being discovered to have accessed the health records of approximately 1,000 patients without authorization. The individual was required to access patients’ protected health information (PHI) for legitimate work reasons, yet data access rights were abused.

The employee worked in the Atmore Community Hospital: A 49-bed facility serving patients in Escambia and Monroe counties in Alabama. A routine audit of PHI access logs on November 18, 2016 revealed that the individual first started inappropriately accessing patient records from October 3, 2015.  Records continued to be inappropriately accessed until November 11, 2016.

According to a press release issued by Infirmary Health, the information accessed was limited to patient names, admission dates and flowsheets. It is unclear why the information was accessed, although it is not believed that any data have been disclosed to any other individual nor copied and removed from the hospital. PHI appears to have been accessed purely out of curiosity.

In accordance with Health Insurance Portability and Accountability Act (HIPAA) Rules, the employee was authorized to view the minimum necessary information to conduct work duties and had received extensive training and specific instructions not to access the PHI of patients for non-work related reasons.

As a result of the discovery, the employee was placed on leave until the matter was investigated, and was later fired for breaching hospital policies and HIPAA Rules.

Infirmary Health has informed affected patients by mail and advised them to monitor their personal financial activity as a precaution, although the risk of any information being used inappropriately is believed to be very low.

Tacking the Problem of Unauthorized PHI Access by Employees

Training must be provided to healthcare employees on HIPAA Rules covering patient privacy, the circumstances under which PHI can be accessed, and the penalties for improper access.

Healthcare organizations should be aware that even with extensive training, unauthorized PHI access is likely to occur. In this case, patient privacy has been violated but no financial harm is believed to have been caused. However, as we have seen on numerous occasions this year, that is not always the case. All too often PHI is stolen and used for identity theft and fraud.

Hospitals and medical centers are required to conduct regular audits of PHI access logs, but all too often those audits occur far too infrequently. Annual checks could potentially allow rogue employees to view vast numbers of patient records before the privacy violations are discovered. During that time, hundreds of patients could suffer financial harm.

Only by regularly conducting audits of PHI access logs can healthcare organizations limit the harm caused to patients and nip the problem in the bud. Regular audits will also send a strong message to healthcare employees that inappropriate PHI access will be rapidly identified and swift action taken against the individuals concerned.

The post Regular PHI Access Log Audits Can Prevent Major PHI Breaches appeared first on HIPAA Journal.

Ransomware Encrypts Health Data for Three Months; PHI Still Inaccessible

Casa Grande, AZ-based Desert Care Family and Sports Medicine has alerted 500 patients to a potential breach of their protected health information (PHI) as a result of a ransomware infection.

The ransomware was installed on a server used to store PHI in August this year; however, despite attempts to unlock the encryption, patient data have still not been decrypted and have remained inaccessible for more than three months. The information stored on the server includes patients’ names, addresses, birthdates, account numbers, diagnoses, treatment information, and disability codes.

The healthcare provider took the affected server to a number of IT specialists in an attempt to unlock the encryption but to no avail. Free decryptors are available for certain ransomware variants via the No More Ransom Project; however, many of the most commonly used ransomware variants have yet to be cracked.

The only options for recovering locked data are to pay the ransom demand or to restore the encrypted files from backups. Unfortunately, there is no guarantee that payment of a ransom will result in the provision of a viable key to unlock the encrypted files.  It is unclear whether Desert Care Family and Sports Medicine refused to pay the ransom or whether the ransom was paid and the attackers failed to supply a working key to decrypt the data.

Under HIPAA Rules, Department of Health and Human Services’ Office for Civil Rights (OCR) must be notified of a ransomware infection that results in ePHI being encrypted if the covered entity believes there is a risk that ePHI was accessed or copied by the attackers.

In most cases, ransomware infections do not result in the exfiltration of data. In this case, no evidence of data access or theft have been uncovered, although the possibility that PHI was viewed or copied could not be ruled out.

The incident was reported to both local law enforcement and the FBI and a breach report has now been submitted to OCR. It is unclear why it took until December 20, 2016 for the notice to be provided to OCR and for patients to be informed of the potential breach. Covered entities are required to issue a breach notice within 60 days of the discovery of a potential data breach.

The incident clearly highlights the severity of the ransomware threat and how important it is for healthcare organizations to implement a range of controls to prevent infection and ensure data can be recovered.

It is essential for backups to be made of ePHI and for those backups to be tested to ensure data can be recovered. Since ransomware can also encrypt backup files, covered entities should store backup files on air-gapped devices or in the cloud.

The post Ransomware Encrypts Health Data for Three Months; PHI Still Inaccessible appeared first on HIPAA Journal.

Patient Posts PHI of New Hampshire State Psychiatric Hospital Patients Online

New Hampshire Department of Health and Human Services has alerted approximately 15,000 patients to a breach of some of their personal and highly sensitive information. Patient data were accessed by a former patient in October 2015 and were posted on a social media website.

The data accessed and posted online by the former patient included names and addresses along with Medicaid ID numbers and Social Security numbers. The patient gained access to the data on a laptop computer located in the hospital library. Patients are permitted to use the library and the computers, although access to patients’ protected health information should not have been possible.

At the time of the breach the patient was observed accessing ‘non-confidential’ hospital data by a staff member. The incident was reported to a supervisor and steps were taken to restrict access to the library computers. At the time, it was not known that sensitive data were accessed. While a supervisor was alerted to the incident, the matter was not escalated and neither the New Hampshire Hospital nor the New Hampshire Department of Health and Human Services (NH-DHHS) were informed.

However, ten months later in August 2016, a security official at the hospital alerted NH-DHHS that the former patient may have posted NH-DHHS data on a social media website. An investigation into the incident was launched and the Department of Information Technology was notified. The matter was also reported to State Police and state officials. However, according to the breach notice published by NH-DHHS on December 27, “An investigation at that time did not reveal any evidence that confidential personal or personal health information had been breached.”

Three months later on November 4, 2016, hospital security notified NH-DHHS that the patient had posted some protected health information to a social media site that day. Within 24 hours of DHHS being informed of the breach, the PHI was removed from the site and a criminal investigation was launched. NH-DHHS says patients impacted by the breach had received services New Hampshire Hospital prior to November 2015, although no evidence has been uncovered to suggest any PHI has been misused.

NH-DHHS Commissioner Jeffrey A. Meyers issued a statement saying the breach was “an isolated incident stemming from unauthorized access in October 2015 as described above and is not the result of an external attack.”

He also confirmed that all state departments are investigating the incident and efforts are being made to strengthen state cybersecurity policies and procedures to better protect patient health data from attacks from hackers, as well as accidental disclosures as a result of human error.

The post Patient Posts PHI of New Hampshire State Psychiatric Hospital Patients Online appeared first on HIPAA Journal.

UCLA Medical Center Investigates Potential Breach of Kanye West’s Medical Records

UCLA Health Medical Center in Los Angeles is conducting an internal investigation into a potential HIPAA breach that occurred around Thanksgiving weekend.

On November 21, 2016, Kanye West checked in to the hospital and stayed for 8 days. During his stay at the hospital, a number of nurses and other medical staff allegedly accessed his medical records without authorization. It would appear than the employees could not resist the temptation to snoop on his medical records.

The unauthorized viewing of celebrities’ medical records is a problem for hospitals, in particular medical facilities in Los Angeles and New York. In recent years, there have been a number of incidences of the privacy of celebrities being violated by curious hospital employees. Numerous employees have been found to have accessed the records of celebrities out of personal curiosity, although in many cases, inside information has been sold to gossip websites and tabloids.

A former employee of UCLA Medical Center plead guilty to accessing and selling the medical records of Farrah Fawcett and Brittney Spears to the National Enquirer in 2008, although an investigation into celebrity health record breaches at the time revealed that more than 120 workers had improperly accessed the celebrities’ health records.

Under Health Insurance Portability and Accountability Rules, HIPAA-covered entities should maintain logs to ensure the improper accessing of PHI can be identified. UCLA Medical Center logs access attempts and can check those logs to determine which staff members viewed a particular patient’s health records and determine whether there was any legitimate reason for access.

If improper access is determined to have occurred, employees will be disciplined accordingly. All too often, improper access results in termination.

While UCLA Medical Center has not confirmed whether any employees have been terminated as a result of accessing Kanye West’s medical records, some online sources claim that dozens of staff at the hospital are facing disciplinary action and that several staff members have already been fired.

The post UCLA Medical Center Investigates Potential Breach of Kanye West’s Medical Records appeared first on HIPAA Journal.

Increase in Ransomware and Cyberattacks Linked to Fall in Price of Health Data

The value of health records on the black market dropped substantially in 2016. A set of health records is now reportedly attracting a price of between $1.50 and $10, according to a recent report from TrapX. Back in 2012, the value of a complete set of health records was around $50 to $60.

The fall in price is easy to explain. Last year saw more than 113 million healthcare records breached, according to figures from the Department of Health and Human Services’ Office for Civil Rights. The vast majority of those records are in the hands of cybercriminals. Supply is now outstripping demand and just like any commodity, that results in a dramatic fall in prices.

Stealing medical records is now much less profitable which means cybercriminals have to recoup their losses from somewhere. That does not mean the healthcare industry is likely to be attacked less. Instead the fall in price is likely to lead to even more attacks. In order to make the same level of profit, more records need to be stolen and sold on.

The fall in the price of healthcare records has also prompted cybercriminals to change their tactics and look for new ways to make money. Many have opted for ransomware. Ransomware offers cybercriminals a quick and easy source of cash. Ransom payments are typically paid within 7 days of the malicious software being installed on healthcare networks. It is also relatively easy to bypass healthcare organizations’ defenses to install ransomware. Given the quick source of cash, the ease of attacks, and the high likelihood of payment, it is no surprise that ransomware has proven so popular.

It is difficult to calculate exactly how many healthcare organizations have been attacked with ransomware in 2016, as not all incidents are reported. However, hacking incidents affecting more than 500 individuals are.

TrapX calculated that major healthcare data breaches increased by 63% in 2016 (January 1 to December 12, 2016) compared to 2015. TrapX classed any breach of more than 500 records as ‘major’ and only included hacking incidents. In 2015, 57 major healthcare data breaches were reported to the Office for Civil Rights, whereas in 2016 there have been 90 reported breaches and the year is not over yet.

Since healthcare organizations have 60 days from the date of discovery of a breach to issue a report to OCR, the final figures for 2016 will not be known until March 1, 2017. The end of year total is certain to be considerably higher than 90 breaches.

The healthcare industry has responded to the rise in attacks by committing more funds to cybersecurity defenses. Employees are being trained on security best practices and overall awareness of security risks such as phishing has increased. Even so, many healthcare organizations are still falling victim to ransomware attacks and hacking incidents continue to rise.

TrapX, along with many security experts, predicts the use of ransomware will continue and attacks on healthcare organizations will increase in 2017. Hacking incidents are also likely to rise, with TrapX predicting attacks on medical devices will significantly increase in 2017.

2017, it would seem, is set to be yet another difficult year for the healthcare industry.

The post Increase in Ransomware and Cyberattacks Linked to Fall in Price of Health Data appeared first on HIPAA Journal.

Fairbanks Hospital Alerts Patients to Potential 3-Year Internal HIPAA Breach

Fairbanks Hospital in Indianapolis, IN., has discovered that the electronic health information of its patients could have been accessed by all of its employees for a period of at least three years.

Protections had been put in place to prevent unauthorized accessing of electronic health records by staff members, but on October 18, 2016, the hospital became aware that some files had been stored on an internal network that lacked those protections and could be accessed by all employees, even those who were unauthorized to view patients’ electronic information.

Following the discovery, an independent forensics expert was called in to determine the nature and scope of the problem. That individual was able to determine that the files were accessible since November 2013, and potentially longer. It was not possible to say whether the files were accessible before that date.

Attempts were made to determine whether the files had been accessed by employees during the time that they were unprotected, but access logs were not kept so it was not possible to determine whether any unauthorized individuals had viewed the information in the files.

The majority of patients impacted by the incident only had their name and a very limited amount of information exposed to unauthorized staff members. In such cases, the information that could have been accessed included admission dates and appointment scheduling information.

However, in some cases, Social Security numbers, dates of birth, addresses, telephone numbers, patient ID numbers, treatment information, medical diagnoses, and health insurance information could have been accessed.

Fairbanks hospital is in the process of informing patients of the potential privacy breach by mail and is providing them with further information on the steps that can be taken to protect against identity theft and fraud. Credit monitoring and identity theft protection services do not appear to have been offered.

Patients have been encouraged to “remain vigilant against incidents of identity theft and fraud, to review your account statements, and to monitor your credit reports and explanation of benefits forms for suspicious activity.” They have also been told “this also includes reviewing account statements, medical bills, and health insurance statements regularly to ensure that no one has submitted fraudulent medical claims using your name and address.” However, no reports of unauthorized use or misuse of the information have been reported to date.

The incident has been reported to appropriate state and federal bodies, including the Department of Health and Human Services’ Office for Civil Rights. It is unclear at this stage exactly how many patients have potentially been impacted.

The post Fairbanks Hospital Alerts Patients to Potential 3-Year Internal HIPAA Breach appeared first on HIPAA Journal.

Website Glitch Exposes Personal Information of KP Members

Kaiser Permanente is alerting certain members to the potential disclosure of a limited amount of their personal information to other KP members after a glitch was discovered in the company’s online ‘Estimates’ tool.

On November 16, 2016, Kaiser Permanente updated the Estimates tool on the kp.org website; however, an error occurred during the update that potentially resulted in members’ name, address, age, copay information, deductible payments from 2016, and out of pocket expenses from 2016 being displayed to another user of the tool.

Individuals potentially affected by the error visited the website and used the tool from the date that the update was applied until November 28, 2016 when the error was discovered and corrected.

Kaiser Permanente has informed affected patients that there was only a small chance that their information was viewed by another person. At no point were Social Security numbers, claims information, or banking details exposed.

The error did not result in the mass disclosure of PHI to other members. In each case, an individual who used the tool may have had their data displayed to the next person who used the tool.

Kaiser Permanente conducts extensive testing of its online systems following any upgrade. Members have now been notified of the incident by mail and told “there is always the rare chance that an error can go undetected until an update is live.”

However, this will be bad news for Kaiser Permanente as it is the second website error to be discovered in just a few weeks. Certain members were impacted by a website error caused during a kp.org site upgrade in October. In that instance, the upgrade was made to improve webpage speed and the error was identified and corrected within 24 hours.

Members affected by the latest breach have been urged to review their Explanation of Benefits statements and to report any irregularities, although due to the type information exposed and the speed of detection and correction of the error, Kaiser Permanente says the privacy risk is ‘limited’.

The post Website Glitch Exposes Personal Information of KP Members appeared first on HIPAA Journal.