HIPAA Breach News

Community Health Plan of Washington Announces 400,000-Record Data Breach

An unplugged security vulnerability at a business associate of Community Health Plan of Washington has resulted in the exposure of the protected health information (PHI) of almost 400,000 plan members.

Community Health Plan of Washington is now in the process of notifying all affected members that highly sensitive information including names, addresses, dates of birth, Social Security numbers, and health insurance information have been exposed and compromised.

The data breach was confirmed on November 30, 2016, although Community Health Plan of Washington first became aware of a potential breach on November 7 after a tip-off was received.

Staff at the health plan picked up a voicemail message from an individual who reported a vulnerability that had been discovered in the network of one of the health plan’s business associates. That vulnerability could be exploited to gain access to members’ data.

Community Health Plan of Washington followed up on the tip-off and contacted the firm in question, which is a subsidiary of NTT Data. The firm provides technical services to the health plan. Rapid action was then taken by the firm to confirm that the vulnerability existed and then correct the flaw to prevent data access.

A computer forensics investigator was hired to conduct a thorough analysis of the network and confirmed that the vulnerability had been exploited and that an unauthorized individual had accessed plan members’ PHI. It is unclear whether that individual was the same person that reported the vulnerability. At the time of writing, plan members’ data are not believed to have been used inappropriately. No reports of data misuse have been received by the health plan or its business associate.

Notification letters to affected plan members were delayed until the investigation into the data breach was completed and while the health plan set put the logistics in place to deal with the breach. A toll-free helpline for members has now been set up and credit monitoring services have been arranged.

According to a report in the Seattle Times, each member will receive an individual notification letter with an identification number that can be used to register for credit monitoring services with Kroll.

381,534 members of the health plan, which provides insurance through Medicaid throughout Washington state, have been affected by the breach.

The post Community Health Plan of Washington Announces 400,000-Record Data Breach appeared first on HIPAA Journal.

Identity Thief Sentenced to 4 Years for Selling Stolen Rotech Healthcare Data

A Florida man has been sentenced to serve four years in federal jail for selling medical records obtained from the medical device firm, Rotech Healthcare.

Vickie Lorenzo Bryant, 39, from Plant City, FL made contact with a government informant in May 2016 and offered to sell personally identifiable information of 957 individuals who had received medical devices from Rotech Healthcare.

This was not the first time Bryant had attempted to sell stolen data to identity thieves and fraudsters. The confidential informant had previously purchased other individuals’ data from Bryant and had used the information to obtain Florida driver’s licenses, make counterfeit credit cards, and purchase mobile phones in the victims’ names.

Bryant met with the informant on two occasions in June 2016 and sold the data of 957 different individuals. Bryant asked to be paid $15,000 for the batch of data or $15 per identity.

Around 1,000 documents were handed over to law enforcement and were found to contain a range of personal and medical information about the victims, including names, addresses, Social Security numbers and dates of birth.  Law enforcement contacted those individuals and all confirmed that they had all previously received respiratory or sleep apnea devices from Rotech Healthcare in the past. Rotech Healthcare was alerted to the data breach by law enforcement on June 13, 2016 and all patients were notified of the incident shortly thereafter.

Bryant was arrested and pleaded guilty to access device fraud and aggravated identity theft on August 23, 2016 and was sentenced by U.S. District Judge Charlene Edwards Honeywell on Tuesday last week.

Bryant did not personally steal the data from Rotech Healthcare. Two co-conspirators who were employed at Rotech allegedly obtained the data and sold it to Bryant. Fontella James and Sharmekia Young were indicted on September 29, 2016 and have been charged with conspiracy, computer intrusion, and crimes related to identity theft and are awaiting trial.

The post Identity Thief Sentenced to 4 Years for Selling Stolen Rotech Healthcare Data appeared first on HIPAA Journal.

Oak Cliff Orthopaedic Associates Alerts Patients to Potential PHI Breach

More than 1,000 current and former patients of Oak Cliff Orthopaedic Associates have been notified that unauthorized individuals may have viewed some of their protected health information.

Boxes of paper business records and other items were stolen from an off-site storage facility used by the Dallas orthopedic firm. It is currently unclear when the theft occurred and how long the thieves had access to the information, although the theft was discovered on October 17, 2016.

The documents contained patients’ names, addresses, and medical record numbers, although an investigation revealed that some of the documents also contained certain patients’ credit card numbers, Social Security numbers, and banking information.  Patients affected by the incident had received medical services from Oak Cliff Orthopaedic Associates between 2006 and 2007.

The Lewisville Police Department did manage to recover the stolen files and they have now been returned to Oak Cliff Orthopaedic Associates and are now secured. The stolen items were found in a hotel room, but it is unclear whether the thieves have been identified or apprehended. All other items not taken by the thieves have since been removed from the storage facility and have now been secured.

Since financial data have potentially been viewed and copied by the thieves, Oak Cliff Orthopaedic Associates notified relevant financial institutions of the risk of fraudulent activity on the affected individuals’ accounts. Patients impacted by the incident have now been notified mail and a press release has been issued in accordance with Health Insurance Portability and Accountability Act Rules.

Oak Cliff Orthopaedic Associates has not received any reports to suggest any of the stolen information has been used inappropriately, although it is possible that patient data were viewed by the thieves. As a precaution against identity theft and fraud, all 1,057 patients affected by the incident have been offered one year of identity theft protection services without charge.

The post Oak Cliff Orthopaedic Associates Alerts Patients to Potential PHI Breach appeared first on HIPAA Journal.

November 2016 Worst Month for Healthcare Data Breaches: 57 Incidents Reported

Many people will be glad to see the back of 2016. It has been a difficult year, especially for healthcare organizations. Ransomware attacks have increased, hacking incidents are up, and more data breaches have been reported this year than in any other year since records started to be kept by the Department of Health and Human Services’ Office for Civil Rights (OCR).

The year is certainly not ending well. November saw the highest number of healthcare data breaches of any month in 2016, including August; a particularly bad month for the healthcare industry when 42 protected health information (PHI) breaches were reported by covered entities.

However, November’s total was 35% higher than August and 60% higher than October, according to the November Breach Barometer Report from Protenus. Last month, 57 healthcare data breaches reported which is almost two incidents per day.

Fortunately, the breaches that were reported were relatively small and the downward trend in the number of exposed/stolen records continued for the second month in a row. In total, 458,639 healthcare records were exposed in November, down 317,894 from the previous month.

November was something of an atypical month due to the nature of reporting of healthcare data breaches. Had the data breaches at Ambucor Health Solutions and EMR4All/Rehab Billing Solutions been reported as single breaches, the breach total for the month would have stood at 39. Still a particularly bad month, but not as bad as August.

As it was, the incidents were reported to OCR separately by each organization that was affected. There were 11 incidents reported by organizations impacted by the Ambucor Health Solutions breach and a further 9 reported by entities affected by the breach at EMR4All/RBS, according to DataBreaches.net, which provided the data for the Protenus report.

Recent surveys have suggested IT professionals are more concerned about insider breaches than cyberattacks by hackers and with good reason. The Breach Barometer report shows how serious the threat of insider breaches is. In November, 54.4% of healthcare data breaches were caused by insiders. 17 breaches were accidental breaches by healthcare employees and 14 were the result of malicious actions by employees with access to PHI.

There were 9 incidents that involved hackers, which was an improvement on October when 14 incidents were attributed to hacking. Ransomware was involved in 3 security breaches reported in November. TheDarkOverlord, who has previously attempted to extort money from a number of healthcare providers after stealing their data, was involved in one incident.

Healthcare providers once again were the worst hit, registering 40 incidents – 70% of incidents – followed by health plans with 11. Business associates reported three breaches, although they were involved to some degree in at least 44% of the breaches reported in November.

Protenus calculated the average time taken to report incidents to OCR to be 135 days from the date of discovery. 65% of breaches were reported after the 60-day window allowed by the HIPAA Breach Notification Rule, most of which were entities affected by the Ambucor breach. The breaches in November were also widespread, with affected entities based in 24 different states.

According to Databreaches.net, the entities involved in the breaches in November were:

Entity Entity Type
Aetna Signature Administrators Business Associate
AON Hewitt Business Associate
Austin Pulmonary Consultants Healthcare Provider
Bay Sleep Clinic Healthcare Provider
Berkshire Medical Center Healthcare Provider
Best Health Physical Therapy, LLC Healthcare Provider
Biomechanics LLC Healthcare Provider
Briar Hill Management Business Associate
Briar Hill Management Business Associate
Broward Health: Broward Health Imperial Point Healthcare Provider
Camas Center Clinic, Kalispel Tribe of Indians Healthcare Provider
Carolina Cardiology Consultants (Greenville Health System) Healthcare Provider
Charleston Area Medical Center Healthcare Provider
CHI Franciscan Health Healthcare Provider
Cleveland Clinic Akron General Healthcare Provider
Command Marketing Innovations Business Associate
Conemaugh Physician Group Cardiology Healthcare Provider
Consultants in Neurological Surgery, LLP Healthcare Provider
Darlingten Business Associate
Darlingten Healthcare Provider
EMR4All/RBS Business Associate
Eye Institute of Marin Healthcare Provider
GHI (Emblem Health) Health Plan
Glendale Adventist Healthcare Provider
Harrisonburg OB GYN Associates, P.C. Healthcare Provider
Horizon BCBS & UnitedHealth Group Health Plan
Horizon Blue Cross Blue Shield of New Jersey Health Plan
HP Enterprise Services, LLC Business Associate
Indiana Family and Social Services Administration -Indiana Health Coverage Program Health Plan
Irvine Company Business Associate
Kaiser Foundation Health Plan Health Plan
Kaiser Permanente Health Plan – N. Cal Health Plan
Kaiser Permanente Health Plan- S. Cal Health Plan
KinetoRehab Physical Therapy, PLLC Healthcare Provider
La Gloria Pharmacy Healthcare Provider
LCS Westminster Partnership IV, LLP d/b/a Sagewood Healthcare Provider
Lebanon Cardiology Associates, PC (now known as WellSpan Cardiology) Healthcare Provider
Lenox Hill Heart and Vascular Institute Healthcare Provider
Lister Healthcare Healthcare Provider
Louisiana Health Cooperative, Inc. in Rehabilitation Health Plan
Luque Chiropractic Healthcare Provider
Main Line Health Healthcare Provider
Managed Health Services Health Plan
Marin Medical Practice Concepts, Inc. Business Associate
New Mexico Heart Institute Healthcare Provider
North Texas Heart Center, P.A Healthcare Provider
OC Gastrocare Healthcare Provider
OptumHealth New Mexico Health Plan
Pikeville Medical Center Healthcare Provider
Pinellas County Board of County Commissioners Health Plan
Primerica Business Associate (Financial Services)
Seguin Dermatology Healthcare Provider
Stony Brook Internists, University Faculty Practice Corporation VA Eastern Colorado Health Care System Healthcare Provider
Unnamed cleaning service Business Associate
Unnamed vendor Business Associate
Unnamed vendor + UPS Business Associate
Vanderbilt U. Psychological & Counseling Center Healthcare Provider
Vascular Surgical Associates Healthcare Provider
Vein Specialists of Northwest Georgia Healthcare Provider
Vision Care Florida, LLC Healthcare Provider
WADA and USADA Anti-Doping Agency
Wal-Mart Stores, Inc. Healthcare Provider
Washington Department of Social and Health Services- Aging and Disability Services Healthcare Provider
Watsonville Chiropractic (David W. Christie, D.C.) Healthcare Provider
Wentworth-Douglass Hospital Healthcare Provider
Young Adult Institute, Inc. Healthcare Provider

The post November 2016 Worst Month for Healthcare Data Breaches: 57 Incidents Reported appeared first on HIPAA Journal.

Princeton Medicine Ransomware Attack Reported

On October 6, 2016, Princeton Medicine physician Dr. Melissa D. Selke discovered an unauthorized individual gained access to a server containing the electronic protected health information of more than 4,200 patients and used that access to install ransomware.

The ransomware encrypted a range of files on the server including an information system containing patients’ names, phone numbers, addresses, Social Security numbers, driver’s license numbers, health insurance details, medical record numbers, diagnoses, treatment information, treating physician information, and treatment dates.

Upon discovery of the ransomware infection, a computer forensics expert was brought in to conduct a thorough investigation. It was possible to rapidly restore the encrypted files; however, the investigation revealed that the person behind the attack could potentially have viewed and copied patient data. No evidence was uncovered to suggest that this was the case, although it was not possible to rule out the possibility that ePHI had been accessed.

The Hillsborough, NJ-based physician has now informed state regulators and the Department of Health and Human Services’ Office for Civil Rights of the potential data breach. The breach report indicates 4,277 individuals have been impacted. All patients are being contacted by mail and informed of the potential exposure of their ePHI and have been provided with further information and resources explaining the actions that can be taken by patients to reduce the risk of identity theft and fraud.

According to Dr. Selke, “We are taking steps to help prevent another incident of this kind from happening, and continue to review our processes, policies, and procedures that address data privacy.”

2016 has been a bad year for ransomware attacks on U.S. healthcare providers; but as we head into 2017, there are no signs that the attacks will abate. In fact, security experts have predicted that the situation will get worse before it gets better and the number of attacks will increase.

Healthcare organizations large and small must therefore prepare for ransomware attacks. Data should be regularly backed up and stored in the cloud or on air-gapped storage devices and a ransomware response plan should be developed that can be rapidly implemented in the event of an attack to reduce the impact on patients.

Further information on ransomware and how to protect networks can be obtained from US-CERT on this link.

The post Princeton Medicine Ransomware Attack Reported appeared first on HIPAA Journal.

Princeton Medicine Ransomware Attack Reported

On October 6, 2016, Princeton Medicine physician Dr. Melissa D. Selke discovered an unauthorized individual gained access to a server containing the electronic protected health information of more than 4,200 patients and used that access to install ransomware.

The ransomware encrypted a range of files on the server including an information system containing patients’ names, phone numbers, addresses, Social Security numbers, driver’s license numbers, health insurance details, medical record numbers, diagnoses, treatment information, treating physician information, and treatment dates.

Upon discovery of the ransomware infection, a computer forensics expert was brought in to conduct a thorough investigation. It was possible to rapidly restore the encrypted files; however, the investigation revealed that the person behind the attack could potentially have viewed and copied patient data. No evidence was uncovered to suggest that this was the case, although it was not possible to rule out the possibility that ePHI had been accessed.

The Hillsborough, NJ-based physician has now informed state regulators and the Department of Health and Human Services’ Office for Civil Rights of the potential data breach. The breach report indicates 4,277 individuals have been impacted. All patients are being contacted by mail and informed of the potential exposure of their ePHI and have been provided with further information and resources explaining the actions that can be taken by patients to reduce the risk of identity theft and fraud.

According to Dr. Selke, “We are taking steps to help prevent another incident of this kind from happening, and continue to review our processes, policies, and procedures that address data privacy.”

2016 has been a bad year for ransomware attacks on U.S. healthcare providers; but as we head into 2017, there are no signs that the attacks will abate. In fact, security experts have predicted that the situation will get worse before it gets better and the number of attacks will increase.

Healthcare organizations large and small must therefore prepare for ransomware attacks. Data should be regularly backed up and stored in the cloud or on air-gapped storage devices and a ransomware response plan should be developed that can be rapidly implemented in the event of an attack to reduce the impact on patients.

Further information on ransomware and how to protect networks can be obtained from US-CERT on this link.

The post Princeton Medicine Ransomware Attack Reported appeared first on HIPAA Journal.

Quest Diagnostics Announces 34,000-Record ePHI Breach

Madison, New Jersey-based clinical laboratory service provider Quest Diagnostics is alerting 34,000 patients that some of their electronic protected health information (ePHI) has been stolen. Quest Diagnostics is business associate of many healthcare providers across the United States. Consequently, patients across the United States have been impacted by the breach.

On November 26, 2016, an unknown individual gained access to the MyQuest by Care360® Internet application and successfully exfiltrated a range of patient data. The intrusion was detected two days later when staff returned to work on Monday.

Upon discovery of the breach, access to the Internet application was blocked to prevent any further data from being accessed or copied and a leading cybersecurity firm was contracted to conduct a thorough investigation of the breach.

The investigation revealed that patients’ test results were copied along with names, dates of birth, and some telephone numbers, although no highly sensitive data such as Social Security numbers, health Insurance information, or financial data were accessed or copied. The cybersecurity firm is also conducting a thorough assessment of cybersecurity protections in place to prevent unauthorized data access. Upon conclusion of that assessment, additional protections will be put in place to prevent future breaches of this nature from occurring.

Quest Diagnostics responded promptly to the breach and has issued notification letters to patients under two weeks after the breach was first discovered, well inside the 60-day breach notification time limit stipulated by the Health Insurance Portability and Accountability Act (HIPAA).

While it has only been two weeks since the breach, Quest Diagnostics has not received any reports of patient data being misused to date. Quest Diagnostics has told patients “we do not believe that you need to take any steps at this time to protect yourself in response to this breach.”

The breach has been reported to the federal law enforcement agencies, and the Department of Health and Human Services’ Office for Civil Rights and state attorneys general have also been notified.

The post Quest Diagnostics Announces 34,000-Record ePHI Breach appeared first on HIPAA Journal.

Further 4,100 Cardiac Patients Notified of Breach of ePHI

A further 4,100 cardiac patients have been notified that some of their protected health information was exposed due to a security breach at Wilmington, DE-based Ambucor Health Solutions (AHS). The patients had previously had cardiac devices fitted at the New Mexico Heart Institute in Albuquerque.

The Heart Institute contracted Ambucor Health Solutions to provide a cardiac monitoring service for its patients. AHS had implemented appropriate technical, physical, and administrative safeguards to prevent the unauthorized disclosure of patients’ electronic protected health information in accordance with HIPAA Rules; however, a former AHS employee breached company policies and accessed and copied patients’ ePHI to two flash drives prior to leaving employment.

The data copied to the devices included patients’ names, birthdates, phone numbers, addresses, medication information, testing data, information about patients’ medical devices, where the patient had the device fitted, the name of the technician who fitted the device, and the name of patients’ physicians.

It is unclear why the data was copied, although AHS does not believe any of the information has been used inappropriately or disclosed to anyone other than the employee who copied the data. The flash drives have since been recovered via law enforcement. An analysis of the data on the devices showed no Social Security numbers, financial data, or insurance information were compromised. At this stage it is unclear whether the former AHS employee will face criminal charges. Both AHS and the New Mexico Heart Institute have taken further precautions to prevent future ePHI breaches of this nature from occurring.

Ambucor Health Solutions is providing affected patients with identity theft protection services and cover with a $1 million identity theft insurance policy, but it is the responsibility of each covered entity to submit its own breach report to the Department of Health and Human Services’ Office for Civil Rights. It is therefore unclear at this stage exactly how many patients have been impacted by the breach. This announcement brings the running total of individuals affected by the Ambucor Health Solutions breach to 9,657. Those individuals reside in Massachusetts, New Hampshire, New Mexico, Pennsylvania, and South Carolina.

The post Further 4,100 Cardiac Patients Notified of Breach of ePHI appeared first on HIPAA Journal.

Lost CD Contained Social Security Numbers of 18,854 Health Plan Members

18,854 health plan members have been notified of a potential breach of their protected health information following the loss of a compact disc in the mail.

An employee at Aetna Signature Administrators (ASA), a provider of network and management services to group health plans, mailed a CD containing sensitive health plan members’ information to another ASA employee. The CD was mailed on September 6 and the envelope was delivered on September 9; however, the CD was missing from the envelope.

The CD contained reports that had been provided to ASA by health plans or health plan administrators. The reports were used by ASA to evaluate and select programs and services for health plan members.

The reports contained the dates of birth of health plan members along with their Social Security numbers, and in some instances, names and addresses. Individuals impacted by the incident were notified of the potential ePHI breach last month.

Since Social Security numbers were exposed, ASA has offered all affected individuals a year of identity theft protection services through Equifax (Equifax Credit Watch Gold) without charge. The services are provided as a precaution against identity theft and fraud. ASA has not received any reports to suggest the CD has been accessed or used by unauthorized individuals. Neither ASA nor the U.S. Postal Services has located the missing CD.

This is the second incident of this nature to be reported in the past week. Last week, OptumHealth New Mexico announced that a business associate had mailed an unencrypted flash drive in the mail, but it failed to arrive at its destination.

ASA has now taken the decision to stop mailing CDs containing ePHI and will use other, more secure methods of communication in the future. Staff members have also been retrained on handling sensitive health plan members’ information and health plans have been instructed not to include members’ Social Security numbers in reports submitted to ASA.

The post Lost CD Contained Social Security Numbers of 18,854 Health Plan Members appeared first on HIPAA Journal.