HIPAA Breach News

Ransomware Attack Reported by East Valley Community Health Center

West Covina, CA-based East Valley Community Health Center (EVCHC) has started notifying patients that some of their electronic protected health information was compromised when ransomware was installed on one of its servers.

The ransomware attack occurred on October 18, 2016 and involved a ransomware variant called Troldesh/Shade. As with other forms of ransomware, Troldesh conducts scans of its local environment and encrypts a wide range of file types with an asymmetric encryption algorithm, preventing the files from being accessed.

Troldesh is supplied by the ransomware author as a development kit, which allows affiliates to run their own ransomware campaigns. The ransomware is usually distributed via spam email campaigns via file attachments containing malicious JavaScript code. However, in this case, an unauthorized individual logged onto a EVCHC server and installed the ransomware.

Many different files were encrypted, one of which contained the electronic health information of EVCHC patients. The file was used by EVCHC for logging claims that had been submitted to health plans. The file contained names, addresses, birthdates, medical record numbers, insurance account numbers, and health diagnosis codes. No financial information, Social Security numbers, nor Driver’s license numbers were present in any of the encrypted files.

Ransomware is typically used to extract a ransom payment from the victim, not to gain access to sensitive information. However, it is possible that the attacker was able to view the ePHI contained in the file. No evidence of file access or exfiltration was discovered by EVCHC.

EVCHC has not disclosed how many individuals were affected by the incident, although the ransomware attack has now been reported to the Department of Health and Human Services’ Office for Civil Rights and the California Attorney General’s office.

Steps have been taken to reduce the likelihood of future ransomware attacks, including the implementation of additional technical controls and the transfer of patient’ protected health information to a third party off-site server maintained by a health information technology company. EVCHC will also be conducting a full review of privacy practices and updates will be made, as appropriate, to maintain the highest level of privacy for patients.

The post Ransomware Attack Reported by East Valley Community Health Center appeared first on HIPAA Journal.

Tampa General Hospital Settles Class Action Data Breach Lawsuit

According to figures from the Federal Trade Commission, Florida is one of the top three states for fraud and identity theft. Criminals in the state use stolen consumer data to steal identities and file fraudulent tax returns, with the data often coming from healthcare organizations.

Fraudsters often target the lowest paid healthcare workers and pay them to steal patients’ personal information and Social Security numbers. Many Florida hospitals have fired employees who have been discovered to have abused their access to patient health information and passed stolen information on to identity thieves.

Victims of fraud can suffer considerable losses which can prove difficult to recover. Legal action can be taken against the healthcare organizations that experience internal data breaches, although the lawsuits very rarely succeed.

One such lawsuit was filed against Tampa General Hospital. The class action lawsuit – John Doe v. Florida Health Sciences Center Inc. d/b/a Tampa General Hospital – alleged the hospital had been negligent for failing to protect patient data; breached its fiduciary duty, breached an implied contract, and violated Florida’s Deceptive and Unfair Trade Practices Act.

The plaintiffs claimed that in May 2014, the hospital had “actual or constructive knowledge that unknown individuals wrongfully accessed and obtained Plaintiff’s and Class Members’ PHI and PII in Defendant’s possession which included names, addresses, dates of birth, Social Security numbers, admitting diagnoses, and insurers.”

The lawsuit listed numerous cases of data theft at the hospital between 2012 and 2015, including an incident in 2014 that was uncovered by the Tampa Police Department. An individual was arrested and found to be in possession of patient records that had been stolen from Tampa General. The individual did not work at the hospital but had allegedly obtained the data from a hospital employee.

According to the lawsuit, many patients had suffered losses due to identity theft following the theft of data from the hospital. Even if losses had not been suffered, patients now face an increased risk of identity theft and fraud due to the hospital’s failure to protect their sensitive information. The lawsuit claims Tampa General Hospital’s “history of protecting patient information has been poor.”

Lawsuits filed against organizations that have experienced data breaches rarely succeed, even when plaintiffs can prove losses have been suffered following a data breach. However, the lawsuit against Tampa General Hospital was successful. Tampa General has recently agreed to a settlement with the plaintiff and class members.

Tampa General has agreed to pay the plaintiffs $10,000 in damages and up to $7,500 to cover the plaintiffs’ attorney fees and litigation expenses. In order to qualify for a percentage of the settlement, plaintiffs must be able to demonstrate that they have suffered actual losses as a result of the breach.

Tampa General Hospital denies any wrongdoing and maintains that it is not responsible for the alleged actions of some of its former employees. The decision to settle the case was taken to avoid the expense and burden of taking the case to trial.

The post Tampa General Hospital Settles Class Action Data Breach Lawsuit appeared first on HIPAA Journal.

Glendale Adventist Medical Center Fires Nurse for Inappropriately Accessing ePHI

A nurse employed by Glendale Adventist Medical Center in Glendale, CA has been fired for inappropriately accessing the medical records of 528 patients of the medical center and White Memorial Medical Center in Boyle Heights, CA.

The privacy breach was discovered in June 2016, although it is unclear when the nurse first started inappropriately accessing patient data. Glendale Adventist Medical Center discovered patient data were being accessed during a routine security review.

An investigation into the privacy violations was launched after access logs showed that the employee had been abusing data access privileges. The nurse had been provided with access to ePHI in order to perform work duties. The former employee worked as a per-diem nurse according to a report in the Los Angeles Times.

The investigation into the privacy breaches is ongoing, and as such, only a limited amount of information has been released. A spokesperson for Glendale Adventist Medical Center did confirm with the L.A Times that sensitive patient information that was potentially accessed included names, addresses, dates of birth, Social Security numbers, and medical diagnoses. It is unclear whether data were accessed out of curiosity or whether information was accessed with malicious intent.

All patients whose personal information was accessed by the former employee have now been contacted by mail and informed of the incident. Additional steps have now been taken at the medical center to prevent future privacy breaches from occurring.

The incident shows that while it is important to implement a host of security defenses to protect the electronic protected health information of patients from external attacks, it is also important to take steps to protect against insider breaches.

It may not be possible to prevent members of staff from inappropriately accessing ePHI, but conducting regular audits of data access logs will limit the damage caused in the event that rogue employees abuse their data access rights.

The post Glendale Adventist Medical Center Fires Nurse for Inappropriately Accessing ePHI appeared first on HIPAA Journal.

Sagewood Retirement Community Attacked with Ransomware

Sagewood, a retirement community in Phoenix, AZ, has notified 800 current and former residents about a ransomware attack that has potentially resulted in some of their electronic protected health information (ePHI) being accessed by the attackers.

Sagewood enlisted the services of a computer forensics firm to investigate the attack. According to the substitute breach notice on the Sagewood website, the attack was short-lived. It was possible to isolate and contain the infection within an hour of it being discovered.

Since it is possible that access to ePHI was gained, the incident has been reported to the Department of Health and Human Services’ Office for Civil Rights in accordance with HIPAA Rules. Patients have also been notified of the incident by mail if they have been affected.

Ransomware locks files with powerful encryption which prevents the victims from gaining access to their data. After files are locked, the victims are presented with a ransom demand. Payment must be made in order to receive the key to unlock the encryption.

Ransomware could also potentially give the attackers access to sensitive data, although typically the attacks are performed only to obtain ransom payments. However, in this case, files were locked but no ransom demand was received.

It is unclear whether the ransomware variant used in the attack failed, or if the attackers had other reasons for locking data.

It is possible that data access was gained and patients’ names, phone numbers, addresses, dates of birth, Medicare numbers, Social Security numbers, and other national ID numbers could potentially have been viewed.

Based on the short time period when data could have been accessed – and the lack of a ransom demand – “Sagewood does not believe that the attack was performed in order to gain access to a “hacker” was looking to compromise or misuse identities or personal information.”

Current and former residents impacted by the incident have been informed to be vigilant nonetheless and monitor payment card statements for any sign of fraudulent activity and to consider placing a fraud alert on their credit cards.

The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates 863 individuals were potentially impacted by the breach.

The post Sagewood Retirement Community Attacked with Ransomware appeared first on HIPAA Journal.

OptumHealth New Mexico Announces 2000-Record Data Breach

OptumHealth New Mexico has notified 2,006 patients of a privacy breach that was caused by one of its vendors. The vendor had downloaded some electronic protected health information to a flash drive, which was then sent to an undisclosed recipient by mail using the U.S. Postal Service. The flash drive did not arrive at its destination.

Upon discovery of the loss, the U.S. Postal Service was notified but attempts to locate the device have so far failed, although according to the substitute breach notice issued by OptumHealth, the matter is still being investigated.

It is unclear why, with many secure methods of sending sensitive data, the vendor chose to post the flash drive nor why the contents of the drive were not encrypted.

OptumHealth was notified of the potential privacy breach on September 26, 2016 and breach notification letters were mailed to all affected individuals on November 17. A substitute breach notice was recently uploaded to the OptumHealth website as it was not possible to contact all affected individuals by mail.

Patients have been informed that the data stored on the drive includes names, telephone numbers, addresses, full or partial dates of birth, health identification numbers, providers’ names, medical diagnoses, and other health information. Some patients’ full or partial Social Security numbers were also present on the device. OptumHealth was informed that only “a limited number” of Social Security numbers were saved to the flash drive.

It is not possible to tell whether the device was lost or stolen, nor whether any of the information stored on the device has been accessed. Since there is a possibility of the data on the device being viewed by unauthorized individuals, all affected patients have been offered one year of identity theft protection services through LifeLock.

Affected patients have been encouraged to check healthcare documents, tax returns, and bank and credit card statements and to be vigilant for any signs of fraudulent activity.

OptumHealth has responded to the incident by updating its processes relating to vendors to prevent similar privacy breaches from occurring in the future.

The post OptumHealth New Mexico Announces 2000-Record Data Breach appeared first on HIPAA Journal.

1,745 Berkshire Medical Center Patients Impacted by Ambucor Health Solutions Breach

Berkshire Medical Center (BMC) in Pittsfield, Massachusetts has been informed that 1,745 patients of its cardiology department have been impacted by the security breach at Ambucor Health Solutions (AHS).

The Wilmington, DE-based business associate provides a remote monitoring service for BMC patients that have been fitted with cardiac devices. In July, AHS discovered an employee had emailed the protected health information of 41 patients to a personal email account prior to leaving the company.

However, an investigation into the incident revealed that more patient had been affected than was initially thought. The employee had also copied some protected health information onto two thumb drives. Those devices were recovered via law enforcement and were found to contain the sensitive data of thousands of patients.

AHS has now contacted all healthcare providers whose patients have been impacted by the breach and is notifying all affected individuals by mail, although it is the responsibility of each impacted healthcare provider to notify the Department of Health and Human Services’ Office for Civil Rights.

While the total number of individuals impacted by the security breach has not been released, the data of 2,500 patients of Greenville Health System in South Carolina, 775 patients of Wentworth-Douglass Hospital in Dover, New Hampshire, and 537 patients of WellSpan Cardiology (formerly Lebanon Cardiology Associates) have also been affected.

BMC patients have been told that their name, address, phone number, date of birth, patient ID number, ethnicity, testing data, Ambucor enrolment number, diagnosis, medications, medical device information, practice where they were being seen, and the names of the Ambucor technician that fitted the device and their physician were also present on one of the thumb drives.

Affected patients will be protected by a $1 million identity theft insurance policy and will be provided with credit monitoring and identity theft protection services for a period of one year without charge; although AHS does not believe any patient data have been used inappropriately. Additional security controls have now been implemented by AHS to prevent future breaches of patient health information.

The post 1,745 Berkshire Medical Center Patients Impacted by Ambucor Health Solutions Breach appeared first on HIPAA Journal.

1,745 Berkshire Medical Center Patients Impacted by Ambucor Health Solutions Breach

Berkshire Medical Center (BMC) in Pittsfield, Massachusetts has been informed that 1,745 patients of its cardiology department have been impacted by the security breach at Ambucor Health Solutions (AHS).

The Wilmington, DE-based business associate provides a remote monitoring service for BMC patients that have been fitted with cardiac devices. In July, AHS discovered an employee had emailed the protected health information of 41 patients to a personal email account prior to leaving the company.

However, an investigation into the incident revealed that more patient had been affected than was initially thought. The employee had also copied some protected health information onto two thumb drives. Those devices were recovered via law enforcement and were found to contain the sensitive data of thousands of patients.

AHS has now contacted all healthcare providers whose patients have been impacted by the breach and is notifying all affected individuals by mail, although it is the responsibility of each impacted healthcare provider to notify the Department of Health and Human Services’ Office for Civil Rights.

While the total number of individuals impacted by the security breach has not been released, the data of 2,500 patients of Greenville Health System in South Carolina, 775 patients of Wentworth-Douglass Hospital in Dover, New Hampshire, and 537 patients of WellSpan Cardiology (formerly Lebanon Cardiology Associates) have also been affected.

BMC patients have been told that their name, address, phone number, date of birth, patient ID number, ethnicity, testing data, Ambucor enrolment number, diagnosis, medications, medical device information, practice where they were being seen, and the names of the Ambucor technician that fitted the device and their physician were also present on one of the thumb drives.

Affected patients will be protected by a $1 million identity theft insurance policy and will be provided with credit monitoring and identity theft protection services for a period of one year without charge; although AHS does not believe any patient data have been used inappropriately. Additional security controls have now been implemented by AHS to prevent future breaches of patient health information.

The post 1,745 Berkshire Medical Center Patients Impacted by Ambucor Health Solutions Breach appeared first on HIPAA Journal.

CHI Franciscan Health Alerts Patients to ePHI Exposure

CHI Franciscan Health has started notifying patients about the potential exposure of some of their electronic protected health information after a laptop computer was stolen from an employee.

According to The News Tribune, a CHI Franciscan Health employee had a backpack stolen on October 18. The backpack contained documents that included some patient health information, a work laptop computer, and a mobile phone.

The backpack also contained a day planner, in which the login credentials for the laptop were recorded. The information in the documents could potentially have been viewed and the login credentials could have been used to gain access to the electronic protected health information stored on the laptop.

CHI Franciscan Health has not received any reports to suggest any information has been accessed or used inappropriately, although patients have been informed to take precautions against identity theft. All affected individuals have been offered a year of credit monitoring services without charge.

The exposed ePHI/PHI includes the names, phone numbers, Social Security numbers, demographic information, and next of kin names of current and deceased patients.

Law enforcement was notified upon discovery of the theft, although laptop computer has not been recovered. The incident has yet to appear on the Department of Health and Human Service’ Office for Civil Rights Breach Portal so it is currently unknown how many individuals have been affected.

This is the third data security incident affecting CHI Franciscan Health this year. In early September, CHI Franciscan Health’s Highline Medical Center in Burien, WA reported a potential breach of 18,399 patient records after its network server. A vendor of Highline Medical Center, R-C Healthcare Management, removed security protections during a server upgrade and failed to reactivate them when work had been completed.

CHI Franciscan Health also reported a data security incident in September that affected St. Clare Hospital in Lakewood, WA and St. Joseph Medical Center in Tacoma, WA. That electronic medical record breach impacted 2,818 individuals.

The post CHI Franciscan Health Alerts Patients to ePHI Exposure appeared first on HIPAA Journal.

Vascular Surgical Associates Hacking Incident Reported

Vascular Surgical Associates – A group of specialty-trained vascular surgeons in Atlanta – has announced that it has been the victim of a hacking incident that has potentially resulted in certain protected health information being viewed by unauthorized individuals.

IT staff noticed unusual activity on one of the company’s servers on or around September 13, 2016. An investigation into the anomaly was launched, which revealed the server had been improperly accessed using login credentials supplied to some of the group’s vendors. Access to patient data was first gained on March 25, 2016 when a software application upgrade was performed.

The investigation did not confirm whether patient health information had been obtained by the hackers, although for more than five months it would have been possible for the login credentials to have been used to view patient data. As soon as IT staff determined the server had been compromised access was immediately terminated. The server is now secure and Vascular Surgical Associates is confident that no further unauthorized access is possible.

It would not have been possible for the intruders to view Social Security numbers or financial data, as that information was stored elsewhere on a part of the network that was not compromised. However, names, addresses, birth dates, demographic data, and medical records were all potentially viewed.

The investigation did not confirm the identity of the hackers, although evidence was uncovered to suggest the attackers were based in other countries. The login credentials used to gain access to the server were only used by vendors and their staff members. Vascular Surgical Associates is confident that none of its staff members were involved in the breach.

Vascular Surgical Associates has reported to the incident to the appropriate federal and state authorities and investigations will be launched by the FBI and Department of Health and Human Services’ Office for Civil Rights. At present, no announcement has been made about the number of patients that have been impacted by the incident. Affected individuals will be notified of the security breach by mail.

The post Vascular Surgical Associates Hacking Incident Reported appeared first on HIPAA Journal.