HIPAA Breach News

Privacy Breach Reported by Wentworth-Douglass Hospital

Wentworth-Douglass Hospital in Dover, New Hampshire has started alerting patients to a privacy breach experienced by one of its vendors, Ambucor Health Solutions.

Ambucor Health Solutions provides a remote-monitoring service for cardiac devices for hospitals throughout the United States. Earlier this month, the company started notifying its clients of a privacy breach caused by one of its former employees.

Prior to leaving employment, the employee downloaded sensitive company data onto two flash drives. The data breach was discovered by Ambucor Health Solutions over the summer and an investigation was launched.

The incident was reported to law enforcement, and the subsequent investigation resulted in the flash drives being recovered in July.

An analysis of the contents of the drives, which was completed in September, revealed the downloaded data included a range of electronic health information of cardiac patients from a number of the company’s clients, and included the protected health information of 775 patients of Wentworth-Douglass Hospital.

Social Security numbers, financial information, insurance information, and Medicare/Medicaid numbers were not copied to the flash drives so Wentworth-Douglass Hospital believes the risk of data being used to make fraudulent claims or steal identities is low. No evidence has been uncovered by law enforcement, Ambucor Health Solutions, nor Wentworth-Douglass Hospital to suggest any of the downloaded data have been used inappropriately.

However, out of an abundance of caution, all affected patients have been offered 12 months of identity theft protection services without charge. Patients will also be protected by a $1 million identity theft insurance policy.

The protected health information copied to the device included names, phone numbers, home address, race, Ambucor enrollment numbers, Ambucor enrollment dates, Ambucor technician names, patient ID numbers, Physicians’ names, testing data, medications, medical diagnoses, names of the practices visited, and details of the cardiac devices that had been fitted.

Ambucor Health Solutions has since taken steps to improve security to prevent future breaches of this nature from occurring, including conducting a thorough review and update of all HIPAA policies covering data security.

The post Privacy Breach Reported by Wentworth-Douglass Hospital appeared first on HIPAA Journal.

Chiropractic Clinics Alert Patients to Billing Vendor Breach

Two providers of chiropractic services in California have started notifying their patients of a security breach affecting their billing software company.

Luque Chiropractic, Inc., and Watsonville Chiropractic, Inc., were alerted to a cloud storage account breach on November 18, 2016., following a data security incident that saw patient data accessed by an unauthorized individual.

The breach was experienced by EMR4all, Inc., and affected clients that used the company’s associated billing service.

EMR4all, Inc provides free EMR software for physical therapy, occupational therapy, and chiropractic practices throughout the United States, while billing services are provided by Rehab Billing Solutions.

In early September, security researcher Chris Vickery discovered a cloud storage account used by EMR4all/Rehab Billing Solutions could be freely accessed via the Internet. The cloud storage account contained the health records and personal information of many thousands of patients from more than 30 providers of physical therapy and chiropractic services.

Vickery was able to access and download the data from the account. In total, around 61GB of data – and approximately 240,000 unencrypted files – were stored in the account.

Luque Chiropractic and Watsonville Chiropractic were informed that their patients’ names, addresses, birth dates, medical diagnoses, Social Security numbers, treatment dates, and treatment locations, had been compromised and had potentially been accessed.

The data in the account was downloaded by Vickery on September 10, 2016, although the account was left unsecured for a period of around 4 months from May 2016 to September 2016.

As soon as the billing service provider was informed of the lack of security protections, rapid action was taken to secure the account. Proper access credentials are now required to access patient data.

Vickery only downloaded the data for the purpose of highlighting the lack of security protections and to ensure that all companies/individuals affected could be notified. Vickery has agreed to delete the data and not to disclose the information to any other individuals. However, it is possible that other individuals may have accessed the data during the time that the storage account was left unprotected. To date, Luque Chiropractic, Inc., and Watsonville Chiropractic have not received any reports to suggest that patient data have been used inappropriately.

The post Chiropractic Clinics Alert Patients to Billing Vendor Breach appeared first on HIPAA Journal.

Briar Hill Management Notifies 2,000 Individuals of February Laptop Loss

Briar Hill Management, a Ridgeland, MS-based provider of management services for skilled nursing facilities in Mississippi, has lost a laptop computer containing the sensitive data of 2,000 nursing facility residents.

The laptop was discovered to be missing on February 26, 2016, although at the time it was not believed that the laptop contained any resident health information. However, according to the breach notice recently uploaded to the company website, an investigation into the incident revealed that the employee who had been assigned the laptop computer had breached company policies and had downloaded sensitive information onto the device.

The data stored on the unencrypted laptop included residents’ names, addresses, birth dates, dates of service, Social security numbers, prescription information, and medical records. Briar Hill Management says “the laptop did not contain all of these types of information for every affected resident.” The breach notice does not state when Briar Hill Management discovered sensitive information had been exposed.

Briar Hill Management conducted an “exhaustive” search for the device, but it was concluded that the laptop was lost off-site. Briar Hill Management says the employee also breached company policies by failing to “properly secure the laptop when outside of the company’s office.” Law enforcement has been notified of the loss, but after more than 8 months since the laptop was lost it can be safely assumed that the device will not be recovered.

Residents impacted by the breach have been informed that the company’s investigation into the incident has not uncovered any evidence to suggest that residents’ information has been improperly accessed, although as a precaution, individuals affected by the breach have been offered a year of credit monitoring and identity theft protection services without charge.

To prevent future breaches of this nature, Briar Hill Management has implemented additional safeguards for all mobile devices used by company employees. The employee responsible for the device has also been sanctioned.

The post Briar Hill Management Notifies 2,000 Individuals of February Laptop Loss appeared first on HIPAA Journal.

Eye Institute of Marin Notifies Patients of Ransomware Data Loss

The San Rafael, CA-based Eye Institute of Marin has informed some of its patients that a ransomware attack on its electronic medical record provider has potentially resulted in some of their electronic protected health information being accessed by the attackers.

The EMR system contained a considerable amount of sensitive patient data including names, telephone numbers, addresses, birth dates, race, gender, Social Security numbers, medical histories, medical diagnoses, prescription information, health insurance details, health visit information, charges and payment details, and emergency contact information. No financial information or credit/debit card numbers were exposed as these were stored separately in a different system.

The incident was investigated at the time by a third party computer forensics company. The firm’s analysis of the attack did not uncover any evidence to suggest that patient data were accessed or copied by the attackers, although the possibility of data access could not be ruled out entirely.

The ransomware attack took place on July 26, 2016. The electronic medical record provider discovering the attack the following day. Systems were rapidly secured following the attack and data were restored from backup files.

Eye Institute of Marin was notified of the malware attack by its EMR provider on August 22, 2016. Further information about the incident was requested from the EMR provider, including details of the patients that had been affected. On September 14, Eye Institute of Marin discovered that the malware attack involved ransomware.

Eye Institute of Marin also discovered that some patient data were irrevocably lost. The majority of patient data were restored from backup files, although some patients’ consultation notes could not be recovered from the backup files.

The data that were lost included clinical histories, vital signs, and records of communications with patients. Details of refraction examinations may also have been lost. Patients whose data were lost had visited the Eye Institute of Marin between 7/11/16 and 7/26/16.

The Eye Institute of Marin did notify patients of the data loss on October 18, 2016, although breach notification letters have now been sent to all Eye Institute of Marin patients regarding the ransomware infection in accordance with HIPAA Rules. A press release was also issued on November 18 alerting the media to the possible data breach.

Eye Institute of Marin has confirmed that its EMR provider has appropriately secured its systems and policies and procedures have been reviewed. While credit monitoring and identity theft protection services have not been offered to patients, the Eye Institute of Marin has suggested patients place a credit freeze on their accounts and obtain a credit report from one of the three credit monitoring agencies if they are concerned about possible misuse of their data.

The post Eye Institute of Marin Notifies Patients of Ransomware Data Loss appeared first on HIPAA Journal.

Patients Notified of KinetoRehab Physical Therapy Laptop Theft

New York-based KinetoRehab Physical Therapy has started sending HIPAA breach notification letters to patients alerting them to the potential exposure of some of their protected health information.

On September 16, 2016, KinetoRehab discovered a laptop computer was missing from its facilities. A review of security camera footage revealed the laptop computer had been stolen. While the laptop bag has now been found, the laptop computer had been removed and has not been recovered. The incident was reported to law enforcement and efforts are currently being made to locate the individual identified from the CCTV camera footage.

The laptop contained data on a limited number of patients, although those affected by the breach have had highly sensitive information exposed. The laptop contained patients’ names, birthdates, Social Security numbers, insurance information, and notes relating to the physical therapy provided by the clinic. Patients affected by the incident had visited KinetoRehab Physical Therapy for treatment between November 2011 and March 2013.

While the data stored on the device could potentially be accessed by unauthorized individuals, there is no indication that data have been accessed or that they will be used inappropriately. However, since highly sensitive information has been exposed, KinetoRehab Physical Therapy is offering all affected patients 12 months of credit monitoring and identity theft protection through Experian’s® ProtectMyID® Alert or Family Secure®.

KinetoRehab Physical Therapy has informed patients “We have taken every step necessary to address the incident, and that we are committed to fully protecting all the information that has been entrusted to us.” A review of the organizations technical safeguards is being conducted and improvements will be made to prevent similar incidents from occurring in the future.

The ePHI breach has been reported to the New York Attorney General and the Department of State’s Division of Consumer Protection. The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates 665 individuals have been affected.

The post Patients Notified of KinetoRehab Physical Therapy Laptop Theft appeared first on HIPAA Journal.

Healthcare Data Breaches Fell in October

There was a fall in the number of data breaches reported by healthcare organizations in the United States in October, according to the latest Breach Barometer report from Protenus. This is the second month in a row where the number of data breaches have fallen.

The number of reported breaches dropped from an annual high of 42 incidents in August to 35 breaches in October; two fewer breaches than were reported last month. However, the number of exposed records increased from 246,876 in September to 776,533 records in October. The final victim count for the month could be considerably higher as while 35 breaches were reported, the number of individuals impacted by four of those incidents is not yet known.

There were some notable IT security incidents reported last month:

Four healthcare organizations reported being attacked with ransomware in October. Three of those incidents resulted in a permanent loss of healthcare data. Two organizations attempted to recover data from backups, only for the backup recovery process to fail, while one healthcare organization reported data loss as a direct result of the infection. The extent of data loss in each of these incidents was not disclosed publicly.

Two healthcare organizations were subject to extortion attempts after data were stolen. The organizations in question were told that the stolen data would be published or sold if payment was not made to the attacker.

The hacker responsible for those attacks was The Dark Overlord, who has previously hacked a number of healthcare organizations and held their data to ransom. While The Dark Overlord claims to have been paid by some healthcare organizations, there is no evidence of any payments actually being made according to Dissent of DataBreaches.net. Some of the stolen data have been dumped online and listings have been placed on darknet marketplaces offering the stolen data for sale.

Hacking and ransomware/malware infections were the main causes of healthcare data breaches in October, accounting for 40% of all data breaches. Those breaches were the most severe and accounted for the majority (86%) of stolen/exposed records for the month. (664,549/776,533).

Hacking and ransomware attacks were closely followed by accidental and deliberate insider breaches. 37% of October healthcare data breaches were due to insiders. Those incidents impacted 79,974 individuals. Two insider breaches occurred for which the victim count is not yet known.

The majority of breaches (82.8%) involved healthcare providers, followed by business associates of covered entities (8.6%), health plans (5.7%), and health information exchanges (2.9%). For the second month running, California was the worst hit state, recording 4 healthcare data breaches.

According to Robert Lord, Co-Founder & CEO of Protenus,”A few things stand out as particularly interesting this month.  First, there were the public reports of data loss due to ransomware, which confirmed the rumors that ransomware payments aren’t always leading to recovered data.  Second, the continued consistency of insider threats demonstrates the critical necessity of thinking about how we can mitigate these types of health data breaches and HIPAA violations.”

While it is certainly good news that the downward trend in breaches is continuing, this does not necessarily mean that healthcare organizations are getting better at securing protected health information. As Lord explains, “while breach numbers aren’t as high as the catastrophic numbers of the summer, we don’t see the fundamentals of a severely-threatened health data landscape changing anytime soon.”

The Protenus Breach Barometer is a monthly report of healthcare data breaches reported to the Department of Health and Human Services’ Office for Civil Rights or disclosed to the media or other trusted online sources.

The post Healthcare Data Breaches Fell in October appeared first on HIPAA Journal.

Emblem Health Mailing Error Exposes Members’ Social Security Numbers

Emblem Health, one of the largest health plans in the United States, has discovered a printing error has resulted in some members’ Social Security numbers being printed on the outside of envelopes during a recent mailing.

The New York-based health insurer says the privacy breach affects members of its subsidiary company, Group Health Inc. (GHI).

The error was made while mailing Medicare Prescription Drug Plan Evidence of Coverage documents to health plan members. Normally, all mailings include a unique mailing identifier which is printed on the envelope. These ID numbers are randomly generated and are included on the envelopes to help keep track of mailings.

However, for the latest mailing, an error was made that resulted in members Health Insurance Claim Number (HICN) being included in the electronic file that was sent to the health plan’s mailing vendor. That number was then printed on the envelopes instead of the mailing identifier. HICN numbers are formed from members’ 9-digit Social Security numbers.

Affected members therefore had their Social Security numbers printed on the outside of the envelopes along with their name and address. The HICN numbers were listed as a package number on the envelope (PKG#), not as a HCIN number or Social Security number. Even if the envelopes were viewed, it would likely be unclear that the number was the same as members’ Social Security numbers.

However, since SSNs were exposed, Emblem Health is taking no chances and has offered all affected members free enrolment in AllClear’s credit monitoring and identity repair services. Members will also be protected by a $1 million identity theft insurance policy and the services will be available for a period of two years rather than the standard 12 months.

Affected members are now being notified of the breach by mail and have been advised to sign up for the services and ensure that the label from the Evidence of Coverage mailing is removed and disposed of in a secure manner.

Emblem Health will be reviewing its policies and procedures and implementing new controls to ensure that errors of this nature are prevented in the future.

The post Emblem Health Mailing Error Exposes Members’ Social Security Numbers appeared first on HIPAA Journal.

Horizon BCBS of New Jersey Privacy Breach Impacts 170,000 Members

Horizon Blue Cross Blue Shield of New Jersey has been alerted to a printing error that resulted in a limited amount of members’ protected health information being disclosed to other plan members. According to a statement issued by Horizon BCBSNJ, the error was made by its printing vendor, Command Marketing Innovations of Garfield.

Between October 31 and November 2, Horizon BCBSNJ’s vendor printed and mailed Explanation of Benefit letters to members; however, an error resulted in some members’ names, claim numbers, Member ID numbers, dates of service, service codes, provider and facility names, and a limited description of services being printed on EOB letters that were send to other members.

Horizon BCBSNJ says the error was identified on November 2 and the printing run was halted, but not before letters had been mailed to around 170,000 members. Not all of those members will have received letters containing the PHI of other members, but Horizon BCBSNJ has been unable to determine exactly how many of the letters included other members’ PHI.

According to Horizon spokesman Kevin McArdle, all that is known is that 170,000 EOB letters were mailed by its vendor before the error was identified. Horizon BCBSNJ is now working with its vendor to determine exactly how many individuals have been impacted.

Horizon BCBSNJ has confirmed that no Social Security numbers, dates of birth, addresses, or financial information were included in the letters, but since insurance information was disclosed there is a risk of the information being misused.

Horizon BCBSNJ has said it will be monitoring affected members’ accounts to check for fraudulent medical claims, and members should do the same. Correct EOB letters will be mailed to all members next week along with breach notification letters about the privacy breach, although many members have already noticed the error and have contacted Horizon BCBSNJ and have expressed concern about the incident.

The post Horizon BCBS of New Jersey Privacy Breach Impacts 170,000 Members appeared first on HIPAA Journal.