HIPAA Breach News

Patient Data Stolen in July 2021 Cyberattack on Chelan Douglas Health District

Chelan Douglas Health District in East Wenatchee, WA, has announced it was the victim of a cyberattack in July 2021 in which the personal and protected health information of patients was exfiltrated from its systems. The breach notice uploaded to Chelan Douglas Health District website does not disclose when the breach was detected but says a third-party cybersecurity company was engaged to investigate the cyberattack and confirmed that its network was accessed by unauthorized individuals between July 2 and July 4, 2021. A representative for the health district said this was not a ransomware attack.

The review of the files that were removed from its systems was completed on February 12, 2022, and confirmed the following types of patient data had been stolen: Names, Social Security numbers, dates of birth/death, financial account information, treatment information, diagnosis information, medical record/ patient numbers, and health insurance policy information.

Notification letters started to be sent to affected individuals on March 15, 2022. Individuals who had their Social Security numbers stolen have been offered complimentary credit monitoring services. Chelan Douglas Health District said it is unaware of any cases of identity fraud or other misuse of patient data. Steps have since been taken to improve the security of its systems to prevent further data breaches in the future.

The incident has not yet appeared on the HHS’ Office for Civil Rights website, so it is currently unclear exactly how many individuals have been affected. There have been some reports in the media that suggest the PHI of approximately 109,000 individuals was stolen in the attack.

BEC Attack Reported by Liberty of Oklahoma Corporation

Oklahoma’s Department of Human Services and Liberty of Oklahoma Corporation (LOC) have announced that patient information was potentially accessed in a business email compromise attack in early December 2021.

On December 7, 2022, an employee in the Oklahoma Waitlist program received an email from a spoofed email account that attempted to redirect payments that were owed to LOC. The scam was detected and no fraudulent payments were made, but while investigating the incident they determined the email account of a LOC employee had been compromised.

The email account was immediately disabled, and a review was conducted to determine the types of information that may have been accessed or stolen. The review confirmed names, addresses, dates of birth, phone numbers, Social Security numbers, Oklahoma client Numbers, and the contact information of representing persons had been exposed.

LOC reported the breach to the HHS’ Office for Civil Rights as affecting 5,746 individuals.

East Tennessee Children’s Hospital Investigating Security Breach

East Tennessee Children’s Hospital is currently investigating a security breach that occurred on March 13, 2022, and caused disruption to its IT systems. A spokesperson for the hospital said the incident has not affected the ability of the hospital to provide care to patients and its internal teams and external agencies are working to minimize the disruption caused by the incident.

A forensic investigation has been initiated to determine the nature and scope of the security incident, but at this stage of the investigation, it is not known whether any patient information has been accessed or stolen.

The post Patient Data Stolen in July 2021 Cyberattack on Chelan Douglas Health District appeared first on HIPAA Journal.

Data Breaches Reported by New Jersey Brain and Spine, Highmark Inc. and Dialyze Direct

New Jersey Brain and Spine (NJBS) has recently announced it was the victim of a cyberattack on or around November 16, 2021, that encrypted data on its network. NJBS said it immediately took steps to secure its network and engaged a computer forensic firm to investigate the security breach. While no evidence has been found to indicate there has been any misuse of patient data as a result of the attack, the forensics firm said the attacker may have accessed files containing patient data.

A third party vendor was engaged to conduct a review of all files on its network that had potentially been accessed, and while the data mining process is ongoing, it has been confirmed that the files contained information such as names, addresses, dates of birth, email addresses, telephone numbers, social security numbers, financial account information, debit or credit card information, driver’s license numbers or other ID numbers, and medical information. Notification letters were sent to affected individuals on March 10, 2022.

NJBS said that following the breach, several steps were taken to better protect patient data, including implementing 2-factor authentication, migrating patient data to a third-party hosted cloud-based platform, and installing a new server. NJBS has also implemented an ongoing monitoring response solution that tracks user activity, services, and ports, and coordinates logging.

The breach has been reported to the HHS’ Office for Civil Rights as affecting up to 92,453 individuals.

Highmark Inc. Patients Affected by Breach at Printing and Mailing Vendor

Highmark Inc., a Pittsburgh, PA-based non-profit healthcare company and Integrated Delivery Network has recently announced that some HIPAA-protected data has been exposed in a data breach at the printing and mailing vendor, Quantum Group, which was used by its vendor, Webb Mason, which provides marketing services to Highmark.

Webb Mason provided patient data to Quantum Group in 2017 to assist with marketing efforts for Highmark, and that information has potentially been accessed by unauthorized individuals. Highmark stressed that its own IT systems were not compromised.

Highmark reported the breach as affecting up to 67,147 individuals, who have been offered complimentary online identity monitoring services for 12 months at no cost.

Dialyze Direct Alerts Patients About PHI Exposure in Cyberattack

Dialyze Direct, a Neptune City, NJ, provider of kidney care services, has suffered a data breach that has affected up to 14,203 patients. According to a March 10, 2022 data breach notice, Dialyze Direct said it discovered on February 14, 2022, that an unauthorized individual had gained access to an employee email account between January 21, 2021, and March 4, 2021.

A comprehensive review of the email account confirmed it contained patients’ protected health information such as names, dates of birth, Social Security numbers, government identification numbers, financial account information, payment card information, and medical information that potentially includes financial identification numbers, medical diagnostic and treatment information, and/or health insurance plan information.

Notification letters have been sent to affected patients. Individuals whose Social Security numbers were potentially compromised have been offered complimentary credit monitoring services. Dialyze Direct said it has found no evidence to suggest that there has been any misuse of patient data.

The post Data Breaches Reported by New Jersey Brain and Spine, Highmark Inc. and Dialyze Direct appeared first on HIPAA Journal.

February 2022 Healthcare Data Breach Report

For the third successive month, the number of data breaches reported to the HHS’ Office for Civil Rights (OCR) has fallen. 46 healthcare data breaches of 500 or more records were reported to OCR in February – an 8% fall from January. February saw the lowest number of data breaches in the past 5 months. Even with the reduction in breaches, on average, more than 2 healthcare data breaches have been reported each day over the past 12 months. From March 1, 2021, to February 28, 2022, there have been 723 reported data breaches of 500 or more records.

Healthcare data breaches in the past 12 months

Across February’s 46 incidents, the records of 2,525,023 individuals were exposed or compromised – a 2.28% fall from the previous month – which is considerably lower than the 3,506,400 records that have been breached each month, on average, from March 1, 2021, to February 28, 2022. At least 42,076,805 healthcare records were exposed over that period. In February, the average breach size was 48,957 records and the median breach size was 7,014 records.

breached healthcare records over the past 12 months

Largest Healthcare Data Breaches Reported in February 2022

22 HIPAA-regulated entities reported breaches of 10,000 or more healthcare records in February. The largest breach of the month was reported by Morley Companies, which was a hacking incident that resulted in the exposure and possible theft of the protected health information of 521,046 members of its health plan.

Monongalia Health System reported a major hacking incident that potentially resulted in the theft of the PHI of 492,861 individuals. The breach was discovered a few days after the health system announced a previous data breach – a phishing and business email compromise attack – that affected almost 398,164 individuals.

Name of Covered Entity State Covered Entity Type Individuals Affected Type of Breach Cause of Breach
Morley Companies, Inc. MI Business Associate 521,046 Hacking/IT Incident Unspecified hacking incident
Monongalia Health System, Inc. WV Healthcare Provider 492,861 Hacking/IT Incident Unspecified hacking incident
Norwood Clinic AL Healthcare Provider 228,000 Hacking/IT Incident Unspecified hacking incident
Logan Health Medical Center MT Healthcare Provider 213,543 Hacking/IT Incident Unspecified hacking incident
South Shore Hospital Corporation IL Healthcare Provider 115,670 Hacking/IT Incident Unspecified hacking incident
Comprehensive Health Services FL Healthcare Provider 106,752 Hacking/IT Incident Business email compromise
US Radiology Specialists, Inc. NC Business Associate 87,552 Hacking/IT Incident Unknown
Memorial Village ER TX Healthcare Provider 80,000 Hacking/IT Incident Unspecified hacking incident
Montrose Regional Health CO Healthcare Provider 52,632 Hacking/IT Incident Compromised email accounts
Cross Timbers Health Clinics dba AccelHealth TX Healthcare Provider 48,126 Hacking/IT Incident Ransomware attack
Jacksonville Spine Center, P.A. FL Healthcare Provider 38,000 Hacking/IT Incident Ransomware attack
The Puerto Rican Organization to Motivate, Enlighten, and Serve Addicts, Inc. NY Healthcare Provider 30,220 Hacking/IT Incident Compromised email accounts
EPIC Pharmacy Network, Inc. VA Healthcare Provider 28,776 Hacking/IT Incident Compromised email accounts
Ascension Michigan (single affiliated covered entity) ACE MI Healthcare Provider 27,177 Unauthorized Access/Disclosure Unauthorized EHR access by an employee
Bako Diagnostics GA Healthcare Provider 25,745 Hacking/IT Incident Unspecified hacking incident (data exfiltration confirmed)
Ultimate Care, Inc. NY Healthcare Provider 15,788 Hacking/IT Incident Compromised email accounts
Alliance Physical Therapy Group, LLC MI Business Associate 14,970 Hacking/IT Incident Unspecified hacking incident
University Medical Center Southern Nevada NV Healthcare Provider 12,230 Hacking/IT Incident Unknown
Seneca Nation Health System NY Healthcare Provider 12,000 Hacking/IT Incident Unknown
CareOregon Advantage OR Health Plan 10,467 Unauthorized Access/Disclosure Misdirected email
Extend Fertility NY Healthcare Provider 10,373 Hacking/IT Incident Ransomware attack
Houston Health Department TX Healthcare Provider 10,291 Unauthorized Access/Disclosure Misconfigured web portal

Causes of February 2022 Healthcare Data Breaches

As the table above shows, hacking incidents dominated the breach reports in February. 39 of the month’s data breaches were hacking/IT incidents, the majority of which saw unauthorized individuals hack into networks and view and/or exfiltrate sensitive data. It is common for breached entities to disclose hacking incidents but not publicly disclose details about the exact nature of the attacks, such as if they involved malware or ransomware. Across those 39 breaches, the records of 2,184,973 individuals were exposed or compromised. The average breach size was 56,025 records and the median breach size was 6,221 records.

causes of february 2022 healthcare data breaches

There were 6 unauthorized access/disclosure incidents reported in February involving the records of 62,550 individuals. The average breach size was 10,425 records and the median breach size was 8,953 records. There was one loss incident involving a desktop computer that contained the PHI of 4,500 individuals. There were no reported theft or improper disposal incidents.location of breached PHI in February 2022 healthcare data breaches

Healthcare Data Breaches by State

HIPAA-regulated entities in 23 states reported data breaches in February. New York the worst affected state with 6 reported breaches, followed by Florida, Michigan, and New Jersey which each had 5.

State Number of reported breaches
New York 6
Florida, Michigan, and New Jersey 5
Texas and Virginia 3
Pennsylvania and West Virginia 2
Alabama, Arizona, Colorado, Connecticut, Georgia, Illinois, Massachusetts, Montana, Nevada, North Carolina, Oklahoma, Oregon, Rhode Island, Utah, and Washington 1

Healthcare Data Breaches by HIPAA-Regulated Entity Type

Healthcare providers were the worst affected entity in February 2022 having reported a total of 35 data breaches involving the records of 1,597,155 individuals. There were 6 data breaches reported by health plans involving 21,284 records, and 5 data breaches were self-reported by business associates of HIPAA-covered entities, which involved the records of 633,584 individuals.

10 breaches occurred at business associates but were reported by the affected covered entity, with the adjusted figures shown in the chart below.

February 2022 healthcare data breaches by HIPAA-regulated entity type

HIPAA Enforcement Actions in February 2022

There were no announcements by the HHS’ Office for Civil Rights or state Attorneys General about HIPAA enforcement actions in February. In fact, there have been no financial penalties imposed for HIPAA violations so far in 2022.

OCR Director, Lisa J. Pino, has confirmed that the Department of Health and Human Services has an ambitious regulatory agenda for 2021, which will include strong enforcement of HIPAA compliance, including the continuation of its enforcement initiative targeting healthcare providers that violate the HIPAA Right of Access and fail to provide individuals with timely access to their medical records.

The post February 2022 Healthcare Data Breach Report appeared first on HIPAA Journal.

JDC Healthcare Management Data Breach Affects More than 1 Million Texans

On March 17, 2022, Dallas, TX-based JDC Healthcare Management, which runs more than 70 Jefferson Dental & Orthodontics practices throughout the state of Texas, reported a security breach to the Office of the Attorney General of Texas that has affected more than 1 million Texans.

As previously reported on this site, JDC Healthcare Management detected malware within its IT network on or around August 9, 2021, with the forensic investigation into the security breach confirming the malware was downloaded onto its systems on July 27, 2021.

Further information on the data breach has now been obtained. JDC Healthcare Management explained that the malware gave unauthorized individuals access to its IT systems from July 27, 2021, to August 16, 2021, and its forensic investigation confirmed the attackers viewed or copied files on its systems that contained patients’ electronic protected health information (ePHI).

JDC Healthcare Management explained in its March 2022 breach notification letters that the comprehensive review of the impacted files is ongoing, but it has been confirmed that the types of exposed and compromised ePHI included names, dates of birth, Social Security numbers, driver’s license numbers, financial information, health insurance information, and medical information.

In its breach notification letters, JDC Healthcare Management said, “Upon learning of this incident, we moved quickly to investigate and respond to this incident, assess the security of our systems, restore functionality to our environment, and notify potentially affected individuals.”

JDC Healthcare Management said it is reviewing and enhancing its existing policies and procedures to reduce the likelihood of further security breaches. Affected individuals have been advised to check their accounts, explanation of benefits statements, and free annual credit reports, although there is no mention in the breach notification letters about credit monitoring and identity theft protection services being offered.  JDC Healthcare Management said that at the time of issuing notification letters, it was unaware of any actual or attempted misuse of patient data.

Notification letters are now being sent and the incident will be reported to the HHS’ Office for Civil Rights. The breach report submitted to the Texas Attorney General indicates the ePHI of 1,026,820 Texans was potentially compromised.

Wheeling Health Right Inc. Suffers Ransomware Attack

Wheeling Health Right Inc. in West Virginia has announced it was the victim of a ransomware attack in January 2022. The security breach was detected on January 18, 2022, when access to files on its IT systems was prevented. Wheeling Health Right said it engaged legal counsel and a data breach remediation firm to investigate the attack and determine the extent to which its systems had been compromised.

A review of all files on the affected parts of its systems confirmed they contained sensitive patient and employee information such as full names, addresses, email addresses, phone numbers, driver’s license numbers, medical record numbers, Social Security numbers, tax information, income information, and health information of patients who applied for or received services from Wheeling Health Right.

Wheeling Health Right said its information technology service provider decrypted, recovered, and rebuilt its systems, initiated a password reset for all system end-users, implemented multi-factor authentication for employee email accounts, and installed additional endpoint detection and response software. Further privacy and security measures have also been implemented, including providing additional cybersecurity training to the workforce.

Wheeling Health Right said affected individuals were notified on March 18, 2022, and have been offered identity monitoring to affected individuals at no cost for 12 months. The incident has not yet appeared on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected.

The post JDC Healthcare Management Data Breach Affects More than 1 Million Texans appeared first on HIPAA Journal.

Central Indiana Orthopedics & Duncan Regional Hospital Report 80K-Record Data Breaches

Cyberattacks have been reported by Duncan Regional Hospital in Oklahoma and Central Indiana Orthopedics that have affected a total of 170,084 individuals.

Duncan Regional Hospital

Duncan Regional Hospital has recently announced it was the victim of a cyberattack in January. The incident was detected on January 20, 2022, when suspicious activity was identified in some of its IT systems. All systems were immediately taken offline to prevent further unauthorized access and a third-party computer forensics firm was engaged to determine the nature and scope of the breach.

Duncan Regional Hospital said the hackers did not gain access to its electronic medical record system but did access parts of the network where files containing patient data were stored. Those files contained patient names, addresses, phone numbers, dates of birth, Social Security numbers, appointment information such as dates of service and healthcare provider names, and limited treatment information.

Steps have been taken to improve security and prevent further attacks, including an organization-wide password reset and implementing new endpoint threat detection and response monitoring software and more robust firewall restrictions. Affected individuals have been notified and offered complimentary credit monitoring and identity protection services.

The incident has been reported to the HHS’ Office for Civil Rights as affecting 86,379 patients.

Central Indiana Orthopedics

Earlier this month, Central Indiana Orthopedics announced it was the victim of a cyberattack that was detected on October 16, 2021. Steps were immediately taken to secure its network and a third-party computer forensics firm was engaged to investigate the breach.

The investigation revealed files containing patient information had been accessed by unauthorized individuals, although no reports have been received that suggest any patient information has been misused. The types of information in the files varied from patient to patient and may have included names, addresses, Social Security numbers, and limited medical information.

Central Indiana Orthopedics said several steps have been taken in response to the breach to improve security, prevent further cyberattacks., and mitigate the risk of future harm. All individuals affected by the breach have been notified and offered complimentary credit monitoring, dark web monitoring, and identity theft protection services.

The incident has been reported to the HHS’ Office for Civil Rights as affecting 83,705 individuals.

The post Central Indiana Orthopedics & Duncan Regional Hospital Report 80K-Record Data Breaches appeared first on HIPAA Journal.

Capital Region Medical Center and Labette Health Announce Potential PHI Breaches

Capital Region Medical Center (CRMC) in Jefferson City, MO has recently confirmed patient information was accessed by unauthorized individuals in a December 2021 cyberattack that took its network and phone systems offline for several days.

The attack was detected on December 17, 2021, when network systems were disrupted. An investigation was launched to determine the nature and scope of the breach, and a public announcement about the security incident was issued on December 23, 2021. It was initially unclear if patient information had been compromised but that has now been confirmed.

CRMC said at this stage of the investigation it does not appear that the attackers gained access to its electronic medical record database; however, the files accessed or potentially accessed by the attackers included information such as patient names, addresses, birth dates, medical information, and health insurance information. A subset of patients also had their Social Security numbers, driver’s license numbers, and/or financial account information exposed. That subset of patients has been offered a complimentary 12-month membership to credit monitoring services. CRMC said it has found no evidence to date to indicate any patient information has been misused.

CRMC said it will continue to evaluate its security practices and will look for opportunities to implement additional cybersecurity measures to bolster security and prevent similar cyberattacks in the future.

The incident has yet to appear on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected.

Labette Health Notifies Patients About October 2021 Cyberattack

Labette Health in Kansas has recently announced its IT systems were accessed by unauthorized individuals between October 15, 2021, and October 24, 2021.

Labette Health said that it took immediate steps to secure its network and limit the potential for additional harm. Third-party cybersecurity professionals were engaged to investigate the security breach and determine the nature and scope of the cyberattack. The investigation concluded on February 11, 2022, that certain files and folders on its network that contained patients’ protected health information had been accessed by unauthorized individuals, who may have exfiltrated some of those files.

The files contained employee and patient names and one or more of the following types of information: Social Security number, medical treatment and diagnosis information, treatment costs, dates of service, prescription information, Medicare or Medicaid number, and health insurance information.

It has been four months since the breach occurred, and to date, Labette Health has not found any evidence of misuse of patient or employee information.  Labette Health said on March 11, 2022, written notifications were sent to affected individuals out of an abundance of caution. Individuals whose Social Security numbers were exposed have been offered complimentary credit monitoring services.

Labette Health said it followed the recommendations of cybersecurity experts and has strengthened network security, implemented more robust password security policies and multi-factor authentication for network access, and has upgraded endpoint detection software and provided additional network security and threat detection training to the workforce.

The data breach has not yet appeared on the HHS’ Office for Civil Rights breach portal so it is currently unclear how many individuals have been affected.

The post Capital Region Medical Center and Labette Health Announce Potential PHI Breaches appeared first on HIPAA Journal.

South Denver Cardiology Associates Confirms Data Breach Affecting 287,000 Patients

South Denver Cardiology Associates (SDCA) has recently announced it was the victim of a cyberattack in January 2022 in which files containing patient information were accessed and potentially stolen by hackers.

Unusual network activity was detected on January 4, 2022, and the SDCA breach response process was immediately initiated. Systems were isolated from the network and shut down, with the investigation determining hackers had access to certain systems from January 2, 2022, to January 5, 2022.

During that time, the hackers accessed certain files stored on its systems, some of which contained patients’ personal and protected health information. A comprehensive review of those files confirmed they contained patient names along with one or more of the following types of information: dates of birth, Social Security numbers, drivers’ license numbers, patient account numbers, health insurance information, and clinical information such as physician names, dates and types of service, and diagnoses.

SDCA said the contents of medical records were unaffected, the patient portal was not compromised, and the investigation did not uncover any evidence of actual or attempted misuse of patient information; however, as a precaution, affected individuals have been offered complimentary access to credit monitoring and identity theft protection services.

The breach has been reported to the HHS’ Office for Civil Rights as affecting up to 287,652 individuals.

Up to 80,000 Patients Affected by Memorial Village ER Cyberattack

Memorial Village ER in Houston TX, has recently started notifying 80,000 patients that some of their protected health information was stored on a server that was accessed by hackers on February 18, 2022.

Memorial Village ER said the server was secured with HIPAA-compliant safeguards, but the security defenses were breached by an unknown entity who potentially viewed and/or obtained files on the server. A comprehensive review was conducted to determine the types of information on the server, which confirmed the breach was limited to names, addresses, birth dates, and COVID-19 test results. Affected individuals were notified on March 9, 2022, less than a month after the breach was detected.

Social Security numbers, financial information, and insurance information were not compromised; however, out of an abundance of caution, affected individuals have been offered a complimentary 12-month membership to Experian’s IdentityWorks identity theft protection service.

Memorial Village ER said it has now upgraded its cybersecurity platform to prevent further security breaches in the future.

The post South Denver Cardiology Associates Confirms Data Breach Affecting 287,000 Patients appeared first on HIPAA Journal.

Logan Health Facing Class Action Lawsuit Over Data Breach

Legal action is being taken against Logan Health and subsidiary, sister, and related entities of Logan Health over a data breach that occurred in 2021 and affected 213,543 Logan Health Medical Center patients.

The class action lawsuit was filed in the U.S. District Court for the District of Montana Great Falls Division by law firm Heenan & Cook on behalf of plaintiff Allison Smeltz and all similarly affected individuals over the alleged failure of the health system to protect the plaintiff’s and class members’ sensitive personal information.

The data breach in question was reported by Logan Health in February 2022, with its investigation confirming unauthorized individuals had access to its system between November 18, 2021, and November 22, 2021. Hackers gained access to a single file server housing files that contained patients’ protected health information such as names, contact information, insurance claim information, date(s) of service, medical bill account number, and health insurance informa­tion. Logan Health said it had found no evidence of misuse of patient data, offered affected individuals complimentary credit monitoring and identity protection services, and said it is implementing additional measures to prevent similar data breaches.

According to the lawsuit, the cyberattack and data breach were due to the failure of Logan Health to “implement adequate and reasonable training of employees and/or procedures and protocols,” and claims Logan Health and the other defendants should have been aware of the value of protected health information to hackers and the risk of data breaches, given the number of breaches now being reported and the warnings from Federal agencies to the healthcare industry.

The lawsuit points out that data breach was one of several to have affected Logan Health. Logan Health reported another breach in January 2021 that affected 2,081 Montanans, and another in 2019 that affected 126.805 Montanans when Logan Health was operating as Kalispell Regional Healthcare.

The lawsuit claims that as a direct result of the failure to prevent the data breach, victims have suffered and will continue to suffer damages, including the compromise, publication, theft and/or unauthorized use of their PII/PHI, out-of-pocket costs from the prevention, detection, recovery, and remediation from identity theft or fraud, lost opportunity costs and lost wages, and the continued risk to their PII/PHI from the failure of Logan Health to implement appropriate safeguards to protect against data breaches.

The lawsuit cites several causes of action, including negligence, invasion of privacy, breach of implied contract, unjust enrichment, and violations of the Montana Consumer Protection Act, and alleges Logan Health had failed to comply with the requirements of the Health Insurance Portability and Accountability Act (HIPAA).

The lawsuit seeks class action status, a jury trial, injunctive relief, compensatory, statutory, and punitive damages, and attorneys’ fees.

The post Logan Health Facing Class Action Lawsuit Over Data Breach appeared first on HIPAA Journal.

Breach Barometer Report Shows Over 50 Million Healthcare Records Were Breached in 2021

Protenus has released its 2022 Breach Barometer Report which confirms 2021 was a particularly bad year for healthcare industry data breaches, with more than 50 million healthcare records exposed or compromised in 2021.

The report includes healthcare data breaches reported to regulators, as well as data breaches that have been reported in the media, incidents that have not been disclosed by the breached entity, and data breaches involving healthcare data at non-HIPAA-regulated entities. The data for the report was provided by databreaches.net.

Protenus has been releasing annual Breach Barometer reports since 2016, and the number of healthcare data breaches has increased every year, with the number of breached records increasing every year since 2017. In 2021, it has been confirmed that at least 50,406,838 individuals were affected by healthcare data breaches, a 24% increase from the previous year. 905 incidents are included in the report, which is a 19% increase from 2020.

The largest healthcare data breach of the year occurred affected Florida Healthy Kids Corporation, a Tallahassee, FL-based children’s health plan. Vulnerabilities in its website had not been addressed by its business associate since 2013 and those vulnerabilities were exploited by hackers who gained access to the sensitive data of 3,500,000 individuals who applied for health insurance between 2013 and 2020.

Hacking incidents increased for the 6th successive year, with 678 breaches – 75% of the year’s total number of breaches- attributed to hacking incidents, which include malware, ransomware, phishing and email incidents.  Those breaches resulted in the records of 43,782,811 individuals being exposed or stolen – 87% of all breached records in 2021.

There has been a general trend over the past 6 years that has seen the number of insider incidents fall, albeit with an increase in 2020. There were 111 insider incidents in 2021, similar to the 110 incidents in 2019, which is a 26% decrease from 2020. The increase in 2020 is believed to be pandemic-related, with Protenus suggesting the 2020 spike was driven by a pandemic-related increase in insider curiosity or organizational detection of impropriety that has since subsided.

There were 32 theft-related breaches involving at least 110,6656 records and 11 cases of lost or missing devices or paperwork containing the records of at least 30,922 individuals. 73 incidents could not be classified due to a lack of information.

Healthcare providers continue to be the worst affected HIPAA-covered entity type, but business associate data breaches have increased to almost double the level of 2019. 75% of those incidents were hacking-related, 12% were due to insider error, and 1% were due to insider wrongdoing. Across those incidents, 20.986,509 records were breached. Protenus says that the average number of records breached in business associate data breaches is higher than any other breach.

The time taken to discover a data breach decreased by 30% since 2020. The average time from the date of the breach to discovery is now 132 days; however, it is taking much longer for organizations to disclose data breaches than in 2020. In 2021, the average time to report a data breach was 118 days, which is well over the 60 days stipulated by the HIPAA Breach Notification Rule. In 2020, the time from discovery to reporting was 85 days. The median time for reporting breaches was 62 days in 2021, which is also over the Breach Notification Rule reporting deadline.

“The need for proactive patient privacy monitoring has never been greater. The threats we’re seeing today are much more intrusive than in years past and can come from multiple sources — a random employee snooping or a sophisticated cybersecurity hacker that gains access through an employee channel,” said Nick Culbertson, CEO of Protenus. “Once a breach erodes patient trust in your organization, that’s extremely difficult to recover from.”

The post Breach Barometer Report Shows Over 50 Million Healthcare Records Were Breached in 2021 appeared first on HIPAA Journal.