25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

HIPAA Breach Report: March 2014

March 2014 HIPAA Breach Summary:

The HIPAA Breach Notification Rule requires covered entities to report all data breaches involving HIPAA-covered data to the Department of Health and Human Services’ Office for Civil Rights.

Breach reports must be submitted via its website portal, and CEs have 60 days from the discovery of the breach in order to do this.

This report contains a summary of the breaches which have been reported to the OCR during the month of March, 2014.

Major HIPAA Breaches in March 2014

The number of individuals affected by data breaches in March 2014 was substantially lower, with 68% fewer victims compared to last month, although there were 7 more breaches reported in March.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Phoenix-based not-for-profit health system, Banner Health (AZ), reported the largest HIPAA breach after 55,207 individuals had their Social Security numbers or Medicare numbers printed on magazine labels in a marketing error when sending its quarterly magazine to patients.

HealthPartners, Inc. (MN) reported a 27,839-record accidental disclosure data breach, in addition to three data breaches reported under HealthPartners Administrators, Inc, which exposed a total of 3,210 records.

The loss or theft of unencrypted devices (laptops, pen drives, desktop computers) was a major cause of data breaches in March, with the University of California, San Francisco (CA) – 9,861-records – Mission City Community Network (CA) – 7,800 records – Todd M. Burton, M.D. (TX) – 5,000 records and NOVA Chiropractic & Rehab Center (VA) – 5,534 records – and Palomar Health (CA) – 5,499 records – and Valley View Hospital Association (CO) – 5,415 records – all reporting data breaches.

Franciscan Medical Group (WA) – reported an email phishing scam which resulted in hackers obtaining 8,300 records.

Summary of Reported Breaches

In March, 2014, a total of 160,855 individuals were affected in 30 data/HIPAA/HIPAA data breaches that were reported to the OCR through its breach report portal.

Breach Type

A wide range of security incidents occurred in March, and while the loss and theft of unencrypted devices caused a number of breaches, it was unauthorized disclosures of PHI which dominated the monthly breach reports in March.

hipaa-breach-type-mar-14

 

Breaches by Covered Entity

A high number of breaches were recorded in March compared to previous months, with Business Associates hit hard with 10 breaches – the worst they have fared in the past 6 months. Two health plans were affected and 18 healthcare providers.

hipaa-breach-report-march-14

Location of Breached Information

 

HIPAA-breaches-by-location-mar-14

 View Breach Report for February, 2014

Data Source:

HHS OCR Breach Portal: ttps://ocrportal.hhs.gov/ocr/breach/breach_report.jsf;jsessionid=9BF4AF4A0922D09B6E1CF5DAE375E0D0.ajp13w

*Data does not include HIPAA breaches reported to the OCR after the 60-day reporting deadline, as demanded by the Breach Notification Rule. Any errors made by CEs during the submission of HIPAA breach reports via the online portal will be reflected in this breach summary. Figures are deemed to be correct at the time of publishing, although covered entities are permitted to update breach reports after the 60 day deadline as further information becomes available.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist