25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Prominence Health Plan Data Breach Impacts up to 45,000 Individuals

The Nevada health insurer Prominence Health Plan has announced it suffered a security breach on November 30, 2020 in which hackers potentially obtained the protected health information of some of its plan members. The data breach was discovered on April 22, 2021 and steps were immediately taken to prevent further unauthorized access, including changing the credentials used by the attacker to gain access to its network.

While Prominence Health Plan has not confirmed whether this was a ransomware attack, all affected plan member data has been restored from backups. The incident involved audio recordings of phone calls to the Prominence call center along with PDF files that included provider claim forms and letters to patients advising them about claim approvals and denials.

The audio files typically included full names, dates of birth, and member ID numbers, while the PDF files contained a member’s name, date of birth, sex, member ID number, mailing address, and claim code. The files included PHI of individuals who had been members between 2010 and 2020. Approximately 45,000 individuals have been affected.

There have been no reported cases of misuse of PHI and the information in the files was not in a readily usable format, which limits the potential for misuse. Prominence is conducting online monitoring for any signs of attempted misuse of the stolen data and affected individuals have been notified and offered complimentary credit monitoring and identity theft protection services. Additional security measures are being implemented to prevent any further data breaches.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Mississippi Center for Advanced Medicine Discloses December 2020 Ransomware Attack

Mississippi Center for Advanced Medicine (MCAM) has started notifying certain patients about a ransomware attack that occurred in December 2020. Hackers gained access to an internal server that contained the protected health information of its patients and encrypted files.

A third-party IT company was engaged to assist with the investigation and determine whether PHI had been accessed or stolen by the attackers. The investigation confirmed on April 26, 2021 that PHI had potentially been compromised, although to date there have been no reports of any misuse of patient data.

The compromised server contained documentation about MCAM programs and services which included names, email addresses, phone numbers, home addresses, dates of birth, Social Security numbers, information to process insurance claims, prescription information such as prescription number, prescribing doctor, medication names and dates, medical histories, and some clinical information, such as whether an influenza test was ordered.

All affected individuals are being notified and additional security measures are being implemented to prevent further attacks.

The HHS’ Office for Civil Rights breach portal shows 9,664 individuals were affected.

 

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist