Lincare Settles W-2 Phishing Scam Lawsuit for $875,000
The respiratory therapy supplier Lincare Inc., has agreed to settle a class-action lawsuit filed by employees whose W-2 information was sent to cybercriminals when an employee responded to a phishing scam. On February 3, 2017, a member of Lincare’s human resources department received an email from a high-level executive requesting copies of W-2 information for all employees of the firm. Believing the email was a genuine request, the employee responded and attached W-2 information for ‘a certain number of employees of Lincare and its affiliates.’ After discovering the accidental disclosure of sensitive information, Lincare contacted affected employees and offered them two years of credit monitoring, identity theft insurance, and remediation services without charge. On October 16, 2017, three employees – Andrew Giancola, Raymond T. Scott, and Patricia Smith – took legal action against Lincare alleging negligence, breach of implied contract, breach of fiduciary duty, and violation of Florida’s Deceptive and Unfair Trade Practices Act. The lawsuit survived a motion to dismiss and...
GAO: Medical Records Can be Difficult and Expensive to Obtain
A recent audit conducted by the Government Accountability Office (GAO) has shown patients still face many challenges obtaining copies of their health information and healthcare providers and insurers are struggling to meet HIPAA requirements – and in some cases – are violating HIPAA Rules. A 21st Century Cures Act provision required GAO to conduct a study on patient access to medical records. The audit involved interviews with stakeholders, vendors, provider organizations, patient advocates, and state and HHS officials. The audit was conducted in four states – Ohio, Kentucky, Rhode Island and Wisconsin – which were chosen, in part, due to the range of fees charged for providing patients with copies of their medical records. Under HIPAA, patients are permitted to request copies of their health records from their providers. Patients can request their health records in paper or digital form and the requests must be processed within 30 days. HIPAA-covered entities are allowed to charge a reasonable, cost-based fee for providing patients with copies of their health data. Patients obtain...
Former Employee of Nuance Communications Stole PHI of 45,000 Patients
In a recent filing with the U.S. Securities and Exchange Commission, Burlington, MA-based Nuance Communications disclosed it experienced a data breach involving the protected health information of 45,000 individuals in December 2017. Nuance Communications stated in its May 10, 2018 SEC filing that a third party accessed certain reports hosted on a single Nuance transcription platform, which was promptly shut down when unauthorized access was discovered. The filing states law enforcement was notified about the breach and assisted with the investigation and apprehended the individual responsible. There is no mention of when the breach was discovered, although the company has notified all customers who used the platform to allow them to issue notifications to affected individuals. One of those customers, The San Francisco Health Network, published a substitute breach notice on its website on May 11 providing further information on the breach. The breach notice explains that the protected health information of 895 patients who received medical services at Zuckerberg San Francisco...
Cofense Triage Now Helping ADT Protect its Customers from Phishing Attacks
Cofense has announced it has partnered with the monitored security and interactive business automation solution provider ADT. ADT provides cybersecurity solutions to enterprises and mid-sized companies throughout the United States and Canada. The firm’s managed detection and response services allow businesses to mitigate cyber threats in real-time before they lead to a data breach. Perimeter defenses only go so far. They will block the majority of cyber threats, although no solution is capable of preventing all phishing emails from reaching inboxes. It is therefore essential for organizations to have a solution in place to allow phishing attacks to be mitigated in real time. The partnership will see Cofense Triage incorporated into ADT’s unified platform for organizing, managing, and collecting cyber intelligence. Cofense Triage is the industry’s first phishing-specific automated incident response platform. The platform provides security teams with detailed information on phishing attacks in real-time, helping them separate attacks in progress from the background noise and...
Eye Care Surgery Center Data Breach Impacts 2,553 Patients
A laptop computer containing the protected health information of 2,553 patients of Eye Care Surgery Center, Inc., of Baton Rouge, LA has been stolen. The theft was discovered by Eye Care Surgery Center on February 26, 2018 although it is unclear where the device was stolen from. The theft prompted Eye Care Surgery Center to install a new multi-camera system at its facilities, both inside and outside buildings. The decision has also been taken to use encryption on most of the portable electronic devices used by Eye Care Surgery Center to prevent protected health information from being exposed in the event that any further portable electronic devices are stolen. An investigation was conducted to determine the types of information stored on the stolen device and the patients affected by the incident. Highly sensitive information such as health insurance information, Social Security numbers, and financial information were not stored on the device and remained secure at all times. The breach was limited to names, birth dates, and diagnosis information. No reports have been received to...



