PeaceHealth Employee Accessed Medical Records Without Authorization for Almost 6 Years
PeaceHealth, a not-for-profit Catholic health system based in Vancouver, WA, has discovered one of its former employees had accessed the medical records of almost 2,000 of its patients without any legitimate work reason for doing so. The unauthorized access was discovered by PeaceHealth on August 9, 2017, triggering an investigation. PeaceHealth determined the improper access started in November 2011 and continued until July 2017. The investigation confirmed Social Security numbers and financial information were not accessed by the employee, although patient names, medical record numbers, admission and discharge dates, medical diagnoses, and progress notes were all viewed. Due to the nature of information that was accessed, and the results of the internal investigation, PeaceHealth does not believe any patients impacted by the breach are at risk of identity theft. However, all impacted individuals have been advised to remain vigilant and review their credit reports and account statements for any sign of fraudulent activity. Patients impacted by the breach had visited either the...
Ransomware Attack Potentially Impacts 128,000 Arkansas Patients
Arkansas Oral Facial Surgery Center in Fayetteville has experienced a ransomware attack that has potentially impacted up to 128,000 of its patients. Ransomware was believed to have been installed on its network between July 25 and 26, 2017. The attack was detected rapidly, although not before files, x-ray images, and documents had been encrypted. The incident did not result in the encryption of its patient database, except for a ‘relatively limited’ set of patients who data related to their recent visits encrypted. Those patients had visited the center for medical services in the three weeks prior to the ransomware attack. The ransomware attack is still under investigation, although to date, no evidence of data theft has been found. Arkansas Oral Facial Surgery Center believes the sole purpose of the attack was to extort money, and not to steal data; however, it has not been possible to rule out data access or data theft with a high degree of certainty. The files and images that were potentially accessed included information such as names, addresses, dates of birth, Social Security...
HITRUST/AMA Launch Initiative to Help Small Healthcare Providers with HIPAA Compliance
HITRUST has announced it has partnered with the American Medical Association (AMA) for a new initiative that will help small healthcare providers with HIPAA compliance, cybersecurity, and cyber risk management. Small healthcare providers can be particularly vulnerable to cyberattacks, as they typically lack the resources to devote to cybersecurity and do not tend to have the budgets available to hire skilled cybersecurity staff. This week has underscored the need for small practices to improve their cybersecurity defenses, with the announcement of two cyberattacks on small healthcare providers by the hacking group TheDarkOverlord. Recent ransomware attacks have also shown that healthcare organizations of all sizes are likely to be attacked. Organizations of all sizes must practice good cyber hygiene and have the right defenses in place to improve resilience against ever changing cyber threats. HITRUST and AMA will be hosting 2-hour workshops where physicians and other healthcare staff will be educated on key areas of risk management, HIPAA compliance, and cybersecurity, with the...
SonicWall Responds to Increasing Cyber Threats with Major Expansion of Cybersecurity Solutions
The massive rise in new ransomware and malware variants, and the increasing sophistication of cyberattacks on businesses have been accompanied by unprecedented innovation at SonicWall, which has rapidly expanded its range of cybersecurity solutions in response to the growing demand for more powerful solutions. SonicWall has now released its new SonicOS operating system, which includes more than 50 new features to enhance security and is the biggest customer-driven release in the history of the company. The SonicOS (v6.5) powers SonicWall’s Automated Real-Time Breach Detection and Prevention Platform. The new release has enhanced threat API capabilities that allow businesses to automate security systems and incorporate third-party intelligence feeds. New wireless features improve connectivity for an increasingly mobile workforce and help security teams enforce their policies across the entire organization. Advanced networking and connectivity capabilities have also been introduced to provide uninterrupted threat protection for connected networks of all types and sizes. The new...
The Benefits of Using Blockchain for Medical Records
Blockchain is perhaps best known for keeping cryptocurrency transactions secure, but what about using blockchain for medical records? Could blockchain help to improve healthcare data security? The use of blockchain for medical records is still in its infancy, but there are clear security benefits that could help to reduce healthcare data breaches while making it far easier for health data to be shared between providers and accessed by patients. Currently, the way health records are stored and shared leaves much to be desired. The system is not efficient, there are many roadblocks that prevent the sharing of data, and patients’ health data is not always stored by a single healthcare provider – instead, a patient’s full health history is fragmented and spread across multiple providers’ systems. Not only does this make it difficult for health data to be amalgamated, but it also leaves data vulnerable to theft. When data is split between multiple providers and their business associates, there is considerable potential for a breach. The Health Insurance Portability and Accountability...



