Third-Party Mailing Error Sees Aetna Plan Members’ HIV Status Disclosed
Aetna is in the news again for the wrong reasons, having experienced another protected health information breach. The latest incident impacts approximately 12,000 Aetna plan members and resulted in highly sensitive information being disclosed to unauthorized individuals. An error was made in a recent mailing to plan members. That error resulted in the HIV positive status of members being disclosed to other individuals. The letters advised plan members about their options for filling in their HIV prescriptions. However, some of that information was visible through the transparent plastic window in the envelope along with names and addresses. The mailing was sent by a third-party vendor on July 28, 2017. Aetna was notified of the error by the Legal Action Center and the AIDS Law Project of Pennsylvania, which in turn were notified of the error by some individuals whose HIV status had been disclosed. Those individuals said that in addition to the information being visible to the mailman, the letters had been viewed by roommates, neighbors and family members. The potential harm caused...
Credit Monitoring Services Must Now Be Offered to Breach Victims in Delaware
For the first time in 10 years, Delaware has amended its data breach notification law and has now introduced some of the strictest requirements of any state. Any ‘person’ operating in the state of Delaware must now notify individuals of the exposure or theft of their sensitive information and must offer breach victims complimentary credit monitoring services for 12 months. Connecticut was the first state to introduce similar laws, with California also requiring the provision of credit monitoring services to breach victims. Breach victims must also be advised of security incidents involving their sensitive information ‘as soon as possible’ and no later than 60 days following the discovery of a breach. The new law also requires companies operating in the state to implement “reasonable” security measures to safeguard personal information – Delaware is the 14th state to require companies to adopt security measures to ensure sensitive information is protected. The definition of ‘personal information’ has also been expanded and now includes usernames/email addresses in combination with a...
MJHS Phishing Attack Result in the Exposure of 28,000 Individuals’ PHI
There has been a spate of phishing attacks on healthcare organizations in the past few weeks. The increased threat of attacks prompted the Department of Health and Human Services’ Office for Civil Rights to issue a warning to healthcare organizations, urging them to improve their defenses by conducting regular security awareness training sessions for employees. Phishing is the number one attack vector for delivering malware and successful attacks can result in the theft of considerable amounts of sensitive data. Email accounts contain a wide range of sensitive data on patients – information that can be used to commit identity theft and medical fraud, although oftentimes attacks are conducted to gain access to emails accounts for the purposes of spamming. In the case of the phishing attack on MJHS, the motive of the malicious actor is unknown. Fortunately, rapid identification and mitigation of the attack limited the attacker’s window of opportunity. The compromised email accounts were secured before the accounts could be used to send any emails, although it is possible that the...
Security Weaknesses Discovered in New Mexico and North Carolina Medicaid Programs
The Department of Health and Human Services’ Office of Inspector General has conducted reviews of the Medicaid programs run by North Carolina and New Mexico and has identified information security weaknesses that could potentially be exploited by cybercriminals to gain access to systems and the sensitive data of Medicaid recipients. If the vulnerabilities were exploited, it would have placed the states’ Human Services Departments (HSD) at risk and compromised the confidentiality, integrity, and availability of eligibility systems. Similar reviews have been conducted to assess the security controls in place in other states. Vulnerabilities were also detected in the systems used in Colorado, Massachusetts, South Carolina and Virginia, suggesting many states are struggling to implement appropriate policies, procedures and technology to comply with federal regulations on information security. As with healthcare organizations, state Medicaid programs face budgetary constraints and a lack of resources. It can be a major challenge to ensure appropriate resources are directed to...
34,000 Impacted by Ransomware Attack at St. Mark’s Surgical Center
Another healthcare organization has been attacked with ransomware, resulting in the protected health information of almost 34,000 patients being encrypted and made inaccessible. St. Mark’s Surgical Center in Fort Myers, FL experienced the ransomware attack on April 13, 2017, which prevented patient data from being accessed until April 17, 2017. The ransomware was installed on the center’s server which contained patient’s names, dates of birth, Social Security numbers and treatment information. An investigation into the breach was immediately conducted to determine the extent of the attack and to find out which data had been encrypted and the number of patients impacted. That investigation revealed the protected health information of 33,877 patients was potentially accessed by the attackers. A third-party cybersecurity firm was called in to assist with the removal of the ransomware and to conduct a thorough forensic investigation. The firm was able to confirm that all traces of the malware were removed and further access to the server was blocked. The firm also investigated whether...



