$475,000 Settlement for Delayed HIPAA Breach Notification
The Department of Health and Human Services’ Office for Civil Rights (OCR) has announced the first HIPAA settlement of 2017. This is also the first settlement to date solely based on an unnecessary delay to breach notification after the exposure of patients’ protected health information. Presence Health, one of the largest healthcare networks serving residents of Illinois, has agreed to pay OCR $475,000 to settle potential HIPAA Breach Notification Rule violations. Following a breach of PHI, the HIPAA Breach Notification Rule requires covered entities to issue breach notification letters to all affected individuals advising them of the breach. Those letters need to be issued within 60 days of the discovery of the breach, although covered entities should not delay the issuing of breach notifications to patients or health plan members unnecessarily. Additionally, if the breach affects more than 500 individuals, a breach report must be submitted to Office for Civil Rights within 60 days and the Breach Notification Rule also requires covered entities to issue a breach notice to...
Emory Healthcare Joins 28,000 Other Victims of MongoDB Ransom Attacks
A hacker by the name of Harak1r1 has taken advantage of a misconfigured MongoDB healthcare database containing 200,000 records of Emory Healthcare patients. The hacker stole the database and issued a 0.2 Bitcoin ransom demand for its safe return. Emory healthcare is the largest healthcare provider in Georgia with headquarters in Atlanta. The database contained the protected health information of patients of the Emory Brain Health Center. Information in the database includes patients’ names, addresses, email addresses, dates of birth, medical ID numbers, and phone numbers. However, while the attack involves a ransom demand, Harak1r1 is not using ransomware. The database of Emory Healthcare was accessed, the database was stolen, and the data tables wiped. Emory Healthcare is far from the only victim. More than 4,000 companies have been attacked by Harak1r1. The attacks on misconfigured MongoDB databases were discovered by the ethical hacker Victor Gevers of GDI Foundation on December 27, 2016. Gevers found a MongoDB database that had been left unsecured. When the database was...
Foreign Government-Backed Hacker Was Behind 2015 Anthem Breach
The massive 2015 data breach at Anthem Inc., which resulted in the theft of more than 78.8 million health plan members’ records, was likely the work of a foreign government-backed hacker, according to a recent report issued by the California Department of Insurance. Anthem Inc., the second largest health insurer in the United States, announced the massive cyberattack in February 2015, almost a month after the breach was discovered. However, the cyberattack occurred almost a year earlier with Anthem’s database discovered to have been infiltrated on February 18, 2014. Data stolen in the attack included members’ Social Security numbers, birth dates, employment details, addresses, email addresses, and Medical identification numbers. The attackers were able to bypass multiple layers of cybersecurity defenses with a single phishing email sent to an employee of one of Anthem’s subsidiaries. The response to the email allowed the attacker to download malware onto Anthem’s network, which in turn allowed access to Anthem’s database of members. The attackers also managed to infiltrate 90 other...
L.A. Care Health Plan Information Exchange Platform Links 21 Hospitals
Members covered by the L.A. Care Health Plan in Los Angeles are now benefiting from improved health information sharing with healthcare providers following the launch of a new health information exchange platform. L.A. Care Health Plan (formerly known as Local Initiative Health Authority of Los Angeles County) is a public entity providing an accountable care program and other health plans (such as L.A. Care Covered, L.A. Care’s Healthy Kids and PASC-SEIU Homecare Workers Health Care Plan) for Los Angeles residents. Through its 6 health care plans, L.A. Care Health Plan provides coverage for more than 2 million individuals including some of the most vulnerable populations in the County, and is now the largest publicly operated health plan in the United States. Last year, the health plan conducted a pilot with the eConnect information exchange platform supplied by Safety Net Connect. The eConnect platform enables users to provide real-time alerts on admissions, discharges, and transfers using the HL7 Admit Discharge Transfer Protocol. The pilot was a success and in August 2015, L.A....
New York Rule Change Allows Clinicians to Access Minors’ PHI via State HIE
Healthcare providers that participate in the Western New York health information exchange – HEALTHeLINK – are now able to access the health information of minors aged between 10 and 17 after the passing of a new rule covering patient data access through qualified information exchanges. The new rule allows the information of minors to be accessed if prior consent has been obtained by from parents or legal guardians via signed consent forms. To date, more than 870,000 adults in Western New York have already signed consent forms allowing their children’s information to be shared. The rule change will ensure that treating pediatricians have access to the most up to date information, thus allowing them to make informed decisions about the best treatments to provide. The move will help to ensure that full access to the full range of health information can always be obtained, which has previously been an issue when minors have received medical services from multiple healthcare providers. The rule change will help to ensure safer and more efficient provision of clinical care....



