Chiropractic Clinics Alert Patients to Billing Vendor Breach
Two providers of chiropractic services in California have started notifying their patients of a security breach affecting their billing software company. Luque Chiropractic, Inc., and Watsonville Chiropractic, Inc., were alerted to a cloud storage account breach on November 18, 2016., following a data security incident that saw patient data accessed by an unauthorized individual. The breach was experienced by EMR4all, Inc., and affected clients that used the company’s associated billing service. EMR4all, Inc provides free EMR software for physical therapy, occupational therapy, and chiropractic practices throughout the United States, while billing services are provided by Rehab Billing Solutions. In early September, security researcher Chris Vickery discovered a cloud storage account used by EMR4all/Rehab Billing Solutions could be freely accessed via the Internet. The cloud storage account contained the health records and personal information of many thousands of patients from more than 30 providers of physical therapy and chiropractic services. Vickery was able to access and...
Briar Hill Management Notifies 2,000 Individuals of February Laptop Loss
Briar Hill Management, a Ridgeland, MS-based provider of management services for skilled nursing facilities in Mississippi, has lost a laptop computer containing the sensitive data of 2,000 nursing facility residents. The laptop was discovered to be missing on February 26, 2016, although at the time it was not believed that the laptop contained any resident health information. However, according to the breach notice recently uploaded to the company website, an investigation into the incident revealed that the employee who had been assigned the laptop computer had breached company policies and had downloaded sensitive information onto the device. The data stored on the unencrypted laptop included residents’ names, addresses, birth dates, dates of service, Social security numbers, prescription information, and medical records. Briar Hill Management says “the laptop did not contain all of these types of information for every affected resident.” The breach notice does not state when Briar Hill Management discovered sensitive information had been exposed. Briar Hill Management conducted...
OIG to Conduct Penetration Tests to Assess HHS Application Security
The Office of Inspector General (OIG) has announced that it will be continuing to assess the information security controls of the Department of Health and Human Services (HHS) in 2017 to ensure those controls meet federal information security standards. Audits will be conducted to assess the network security posture of the HHS. The main focus of the audits will be access controls and physical security. The audits will also look at web application and database security. The OIG has announced that next year’s HHS audits will include penetration tests to check for vulnerabilities that could potentially be exploited by hackers to gain access to HHS systems. State-sponsored hacking groups have been attacking government agencies with increased frequency in recent years. It is therefore essential to thoroughly assess security controls to ensure that networks and applications are not susceptible to cyberattacks. Penetration testing will allow the OIG to assess how hackers could potentially gain access to networks and sensitive data and well as the tools and techniques that could...
Eye Institute of Marin Notifies Patients of Ransomware Data Loss
The San Rafael, CA-based Eye Institute of Marin has informed some of its patients that a ransomware attack on its electronic medical record provider has potentially resulted in some of their electronic protected health information being accessed by the attackers. The EMR system contained a considerable amount of sensitive patient data including names, telephone numbers, addresses, birth dates, race, gender, Social Security numbers, medical histories, medical diagnoses, prescription information, health insurance details, health visit information, charges and payment details, and emergency contact information. No financial information or credit/debit card numbers were exposed as these were stored separately in a different system. The incident was investigated at the time by a third party computer forensics company. The firm’s analysis of the attack did not uncover any evidence to suggest that patient data were accessed or copied by the attackers, although the possibility of data access could not be ruled out entirely. The ransomware attack took place on July 26, 2016. The electronic...
Patients Notified of KinetoRehab Physical Therapy Laptop Theft
New York-based KinetoRehab Physical Therapy has started sending HIPAA breach notification letters to patients alerting them to the potential exposure of some of their protected health information. On September 16, 2016, KinetoRehab discovered a laptop computer was missing from its facilities. A review of security camera footage revealed the laptop computer had been stolen. While the laptop bag has now been found, the laptop computer had been removed and has not been recovered. The incident was reported to law enforcement and efforts are currently being made to locate the individual identified from the CCTV camera footage. The laptop contained data on a limited number of patients, although those affected by the breach have had highly sensitive information exposed. The laptop contained patients’ names, birthdates, Social Security numbers, insurance information, and notes relating to the physical therapy provided by the clinic. Patients affected by the incident had visited KinetoRehab Physical Therapy for treatment between November 2011 and March 2013. While the data stored on the...



