HHS Issues Final Rule on Confidentiality of Alcohol and Drug Abuse Patient Records Regulations
In February 2016, the Department of Health and Human Services published a proposed change to the Confidentiality of Alcohol and Drug Abuse Patient Records regulations, (42 CFR Part 2) to facilitate health integration and information exchange. HHS has now finalized the Part 2 changes following an extensive evaluation of public comments, according to a recent press release from the Substance Abuse and Mental Health Services Administration (SAMHSA). The Confidentiality of Alcohol and Drug Abuse Patient Records regulations were introduced in 1975 to protect the privacy of patients receiving treatment for substance abuse and mental health disorders. At the time there was concern that the revelation of patients’ identities would have serious social consequences and a lack of privacy may deter individuals from seeking treatment. The healthcare delivery system has changed considerably during the past 40 years and Part 2 regulations were in need of modernization. While the privacy of patients must and will still be protected, the Part 2 changes will help to promote health integration and...
Potential ePHI Breach Impacts 3,600 Children’s Hospital Los Angeles Patients
3,594 patients of Children’s Hospital Los Angeles (CHLA) and Children’s Hospital Los Angeles Medical Group (CHLAMG) are being notified of a potential breach of their electronic protected health information following the theft of an unencrypted, password-protected laptop computer. The laptop was stolen from the locked vehicle of a CHLAMG employee who practices at CHLA. The theft is understood to have occurred on October 18, 2016. CHLAMG encrypts its laptop computers, and while the investigation into the breach initially indicated the laptop had been encrypted to institutional standards, on December 21, 2016, CHLA determined that there was a possibility that the device had not been encrypted. Typically, laptops are stolen by thieves for the value of the device, not for data stored on the devices. Laptops are wiped, have software reinstalled, and are sold on. While it cannot be confirmed that this was the case in this instance, CHLA investigators were able to determine that the laptop computer has not been used to connect to the Internet since it was stolen, suggesting the device was...
Sentara Healthcare Informs 5,454 Patients of ePHI Breach
Sentara Healthcare is notifying 5,454 patients that some of their electronic protected health information has been accessed by an unauthorized individual. It is unclear when the cybersecurity incident occurred, although law enforcement informed Sentara Healthcare of the security breach on November 17, 2016. Sentara Healthcare launched an investigation into the potential data breach in November and determined that the cybersecurity incident was experienced by one of its third party vendors. Sentara has not disclosed which vendor was attacked, nor whether the incident was an internal breach involving one of the vendor’s employees or if patient data were accessed by a hacker. The data breach affects vascular and thoracic patients who received medical services at Sentara Healthcare’s Virginia hospitals between 2012 and 2015. Patients have been notified of the data breach by mail and have been told that highly sensitive protected health information was inappropriately accessed. The information viewed – and potentially copied – by an unauthorized third party includes patients’ names,...
Highmark BCBS of Delaware Investigates Data Breach Affecting 19,000 Individuals
Highmark BlueCross BlueShield of Delaware is investigating a data breach that has impacted 19,000 beneficiaries of employer-paid health plans. The data breach involves two subcontractors of Highmark BCBS – Summit Reinsurance Services and BCS Financial Corporation. Karen Kane, Highmark BSBC director of privacy and information management, issued a statement saying 16 current and former Highmark self-insured customers have been impacted. Affected individuals have now been notified of the breach by mail. The breach notification letters were sent by Summit Reinsurance Services (SummitRe). In the letters, consumers were informed that some of their highly sensitive protected health information had potentially been accessed by unauthorized individuals. A ransomware infection was discovered by SummitRe on August 5, 2016, although a forensic analysis of the cyberattack revealed that access to Summit’s systems was first gained on March 12, 2016. SummitRe stated in the letters that the forensic investigation into the breach is ongoing, although no direct evidence has been uncovered to suggest...
Brandywine Pediatrics Alerts 27,000 to Potential ePHI Breach
Wilmington, DE-based healthcare provider Brandywine Pediatrics, P.A. has informed tens of thousands of its patients that some of their protected health information has potentially been accessed by an unknown individual. The security breach involved a computer virus, which was discovered on one of the organization’s file servers. While it has not been explicitly stated that the virus was ransomware, Brandywine Pediatrics has informed patients that the virus rendered ePHI inaccessible. In order to regain access to files it was necessary to restore files from data backups. The virus infection was discovered on October 25, 2016, sparking a full investigation. A third-party computer forensics expert was contracted to conduct an investigation. That investigation revealed that a number of practice files containing ePHI had potentially been accessed. Sensitive data in the files included names, addresses, medical information, and health insurance details of patients. Brandywine Pediatrics has confirmed that Social Security numbers, credit card/debit card numbers and financial data were not...



