Singh and Arora Oncology Hematology Breach Notifications Sent After 5 Months
A Singh and Arora Oncology Hematology breach is finally being communicated to individuals who had their electronic protected health information exposed, although it has taken 5 months for those letters to be sent. The Health Insurance Portability and Accountability Act’s (HIPAA) Breach Notification Rule requires covered entities – healthcare providers, health plans, healthcare clearinghouses, and business associates of covered entities – to send breach notification letters to patients within 60 days of the discovery of an ePHI breach. The Department of Health and Human Services’ Office for Civil Rights (OCR) must also be notified of a breach in the same timeframe. However, in the case of the Singh and Arora Oncology Hematology breach, the Flint, MI-based cancer treatment center discovered that its systems had been breached on August 22, 2016. While OCR was notified of the breach on October 21, 2016, patients have only just started receiving their letters. The Singh and Arora Oncology Hematology breach actually occurred between February 27, 2016 and July 14, 2016. An...
New York Giants Star and ESPN Agree to Settle Privacy Breach Lawsuit
A privacy breach lawsuit filed against ESPN by New York Giant’s defensive end Jason Pierre-Paul has been amicably resolved. ESPN has agreed to settle the lawsuit, although the terms of the settlement have not been announced. On July 4, 2015, Pierre-Paul was involved in a fireworks accident and sustained serious burns to his hand. He was rushed to Jackson Memorial Hospital in Miami to receive treatment for his injuries. News soon broke that the NFL star had been taken to hospital, although it was initially unclear what injuries had been sustained. That was until details of the injuries were leaked to Schefter. Schefter sent a tweet containing a photograph of Pierre-Paul’s medical chart which showed Pierre-Paul had sustained serious damage to his hand that required the amputation of his index finger. The disclosure and dissemination of Pierre-Paul’s medical charts involved a violation of the Health Insurance Portability and Accountability Act (HIPAA), although not by Adam Schefter. While the HIPAA Privacy Rule prohibits the unauthorized disclosure of patients’ Protected Health...
Hacker Gains Access to Records of 4,668 Princeton Pain Management Patients
Princeton Pain Management, a healthcare provider specializing in the management of chronic pain, has reported a hacking incident has impacted 4,668 of its patients. The breach affects individuals who visited its medical centers in New Jersey, Pennsylvania, and New York for treatment. It is not known for how long the hacker had access to Princeton Pain Management’s systems, although the breach was discovered on November 28, 2016. Upon discovery of the breach, a cybersecurity firm was retained to conduct a thorough forensic investigation to determine how access to its systems had been gained, the types of information that were potentially accessed, and which patients were impacted. An internal investigation into the breach was also launched. The investigation revealed that a wide range of sensitive electronic protected health information (ePHI) had potentially been accessed, including names, telephone numbers, addresses, birth dates, Social Security numbers, driver’s license numbers, Medicare numbers, government identification numbers, diagnostic information, treatment information,...
WellCare Health Reports Security Breach Affecting 24,800 Patients
In August 2016, Summit Reinsurance Services experienced a data breach affecting a number of its healthcare clients. Highmark Blue Cross Blue Shield of Delaware was informed in early January that 19,000 of its members were impacted by the breach. Now, WellCare Health Plans has announced that 24,809 of its members have also been impacted by that security incident. Summit Reinsurance Services had previously been contracted by WellCare to provide reinsurance services. WellCare no longer uses SummitRe as its reinsurance service provider, although the breach dates back to before WellCare’s association with the company was terminated. WellCare was informed on December 27, 2016 that a ransomware infection had occurred at SummitRe on August 8, 2016 and that its members’ electronic protected health information had potentially been accessed by the attacker. The ransomware encrypted a range of sensitive data including names, member IDs, home addresses, dates of birth, Social Security numbers, medical diagnoses and provider names and locations. While many ransomware infections occur randomly as...
Verity Health System Announces Details of 10K-Record Data Breach
Verity Health System – A Redwood City-based Californian health system comprising six hospitals, the Verity Medical Foundation, and the Verity Physician Network – has discovered that one of its websites was breached by a hacker who gained access to the electronic protected health information (ePHI) of thousands of its former patients. The unauthorized individual accessed a Verity Medical Foundation (San Jose) Medical Group website that contained a wide range of protected health information on “more than 9,000 patients”. Verity Health System discovered that its systems had been breached on January 6, 2017. An investigation into the breach was immediately launched and a third-party cybersecurity firm was brought in to conduct a full forensic analysis. That analysis determined that access to the website was first gained in October 2015 and continued until early January 2017. Verity Health System reports that Social Security numbers were not stored on the website and financial information was not viewed, apart from the last four digits of credit/debit card numbers. The website...



