Updated Security Risk Assessment Tool Released by ONC
OCR prefers to settle HIPAA compliance issues through voluntary compliance and non-punitive means, although financial penalties are now becoming more commonplace. If OCR investigators uncover HIPAA violations, financial penalties may be issued. Fines of up to $1.5 million can be issued for each violation category discovered. One of the most common reasons for a financial penalty is the failure to conduct a comprehensive, organization-wide risk assessment. The risk assessment is a foundational requirement of the HIPAA Security Rule – 45 C.F.R. §§ 164.308(a)(1)(ii)(A), and is one of four required implementation specifications in the Security Management Process. The purpose of the risk assessment is to identify all potential risks to the confidentiality, integrity, and availability of all ePHI that a covered entity creates, receives, maintains, or transmits. The risk assessment must cover all forms of ePHI, and all devices and systems that touch ePHI. As was seen with the pilot phase of the HIPAA compliance audits and subsequent PHI breach investigations, small to medium-sized covered...
Medical College of Wisconsin Reports Email Breach
Almost 3,200 patients of the Medical College of Wisconsin have been notified that some of their protected health information has potentially been viewed by an unauthorized individual. A security breach was suspected when IT staff noticed unusual activity associated with the email account of an employee. Rapid action was taken to block access to the email account and the College enlisted the help of an external computer forensics company to conduct a thorough investigation into the activity. On August 3, 2016, the firm determined the email account had been accessed by an unauthorized third party and a full forensic analysis of email accounts, servers, and networks was initiated. The firm concluded that no other MCW systems had been compromised. Access was only gained to a single email account. The email account was accessed by the third party between July 2, and July 4, 2016 inclusive. All emails in the account were checked by the firm to determine whether any protected health information could potentially have been accessed. The PHI in the email account was limited to the full...
Another Employee is Fired for Emailing PHI to a Personal Account
Today, a breach notice has appeared – dated August 18 – on the Department of Health and Human Services’ Office for Civil Rights breach portal from Village of Oak Park Health Plan in Illinois. The breach involved the unauthorized accessing and disclosure of the personal information of 688 individuals. The breach in question dates back to January. On January 22, 2016, officials at Village of Oak Park discovered an employee had emailed spreadsheets containing the PHI of 688 individuals to a personal email account. The breach was discovered during a search of employees’ emails which was initiated after some employees claimed that their premiums had not been paid to their insurers. While searching for email correspondence between insurers and employees, the email containing the spreadsheets was discovered. The spreadsheets contained personal information of current and former employees of Village of Oak Park, Oak Park Library, Oak Park Township, the Park District of Oak Park, and the West Suburban Consolidated Dispatch Center. The spreadsheets included names, dates of birth,...
Patients Notified of Burrell Behavioral Health Cyberattack and PHI Exposure
Springfield Missouri-based Burrell Behavioral Health has announced it has been the subject of a cyberattack which has potentially resulted in the protected health information of certain patients being obtained by unauthorized individuals. The electronic medical record system was not accessed, although an unauthorized individual – or individuals – gained access to the organization’s email system between July 6 and July 7, 2016. The unauthorized access was identified on July 7 and counter measures were rapidly deployed to block access to the compromised account. An internal investigation was launched and a leading cybersecurity company was contracted to conduct a thorough forensic investigation. The investigators were unable to establish whether the protected health information of patients was accessed, although it was not possible to rule out the possibility that PHI had been viewed or obtained in the attack. No reports of identity theft or other misuse of PHI have been received by Burrell Behavioral Health at this point in time. An analysis of the emails stored I the account...
Children’s Mercy Hospital Announces Breach of Children’s PHI
Children’s Mercy Hospital in Kansas City, MO has announced that 238 children’s medical records have been stolen from a vehicle used by a hospital employee. The vehicle was locked and the records were stored in a hard-sided case, which was also locked. However, it is probable that the thieves managed to open the case and view the contents. The theft occurred on August 4, 2016 and the incident was immediately reported to local law enforcement. It took a number of days for the hospital to determine the exact contents of the case and to verify which patients had been affected. Patients were notified of the incident 26 days later, well within the time limit required by the Health Insurance Portability and Accountability Act (HIPAA). The data obtained by the thieves was limited in nature and did not include the types of information typically used for identity theft and fraud. No financial data, insurance information, or Social Security numbers were exposed. However, the families impacted by the breach have been urged to “take reasonable precautions” against identity theft and fraud. They...



