655,000 Bon Secours Patients Notified of Potential PHI Breach
Bon Secours Health System is in the process of notifying 655,000 patients that some of their protected health information was exposed as a result of an error made by one of its business associates. The error was made by Arizona-based reimbursement optimization firm R-C Healthcare Management. Network settings were reconfigured between April 18 and April 21; however, an error was made that allowed files containing PHI to be accessed via the Internet. The configuration error was discovered by Bon Secours on June 21, almost two months later. Bon Secours notified R-C Healthcare Management of the error and prompt action was taken to ensure that files were secured. It is unclear whether PHI were accessed, although Bon Secours has said the vulnerability has now been addressed and PHI has been secured. No information has been received to suggest that any patient data were misused in any way. The files contained the names of patients, banking information, insurer names, insurance ID numbers, Social Security numbers, and some clinical data. No medical records were accessible at any point,...
CMS Cracks Down on Social Media Abuse of Nursing Home Residents
A significant number of cases of abuse of nursing home and assisted living center residents have come to light in recent months. The cases involved the taking of degrading and demeaning photographs and videos of residents by employees of nursing facilities, and sharing the images and videos on social media websites. Photographs of residents in various states of undress, covered in feces, or made to pose in degrading positions have been published on social media websites such as Snapchat, Instagram, and Facebook. The cases were recently highlighted in a ProPublica report, which uncovered 47 reports of such abuse since 2012. That report, along with other media coverage of abuse in nursing facilities, has spurred the Centers for Medicare and Medicaid Services (CMS) to take action. The CMS recently sent a memo to state health departments reminding them of facility and state agency responsibilities and the rights of residents to be free from all types of abuse, including mental abuse. The taking of demeaning videos and/or photographs and publishing the imagery on social media websites...
Walgreens Improper PHI Dumping Case Closed by OCR After 9 Years
Ten years ago, WTHR 13 conducted an investigation into the improper disposal of sensitive information by pharmacies. The investigation was conducted following a robbery that took place at the home of an Indiana resident. A drug addict targeted the individual knowing that she had pain medication. That information was obtained from a pharmacy dumpster. The investigation involved reporters checking the dumpsters behind a number of pharmacies in Indiana. The reporters discovered bags of trash, many of which contained sensitive information such as prescription details, names, addresses, and phone numbers. Reporters also discovered that in some cases, credit card details were also printed on documents discarded with regular trash. The investigation was first conducted on Walgreens, although it was later expanded to a number of other pharmacy chains including CVS and Rite Aid. The investigation was expanded to 12 states. Initially reporters were told by Walgreen’s representatives that the improper dumping of sensitive information was not company policy and occurred in isolated incidents....
13.6% Growth Expected in Hospital Cybersecurity Market to Combat New Threats
Over the next five to six years, growth in the healthcare cybersecurity solution market is expected to increase by 13.6%, according to a new Frost & Sullivan report. Healthcare organizations have to protect a much broader attack surface now that the vast majority of organizations have transitioned from paper to digital PHI formats. Keeping data protected from attacks by malicious actors is now a major concern for healthcare organizations. The threat landscape has changed considerably and traditional cybersecurity solutions are failing to prevent increasingly sophisticated attacks. The increase in cybersecurity threats will fuel considerable growth in the hospital cybersecurity market. As we have seen in the past few weeks, the Department of Health and Human Services’ Office for Civil Rights has stepped up enforcement of HIPAA regulations and has issued a number of multi-million dollar files to companies that have failed to protect adequately protect the ePHI of patients. The FTC and state attorneys general have also taken action against healthcare organizations that have failed...
Karen DeSalvo Leaves ONC: Vindell Washington Takes Over
For the past two years, Karen DeSalvo has served as the National Coordinator for Health Information Technology of the Office of the National Coordinator for Health Information Technology (ONC). That role has now come to an end, as today, DeSalvo will be stepping down. The new ONC head will be the former deputy national coordinator, Dr. Vindell Washington. DeSalvo will not be leaving the Department of Health and Human Services (HHS) as she will continue in her role as acting assistant secretary for health, a position she has held since October 2014. DeSalvo took on that post to oversee the nation’s response to the Ebola crisis. Leaving the position of national coordinator will allow DeSalvo to concentrate on that position. Before DeSalvo joined the ONC, one of the ONC’s main roles was to oversee the adoption of electronic health records by the healthcare industry. When DeSalvo took over as head the ONC was becoming increasingly involved with promoting interoperability. DeSalvo played an important part in driving the meaningful use EHR incentive program forward and advancing...



