Apology Issued by Sharp Grossmont Hospital for Filming and Sharing Videos of Obstetrics Patients
An apology has been issued by Sharp Grossmont Hospital for violating the privacy of patients by filming them undergoing surgical procedures and subsequently sharing those videos with a third party. Videos were recorded using hidden surveillance cameras as part of a sting operation to catch a thief who was believed to be stealing narcotic drugs from anesthesia carts in the operating theater of the Women’s Health Center. The hospital set up surveillance cameras hidden inside moveable monitors in three operating rooms at the Women’s Health Center at Sharp Grossmont Hospital to obtain evidence of drug thefts from anesthesia carts. Some of the recorded clips show an anesthesiologist taking bottles of the anesthetic propofol from the carts and placing them in his top pocket. Over the course of the surveillance operation – which took place between July 2012 and July 2013 – 12 bottles of propofol were allegedly stolen from the cart by the anesthesiologist. The video footage of the thefts was submitted to the California Medical Board as evidence. The accused anesthesiologist’s...
4000 Michigan Chiropractic Patients Notified of Potential Data Breach
4,082 patients of Complete Chiropractic & Bodywork Therapies (CCBT) of Ann Arbor, MI., have been notified of a potential breach of protected health information after malware was discovered on one of the company’s servers. The malware was discovered on March 19, 2016., after the server malfunctioned. The malfunctioning of the server triggering CCBT’s security protocols which included isolating the server, blocking Internet access, and changing all workstation and third party passwords. CCBT also installed an additional firewall as an extra precaution. External forensics experts were brought in to investigate the security incident. Their investigation revealed malware had been installed which scanned the network for passwords and login information and transmitted sensitive data to the hacker(s) command and control server. The server stored patient data including treatment and billing information, in addition to encrypted medical record data. Encrypted information included patient names, addresses, dates of birth, health and diagnosis information, and Social Security numbers. The...
Zocdoc Notifies Patients of Breach Discovered in June 2015
This week, Zocdoc – an online medical booking system – notified the California Attorney General’s office of a breach of personal information that was first identified almost a year ago. Programming errors were discovered in June 2015., that allowed past and present practice staff members to gain access to their Provider Dashboard’s after their usernames had been removed from the system or their access had otherwise been limited. The usernames had been provided to medical and dental practices that had signed up to use the Zocdoc appointment system. Patients affected by the data breach have now been sent notification letters advising them that their name, phone number, email address, appointment history, and in some cases Social Security number, could have been accessed by staff members at each practice that were unauthorized to view the information. Health insurance information and medical histories could also have potentially been accessed if patients had provided that information via Zocdoc when making appointments. According to the breach notice, “Access may have...
Department of Veteran Affairs Seeks Vendors to Search for Stolen Data
Even when appropriate controls are implemented to secure electronic protected health information (ePHI), data breaches can still occur. Mistakes are made with the configuration of firewalls, ePHI is accidentally disclosed to unauthorized individuals, and phishing attacks and malware allow criminals to gain access to ePHI. Healthcare data breaches have now become as inevitable as death and taxes despite the best efforts of healthcare organizations to keep ePHI secured. The Department of Veteran Affairs is the largest integrated health system in the United States, with more than 1,700 locations providing healthcare services to more than 8.76 million veterans. The VA stores a considerable volume of ePHI which makes it a large target for cyberattackers. In April alone, the VA blocked 77.69 million intrusion attempts, blocked and/or contained almost 460 million malware samples, as well as more than 105 million malicious emails. With so many attempted attacks, occasional data breaches are to be expected. When breaches occur, lessons are learned, systems are improved, and security...
2,100 Veterans Had Their PHI Exposed in April
Each month the Department of Veteran Affairs issues a report to congress on the information security incidents experienced by VA facilities over the course of the month. Protected health information (PHI) exposures increased considerably in April, with 2,105 veterans’ PHI being accidentally disclosed or exposed. In total, 2556 veterans were affected by information security incidents in April, resulting in the VA sending 1,690 breach notification letters. Due to the relatively high risk of misuse of data, 866 veterans were offered credit protection services. While the number of veterans affected by these security incidents was considerably higher than in March – when 522 veterans were affected by information security incidents and 417 had their PHI exposed – fewer incidents were reported by VA facilities. In April there were 39 lost and stolen device incidents compared to 54 in April, lost PIV cards fell from 172 to 128, mishandling incidents dropped from 89 to 87, and 146 mis-mailed incidents were reported compared to 147 incidents last month. Major VA Data Breaches Reported in...



