Laptop Thefts Expose the PHI of California Healthcare Patients
Three potential healthcare data breaches have been recently reported, two of which occurred as a result of the theft of laptop computers and exposed the protected health information (PHI) of healthcare patients in California. California Correctional Health Care Services Reports Theft of Laptop Computer On February 25, 2016., an unencrypted password-protected laptop computer was stolen from the vehicle of an employee of California Correctional Health Care Services (CCHCS). The laptop may have been used to store the PHI of patients of the California Department of Corrections and Rehabilitation. According to a May 14 substitute breach notice submitted to the California Office of the Attorney General, CCHCS identified the breach on April 25. CCHCS conducted an investigation into the incident but was not able to determine whether sensitive data were actually stored on the device. CCHCS believes that if sensitive data were exposed, affected individuals would be those who had been imprisoned between 1996 and 2014. Data potentially stored on the laptop include custodial information,...
Ponemon: 89 Percent of Healthcare Organizations Have Experienced a Data Breach
This week saw the publication of the Ponemon Institute’s Sixth Annual Benchmark Study on Privacy and Security of Healthcare Data. This year’s study shows 89% of healthcare organizations have now experienced a data breach while 60% of business associates of healthcare organizations have experienced a breach of healthcare data. All of these healthcare data breaches are taking their toll and are costing the industry dearly. An estimated $6.2 billion is being spent on resolving healthcare data breaches. This year’s report shows that cybercriminals caused 50% of the healthcare data breaches reported over the course of the last 12 months; an increase of 5% year on year. The remaining data breaches were caused by mistakes made by healthcare employees and their vendors. Frequency and Severity of Cyberattacks Continue to Rise The healthcare industry is uniquely vulnerable to cyberattacks. Healthcare organizations store vast quantities of valuable data, yet many organizations do not have sufficiently robust defenses to keep those data secured. Security infrastructure is often found to be...
Florida Medical Clinic Notifies 1,000 Patients of Privacy Breach
Florida Medical Clinic, PA., has notified 1,000 patients that their due balance statements were exposed online as a result of a misconfiguration of its Patient Portal. Between November 18, and January 6, 2016., due balance statements of some patients were viewed by industrial account patients when they logged onto the Patient Portal. Only a limited amount of patient data was viewable so there is not believed to be a high risk of patients coming to harm or suffering losses as a result of the breach. Patients’ names, mailing address, provider names, dates of service, descriptions of procedures, and charges due were viewable by individuals unauthorized to view the information. At no point were Social Security numbers, dates of birth, credit card numbers, financial information, or other highly sensitive data accessed. Upon discovery of the HIPAA Privacy Rule violation, Florida Medical Clinic launched an investigation which revealed that the vendor of its Patient Portal – Greenway Health – had turned on a setting on the Portal by accident which resulted in due balance statements...
Anti-Malware Scan Stops Cardiac Catheterization Procedure
It is important for anti-malware solutions to be used to protect medical devices, although care must be taken when configuring software. As was recently highlighted at a U.S. hospital, a software misconfiguration has the potential to have an adverse effect on patients. Earlier this year, a cardiac catheterization procedure had to be halted when a hemo monitor PC was prevented from communicating with the hemo monitor. This resulted in the hemo monitor screen going black, preventing the operating room staff from viewing the patient’s physiological data. There was a delay to the procedure of around five minutes while the application was rebooted, during which time the patient was sedated. The procedure continued after the application was brought back online and was completed successfully, although the delay could potentially have caused the patient to come to harm. The Food and Drug Administration (FDA) has recently issued a report on the incident, which occurred on February 8, 2016. The FDA investigation revealed that the temporary failure of the equipment – Merge Hemo V9.40.1...
UnityPoint Health’s Allen Hospital Discovers 7-Year Privacy Breach
An employee of UnityPoint Health’s Allen Hospital in Waterloo, Iowa, was recently discovered to have abused her access rights to patient health information over a period of seven years. During that time, the employee is understood to have improperly accessed the protected health information of 1,620 patients. The inappropriate accessing of PHI was discovered by Allen Hospital on March 14, 2016. The discovery triggered a full review, which revealed the employee had first started inappropriately accessing patient records in September 2009. The data potentially accessed by the employee include patients’ names, dates of birth, home addresses, health insurance information, medical record numbers, and treatment information. Some patients’ Social Security numbers may also have been viewed. Many employees are discovered to have accessed patient records without authorization, although what makes this case stand out is how long it took Allen Hospital to discover the HIPAA Privacy Rule violation. Jim Waterbury, Allen Hospital’s vice president for institutional advancement, said the reason it...



