Brookings Offers Breach Prevention Advice to OCR and Healthcare Organizations
A recent report issued by the Brookings Institution delves into the problems faced by the healthcare industry now that so much patient data is being collected, stored, and transmitted by healthcare institutions. In its report, Brookings offers advice to healthcare organizations and the Department of Health and Human Services’ Office for Civil Rights (OCR) about how patient privacy can be better protected, and strategies that can be adopted to prevent data breaches. 23% of All Data Breaches Affect the Healthcare Industry Over the past two years, the number of breaches suffered by healthcare organizations has increased significantly. 23% of all data breaches now affect the healthcare industry. Since OCR started publishing details of data breaches reported by healthcare organizations six years ago, almost 1,500 separate data breaches have occurred. Those breaches have exposed the healthcare data of over 155 million Americans. To investigate the problem, the Brookings Institution conducted a study to find out more about why healthcare data breaches are occurring with such regularity,...
HIPAA Incident Highlights Importance of Using a Secure Messaging Platform
Earlier this year, BioReference Laboratories Inc., (BRLI) discovered that a number of phlebotomists had adopted the practice of using their smartphones to take photographs of laboratory test requests in order to transmit them to BLRI. The practice was drawn to the attention of BRLI on February 9 this year. An investigation was conducted which revealed smartphones had been used by some of the company’s phlebotomists in Florida for this purpose since January 2013. The practice continued until February 10, 2016. Over the course of four years, the lab test requests relating to 3,563 individuals had been photographed and transmitted over an unsecured network. The data typically photographed included full names of patients, birth dates, addresses, medical record numbers, admission/discharge dates, health insurance information, details of the laboratory tests that were ordered, diagnosis codes, and Social Security numbers. BRLI has no reason to believe that any of the photographs were intercepted, obtained, or viewed by unauthorized individuals or that any data have been used in...
OIG Report: Veterans Benefits Administration Not Tracking Information Security Violations
In April last year, the Office of Inspector General received an anonymous tip-off alleging the Veterans Benefits Administration (VBA) had not integrated appropriate audit logs into the Veterans Benefits Management System. The subsequent investigation substantiated the allegation and revealed that the VBA had not been identifying and logging all security violations accurately. OIG checked for the existence of audit logs and tested their accuracy by having 17 employees try to access same-station veteran employee compensation claims in the Veterans Benefits Management System (VBMS). Those that were logged were identified as existing in the Share application used by VA Regional Offices (VAROs) or said to have occurred in an unknown system. The actions of two of the 17 employees were not tracked and recorded in the audit logs. The tests were conducted at two VAROs in Texas (Houston and Waco) and one in Washington (Seattle). OIG was unable to determine why two employees’ audit logs were not recorded, although OIG did conclude that the Office of Business Process Integration (OBPI) had not...
Transcription Service Provider Exposes PHI of Children’s National Health System Patients
Washington D.C.-based Children’s National Health System (CNHS) has alerted patients to a breach of their protected health information following an error by a transcription service provider which allowed patients’ data to be indexed by the search engines. CNHS is one of a number of healthcare clients affected by the data breach. Ascend Healthcare Systems was contracted by CNHS to transcribe physician’s notes and was supplied with transcription documents in 2014; however, those documents could potentially have been accessed via search engines due to a misconfiguration with a File Transfer Protocol (FTP) site. Transcription services were provided to CNHS by Ascend between May 1, 2014 and June 23, 2014; however, on February 25, 2016, CNHS discovered that some of its patients’ data had been exposed online. An investigation into the privacy breach was immediately launched and CNHS determined that for a period of one week in February, data were accessible via Google. The breach is understood to have lasted between February 19 and February 25, 2016. The data stored in the transcription...
23K Patients of Mayfield Clinic Sent Malware-Infected Email
In February, patients of the Mayfield Clinic of Cincinnati, Ohio were sent an email containing a malicious attachment which downloaded ransomware onto their devices. The entry on the HHS’ Office for Civil Rights breach portal indicates 23,341 patients were sent the email, although it is unclear how many email recipients opened the malicious attachment and infected their computers. The email was sent by an individual who gained access to a database held by one of Mayfield’s vendors. That vendor was contracted to send out newsletters, invitations, announcements, and educational information via email to patients, event attendees, business associates, website contacts, and other friends of Mayfield. The emails were sent out on February 23, 2016 and had the subject line “Important Information: invoice 11471.” Opening the attached file triggered the download of ransomware – malware that encrypts files preventing them from being accessed. The victims are then told they must pay a ransom to obtain the key to unlock the encryption. The individual who gained access to the email database was...



