Case Manager Duped naviHealth; Dignity Health Alerts Patients to Privacy Breach
Dignity Health is notifying 520 patients that their privacy was violated by a naviHealth employee who gained employment as a case worker using a false name and nursing license. Dignity Health is a not-for-profit public benefit corporation operating in 17 states. The San Francisco-based health system is the fifth largest hospital system in the United States, and is the largest non-profit hospital provider in the state of California. Dignity Health works with a large number of hospitals and provides in-home health services to patients after they have been discharged from hospital. Dignity Health outsources some of its services to the Nashville, Tennessee-based post-acute care management company naviHealth. naviHealth provides PAC management services to over 1.5 million beneficiaries throughout the United States. On June 6, 2016., Dignity Health was informed by naviHealth that an individual had gained employment under false pretenses. The individual was employed by naviHealth as a case worker between June 2015 and May 2016. The case worker was provided with access to the protected...
Bizmatics Data Breach Victim Count Rises to Almost 177,000
Two further healthcare providers have reported security breaches that have potentially exposed patients’ protected health information, both of which have links to the Bizmatics data breach discovered in December 2015. The Vein Doctor, a Liberty MO-based provider of treatment services for varicose and spider veins, recently submitted a breach report to the Department of Health and Human Services’ Office for Civil Rights indicating 3,000 patients had been affected by a network server and EMR hack. A breach notice has not appeared on the healthcare provider’s website at the time of posting, and it is unclear how much protected health information was exposed in the cyberattack. However, the breach does appear to be linked to Bizmatics. The Vein Doctor uses the PrognoCIS EMR tool developed and maintained by Bizmatics. Other healthcare providers impacted by the Bizmatics breach also used the PrognoCIS tool. Grace Primary Care P.C., also reported a data breach to the OCR which was similarly caused by the hacking of a network server. The breach report, submitted to the OCR on June 7,...
Bill Introduced to Better Protect Veterans from Identity Theft and Fraud
Last week, a bipartisan Senate bill was introduced by Sen. Tammy Baldwin, D-Wis., and co-sponsor Sen. Jerry Moran, R-Kansas., to reduce the risk of veterans becoming victims of identity theft and fraud. The new bill would require the Department of Veteran Affairs (VA) to discontinue the use of veterans’ Social Security numbers as identifiers in all VA information systems. The bill would require the VA to phase out the use of SSNs as identifiers for all veterans in its system within five years, although a deadline of two years would be set to replace SSNs for new claims for benefits. The new Senate bill has now been referred to the Senate Veterans Affairs Committee. Should the new bill be passed it would certainly be a major step in the right direction and could significantly reduce the risk of veterans becoming victims of identity theft and fraud in the event of a VA security breach. However, changing identifiers is not a straightforward process and it could prove costly. Any exchange of information between other agencies may still require the use of SSNs. The phasing out of the...
Nurse Charged with Bank Fraud: HIPAA Breach Trial for Respiratory Therapist
Healthcare workers can face lengthy jail terms and heavy fines for improperly accessing patient health information. This week, a nurse has been charged with fraud and identity theft and the trial of a respiratory therapist has commenced in Toledo. If found guilty, both could spend time behind bars. Virginia Nurse Charged with Bank Fraud and Identity Theft A nurse formerly employed at Commonwealth Primary Care in Richmond, VA., has been charged with bank fraud and identity theft and is expected to plead guilty to the charges at a plea agreement hearing scheduled for Friday morning. Capri Williams worked for at the West End branch of Commonwealth Primary Care for almost a year. During that time, she is believed to have accessed and copied the protected health information of hundreds of patients. Williams is alleged to have used patient information to fraudulently open bank and credit accounts in patients’ names. Williams has also been accused of making a fraudulent transfer of over $4,000 from one of the patients’ credit cards. According to WTVR, Commonwealth Primary Care received a...
Texas Health and Human Services Commission Notifies 600 of PHI Exposure
A storage contractor has informed the Texas Health and Human Services Commission (HHSC) that 15 storage boxes have been discovered to be missing. The boxes were stored at three Iron Mountain facilities in Dallas, Fort Worth, and Irving. The boxes contained files relating to individuals who had applied to HHSC for medical assistance between January 1, 2008 and August 31, 2009. The files contained names, addresses, dates of birth, Social Security numbers, Social Security claim numbers, bank account numbers, Medicaid/individual numbers, and medical record numbers. The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates 600 individuals were affected. Iron Mountain was contracted by HHSC to store boxes of client files prior to the records being permanently destroyed. HHSC is now conducting an investigation into Iron Mountain’s handling of the files and to determine how the boxes were lost. Once the investigation has concluded, HHSC will revise its policies and procedures to reduce the probability of similar incidents occurring in the...



