16K ENT and Allergy Center Patients Affected by Bizmatics Breach
ENT and Allergy Care, P.A. has announced that its patients have been affected by the data breach at Bizmatics. In early 2015, the server used to host the Bizmatics PrognoCIS tool was hacked. Access to the server was gained and data stored on the server were potentially accessed. In December, 2015., the intrusion was detected and access to the server was rapidly shut down. Bizmatics started investigating the cyberattack and enlisted the services of an external computer forensics company. Law enforcement was also notified on the security breach. Bizmatics notified ENT and Allergy Care of the security breach by mail in January 2016; however, at the time it was not possible to tell whether ENT and Allergy Care patients had been affected. The Bizmatics investigation continued, and in April 2016 ENT and Allergy Care was notified that “at least some” data stored in the PrognoCIS tool had been accessed and possibly copied. Bizmatics was unable to determine exactly which patients’ data were accessed. The data stored in the PrognoCIS tool included patients’ names, addresses, and information...
OIG Discovers Security Flaws in Washington State Insurance Exchange Website
A review of Washington State’s health insurance exchange conducted by the Department of Health and Human Services’ Office of Inspector General (OIG) has revealed a number of website and database security issues that have placed personally identifiable information (PII) at risk of exposure. OIG conducted its review to determine whether the Washington health insurance marketplace had implemented appropriate controls to ensure PII was protected in line with Federal requirements, including those detailed in the Centers for Medicare & Medicaid Services’ (CMS) Minimum Acceptable Risk Standards for Exchanges. The CMS requires all exchanges to develop security plans, perform risk assessments, conduct scans for security vulnerabilities, develop patch management policies and procedures, conduct penetration testing, and remediate any security vulnerabilities that are identified. OIG assessed the Washington marketplace’s policies and procedures, and evaluated the security controls that had been implemented to protect the website and database. The marketplace’s internal controls were...
BA Printing Error Exposed PHI of Walmart Pharmacy Patients
An error by a vendor of Walmart has resulted in a limited amount of protected health information being disclosed to other pharmacy customers. An error was made when one of Walmart’s vendors printed letters accompanying patient refund checks. That error resulted in patients’ protected health information being printed on letters intended for other individuals. Only a limited amount of information was disclosed, although this was sufficient to warrant the issuing of breach notification letters. The incident has now been reported to the Department of Health and Human Services’ Office for Civil Rights. The breach report indicates 27,393 patients were impacted by the privacy breach. The breach has not been posted on Walmart’s website at the time of writing, although an explanation of the breach was provided to databreaches.net. Walmart explained that the error occurred on or around May 13, 2016. The letters were mailed to patients on May 15, 2016., and Walmart was made aware of the error 5 days later. Affected patients had their name, pharmacy prescription number or optical order...
Aspen Hospital Sued for HIPAA Breach by Former Employee
A healthcare IT worker formerly employed by Aspen Hospital is suing the hospital and five of its employees for an alleged HIPAA breach after it was disclosed he had contracted HIV. The former employee, only identified as John Doe in the suit, was also a patient at the hospital. His attorneys, Mari Newman, Darold Killmer and Eudoxie Dickey, filed the suit on his behalf and are seeking compensatory and punitive damages, legal fees, and an apology from the hospital for the violation of his privacy. Doe also wants the hospital to change its policies to prohibit the disclosure of sensitive medical information to members of the hospital staff. John Doe had worked in the IT department of Aspen Hospital for 11 years prior to losing his job. Doe was an excellent employee and was well respected in the department according to the suit. He was regularly told he had exceeded expected standards and had often been rated as ‘outstanding’ in his performance evaluations. After filing complaints against the hospital for the disclosure of his HIV status and subsequent retaliatory acts by hospital...
Ponemon Institute Publishes 2016 Cost of Data Breach Study
For the past 11 years, the Ponemon Institute has conducted an annual benchmark study on the cost of data breaches. This week, the Ponemon Institute published the results of its 2016 Cost of Data Breach Study, which shows the cost of breach resolution continues to rise. The IBM-sponsored study indicates the average total cost of the breach response and resolution has increased to $7.01 million from $6.53 million last year: A rise of 7% year on year. Ponemon puts the average cost per compromised record at $221: A rise of 2% from last year’s figures or $4 per record. The 2016 cost of data breach study was conducted on organizations around the world, including companies based in Australia, Brazil, Canada, France, Germany, India, Italy, Japan, Saudi Arabia, the United Arab Emirates, and the United Kingdom. The global average data breach cost increased from $154 per record to $158 per record, with the total cost increasing from $3.8 million to $4 million per data breach. 383 companies took part in the global study. 64 U.S. companies took part in this year’s benchmark study and 16...



