Up to 400,000 Prisoners’ PHI and SSNs Exposed
Up to 400,000 current and former prisoners incarcerated by the California Department of Corrections and Rehabilitation between 1996 and 2014 have potentially had their Social Security numbers, medical data, and personally identifiable information exposed. The data breach was reported last month by California Correctional Healthcare Services (CCHCS) and a substitute breach notice was posted on the CCHCS website on May 13; however, at the time it was unclear exactly how many prisoners had been affected. While this is still uncertain, the Office for Civil Rights breach report indicates as many as 400,000 individuals may have been affected. An exact figure is not known as the investigation conducted by CCHCS has not determined which individuals’ data were stored on the device. The figure of 400,000 is the total number of patients who had received healthcare services from CCHCS between 1996 and 2014. That makes this the third largest healthcare data breach so far reported in 2016, behind only the 483,000-record breach at Radiology Regional Center, and the 2.2 million-record data breach...
Anthem Data Breach Lawsuit Heading for Trial
Following the mammoth 2015 data breach at Anthem Inc., around 100 lawsuits were filed by plan members seeking damages for the exposure of their protected health information. In June last year, the lawsuits were consolidated and moved to the Northern District of California and are being presided over by the Honorable Lucy H. Koh. The cyberattack on Anthem was the largest healthcare data breach ever reported, involving approximately 37 million records and affecting close to 78.8 million individuals. The persons responsible for the cyberattack have not been identified, although the security breach is widely believed to have been a state-sponsored attack by Chinese hackers. Class-action lawsuits are often filed by data breach victims following the exposure of personally identifiable information, although the cases are usually dismissed unless there is concrete evidence of actual harm of losses being suffered by the victims. However, the huge data breach case has survived motions to dismiss and looks set to be heading to trial. Last week, Koh indicated the latest motion by the defense...
Head of House Select Investigative Panel Calls for HIPAA Investigation into Abortion Clinic PHI Disclosures
Last week, the head of the House Select Investigative Panel tasked with investigating the trade of baby body parts by abortion clinics wrote to the director of the Department of Health and Human Services’ Office for Civil Rights requesting an investigation into violations of the Health Insurance Portability and Accountability Act (HIPAA). It is alleged that Planned Parenthood – Planned Parenthood Mar Monte (PPMM) and Planned Parenthood Shasta Pacific (PPSP) – and Family Planning Specialists Medical Group (FPS) improperly disclosed the protected health information (PHI) and personally identifiable information (PII) of female patients to StemExpress. In her June 1 letter to Jocelyn Samuels, Rep. Marsha Blackburn explains that employees of StemExpress were provided with details of the abortions that were scheduled to take place on each day and were also given access to the medical files of patients who would be likely to provide fetal tissue donations. Blackburn claims that StemExpress employees were allowed inside of clinics and were given permission to interview patients in...
ONC Releases Videos Explaining Patients’ HIPAA Rights
Earlier this year, the HHS’ Office for Civil Right (OCR) released guidance for healthcare organizations on patients’ HIPAA rights in an attempt to clear up confusion over access and ensure that covered entities were aware of their obligations under the HIPAA Privacy Rule. The guidance covered many of the questions commonly asked by healthcare organizations, including the models that can be adopted by healthcare organizations for charging for PHI copies. Now that covered entities are prepared, efforts have shifted to advising patients of their access rights under HIPAA. This week, the Office of the National Coordinator for Health Information Technology (ONC) -in conjunction with the OCR – released a series of educational videos to improve understanding of patients’ HIPAA rights. The ONC wants to improve patient engagement and get patients to take greater interest in their health. Encouraging patients to obtain copies of their ePHI can help in this regard. Having access to medical records allows patients to check for errors, provide their data to other healthcare providers or...
ProMedica Uncovers Unauthorized Accessing of PHI by 7 Employees
ProMedica has recently discovered that seven of its employees had been improperly accessing the protected health information of patients for almost two years. The employees in question had been granted access to patient files in order to perform their work duties, but had accessed the medical records of patients who they were not required to treat, nor was there any legitimate business reason for patient data being accessed. ProMedica was alerted to the privacy breaches on April 7, 2016., and a thorough internal investigation was launched. That investigation revealed that the records of 3,500 patients had been improperly accessed over a period of two years, from May 1, 2014., to April 26, 2016. Affected patients had received medical services at either ProMedica’s Bixby Hospital in Adrian, MI., or Herrick Hospital in Tecumseh, MI. The type of data viewed by the employees include patients’ names, addresses, dates of birth, contact telephone numbers, insurance information, medical diagnoses, details of medications that had been prescribed, and other clinical data. ProMedica’s...



