Government Accountability Office Report Identifies Many HealthCare.Gov Security Flaws
A new report published by the Government Accountability Office has highlighted a number of security weaknesses with the HealthCare.gov website “that could place sensitive information at risk of unauthorized disclosure, modification, or loss.” Under the Patient Protection and Affordable Care Act, the Centers for Medicare and Medicaid Services is responsible for overseeing state-based marketplaces that allow consumers to compare and purchase health insurance and for securing federal systems to which marketplaces connect, which include its data hub. GAO was requested to conduct a review of security issues relating to the data hub, in addition to assessing CMS oversight of state-based marketplaces. The review included describing security incidents reported by CMS, assessing incident data, analyzing security controls, and reviewing its policies and procedures. The report indicates there were 316 security incidents involving the HealthCare.gov web portal between October 2013 and March 2015. In one instance a hacker was able to break through security defenses and succeeded in...
2,200 Michigan Dental Patients Notified of PHI Breach
2,200 Blue Chip Dental patients have been notified that a backup system installed to safeguard patients’ protected health information (PHI) has played a part in its exposure. The Social Security numbers, medical insurance information, names, and addresses of patients have potentially been compromised as a result of the loss of a portable storage device used to store data backups. Late last year, Blue Chip Dental implemented a backup system to better protect patient data. The backup system was installed “to store our digital information offsite in case of fire or other disaster to our building,” according to the substitute breach notice placed on the company website. The backup system was part of a $25,000 digital security overhaul. On January 26, 2016, a portable storage device used for the backup system was discovered to have gone missing. No evidence has been uncovered to suggest data have been obtained or accessed inappropriately although the missing backup drive has now been declared lost. Blue Chip Dental contacted the firm used to install the digital security system and...
Data-Capturing Virus Discovered by Mercy Hospital in Iowa City
A computer virus may have allowed hackers to obtain the data of approximately 15,000 patients of Mercy Iowa City, according to a statement released by the hospital late last week. Patients started to be notified of the security breach by mail on Friday March 25, 2016., and have been informed that their name, address, date of birth, medical diagnoses, treatment information, and health insurance details – including their policy number and provider name – may have been compromised. Some Social Security numbers could also have been improperly accessed as a result of the infection. Only a small percentage of Mercy patients have been affected by the breach, all of whom had previously visited either Iowa City’s Mercy Hospital or Mercy Clinic for treatment. Mercy enlisted the services of a leading computer forensics firm to conduct a full analysis of its computer systems after a tip off was received from law enforcement on January 29, 2015., about a potential computer virus infection. The forensic analysis revealed a number of the hospital’s computers had been infected with a virus...
Virus Forces Shutdown of Medstar Health System’s 10-Hospital Computer Network
On Monday March 28, 2016, Medstar Health System discovered a computer virus had been installed on its computer network. The Columbia-based health system, which runs 10 hospitals and more than 250 outpatient facilities throughout Maryland and Washington D.C., was forced to shut down its electronic health record (EHR) and email systems to prevent the spread of the virus. The virus was discovered on Monday morning and the health system acted rapidly to contain the infection and prevent its spread throughout the organization. The security breach was reported to the FBI and an investigation into the attack has been launched. The health system is currently working with its IT and security partners to determine the exact nature of the cyberattack, the extent to which data and systems have been compromised, and how best to deal with the virus. Medical services are still being provided to patients and all of the health system’s facilities remain operational; however, the decision to take the EHR and email systems offline will have an impact on patients. Medstar Health employs around 30,000...
21st Century Oncology Patients Seek Damages After PHI Exposure
Earlier this month, 21st Century Oncology reported a hacking incident that resulted in the exposure of 2,213,597 individuals’ protected health information (PHI). The security breach, which was discovered by the FBI in November last year, exposed patients’ Social Security numbers, health information, and insurance data. All affected patients were offered a year of credit monitoring and protection services without charge. According to the 21st Century Oncology’s substitute breach notice, in the four months since the discovery of the data breach, no evidence has been uncovered to suggest data have been used inappropriately. Four Class-Action Lawsuits Filed in the Past 3 Weeks Three weeks have passed since the announcement of the data breach and already four class action lawsuits have been filed against 21st Century by patients affected by the breach. Damages of $15 million are currently being sought for the failure to protect patients’ data from unauthorized access. The cancer care provider has also been accused of unjust enrichment, breach of implied covenant of good faith and fair...



