February Information Security Report Released by VA
The Department of Veteran Affairs (VA) may have suffered fewer security incidents in February; however, the number of veterans affected was significantly higher than January. There was also a major increase in the number of veterans who had their PHI exposed. In January, the VA reported that 568 individuals had been affected by security incidents, with 236 having their protected health information exposed. In February, the breach victim count increased to 817 – an increase of 44% – with 707 having had their PHI exposed – an increase of almost 200% month on month. As a result of those data breaches, the VA provided credit monitoring services to 245 veterans – 57 fewer than in January. The number of incidents involving lost and stolen devices fell slightly from 46 incidents in January to 43 incidents in February. The number of lost PIV cards was unchanged, with 46 reported in both January and February. The VA reported a reduction in mishandled incidents and mis-mailed incidents. In January there were 121 reported mishandled incidents, with 106 reported in February. Mis-mailed...
St. Joseph Health Settles Class Action Data Breach Lawsuit
St. Joseph Health System has settled a class action lawsuit filed by two plaintiffs for the breach of 31,800 patient health records that took place in 2012. A settlement of $15 million will be split between patients and attorneys, with $7.5 million going to patients and $7.5 million covering attorneys’ fees and legal costs. All patients affected by the breach will receive a check for $242. A $3 million fund has also been set up to cover Identity theft losses that resulted from the exposure of patient health data. Each patient can potentially claim up to $25,000 if they can demonstrate they have suffered losses as a result of the data breach. The data breach in question lasted almost a year and affected patients from a number of hospitals and medical centers run by St. Joseph Health, including Queen of the Valley Medical Center in Napa, Santa Rosa Memorial Hospital, Petaluma Valley Hospital; St. Jude Medical Center in Fullerton, the Auxiliary of Mission Hospital in Mission Viejo and Laguna Beach, Redwood Memorial Hospital of Fortuna, Saint Joseph Hospital of Orange and Eureka. Full...
JASACare Email System Breach Impacts 1,154 Patients
JASACare, a New York-based home care services provider, has reported it has been attacked by hackers who managed to gain access to its email system. The attack is believed to have been conducted in order to steal money from corporate accounts by making fraudulent bank transfers. However, as a consequence of the breach of an employee’s email account, patient and employee data was potentially compromised. The attack took place on January 29, 2016., with the breach lasting for under two hours. Rapid identification of the attack is believed to have severely limited the opportunity for any harm to be caused to employees and patients. However, the possibility exists that data was viewed or copied by the attackers during the time they had access to the email account. JASACare has reported that no evidence has been uncovered to suggest that was the case, or that any data were actually downloaded by the attackers. As soon as the email system compromise was discovered, access was blocked by changing the password of the compromised account. An analysis of the compromised email account...
Two More Californian Hospital Ransomware Attacks Reported
Two more hospitals in Southern California have reported being attacked with ransomware. The Chino Valley Medical Center and Victorville’s Desert Valley Hospital, which are both operated by Prime Healthcare, were attacked on Friday last week. A number of computers had data locked with the file-encrypting malware and the attackers managed to infiltrate some of the hospitals’ servers before the attack was discovered and contained. As soon as the ransomware attacks were discovered, IT systems were taken offline to prevent the spread of the infections. While some computers and servers were taken out of action, patient health records were not compromised and the attack did not affect patient safety. Healthcare services are still being provided to patients at both hospitals, although the attack did cause significant disruption to the hospitals’ IT systems on Friday last week. Prime Healthcare Spokesperson, Fred Ortega, said “most of the systems and critical infrastructure has been brought back online.” A ransom demand was received by Prime Healthcare, although no details have been...
HHS Effort to Address Confusion over Mobile Apps is Disappointing, Say Federal Legislators
Last month the Department of Health and Human Services issued new guidance to clear up confusion about HIPAA Regulations and how they apply to mobile health apps. The four-page document explained how HIPAA Rules apply to health information that is created by patients and entered into health apps, and set out to explain when developers of health apps needed to comply with HIPAA Rules. The guidance covered six scenarios and explained how and when HIPAA Rules applied. The guidance has helped to explain some of the obligations mobile health app developers have under HIPAA Rules, but according to one bipartisan group of congressmen, the guidance only covered a very narrow set of circumstances, and has “led to more questions than answers.” Reps Tom Marino (R-Pa.), Peter DeFazio (D-Ore.), Earl Blumenauer (D-Ore.), Blake Farenthold (R-Texas), Ted Lieu (D-Calif.), Suzanne Bonamici (D-Ore.), Renee Ellmers (R-N.C.), and Rep. Will Hurd (R-Texas) signed a letter sent to HHS Secretary Sylvia Mathews Burwell earlier this month in which the efforts of the HHS to address the confusion over HIPAA...



