UCLA Health Cleared in Landmark Patient Privacy Case
If a healthcare employee illegally accesses the medical records of a patient and discloses that information to a third party, is the healthcare provider liable to pay damages? According to a California jury, they are not. The recent ruling on the Lozano Vs UCLA Health case could well set a legal precedent, with the lawsuit almost certain to be named in future patient privacy breach cases. Norma Lozano, a patient of the UCLA Health System, had her privacy violated when a medical assistant, Alexis Price, illegally accessed her medical records, took a photo of her medical history, and showed the photo to her current boyfriend. That individual was a former partner of Lozano. Price had been provided with the login credentials of UCLA Health physician, Dr. John D. Edwards, in order to conduct certain work duties. Those login credentials were also allegedly shared with other members of his office staff. Lozano clearly had her privacy violated, and Price appeared to have illegally accessed and copied her medical records with apparent intent to cause Lozano harm. That proved to be the case,...
How to Respond to a Healthcare Data Breach
HIPAA-covered entities that have spent time developing and testing a health data breach response plan will be able to respond more quickly to a suspected data breach and execute an efficient HIPAA breach response. Those that have not invested time and effort into planning, are likely to struggle to react quickly and delays can prove costly. As the Ponemon Institute’s 2017 Cost of a Data Breach study showed, having a health data breach response plan helps organizations execute an efficient HIPAA breach response. The faster the response, the easier it will be to contain the breach quickly and limit the harm caused. Organizations that are able to respond to a data breach quickly end up paying less in breach resolution costs. The cost of a data breach increases the longer it takes to respond and deal with the breach. Cyberattacks and Data Breaches Are Inevitable With hackers targeting healthcare providers for the protected health information (PHI) they hold, data breaches are no longer a probability but an inevitability. In fact, it is now highly likely that healthcare providers,...
How Secure are Your Medical Devices?
How secure are medical devices? According to a data security study presented at the recent DerbyCon Security Conference, not very, it would appear. Not only can hackers gain access to MRIs, drug infusion pumps, X-ray machines and other radiology and medical equipment, even a couple of patients have discovered they can access their drug pumps and increase their morphine dosage. In some cases it doesn’t actually take much technical skill at all to gain access to medical devices. A quick search on the internet can reveal the login credentials for machines from many manufacturers. Of course, anyone looking to gain access to a medical device, and potentially the network it is connected to, would need to know where to look. That is not a difficult task, according to the researchers. The search engine Shodan contains lists of thousands of networked medical devices, and even gives names of the devices, what they do, where they are located (what hospital and where exactly in that hospital) and even the doctors who are assigned to use the equipment in some cases. The latter is worrying, as...
OCR Confirms Phase 2 HIPAA Compliance Audits to Commence Early 2016
The Director of the Department of Health and Human Services’ Office for Civil Rights, Jocelyn Samuels, has confirmed the second phase of the HIPAA compliance audits will be commencing in early 2016. No more delays are expected. HIPAA-covered entities will soon have their compliance efforts put to the test and Business Associates will also not escape. They too will be assessed on compliance with the HIPAA Privacy, Security, and Breach Notification Rules. Samuels recently wrote to the HHS Inspector General following strong criticism received about the OCR’s enforcement activities in addition to inconsistencies enforcing HIPAA Rules. At present, the OCR relies heavily on reports of privacy violations from the general public and the self-reporting of data breaches to identify HIPAA violations and to choose which entities to investigate. The agency has yet to develop a permanent HIPAA-compliance audit program, even though such a program was much talked about early in Leon Rodriguez’s tenure as head of the OCR. According to a recent OIG report, released on Tuesday, “Without fully...
OIG Criticizes OCR for Lax Enforcement Standards and Poor Oversight of Covered Entities
Take a look at the Department of Health and Human Services’ Office for Civil Rights website and you will discover relatively few financial penalties have been issued for HIPAA Privacy violations. Even apparently serious violations of HIPAA Rules have not always resulted in financial penalties being issued. Out of the thousands of data breaches listed on the website, only a tiny percentage have resulted in a financial penalties being issued, with the OCR often favoring other enforcement actions. This has not gone unnoticed by the Office of the Inspector General (OIG). The OIG has just published the findings from two studies conducted on the OCR to assess how well the agency is enforcing HIPAA Rules. Poor Oversight of HIPAA Covered Entities The first study was conducted to assess the OCR’s oversight of covered entities’ compliance with the Privacy Rule. OIG investigators took a sample of Medicare Part B providers that had reported data breaches to the OCR between September 2009 and March 2011. The OIG then assessed the extent to which those organizations had addressed five privacy...



