Breach of Patient Data Reported by Barrington Orthopedic Specialists
Barrington Orthopedic Specialists, an Illinois-based healthcare provider, has reported it has suffered a breach of patient data after a laptop computer and an EMG machine were stolen from a vehicle while being transported between its facilities. The equipment theft took place at some point between August 14 and August 18, 2015, and was discovered by Barrington Orthopedic Specialists (BAS) on August 18. Following the discovery of the theft, BAS informed law enforcement officers and an investigation was launched to determine the extent of the breach wand which patients had been affected. That investigation has now been concluded. The data breach is understood to have affected 1,009 individuals and resulted in their names, dates of birth, and EMG test results and reports potentially being exposed to criminals. According to the breach notice issued by BAS, no Social Security numbers, financial data, insurance information or contact details were stored on the equipment. The risk of identity theft and fraud faced by the victims is therefore believed to be particularly low. As such the...
HealthCare.gov Security Vulnerability Critical, Says OIG
A “critical” HealthCare.gov security vulnerability has been discovered which could potentially be exploited by hackers looking to gain access to highly confidential data, according to the Department of Health and Human Services’ Office of the Inspector General. The government’s team of ethical hackers were let loose on the HealthCare.gov website, and discovered a critical weakness in its otherwise robust security features. The team used standard techniques known as vulnerability scanning, which simulate an attack by malicious outsiders. The scans therefore assessed security vulnerabilities that could realistically be exploited by external hackers. The team of “white hat” hackers discovered the vulnerability, although they were not able to exploit it to gain access to data due to a range of other security defenses installed to safeguard stored data. The HealthCare.gov website is the gateway to taxpayer-subsidized health plans and is used by 36 states, with those health plans subscribed to by millions of Americans. The data potentially accessible through the site is extensive. The...
New Rules for Electronic HIPAA Transactions Approved by CAQH CORE
Last week, the CAQH® Committee on Operating Rules for Information Exchange (CORE®) approved a new set of national rules for electronic HIPAA transactions, as part of Phase IV of the CAQH® CORE® Operating Rules. The new rules for electronic HIPAA transactions cover four groups of healthcare business transactions – prior authorizations, employee premium payment, enrollment/disenrollment in health plans, and healthcare claims. The aim of the new rules is to facilitate the exchange of healthcare information, as mandated by the Affordable Care Act (ACA). The new rules will augment existing HIPAA administrative standards to ensure uniform transmission of electronic healthcare data. Phase IV of the CAQH® CORE® Operating Rules addresses infrastructure requirements such as connectivity, system availability, and response times. Rules covering the data content of transactions are due to be added to the Operating Rules at a later date. The approval process involves a vote on the new rules by the subgroups and work groups responsible for preparing the draft version of the Operating Rules. If...
Document Scanner Error Exposes PHI of Silverberg Surgical and Medical Group Patients
Silverberg Surgical and Medical Group is alerting patients to the potential exposure of highly sensitive Protected Health Information after an error made in the configuration of a document scanner resulted in patient information being accessible via the internet. The device had been used to scan documents containing personal information such as patient names, dates of birth, contact telephone numbers, home addresses, fax numbers, and e-mail addresses. Some patients’ Social Security numbers were exposed, as were medical record numbers, health plan ID numbers, beneficiary numbers, medical information, full face photographs and state license numbers: A Smorgasbord of data that could potentially be used by criminals to commit medical, insurance and identity fraud. Silverberg discovered the security breach on August 28, 2015, and immediately launched an investigation. That investigation revealed the device had posted data online since September 10, 2013. The company has now secured the device and data and has enlisted the help of a specialist data security firm to conduct a forensic...
Bogus Doctors Behind Horizon Blue Cross Blue Shield of New Jersey Data Breach
A Horizon Blue Cross Blue Shield of New Jersey data breach has been reported following the discovery that criminals posed as doctors in order to gain access to the Protected Health Information of patients. The bogus physicians obtained insurance ID numbers and other sensitive PHI, after being given access rights to Horizon BCBSNJ members’ data. The information was stolen in order for the criminals to file false insurance claims in the names of the victims. Fraudulent activity was first uncovered on July 30, 2015 and approximately 1,100 individuals are understood to have been affected by the security breach. In addition to member ID numbers, the bogus doctors were able to gain access to patient names, gender, and dates of birth. A notice on the Horizon BCBSNJ website confirms that Social Security numbers and financial information were not obtained by the criminals. It is understood that the information was stolen with the sole purpose of making false insurance claims. Patient PHI is not believed to have been used for any other purpose. All affected members of Horizon BCBSNJ...



