Bogus Doctors Behind Horizon Blue Cross Blue Shield of New Jersey Data Breach
A Horizon Blue Cross Blue Shield of New Jersey data breach has been reported following the discovery that criminals posed as doctors in order to gain access to the Protected Health Information of patients. The bogus physicians obtained insurance ID numbers and other sensitive PHI, after being given access rights to Horizon BCBSNJ members’ data. The information was stolen in order for the criminals to file false insurance claims in the names of the victims. Fraudulent activity was first uncovered on July 30, 2015 and approximately 1,100 individuals are understood to have been affected by the security breach. In addition to member ID numbers, the bogus doctors were able to gain access to patient names, gender, and dates of birth. A notice on the Horizon BCBSNJ website confirms that Social Security numbers and financial information were not obtained by the criminals. It is understood that the information was stolen with the sole purpose of making false insurance claims. Patient PHI is not believed to have been used for any other purpose. All affected members of Horizon BCBSNJ...
Car Theft Results in Exposure of PHI of 2900 Individuals
Insurance Data Services (IDS), a Wyoming-based medical billing company, has started to send breach notification letters to patients of one of its HIPAA-covered clients, Claystone Clinical Associates, to advise them of the potential exposure of some of their Protected Health Information (PHI). IDS had contracted a West Michigan based Delivery Service to deliver client mailings; however the vehicle used by the courier company was stolen on September 15. The vehicle theft occurred at Zondervan Publishing in Kentwood, MI. The vehicle theft was reported to law enforcement officers and an investigation into the theft has commenced. Fortunately, the theft was captured by closed-circuit television cameras; however, the recordings revealed a masked and gloved individual entering the vehicle and driving away. Consequently, it has not been possible to identify a suspect at this time. The vehicle has now been found and recovered, but the contents had been taken by the thief. No electronic PHI was exposed; but patient mailings were taken from the vehicle. The information contained in the...
Healthcare Data Breach Report: August 2015
Healthcare Data Breach Report: August 2015 The number of healthcare data breaches reported to the Department of Health and Human Services’ Office for Civil Rights differs little from July; however the volume of records exposed fell dramatically month on month. In July, over 8,000,000 patient and health plan member records were exposed. August saw ‘only’ 215,556 records exposed. Only one hacking incident was reported in August: The cyberattack on Pediatric Group LLC, which resulted in 10,000 records being exposed. This was a major improvement on last month, which saw 4 hacking incidents discovered. Those four data breaches included major data exposures at Medical Informatics Engineering and UCLA Health, which exposed 3.9 million and 4.5 million records respectively. Main Cause of Data Breaches in August 2015 Was Lost/Stolen Devices August saw eleven reports of lost and stolen PHI containing devices. Each data breach exposed relatively few medical records (Except the Empi Inc / DJO Global data breach that exposed 160,000 records), but all could have been easily prevented had...
McAfee Study Investigates How Hackers Exfiltrate Data
A new data exfiltration study has been released by McAfee, which examines the actors and tactics used by criminals to obtain Protected Health Information and other sensitive data, in addition to effective detection and preventative measures employed by companies to thwart cyberattacks and data theft. The report details the commonest methods used by hackers to get data out of systems once access has been gained. Most cybersecurity reports focus instead of how hackers manage to gain access to computer systems. McAfee has instead concentrated on the little-studied area of data exfiltration. Participants in the study were interviewed by the company’s researchers and asked questions about their main security concerns, the threats they face on a day-to-day basis, the tools used to identify data exfiltration, as well as being asked to provide details of how data were actually exfiltrated. The results of the study provide IT professionals around the world with valuable intel, which can be used to determine the most important measures to address security risks and prevent data theft and...
New Data Breaches Reported by Kindred Healthcare and Rite Aid
Two new data breaches have been announced, highlighting the difficulty organizations have in preventing the exposure of Protected Health Information. Even robust physical, technical and administrative controls are oftentimes insufficient to prevent the exposure of sensitive information. It is therefore essential to have a data breach response plan which can be enacted immediately upon discovery of a security breach. Kindred Healthcare Discovers Locks are not Enough to Prevent Device Theft Healthcare providers are required to implement a host of technical controls to prevent the exposure of PHI under HIPAA Rules; however the volume of records stolen in recent months suggest that some healthcare providers fail to adequately physically secure files, medical images, and computer equipment. However, even when files and equipment are secured under lock and key, there is no guarantee that the PHI is safe. Kindred Healthcare, a Louisville, KY. healthcare company that operates a number of hospitals and nursing centers throughout the United States, took a number of steps to secure its...



