Major Mobile Health Application Growth Predicted
Mobile technology has potential to revolutionize the provision of healthcare. Mobile technology is already having a major impact on the industry. According to PwC, one of the few limiting factors is how the technology can be implemented to allow healthcare providers to obtain the full benefits of the technology. This does not appear to have hindered growth in the sector. PwC has predicted growth to increase six-fold over the course of the next two years. Growth in the sector will mostly come from the development of new mHealth applications and from monitoring services. A new report published by healthcare market research firm Kalorama Information suggests that the growth of mobile health applications will outstrip all other mobile application areas over the next four years. The Kalorama report highlights the substantial growth already seen in the mHealth market so far in 2015. Manufacturers of devices, software developers, and providers of wireless services are capitalizing on growing demand. By the end of the year, the industry is expected to have generated close to $34 billion....
Pathways Professional Counseling Reports Theft of Laptop Containing SSNs
A breach of social security numbers, health insurance information, medical data, and personally identifiable information has been announced by Pathways Professional Counseling after a laptop computer was stolen from the vehicle of an employee. The laptop computer was password protected, but was not encrypted. The device contained highly sensitive information that could potentially be used by criminals to commit identity theft and fraud. Other data stored on the laptop included patient names, dates of birth, addresses, email addresses, phone numbers, demographic data, clinical information, financial information, referring physician names, and medical diagnoses of patients. The theft occurred on September 24, 2015, and was discovered the following day. The incident was immediately reported to law enforcement and to Pathways Professional Counseling, and an investigation into the data breach was immediately launched. Pathways Professional Counseling was able to determine that the laptop had not been used to gain access the organization’s network. Network access was blocked by changing...
Healthcare Industry Data Breaches in 2015
2015 has been a difficult year for healthcare industry cybersecurity professionals. More confidential records have been exposed in 2015 than since the OCR started publishing healthcare data breach reports. Huge healthcare industry data breaches at Anthem Inc., Premera BlueCross, Excellus BlueCross BlueShield, UCLA Health, Medical Informatics Engineering, and CareFirst BlueCross BlueShield have been suffered this year. 2015 Healthcare Industry Data Breaches Have Exposed 120 Million Records With so many large-scale data breaches suffered this year it is perhaps no surprise that healthcare industry data breaches have affected more people than breaches suffered by organizations in other industries. The latest figures from the Identity Theft Resource Center (ITRC) indicate over 120 million people have had their medical and/or personal data exposed so far this year as a result of healthcare industry data breaches. That represents 68.1% of the total number of breach victims created so far in 2015 across all industry sectors. The ITRC first started charting data breaches back in 2005. To...
Texas Attorney General Takes Action over Improper Disposal of PHI
Legal action has been taken by the Texas attorney general’s office against Alliance Health Management & Consulting Inc., for the improper disposal of Protected Health Information (PHI) of patients. The home healthcare management company is no longer in business, having ceased trading in July 2009; however last year, documents containing the PHI of patients were discovered to have been discarded in a dumpster without first having been rendered indecipherable. HIPAA Rules Covering the Disposal of Protected Health Information The HIPAA Privacy Rule requires covered entities to implement physical safeguards to keep all forms of PHI secured at all times. When PHI is no longer required by a covered entity it must be disposed of securely (45 CFR 164.310(d)(2)(i) and (ii)). PHI must be destroyed, or rendered unreadable and indecipherable. It must not be possible for any element of PHI to be reconstructed. The exact method that must be used to destroy records is not stipulated by HIPAA Rules, although for physical records the OCR recommends pulping, burning, shredding, or pulverizing....
OCR Settlement Reached with Lahey Hospital
The HHS has announced that Lahey Hospital and Medical Center has agreed to settle a case with the Office for Civil Rights (OCR) over alleged HIPAA violations following a data breach that occurred back in October, 2011. Lahey Hospital and Medical Center has agreed to pay $850,000 to settle the case without admission of liability. The nonprofit teaching hospital has also agreed to adopt the OCRs corrective action plan to address HIPAA-compliance issues discovered by OCR investigators. The settlement covers six ‘potential’ violations of HIPAA Rules, specifically the failure to implement appropriate administrative and physical controls to prevent the accidental disclosure of ePHI. Failure to Safeguard ePHI Results in $850,000 Settlement The incident which led to the OCR investigation involved the theft of an unencrypted laptop computer that had been left in an unlocked treatment room at the hospital. The laptop contained data recorded from one of the medical center’s CT scanners. The laptop contained electronic Protected Health Information of 599 patients. A financial penalty was...



