Howler of a HIPAA Breach: 15K Social Security Numbers Emailed to Patients
A New York doctor made a simple but highly serious error this week that resulted in approximately 15,000 Social Security numbers and other Protected Health Information (PHI) being emailed to patients. Instead of attaching a coupon to an email, a spreadsheet containing patient names, appointment dates, home addresses, and Social Security numbers was attached and sent, according to an NBC news report. One patient said dates of birth were also included in the spreadsheet, although this was not confirmed by the doctor’s office. The patient also claimed the email said “coupon attached.” The email was sent from the office of Dr. Mary Ruth Buchness. Staff at the office were quickly alerted to the error by patients, and action was taken to recall the message. According to a member of staff from the office, only “a handful” of individuals had opened the email before it was recalled. Recalling a message may not always be successful, and it may be some time before it is known how many people actually viewed the data contained in the spreadsheet. At the present moment in time it is not clear...
PHI Data Breaches Occur in Most Industry Sectors
Healthcare organizations and other HIPAA-covered entities are required to report PHI data breaches to the Department of Health and Human Services’ Office for Civil Rights, so it is easy to track the security breaches suffered over the past few years. However, PHI breaches are not specific to the healthcare industry. Protected Health Information is stored by all manner of organizations, and all are at risk of suffering PHI data breaches. According to a recent study conducted by Verizon Enterprise Solutions, PHI data breaches have been suffered by 90% of companies, including non-healthcare organizations. PHI is not just stored by healthcare providers and insurers. PHI is contained in HR files, in addition to employee program data and workers’ compensation schemes. Verizon completed an analysis of PHI data breaches that have occurred over the course of the past 20 years. 1,931 individual PHI data breaches were analyzed as part of the study. Those data security incidents exposed the PHI of 392 million patients and employees. The HHS’ Office for Civil Rights and the Department of...
FTC Data Breach Case Against LabMD Dismissed
The Federal Trade Commission’s case against healthcare service provider LabMD has been dismissed by a Chief Administrative Judge due to a lack of evidence that patients were exposed to a significant risk of suffering a substantial injury as a result of their personal information being exposed. This is the first time a decision has gone against the FTC after a data breach case has been challenged. The initial decision on November, 13, went against the FTC, although the FTC can lodge an appeal in the next 30 days. At the present time, the FTC is currently considering the matter and deciding whether to appeal and send the case against LabMD to federal court to be decided. Judge Michael Chappell ruled that the FTC “failed to prove its case” that affected individuals were placed at a considerable risk of suffering harm or losses as a result of the incidents. Consequently, they were unlikely to constitute unfair trade practices. The case was originally filed against LabMD in August 2013. The security breaches cited in the case occurred in 2008 and 2012. In 2008, a document containing...
VA Privacy and Security Incidents Decreased in October
The Department of Veteran Affairs’ October Information Security Report to congress makes for easier reading than last month’s report, when the personal information of 1,135 veterans were exposed in security incidents. VA privacy and security incidents decreased in October, with 648 veterans affected. Aside from August when just 431 records were exposed, this was the best month for the VA since March 2015. 453 veterans were reported to have had their Protected Health Information exposed as a result of VA privacy and security incidents last month. 285 incidents were serious enough to warrant credit protection services being offered to reduce the risk of harm or loss, and 363 beach notification letters were mailed to veterans. VA Privacy and Security Incidents Reported in October Security Incident October 2015 September 2015 Difference Percentage Inc/Dec Lost/Stolen Devices 49 64 -15 -23.43% Lost PIV Cards 158 134 +24 +17.91% Mishandled Incidents 81 115 -34 -29.57% Mis-Mailed Incidents 123 137 +14 -10.22% Pharmacy Mis-Mailings 8 5 +3 +60% The month saw a considerable...
Boxes of PHI Left Unprotected at Former Children’s Psychiatric Facility
In Farmingdale, NJ, a former children’s psychiatric facility that was closed after an investigation into the mistreatment of patients, appears to now be mistreating patients’ records as well, in breach of HIPAA regulations. The Arthur Brisbane Child Treatment Center has been closed for 10 years, yet medical records were still being stored in the facility. The center was closed, shuttered, and locked, and the records were protected from prying eyes; however, during the past month the door to the facility was found open on numerous occasions. The property could have been entered by any number of individuals during this time, who would have been able to gain access to medical files containing highly sensitive information on particularly vulnerable individuals. Any individual to discover the boxes of files would be able to easily locate information, as the boxes had been conveniently labeled. Some were marked “medical” and “payroll”, the former containing detailed medical information on employees/patients and the latter containing banking information of former employees of the...



