Even HHS Involvement Did Not Stop Months of Fax Privacy Breaches
A simple mistake can lead to the exposure of hundreds of private and confidential medical records, as discovered by Brooklyn marketing firm, APS Marketing Group. The company started receiving faxes containing the medical information of patients of an unnamed medical clinic in April 2015. Despite efforts to contact the sender, the intended recipient, and the Department of Health and Human Services, the faxes kept on arriving. APS ended up receiving faxed medical documents for months on end and hundreds of patients had their medical records exposed. The information contained in the documents included patient names, contact information, the medical test that had been requested, and in some cases, Social Security numbers. The error was caused as a result of a member of staff entering a fax number incorrectly. That simple mistake resulted in documents being sent to the wrong company, exposing the data of hundreds of patients. However, it is not the error that is worrying in this case, but how long it took for the HIPAA breaches to stop, even after the HHS got involved. The faxes were...
Major Data Exfiltration Discovered at Muhlenberg Community Hospital
Patient, employee, and contractor data have potentially been obtained by unknown third parties as a result of a multi-computer malware infection at Owensboro Health Muhlenberg Community Hospital, KY. According to the breach notice submitted to the Office for Civil Rights, 84,681 individual have been affected by the cyberattack. The security breach was discovered by the FBI after unusual third party network activity was noticed on the hospital’s servers. An alert was issued on September 16, 2015, and the hospital immediately brought in external computer forensics experts to determine the cause of the activity. That investigation revealed a number of computers had been infected with a type of malware that logs all keystrokes on the affected computers. This type of malware then communicates those keystrokes to the hacker’s command and control server. All data entered on the infected computers have therefore potentially be transmitted to the hacker(s) responsible for the attack. The suspicious network activity was only recently discovered, but the investigation revealed that the...
North Carolina DHHS Reveals 524-Patient Record Data Breach
In August 2015, a member of staff employed by North Carolina Department of Health and Human Services was discovered to have sent unencrypted emails containing patient data outside of the company’s email network. The errors resulted in 1,615 patients having their personal information placed at risk of being intercepted or viewed by unauthorized individuals. On Friday, the DHHS discovered that the errors had been made again, this time resulting in the data of 524 patients being sent via unencrypted email. The emails were reportedly sent on September 14, just under a month after the first data breach occurred. This time the emails have more potential to result in patients coming to harm as Social Security numbers, insurance information, and dates of birth were included in the emails. Other data exposed in the latest breach include names, addresses, ethnicity, gender, race, Medicaid recipient numbers and provider names. When a data breach is suffered, HIPAA-covered entities are required to investigate the cause of the breach, issue notification letters to the Office for Civil Rights,...
University of Cincinnati Email Errors Result in 1,064-Patient Data Breach
Email errors have been potentially exposing the Protected Health Information (PHI) of University of Cincinnati Medical Center patients, according to a recent breach report issued by the healthcare provider. The error was discovered to have been made on nine separate occasions over a period of more than a year. As a result of these errors, patient data have been inadvertently sent outside of the UC Health email network. The mistakes were simple errors that can all too easily occur, and go unnoticed if controls are not put in place to prevent the transmission of PHI outside of an organization’s network. When the emails were sent, two letters were accidentally reversed when entering the domain name. The recipient name was entered correctly, but the error entering the domain name resulted in the emails being directed to another organization. When emails are sent to an organization and cannot be delivered, a message is usually automatically sent to the sender advising them of the delivery failure. Some organizations employ a “catch-all”, which would result in an incorrectly addressed...
Senators Demand Answers from CMS and OCR About Medical Identity Theft and Fraud
Four senators have put their names to a letter sent to Jocelyn Samuels, Director of the Department of Health and Human Services’ Office for Civil Rights (OCR), and Centers for Medicare and Medicaid Services (CMS) Acting Administrator Andy Slavitt, requesting answers about the growing issue of medical identity theft. Sen. Lamar Alexander, R-Tenn., Sen. Patty Murray, D-Wash.; Sen. Orrin Hatch, R-Utah, and Sen. Ron Wyden, D-Ore have signed the letter, which demands answers to nine questions relating to the role the HHS, OCR and CMS play in monitoring and addressing medical fraud and identity theft stemming from healthcare data breaches. Healthcare data breaches have exposed the Protected Health Information of over 105,000,000 individuals so far this year, and there are still over six weeks of 2015 to go. That figure is certain to rise. The problem is a growing concern. The total number of breach victims created over the past 6 years stands at 154 million, which equates to close to half the population of the United States. The senators point out that the situation is only likely to get...



