Huntington Medical Research Institutes Discovers Two HIPAA Breaches
Nonprofit biomedical research company Huntington Medical Research Institutes (HMRI) has announced two HIPAA breaches in the space of a month: One involving the improper disposal of records, the other an alleged theft of patient data by a former employee. Insecure Disposal of Laboratory Slides and Medical Files Discovered On August 6, 2015, HMRI discovered paper records and glass laboratory microscope slides had been disposed of in a way that did not comply with HIPAA regulations. The incident is believed to have occurred at some point in the two weeks prior to HMRI becoming aware of the HIPAA breach. The incident resulted in sensitive material potentially being exposed including some diagnosis and treatment data, the source of the tissue being tested, specimen information, and details of the tests that had been ordered. The name of the referring physician, patient names, dates of birth, and potentially other demographic information was also contained in physical files. No Social Security numbers, credit card details or insurance information was exposed, although some...
Healthcare Fraud and HIPAA Violations: Warner Chilcott to Pay $125 Million
A unit of pharmaceutical company Warner Chilcott has agreed to plead guilty to healthcare fraud, and will be required to pay $125 million to resolve civil and criminal liability, according to the Boston US Attorney’s Office. The case against the pharmaceutical company is concerned with the illegal promotion of seven drugs. Payments were made to physicians to prescribe pharmaceuticals to patients over other drugs. This is of course not the first time such allegations have been made against drug firms, and nor is it the first time that pharmaceutical companies have been found to be liable. What makes this case different is the fact that charges have been filed against employees of Warner Chilcott and Warner Chilcott U.S. Sales LLC under HIPAA Rules. The case was possible under the False Claims Act, which permits private individuals to sue companies on behalf of the government under the Act’s whistleblower provisions. Two whistleblowers brought the case against the company and are being represented by law firms MoloLamken, Seeger Weiss, and the Simmer Law Group. The criminal charges...
Did Siobhan Dunnavant Violate HIPAA? Senate Candidate Investigated by OCR
A complaint has been sent to the Department of Health and Human Services’ Office for Civil Rights regarding a Republican State Senate Candidate who sent a mailing to her patients to notify them of her intention to stand for office, and to solicit assistance with her campaign. Questions have been raised about whether Dr. Siobhan Dunnavant violated the Health Insurance Portability and Accountability Act’s (HIPAA) Privacy Rule by doing so. Did Siobhan Dunnavant Violate HIPAA? Dr. Dunnavant used her patient database to obtain the contact information of her patients, and subsequently sent emails and a letter announcing her candidacy, in an apparent effort to secure votes, contributions and volunteers to help her with her campaign. Emails and letters are to be expected from a state senate candidate; however due to the strict rules covering the use of patient information under HIPAA, Dr. Dunnavant may have violated HIPAA Rules by doing so. Dr. Dunnavant also emailed her patients on three separate occasions in the run up to the primary elections in June. HIPAA Rules cover a number of...
Privacy and Security of Personal Wellness Data: CEA Releases New Private Sector Guidelines
Wearable technology has proved popular with consumers, yet numerous questions have been raised about the privacy and security of personal wellness data collected, stored and transmitted by the devices. The Consumer Electronics Association (CEA) is well aware of the potential benefits of the devices, and also the risks of the privacy of users of the devices being violated. Currently the metrics recorded by the devices are limited, although there is considerable potential for devices to be developed that record a huge volume of data collected from consumers: Data that is actively recorded by the devices or entered in by users. Currently there are few privacy and security controls covering data privacy and security, and consequently, considerable variation in those implemented by device manufacturers. As the volume of data recorded grows, so too will the privacy risk. Now is therefore the time to start building security and privacy controls into the devices, yet many manufacturers of wearable technology are unsure about how best to secure data and protect the privacy of users....
Answers Demanded From Dept. Veteran Affairs After Social Security Numbers Exposed
The Department of Veteran Affairs (VA) has come under the spotlight again following an investigation conducted by News 3 reporters into a privacy breach that exposed the Social Security numbers of numerous veterans. The investigation revealed that veterans’ Social Security numbers had been sent via unencrypted email on a number of occasions, violating the privacy of veterans in addition to breaching federal regulations. The news report has prompted two Wisconsin senators to demand answers over the privacy breaches. The News 3 investigation concerned a privacy incident that occurred in April of this year. An employee of the Wisconsin Department of Veteran Affairs was discovered to have emailed hundreds of Social Security numbers to an individual who was not authorized to receive the data. The email in question was sent to Mr. Terry Everson, a Wisconsin veteran, on April 1. Upon opening the attachment, Everson saw a list of unhyphenated nine digit numbers. Approximately 400 Social Security numbers were listed in the attachment. The VA was promptly notified of the apparent...



