Recent Cases of Portable Device Theft Highlight Need for Healthcare Data Encryption
Healthcare professionals can be given training on the importance of keeping electronic equipment secure; however, even the most security minded healthcare professional can make an error of judgement that results in PHI being exposed, such as leaving a laptop computer in a vehicle while patients are attended to. Theft of medical devices containing Protected Health Information (PHI) had declined in recent months; but the HHS’ Office for Civil Rights breach portal now displays a high number of HIPAA violation cases of portable device theft, highlighting the importance of using data encryption software to safeguard PHI. While portable devices carry the highest risk of data exposure, a number of recent burglaries of physicians’ offices show that even data stored on less portable computer hardware, such as desktop computers and servers, is not secure without robust security measures such as encryption. Stolen Portable Electronic Devices Cited in Numerous Recent Breach Reports In June, a physician from the University of Oklahoma’s Department of Obstetrics and Gynecology had a laptop...
VA: PHI Incidents Fall in July; Breach Notification Letters Increase
The Department of Veteran Affairs has issued its July and Q3 data security report to congress, indicating there were fewer Protected Health Information (PHI) exposures in the month of July than June, with fewer breach victims created. However, the total number of security incidents – and the number of individuals affected by those incidents – have been steadily rising throughout the year. The July report shows fewer individuals were affected by data breaches. In June, the VA reported 2,076 individuals had been affected by data breaches. The July figures are much improved, with only 1,031 individuals affected. There was also a reported fall in PHI incidents, which affected 872 individuals in July compared to 935 individuals in June. Even with that reduction, more breach notification letters were sent out in July than the previous month – 779 letters in July compared to 543 notification letters in June. Lost and Stolen Device Reports Increase Lost and stolen devices are still a leading cause of data exposure. In the month of July, the VA reported 56 security...
UCLA Health Cleared in Data Breach Lawsuit
The University of California Los Angeles Health System was cleared of liability in a lawsuit filed against it for the unauthorized disclosure of a patient’s medical records to a “romantic rival”. The patient in question, Norma Lorenzo, filed a lawsuit against UCLA Health for disclosing her personal information to an unauthorized individual in 2012. Lorenzo filed the suit claiming emotional distress and an invasion of her privacy, and sought $1.25 million in damages. The incident which sparked the lawsuit involved a temporary worker using the login credentials of a physician to access Lorenzo’s files. That individual then texted photos of the medical records to Lorenzo, her father and her former boyfriend. The information texted related to a sexually transmitted disease Lorenzo had received treatment for. The individual who accessed and disclosed the records was the current partner of one of Lorenzo’s former boyfriends. While UCLA Health was not directly responsible for the breach of personal information, Lorenzo claimed in the lawsuit that UCLA Health had not taken sufficient steps...
Jocelyn Samuels Gives Update on OCR Compliance Audits
Since the announcement that the second phase of HIPAA compliance audits would be delayed, the Department of Health and Human Services’ Office for Civil Rights has remained tight-lipped over timescales. Now, a year on from the original proposed start date, many expected OCR Director, Jocelyn Samuels, to give a timescale for the HIPAA audit program at the Safeguarding Health Information: Building Assurance through HIPAA Security HIPAA Security Conference in Washington this month. Samuels gave a keynote address at the National Institute of Standards and Technology (NIST) and Office for Civil Rights (OCR) hosted conference, and while she did not provide a date or a timeline for the compliance audits, she did indicate the audits are now very close to becoming a reality. She explained that the OCR has many roles, with compliance audits a part of its enforcement activities. “Audits are really a critical compliance tool for us because they enable us to get out in front of potential industry problems before they result in a breach … and they enable us to better tailor our guidance and...
Data Security Report Shows Main Points of Cyberattack by Industry Sector
SurfWatch, a leading provider of cyber risk intelligence analytics and applications, recently released a mid-year cyber risk intelligence report detailing the most common methods used by hackers to gain access to confidential patient and business data, including the main points of cyberattack by industry sector. The company discovered that despite a number of highly sophisticated attacks on healthcare providers in recent months, the majority of hackers are still using the same tried and tested methods to break through security defenses as they have for years. The most common points of attack are poorly secured websites and applications, patient and customer accounts, and endpoints, which account for 77% of all cyberattacks evaluated by SurfWatch analysts. The main aim of the SurfWatch Labs 2015 Mid-Year Report was to identify the most effective ways organizations can reduce the risk of suffering cyberattacks. Big money is being diverted to improve cybersecurity defenses and to protect against hackers; however it is important that organizations look closely at all potential attack...



