The Age of the Healthcare Data Breach: 40% of Americans Now Victims
According to a new study conducted by iSherriff, almost 45% of Americans have now had their personal information exposed in a healthcare cyberattack; and in some cases, more than once. It is clear that we are now well and truly in the ‘Age of the Data Breach’, and the situation is likely to get worse. This year has already seen the largest ever HIPAA data breach: The 78.8-million record heist at Anthem Inc., and also the second largest healthcare data breach reported: The 11 million record cyberattack at Premera Blue Cross., and recently, a further 4.5 million records were exposed in the UCLA Health cyberattack. More than 100 million new healthcare data breach victims have been created so far this year, representing almost a third of the population of the United States. The total number of records exposed in the last 5 years is now 143 million. We are therefore just over 16 million records short of half the population of the United States. With the volume of breaches now occurring, it is possible that unwanted milestone may even be reached this year. According to iSherriff CEO,...
Frisco Psychiatrist’s Computer Stolen from Vehicle Trunk: PHI Exposed
Vehicles are clearly not good places to store the Protected Health Information of patients, even temporarily, as another medical professional has recently discovered. San Francisco psychiatrist, Robert E. Soper M. D., was transporting an old desktop computer that he intended to give to his brother; however, he left the car unattended and during that time it was broken into and the desktop computer was stolen along with other goods from the car. Although the data on the desktop computer was not encrypted, it was protected by two passwords, making it unlikely that the thieves would be able to access the data. According to the breach notice issued by Dr. Soper, the passwords “were maintained in a format unique to the software used to prepare them. The software program itself was not on the computer, making the data almost impossible to decipher.” The computer also contained email data which included lab test results and some third party healthcare provider reports on patients, as well as email correspondence between the office and patients. Email data was similarly password protected...
Employee Data Theft Announced by Merit Health
With big money to be made from the sale of Protected Health Information, and even bigger gains to be made from using the data for identity theft, many employees are tempted to access and copy medical records. In recent months numerous cases of data theft have reported by hospitals, and this week another has come to light, with the announcement by Merit Health Northwest Mississippi that one of its employees has stolen patient PHI. The now former employee’s acts were uncovered by local law enforcement officers, who notified the hospital of the potential data theft. An investigation into the security breach was initiated immediately to determine the extent of the theft. According to a statement released by Merit Health, the data access is believed to have started in February 2013 with the last data believed to have been removed in June 2015. The healthcare provider was notified of the privacy breach on July 1. The unnamed individual is understood to have accessed and removed the records of up to 810 patients over a period of more than two years without being discovered. The data...
UCLA Health Patient Receives 9 Incorrect Breach Notification Letters
The UCLA Health cybersecurity attack exposed the data of 4.5 million patients, most of whom have been informed if they have been affected by the breach; however it took a considerable amount of time for patients to receive their breach notification letters, and for one victim in particular, the notification process ran anything but smoothly. According to a recent LA Times report, UCLA Health patient, Steve Reasner, was kept in the dark about the risk of identity risk that he faced, and it took many weeks since his data was exposed to learn he had been affected. After hearing about the data breach on the news, Reasner wondered if his information was now in the hands of the hackers. He had previously used UCLA Health services and could conceivably have had his confidential data stolen. He waited for a letter to arrive in the mail, and a few days later he received not one breach notification letter but nine. To add to his confusion, none of the letters were addressed to him. They had his address on the envelope, but the names of different individuals who had – presumably –...
Akron Children’s Hospital Reports Loss of Voice Recordings
Ohio’s Akron Children’s Hospital has reported the loss of a hard drive used to store backed up copies of voice recordings of conversations between medical staff and dispatchers. The backup drive was physically secured under lock and key at the hospital, but the data was not encrypted. An investigation into the equipment loss was conducted by hospital staff as soon as the driver was discovered to be missing. According to Akron Children’s Hospital’s COO, Grace Wakulchik, “Our internal investigation indicated the hard drive was lost and nothing malicious was involved.” Since the storage facility was in a secure location of the hospital, it is highly unlikely that the device was stolen by a patient or member of the public, the most probably explanation being the devices was simply misplaced. Limited Protected Health Information Exposed The recordings were made between Sept. 18, 2014, and June 3, 2015 and involved brief conversations between physicians’ offices and hospital emergency departments. During these conversations a limited amount of Protected Health Information (PHI) of...



