Urology Associates Reports 6500-Record Data Breach
Offsite storage of paper medical records may be convenient if facility space is limited; but the decision to store records offsite may prove to be a costly, as Kailspell-based healthcare provider, Urology Associates recently discovered. The company had taken advantage of a local storage facility and rented a unit to store boxes of old medical records. Unfortunately, the facility was recently burgled. Storage Units are a Risky Place to Keep Sensitive Medical Records Storage units are frequently burgled. The units are secured with locks; but in many cases, all that is required to access the contents is a set of heavy duty bolt cutters. Thieves have realized there are easy pickings to be had from storage units, and law enforcement has had to deal with a spate of storage unit break-ins recently. The problem is not limited to Kalispell; it is a countrywide problem. Records Potentially Accessed, but not Stolen Medical records are extremely valuable. Complete sets of data can fetch in the region of $60 on the black market. Clean records, such as those of children, can be...
Hospital Drug Pump Hacking Risk Discovered
In addition to having to deal with the threat to electronic health records from hackers, hospitals must also be wary of attacks on their medical devices; as evidenced by a new Food and Drug Administration (FDA) warning over a drug pump hacking risk that exists with Hospira’s Symbiq drug pump. Symbiq Drug Pump Hacking Risk Warning Issued by FDA Only a few days ago, two hackers discovered it was possible to hack into the onboard computers of Fiat Chrysler automobiles and take control of the vehicle; now patient’s plugged into the Symbiq drug pump could potentially be at the mercy of malicious hackers. Such is the severity of the Symbiq drug pump hacking risk, on Friday last week the FDA issued a warning to all hospitals using the device, instructing them to retire the devices and make the transition to other, more secure drug infusion pumps. In the meantime the FDA recommended that healthcare providers should “disconnect the pumps from their networks and update their drug libraries manually.” Since the vulnerability can be exploited via unused ports on the devices, the FDA...
New Basic Guide to HIPAA Compliance Released By HHS
The Department of Health and Human Services’ Office for Civil Rights has recently issued a basic guide to HIPAA compliance; a summary of HIPAA Rules for covered entities. A Basic Guide to HIPAA Compliance The Health Insurance Portability and Accountability Act (HIPAA) places a number of requirements on healthcare providers, health plans, healthcare clearinghouses, and Business Associates of HIPAA-covered entities, to safeguard data, protect the privacy of patients, and notify them of incidents that expose their Protected Health Information (PHI). HIPAA legislation is complicated, and many covered entities, especially smaller healthcare providers, struggle to understand the HIPAA Privacy, Security, and Breach Notification Rules, and turn those rules into policies into procedures. The Department of Health and Human Services’ Office for Civil Rights is the enforcer of HIPAA Rules, and while the agency investigates data breaches, it is also charged with improving understanding of data privacy and security legislation. One way it achieves this objective is by issuing guidance to help...
HIPAA Breach: 1,111 Veteran Records Improperly Dumped
The Department of Veterans Affairs has announced the potential exposure of 1,111 veteran health records after files containing Personally Identifiable Information (PII) and Protected Health Information (PHI) were accidentally tossed in a dumpster. The files were thrown out with regular waste by an employee of the VA Hot Springs Hospital in South Dakota on Friday, May 15, during a move to a different location. The files were mistaken for regular rubbish, and would have remained in the publically accessible dumpster were it not for a vigilant employee who noticed the dumped files two days later. The improper dumping was reported to the Veterans Affairs police, who went dumpster diving to retrieve the files. According to a press release issued by the Fort Meade-based VA Black Hills Health Care System, an investigation was launched after the incident came to light. Public Affairs Officer, Teresa Forbes, was interviewed by the Rapid City Journal on Friday last week, and said “It was just an unfortunate mistake during an office move.” The box of files appeared not to have been tampered...
Husband-Wife Tax Fraudsters Get 231 Months Jail Time
A former employee of Tift Regional Hospital has recently been sentenced to serve 84 months in jail for fraudulently submitting 1,100 bogus tax returns, including making 531 tax claims using the data of 16 year olds. Her husband has been sentenced to serve 147 Months in the Bureau of Prisons. Both are required to pay restitution of $1,107,802.00 to the IRS. United States Attorney for the Middle District of Georgia, Michael J. Moore, recently announced Honorable W. Louis Sands’ verdict on Mrs. Patrice Taylor, 34 and her co-conspirator husband, Antonio Taylor, 44, both of Ashburn, Georgia. The total loss suffered by the IRS was $1,199,897.00 Sentencing took place on July 27, 2015 with Mrs. Taylor convicted of aggravated identity theft and conspiracy to commit wire fraud. Taylor had previously pled guilty to the offences and took a plea deal. She admitted to committing the offenses between January 2011 and February 2013. According to evidence presented at trial, Mrs. Taylor used Social Security numbers obtained during her employment at Tift Regional Hospital to file the tax returns....



