Foreign Hacker Responsible for Siouxland Pain Clinic Data Breach
A foreign hacker has gained access to Siouxland Pain Clinic’s patient data, according to a statement released by the healthcare provider’s attorney. The hacker managed to infiltrate the healthcare provider’s computer network, potentially obtaining the Protected Health Information of approximately 13,000 of its patients. The hacker is understood to have first gained access to the Iowa healthcare provider’s computer network on March 26, 2015, with access reportedly continuing until April 2. Siouxland Limited, which operates the Siouxland Pain Clinic, was notified of the security breach on June 26. The statement was issued on Friday, 31 July, with further information released a few days later. It is not clear why access to the computer systems stopped on April 2, and how it then took over two months for the incident to be discovered. The incident is still under investigation, with the healthcare provider having enlisted the help of a private cybersecurity firm to determine the extent of the incident, the data exposed, and whether any of that data has been copied. The news of the...
North East Medical Services HIPAA Breach Reported: 69,246 Affected
A HIPAA breach has been reported by North East Medical Services. The Protected Health Information of almost 70,000 patients has potentially been exposed after an unencrypted laptop was stolen from the car of a NEMS employee’s car. According to a breach notice sent to the California Department of Public Health, the incident occurred on July 11, 2015. The laptop was left in the locked trunk of a vehicle from where it was subsequently stolen. The healthcare provider was alerted to the equipment theft on July 13. North East Medical Services HIPAA Breach Exposed “Limited Personal Information” The investigation launched following the crime revealed that the laptop contained data relating to 69,246 patients, which according to the breach notice, consisted of one or more of the following data elements: Patient name, gender, date of birth, address, phone numbers, and pay/insurer information. No medical records were stored on the laptop, although some patients’ diagnoses, test results, medications, treatments and appointment times were listed in spreadsheets stored on the computer. No...
Data Breach Sparks Medical Informatics Engineering Lawsuit
A Medical Informatics Engineering lawsuit has been filed in Fort Wayne for the security breach that exposed the data of 3.9 million Americans. These days, data breach victims are signed up by lawyers within hours of breach notices being posted. The latest lawsuit is no exception, with the mailing of the breach notification letters only completed on July 25, 2015. The Medical Informatics Engineering lawsuit was filed by Irwin B. Levin, managing partner of Indianapolis law firm Cohen & Malad LLP, on behalf of James Young, who had his health data and Social Security number exposed in the May 26, 2015 cyberattack. The lawsuit has been filed in the U.S. District Court in Fort Wayne. A spokesman for Medical Informatics Engineering, Jeff Donnell, told the Fort Wayne Journal Gazette, “We are aware of the suit, and we are currently reviewing it. Our primary focus at this time is on our response to those affected by this cyberattack.” Young does not appear to have suffered identity theft of fraud as a result of the exposure of his data; instead the suit has been filed against MIE for...
Hackers Stole Anthem Data for Espionage; Not Fraud
The colossal data breach suffered by Anthem Inc., appears to have occurred for reasons related to espionage, not financial gain, according to Symantec. Hackers often break into healthcare databases to steal patient health data and Social Security numbers, which have a high value on the black market. The data can be used to commit identity fraud, file false tax returns, and obtain credit in the names of victims; but that is not the only way data can be used. Human intelligence (HUMINT) has the potential to be much more valuable. The Anthem cybersecurity attack has been linked to a group of hackers operating under the name of Black Vine. Black Vine hackers are well-funded, operate out of China, and are understood to have ties to the Chinese Government, although this is understandably denied by Beijing. The group has previously been linked to major security incidents throughout the U.S., conducted on aviation companies, gas turbine manufacturers, military installations, the financial sector, and some healthcare organizations. Black Vine is not known to engage in cybercrime for...
Email Error Results in Massachusetts General Hospital Data Breach
The spate of employee emailing errors continues, with the latest entry in the Office for Civil Rights “Wall of Shame” being a recent Massachusetts General Hospital data breach; another example of how a simple mistake can result in the Protected Health Information of hundreds of patients being exposed. The latest Massachusetts General Hospital data breach exposed the data of 648 patients, and included patient names, laboratory test results, and a limited number of Social Security numbers, although no insurance information or financial data were exposed. The security incident involved an email that was inadvertently sent to an incorrect recipient; potentially disclosing patient data. The error was identified promptly and the hospital made several attempts to recall the message, but those attempts proved to be unsuccessful. Deborah A. Adair, Massachusetts General Hospital’s Privacy Officer, confirmed in a letter to New Hampshire Attorney General, Joseph Foster, that no evidence has been uncovered to suggest that the data have been used inappropriately; although the letter did not...



