Unauthorized Email Exposes PHI of 855 Advanced Radiology Consultants Patients
On July 24, Advanced Radiology Consultants, LLC., announced a data security event that exposed the data of a small subset of its patients. The breach report submitted to the Department of Health and Human Services’ Office for Civil Rights indicates 855 patients have been affected. The data breach was caused when an employee of the company emailed a list of patients’ PHI to a personal email account. The list of data included patient names, telephone numbers, dates of birth, balance information, patient identification numbers, examination results, treatment information, appointment dates and times, appointment notes, referring physician names, insurance provider, and insurance identification numbers. Advanced Radiology Consultants confirmed in a press release that no Social Security numbers, credit card numbers, driver’s license numbers or financial account information were included in the email. That said, the information that was copied and emailed outside the healthcare providers’ network did contain enough data to enable the employee to file false insurance claims, and...
East Bay Perinatal Medical Associates Data Breach Announced
An East Bay Perinatal Medical Associates data breach has recently been announced, in which names and dates of birth of patients have been exposed. The healthcare provider is now sending notification letters to patients warning them of the privacy violation. The healthcare provider became aware of the breach of personal information on June 2, 2015. The data breach was not uncovered by the hospital; instead it was brought to the attention of East Bay Perinatal Medical Associates (EBPMA) by the Berkeley Police Department as a result of a totally unrelated investigation. 1,494 individuals have been affected according to the HHS breach report. Berkeley Police Discover East Bay Perinatal Medical Associates Data Breach Law enforcement discovered a list of patient names stored on a laptop computer used by an employee of the hospital. An investigating officer alerted the healthcare provider to the potential breach of personal information and the laptop computer was retained by law enforcement. EBPMA’s Information Technology Security Consultant subsequently arranged for the...
Indiana Attorney General Advises Hoosiers to Exercise Extreme Caution after MIE Data Breach
As further details of the MIE data breach emerge, the Indiana State Attorney General, Greg Zoeller, has urged all state residents to exercise extreme caution and put credit freezes on their accounts to protect against identity theft and fraud. The MIE data breach exposed a significant amount of personal and highly sensitive data and is understood to have affected more than 1.5 million individuals in the state of Indiana. In total approximately 4 million records were exposed. High Risk of Fraud and Identity Theft from MIE Data Breach The data breach at Anthem may have exposed about 20 times as many records as the MIE data breach; but what is particularly worrying in this instance is Social Security numbers and health data have been exposed, placing breach victims at a much higher risk of suffering financial losses. Zoeller said, “These are very significant medical records, lab reports, people’s charts essentially online.” Zoeller pointed out that the incident has not just increased the risk of fraud; the information has already been used for fraudulent purposes. He said, “We’re...
FCC Confirms Rules Regarding HIPAA and Patient Telephone Calls
The Federal Communication Commission has issued a Declaratory Ruling and Order to clarify the position on making telephone calls to patients in compliance with HIPAA and TCPA In the past, there has been some misunderstanding about making telephone calls to patients in compliance with Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Telephone Consumer Protection Act of 1991 (TCPA). To resolve any remaining misunderstandings, the American Association of Healthcare Administration Management petitioned the Federal Communications Commission (FCC) to clarify areas of the TCPA rules. The recently published TCPA Omnibus Declaratory Ruling and Order clarifies the federal government´s position on making telephone calls to patients by HIPAA Covered Entities and also exempts Covered Entities from complying with a ban on automated calls to patients´ landline telephones. However, questions still remain about automated calls to patients´ mobile telephones when not made by a third party service provider with whom a BAA has been signed. The Federal Position on Making...
Lawsuit Filed Against Children’s National Medical Center for 2014 Data Breach
Children’s National Medical Center has been named in a new class-action lawsuit filed by a victim of a data breach that occurred in 2014. The plaintiff, Fardoes Khan, has not suffered any harm or loss as a result of the exposure of her PHI, but she is seeking damages for the increased risk of suffering identity theft and fraud. The lawsuit was originally filed in Montgomery County, although last week it was moved to the Maryland federal court. The lawsuit concerns a data breach that occurred during the second half of 2014, when hackers gained access to a number of hospital email accounts after a number of employees responded to phishing emails sent by hackers. As a result of the responses, hackers potentially gained access to email accounts on July 26, 2014. The data breach was discovered by Children’s National Medical Center on December 26, 2014. As soon as the breach was discovered and the affected email accounts identified, they were closed and secured. The hospital recruited the help of an external computer forensics company and a thorough investigation was conducted to...



