Class Action Filed Against UCLA for 4.5 Million-Record Data Breach
It has been less than a week since the announcement that the patient database at UCLA Health Systems was hacked, and already a class action lawsuit has been filed by one patient, Michael Allen of Casper, Wyoming, on behalf of “several million individuals”. Allen, represented by Kevin Mahoney of Long Beach, claims UCLA Health Systems’ failure to encrypt data constitutes unlawful business practices, breach of contract, unjust enrichment and negligence. He is seeking class certification and as of yet unspecified damages for fraud, violation of medical confidentiality, an invasion of privacy and the costs of filing the lawsuit. UCLA hospitals and the University of California Board of Regents were named in the lawsuit which was filed on Monday of this week. The breach was announced on July 17, barely one business day before the lawsuit was filed. In the lawsuit, Allen claims the lack of data protection, specifically the lack of data encryption, amounted to negligence. “Due to defendants’ failure to take the basic steps of encrypting patients’ data, it was much easier...
Pharmacy Technician Suspended over 100-Patient Data Theft
A pharmacy technician who worked at CVS in San Diego has recently had her pharmacy technician’s license suspended (under Business and Professions Code 494) by the California State Board of Pharmacy after she was discovered to have accessed and stolen the Protected Health Information of around 100 patients. Nicole Yvonne Flores was employed at the San Diego’s Imperial Beach branch of CVS Pharmacy, where she had held the position since 2008, until 2015 when the data theft was discovered and she lost her job. The theft was discovered by the Secret Service, which conducted a raid on the apartment of Flores early last month. The Secret Service discovered a number of patient records in her apartment, and notified CVS of the potential theft of data. Flores was interviewed about by CVS management on June 10, 2015. During the interview Flores admitted that she had copied and removed patient records between May, 2013 and November, 2014, as well as during a three month period between February and April, 2015. The records were obtained when patients came to the drop off counter. Flores would...
Mailing Error Exposes PHI of Integral Health Plan Members
On July 6, 2015, Integral Quality Care (IQC) sent breach notification letters to some of its Integral Health Plan (IHP) members advising them of a data breach that exposed a limited amount of Protected Health Information (PHI). Patients’ names, dates of birth, Florida Medicaid ID numbers, diagnosis codes and payment information were exposed, although no addresses, Social Security numbers, credit card numbers or financial information were compromised in the incident. PHI Emailed to Incorrect Recipients In the breach notice, IQC informed patients that their data was accidentally emailed to the wrong doctors by a Business Associate, Independent Living Systems, LLC. The notice does not state how many individuals were affected by the data breach, although patients were told less than 10% of health plan members had their data compromised. The error has been attributed to a “processing mistake” which resulted in patient data being emailed to incorrect individuals who were authorized to view PHI, but not the patient data they were sent. The data breach occurred on May 11, 2015,...
Class Action Filed Against Charleston Area Medical Center for 2013 Data Breach
A class action lawsuit has been filed in the Kanawha Circuit Court against Charleston Area Medical Center, for a data breach that occurred between August 2013 and February 2014. The lawsuit has been filed by two plaintiffs who were patients of the medical center at the time of the data breach and had their data exposed. Tiffany Mallion and Nickole Pullen claim they entered into an agreement with the hospital to receive treatment, and that agreement also included securing their health information. They claim their Protected Health Information (PHI) was exposed as a result of a number of security failures at the medical center. It is alleged that the protections put in place to secure data were insufficient, and left highly sensitive information “unprotected, unguarded and unsecured.” A catalog of security failings have been cited, such as the failure to train staff on privacy and data security matters, a failure to protect data, as well as a there being a lack of physical protections to secure the equipment on which the data was stored. As a result, the plaintiffs claim “their...
The Healthcare Cybersecurity Challenge: How to Keep ePHI Secure
The healthcare industry faces many challenges, but perhaps one of the biggest at present is how to keep electronic protected health information of patients secure. Hackers are targeting healthcare providers for the data they hold, HIPAA-covered entities large and small are under attack, and the volume of cyberattacks is increasing at an incredible rate. New malware is evolving fast, employees are stealing data more frequently, and worse still; the threat landscape is ever-changing. The Workgroup for Electronic Data Interchange (WEDI) Offers Assistance The Workgroup for Electronic Data Interchange (WEDI) is a not-for-profit organization and a leading authority on healthcare IT security. One of the main aims of the organization is to help healthcare providers improve the quality of care provided to patients while introducing efficiencies to drive down costs. One of the ways it achieves this objective is by offering guidance on improvements that can be made to healthcare information exchanges. The organization was formed nearly 25 years ago by the Secretary of Health and Human...



