HIPAA and the New Helping Families in Mental Health Crisis Act
The Helping Families in Mental Health Crisis Act (H.R. 2646) of December, 2013, has been reintroduced by Tim Murphy (R-PA) – Subcommittee Chairman for the House Energy & Commerce Oversight and Investigations – and Rep. Eddie Bernice Johnson (D-TX) with a double purpose. First, it is hoped that the new bill will help to improve the standard of mental health care provided to patients, and secondly a number of new provisions will be introduced to ensure patient privacy is protected. According to Tim Murphy, the new bill “marks a new dawn for mental health care in America,” he went on to say that the new bill “breaks down federal barriers to care, clarifies privacy standards for families and caregivers; reforms outdated programs, expands parity accountability, and invests in services for the most difficult to treat cases while driving evidence-based care.” The bill has been praised by many, but the legislation change has not been universally welcomed. The bill has received criticism from some quarters; in particular for the potential for HIPAA violations to occur. One area of...
ONC Turns Attention to Big Data Security
Big data has huge potential for improving patient care and treatment outcomes, but the use of patient information raises some serious questions about privacy and security. The ONC Health Information Technology (HIT) Privacy & Security Workgroup (PSWG) has been discussing the issues faced by the healthcare industry. At a meeting of the group on Monday a number of healthcare big data issues were raised. The group aims “To address distrust in big data algorithms: Improve trust through algorithmic transparency and to consider applying Fair Credit Reporting Act (FCRA) approaches to promote algorithmic transparency,” in addition to taking action to improve data privacy and security standards. Issues with HIPAA and Healthcare Big Data One of the main concerns raised by the group is the fact that HIPAA only covers certain areas of health big data. There are notable gaps which could cause problems down the line according to the group. “Failing to pay attention to these issues undermines trust in health big data, which could create obstacles to leveraging health big data to achieve gains...
Arkansas Medical Assistant Pleads Guilty to Defrauding Patients
A medical assistant from Little Rock, AR. has plead guilty to one count of Aggravated Identity Theft after she illegally accessed the medical records of 13 patients, stole their Social Security numbers, and used their Protected Health Information (PHI) to secure credit. United States District Court Judge, Susan Webber Wright, heard Mesha White, 34, plead guilty to Aggravated Identity Theft on June 3, 2015. The case has will now be scheduled for official sentencing, although the guilty plea means White will serve a mandatory two years in prison, with three years of supervised release. She must also pay back the thousands of dollars she has illegally obtained and spent in the names of 13 different patients. White potentially faced a very lengthy jail term. She accessed and stole HIPAA-covered data without authorization; that data was taken for personal gain and White then proceeded to defraud thirteen different individuals. In April, a federal grand jury indicted White on seven counts of aggravated identity theft and seven counts of misusing a Social Security number. The guilty plea...
Employee Causes 4K Data Breach at Metropolitan Hospital Center
The Metropolitan Hospital Center in New York has issued breach notices announcing the potential exposure of patients’ Protected Health Information (PHI) after an employee was found to have emailed data to a personal account. The breach notice – issued to the Department of Health and Human Services’ Office for Civil Rights (OCR) on June 1, 2015 – indicates that 3,957 individuals have been affected. Three Email HIPAA Data Breaches Suffered in Quick Succession This is the third major breach to affect a New York City Health and Hospitals Corporation (HHC) hospital this year. All three have been caused by employees emailing PHI to personal or external mail accounts without authorization. The Jacobi Medical Center issued breach notices to 90,060 individuals in April after an employee emailed PHI to a personal email account. HHC’s Belleview Hospital Center sent breach notices to 3,334 individuals on April 28th advising them of a data breach caused by an employee emailing a spreadsheet to the email account of a relative on January 15, 2015. The same day, the Metropolitan...
PHI Potentially Exposed in Fred Finch Youth Center Break-In
Fred Finch Youth Center has issued data breach notices announcing one of its facilities has suffered a burglary that has potentially exposed the Protected Health Information (PHI) of 6,871 individuals. Fred Finch operates youth centers in Alameda, Contra Costa, San Mateo, and San Diego Counties. The San Diego County facility was targeted by thieves, who gained access to the property by forcing open a locked window on April 4 or 5, 2015. The staff discovered the burglary on April 6 and realized that “several pieces of computer equipment” had been stolen. Some of that equipment contained information protected under the Health Insurance Portability and Accountability Act. The information stored on the computer equipment included full names, dates of birth, Social Security numbers and treatment information. An undisclosed number of Medi-Cal numbers were also stored in the records. The breach notice confirms that protections are in place which should keep the information secure; however the data stored on the devices was not encrypted. The equipment had “technical protections (including...



