Los Angeles County Government Has Been Putting Patient PHI at Risk for 7 Years
The Los Angeles County government has failed to safeguard the Protected Health Information (PHI) of state residents for up to seven years, according to a recent audit. Three departmental audits have been conducted since December 2014 and a catalog of data security failures have been uncovered that potentially put PHI in the hands of thieves. Data including Social Security numbers and health information could be accessed by former workers, and the information could already be in the hands of criminals. It is simply not known. Computer equipment has vanished – having been misplaced or stolen – devices were not encrypted, and equipment was simply not tracked. Serious Administrative Failures Lasting up to 7 Years Serious administrative failures in several L.A County government departmenta were discovered by auditors, the most serious being a failure to terminate access to computer systems when employees changed employment. An audit conducted by the Probation Department revealed that 695 former employees still had access to computer systems containing the protected health data of...
Ohio University Hospitals Worker Fired for Improper EHR Access
An Ohio University Hospitals Elyria Medical Center worker has been fired for inappropriately accessing the medical records of patients while employed at the hospital. Alicia Reale, a spokesperson for the hospital, announced yesterday that the medical records of approximately 300 patients had potentially been improperly accessed by an employee of the hospital. The data breach resulted in Protected Health Information (PHI) potentially being viewed and copied. An investigation was triggered when the hospital discovered an employee had accessed the EHR system without a legitimate work purpose for doing so. Reale said “The information that may have been accessed for the impacted patients includes names, dates of birth, medical record numbers, dates of service and diagnostic and treatment information, ” according to a report in the Chronicle-Telegram. Another Case of Hospital Employees Snooping on Medical Records No financial information or Social Security numbers were exposed in the incident, and while the extent of access was determined, Reale said “We did not identify any purpose for...
Florida Hospital Submits Motions to Dismiss Two Data Breach Lawsuits
Last month, the Florida Hospital group reported a data breach had exposed the records – including Social Security numbers – of 94 individuals. A data breach class-action lawsuit for this year’s breach is almost certain to be filed; however, the hospital group’s legal team is already busy with two class action lawsuits. The two potential lawsuits have been filed for two separate data breaches that occurred in 2011 and 2012; the latter was not discovered for two years. Recently the healthcare provider’s lawyers have made the move to have booth class-action motions thrown out, according to a recent report in the Orlando Sentinel. The class-action lawsuits are currently pending in the Florida Orange County Circuit Court. Motions Submitted to Toss the Data Breach Lawsuits Both cases are viewed by the Florida Hospital Group as being speculative claims for non-existent damages. Patient data was exposed, and in one case also sold on; however, there is perceived to be only a low risk of losses or damage being suffered. In the 2011 breach, Patient information was obtained and...
Malware as a Service Being Offered to Criminals on Darknet
You can choose a cloud-platform-as-a-service and software-as-a-service; however for the criminally minded, it is possible to purchase malware-as-a-service. Cybercriminals are now adopting the same business model to sell their malicious software as legitimate software vendors. A platform or software-as-a-service is a business model that allows a product to be used, developed and managed by an individual or company; gaining the benefits of the software without having to develop everything from scratch. Malware-as-a-service is available on the darknet and offers criminals the same benefits. In depth computer knowledge is not required; a criminal can select off-the-shelf malware to suit his or her needs. The creations of skilled hackers can be used by any number of relatively unskilled individuals to allow them to gain access to computers and networks and steal the valuable data they store. Industry leaders are now referring to this mass-market malware sale as “the industrialization of cybercrime,” and it is a highly profitable business. It is so successful and profitable that sales...
HIMSS Releases 2015 Healthcare Cybersecurity Report
297 healthcare leaders and information security professionals have recently given their opinions to HIMSS on the state of healthcare cybersecurity, with the results of the survey recently published in HIMSS’s 2015 Cybersecurity Report. The release of the report coincided with the Chicago Privacy and Security Forum event between June 30 and July 1 of this year. The report highlights a number of concerns about cybersecurity; perhaps the most pressing being the sheer shale of the current attack surface. Hackers are breaking through security defenses left, right and center; but more worrying is the fact that they have been doing that for a number of months, and are already inside many computer systems. Healthcare Professionals are Concerned Their Protections may not be Enough Numerous major breaches have affected tens of millions of employees, consumers and patients over the course of the past few months. New data breaches are being discovered on an almost daily basis and no industry appears to be safe from attack. Hacking groups are (allegedly) being financed by foreign...



