U.S HealthWorks HIPAA Breach Raises Issue of Data Encryption
U.S. HealthWorks, a healthcare provider based in Valencia, California, has reported a breach of PHI and PII after an unencrypted laptop computer was stolen from the vehicle of a company employee. Theft of Laptop Computer from Unattended Vehicle The incident occurred on April 21, 2015, and was discovered by the healthcare provider the following day. The sample breach notification letter – posted on the State of California DoJ Attorney General’s website – explains that a company employee had taken a laptop computer and left it in a vehicle from where it was stolen. Upon discovering the theft, the incident was reported to law enforcement officers, and an investigation was commenced. U.S HealthWorks started an internal investigation to determine the exact nature of the data stored on the laptop; a process which has taken some time to complete. According to the breach notification letter – dated May 30, 2015 – it took until May 5, 2015, to determine that the laptop computer was password protected but lacked data encryption software. The healthcare provider was able to determine that...
Nevada and North Dakota Amend Data Breach Laws
North Dakota and Nevada have joined the growing list of states to update their breach notification laws this year. Last month, new laws were passed to tighten up the legislation and expand “personal information” definitions, with the two states joining California, Florida, Montana, Washington, and Wyoming, which have already updated state breach notification laws. The Health Insurance Portability and Accountability Act (HIPAA) – specifically the Breach Notification Rule of 2009 – places a number of requirements on Covered Entities (CEs) when it comes to responding to a data breach involving Protected Health Information and Personally Identifiable Information. HIPAA Rules are only a minimum set of standards. States can introduce laws to increase data privacy and security protections for patients, plan members, and other individuals affected by a healthcare data breach. Often states include provisions in their new laws for entities covered under HIPAA and other federal laws. New Breach Notification Law in North Dakota The Sixty-fourth Legislative Assembly of North Dakota Met on...
Phishing, Spear Phishing and Malware: How Hackers Gain Access to PHI
Criminals looking to break through the cybersecurity defenses put in place by health insurers and healthcare providers – to safeguard Protected Health Information (PHI) – can choose an easy or hard way to gain access to the data. Unsurprisingly, many choose the easy route in and exploit one of the largest security vulnerabilities; one that many healthcare providers have failed to address. The end users sitting at a terminal, PC or laptop with access to the network, emails and EHRs. IT staff can build multi-layered defenses and lock servers in impenetrable vaults, yet the army of healthcare workers who have full access to EHRs are an easy way for hackers to sneak through sophisticated defenses, undetected. If end users can be convinced to divulge their login credentials, or even easier, click on a malicious link or download and double click a malware affected attachment, the thieves can be in and out of a system almost as quickly as it takes to copy a database full of patient health records. Fortunately, many tech-savvy healthcare workers will be able to spot a phishing...
Patients’ Patience Pays Off: Class Action Payout for InSync HIPAA Breach
Two years ago a class-action lawsuit was filed against Cottage Health System after the healthcare provider – via its Business Associate (BA) InSync – suffered a serious data breach. It has been a victory for the victims – and the legal team – as Cottage Health agreed to settle the case. Rather than fight the case in court, Cottage Health System agreed to settle and pay damages to the individuals affected by the data breach, without any finding of legal liability. 50,918 Individuals Affected by CHS/InSync Data Breach The HIPAA security breach was discovered in December 2013, with the data of up to 32,500 individuals believed to have been exposed. The patients were those that had visited Santa Barbara Cottage Hospital, Goleta Valley Cottage Hospital or the Santa Ynez Valley Hospital between September 29, 2009 and December 2, 2013. However the number of affected individuals was later found to be higher, and 50,918 are understood to have been affected. The data breach was discovered when the company received a voicemail message alerting it to a file containing the PHI of patients...
Buffalo Heart Group Suffers Insider HIPAA Breach
The Buffalo Heart Group (BHG), a Williamsville, NY. provider of cardiac services, has announced – via Hurwitz- Fine, Attorneys at Law – that it has discovered a “serious breach of its computer system” which has resulted in the Protected Health Information (PHI) of up to 600 individuals being accessed being viewed by a third party. The security breach occurred last spring, and resulted in information being accessed by a third party acting under the direction of a physician formerly associated with BHG. The information potentially viewed includes patients’ full names, dates of birth, addresses, contact telephone numbers, their appointment schedules and e-superbills. The information was accessed – and potentially also used – to “solicit patients in connection with the physician’s new employment,” according to the healthcare provider’s attorneys. BHG confirmed that the data breach was confined the spring of last year and no information was accessed after June, 2014. Because no Social Security numbers, health information or financial information has been...



