Spate of Data Breaches Highlights Need for HIPAA Privacy Training
The past few weeks have highlighted the dangers of HIPAA violations from within, with employees and healthcare professionals responsible for causing a number of HIPAA data breaches. Since April 27, the records of 132,432 individuals have been exposed due to breaches caused by human error, and potentially many more: HIPAA covered entities are not obliged to report breaches until 60 days after the incident is discovered. A Spate of Employee HIPAA Breaches Reported in the past 5 weeks. The last week in April saw a number of data breaches added to the Department of Health and Human Services’ Office for Civil Rights (OCR) breach portal. Consolidated Tribal Health Project reported that an employee had inappropriately accessed the PHI of 4,885 patients, while an email sent by a New York City Health and Hospitals Corporation (HHC) worker resulted in 3,334 patients’ records being compromised. In the latter incident, the Bellevue hospital employee sent a spreadsheet containing PHI outside the hospital network to receive some technical help manipulating the spreadsheet. Clinical Reference...
Class Action Lawsuit Prepared for 20K-Record MML Data Breach
The dust has barely settled after the 20,000-record HIPAA data breach at Medical Management LLC (MML), but at least one attorney is poised for action and intends to sign up data breach victims to a new class action lawsuit even though it is too early to tell whether any of the victims have suffered identity fraud or any other damage or harm as a result of the breach. Claims for data breaches tend to only succeed when the plaintiffs can demonstrate that they have suffered harm, damage or loss as a direct result of a breach. The courts are quick to throw out any speculative claims for unsubstantiated damages. At this stage, no hospital – nor MML – has reported that the stolen information has been used inappropriately. Joseph Santoli, a class-action lawyer from Ridgewood, announced this week that he will be filing a suit naming six residents of Bergen County whose personally identifiable information and Social Security numbers were stolen and disclosed to a third party. This information was obtained without patient consent or the employer’s authorization: A clear breach of...
Unity Recovery Group Discovers 12-Month HIPAA Breach
Unity Recovery Group (URG), a provider of drug and alcohol rehabilitation services, has announced that some of its patients have been affected by a data breach that has violated their privacy rights and breached Health Insurance Portability and Accountability Act Rules. The organization is in the process of notifying an as of yet unspecified number of individuals of a privacy breach which lasted almost a year, starting in April, 2014 and lasting until March, 2015. Patients have been advised that some of their Protected Health Information (PHI) “was impermissibly disclosed” to “one or more unaffiliated recovery and/or rehabilitation service providers,” according to the company’s breach notice. HIPAA Breach Exposed Health Information and Social Security Numbers for 12 Months URG is alerting affected individuals that their names, dates of birth, addresses, contact telephone numbers, email addresses, health insurance information, Social Security numbers, and “certain health information” were exposed. Since the breach notice does not provide much information about the exact nature of...
Ohio Radiologist Disciplined for HIPAA Violation
The Ohio State Board of Medicine has taken action against a radiologist who violated the Health Insurance Portability and Accountability Act (HIPAA) by unlawfully accessing the medical records of a colleague. The radiologist, Dr. Aimee Hawley, accessed the records of a work colleague of Mercy Health St. Rita’s Medical Center in September 2013. Hawley has since left the hospital’s medical staff. It is not known why Hawley accessed the records of her physician colleague, when she should have been aware of the restrictions in place covering access to Protected Health Information under HIPAA. The State Medical Board of Ohio’s education & outreach program manager, Joan Wehrle, said the source of the compliant into the HIPAA violation was being kept confidential. He pointed out that patient privacy is a serious matter and “No one can access a patient’s medical records unless they are a treating or consulting physician or have permission from the patient.” As a result of this transgression, Hawley has agreed to sign a consent agreement submitting to disciplinary action. A consent...
Judge Approves HIPAA Protective Order for Auto Accident
St. Clair County Associate Judge, Heinz Rudolf, has approved a HIPAA Protective Order to allow the defendants in a wrongful death lawsuit to have access to the two victims’ medical information. A lawsuit was filed against Access Courier, Inc., Contractor Solutions, LLC – Senad Hodzic and Alfredo McGee – by the plaintiff, Debra Dyer-Webster, for an accident which occurred on Oct. 25, 2013 and resulted in fatal injuries being suffered by two minors. Damages of 1.5 million are being sought. In the compliant, it is alleged that the two victims of the fatal automobile accident – Alicea McGee and Anastashia McGee – were killed as a result of Senad Hodzic failing to keep his vehicle under control, not paying sufficient attention, failing to keep a sufficient lookout and failing to “pull a vehicle off the traveled portion of the highway.” At the time of the accident, Hodzic was employed by Access Courier and Contractor Solutions. Alicea and Anastashia McGee were traveling in a 2000 Chevrolet Impala in the northbound lane of Interstate 55 in Macoupin County when the vehicle...



