Indiana State Medical Association Suffers Major HIPAA Breach
The Indiana State Medical Association has reported a HIPAA breach as a result of the theft of two backup hard drives containing healthcare and insurance information of almost 39,000 individuals. The hard drives contained group health and life insurance databases, with the data including Social Security numbers, medical histories, health plan numbers, email addresses, dates of birth and names and addresses that were supplied on health insurance applications. The backup drives were being transported to an off-site storage facility as part of the group’s disaster recovery plan when they were stolen in what the ISMA called a “random criminal act.” According to the breach notice placed on the ISMA website, 39,090 individuals were potentially affected although the exact data compromised varies from individual to individual. Social Security numbers were present in the databases, but not for all individuals. As a result the decision was made to send individual breach notification letters explaining the exact information that was compromised. Affected individuals are being offered credit...
Delegates Prepare for the 23rd National HIPAA Summit
Next week, government department heads and industry leaders will meet at the 23rd National HIPAA Summit to give updates on the progress that has been made over the past 12 months and to provide information on new laws and regulations. The summit also offers an opportunity for compliance officers and other healthcare professionals to receive training on a wide range of healthcare IT and HIPAA-compliance issues. The threat of cyberattacks on healthcare providers has risen to an all time high and healthcare costs are spiraling out of control. The industry may be in critical condition, yet healthcare providers, health plans and other covered entities must find the funding to improve data security and protect the privacy of patients and health plan members. Since the introduction of HIPAA this has been a major challenge, but with the introduction of HITECH, the Affordable Care Act (Obamacare), the move to IC10 coding and the passing of the HIPAA Omnibus Rule the challenge has grown. HIPAA-covered entities now face a huge financial and administrative burden to comply with these...
Evansville Medical Center Hack Exposes HIPAA Data of 4,400
Hackers have gained access to the E-mail accounts of a number of employees of the St. Mary’s Medical Center in Evansville, Indiana, resulting in the PHI of approximately 4,400 patients potentially being exposed. A spokesman for St. Mary’s Medical Center, Randy Capehart, issued a statement announcing the HIPAA breach to the press. In the statement he explained the nature of the attack and the data that was potentially exposed. The E-mail accounts accessed by the hackers contained Protected Health Information together with personal identifiers and some Social Security numbers. Although the data exposed varied from individual to individual, the information mostly contained names, gender, dates of birth, health and insurance information. The attack occurred in January and all patients affected by the breach are being notified by mail. They have been offered a year of credit and identity protection services if they had their Social Security numbers exposed. All other individuals will be entitled to obtain a free credit report from each of Equifax, TransUnion and Experian. The breach was...
HIPAA Breach Reported After Theft of PHI from Wisconsin Physician’s Car
The theft of laptop computers containing unencrypted Protected Health Information (PHI) accounts for a high proportion of HIPAA breaches reported to the Department of Health and Human Services’ Office for Civil Rights (OCR). The Medical College of Wisconsin will join that list of organizations to suffer a laptop-related HIPAA breach after the device was stolen from the car of a physician. In this case, the theft only resulted in one patient record potentially being exposed; however, paper files containing the PHI of approximately 400 of the physician’s patients were also taken in the theft. Under the Health Insurance Portability and Accountability Act (HIPAA), Covered Entities (CEs) are required to report breaches of PHI to the OCR via its breach reporting portal. CEs have up to 60 days to report breaches involving more than 500 individuals, although there is only an annual requirement to report breaches of fewer than 500 records. A public announcement was issued via a CBS Affiliate, WDJT Milwaukee, regarding the data breach and notification letters were quickly dispatched to all...
Veteran HIPAA Breaches Fell by Over a Third in January
A recent report sent from the Department of Veterans Affairs (VA) to congress indicates that HIPAA breaches involving the PHI of veterans have fallen by 35% from December 2014 to January 2015, while the affected individuals fell by 52%. In December last year, 371 out of 643 veterans affected by a data breach involved HIPAA covered Protected Health Information, while January saw a substantial improvement with only 310 veterans affected by data breaches, of which 242 involved the exposure of PHI. The data breaches were divided by the VA into four categories: Lost or stolen devices (including laptop computers, PCs and portable storage devices), lost personal identity verification (PIV) cards, mis-mailed incidents (when patients are sent data belonging to other patients) and mishandled incidents, which typically involve the mishandling of two patients records. Three of the categories saw a significant drop in number of affected veterans, while lost PIV cards remained broadly the same, having only increased 6% from 120 to 127 affected individuals. The number of veterans affected by lost...



