Theft of HIPAA Records Reported by Texas Healthcare Provider
Hunt Regional Medical Partners, a healthcare provider in Texas, has reported a break in at its Westlake facilities in which an undisclosed number of healthcare records were obtained by thieves. The property was vandalized and old paper medical files of patients who had visited the Hunt Regional Medical Partners Family Practice (HRMP) at Westlake before 2010 were taken. The practice had recently been acquired by the healthcare provider and was previously known as Westlake Medical Center. It is not clear at this stage exactly what information was disclosed in the incident, although according to the breach notice issued by HRMP, the information potentially included Social Security numbers and health information along with personal identifiers making this a HIPAA breach. The vandalizing of the premises and theft of data have been reported to law enforcement officers and an investigation was immediately launched. Breach notification letters have now been sent to all affected individuals, and due to the increased risk of suffering medical or identity fraud, credit monitoring services are...
Possible HIPAA Violations in Medical College of Wisconsin Breach
The Medical College of Wisconsin has issued a statement announcing a data breach that has affected approximately 400 of its patients. WDJT Milwaukee, an affiliate of CBS, was contacted on Feb 28, 2015 by a spokesperson for the Medical College of Wisconsin detailing a data breach which exposed some confidential information of its patients. The breach occurred on February 15, 2015, when a document and a laptop computer were stolen from a physician’s car. The document contained information relating to approximately 400 patients. The laptop is understood only to have only contained the information of one patient. It is not clear exactly what information was stored on the laptop computer or in document at this stage; although MCW has confirmed that no Social Security numbers or patient addresses were stolen. In spite of legislation that requires data encryption is addressed, the healthcare industry has been slow to respond and use data encryption on its desktop computers, laptop computers and other portable storage devices. Data encryption ensures that if a device is stolen, no...
Potential HIPAA Violations by Minnesota Blue Cross Blue Shield Nurse and Hospital
According to a Monday WCCO-TV news report, a nurse employed by Minnesota Blue Cross Blue Shield stands accused of illegally accessing a state database containing the prescription drug records of approximately 1 million state residents. The database – administered by the Minnesota Board of Pharmacy – contains names, addresses and prescription records and was set up in an attempt to monitor the abuse of pharmaceutical products and prescription drugs. When an individual has an addiction, they usually visit multiple locations to obtain their prescriptions and by monitoring the database cases of medication abuse and addiction can be identified. Minnesota Blue Cross Blue Shield is permitted to access the database in order to monitor drug use in state-run medical programs and receives payment from the state to do so. Two employees are granted access for this purpose. In 2010, the Minnesota Department of Human Services and Blue Cross Blue Shield gave one of its registered nurses, Jim Johnson, access to the database for this purpose. In March 2012 he was reassigned and another...
Study Says Website Security Gap in HIPAA Rules is Being Exploited
A recent study into privacy violations on the web has been released indicating that the majority of searches for health information by third-party companies could potentially result in them obtaining Protected Health Information. The study – Privacy Implications of Health Information Seeking on the Web – was devised and conducted by Timothy Libert, a Pennsylvania doctoral student. He claims that the third parties using this method to obtain data included data brokerages and online advertising companies. The problem is widespread with 91% of health-related websites initiating HTTP requests to third parties and these requests, in 70% of cases, contained information that included symptoms and treatments of diseases. The data that is recorded on consumers is extensive, and the study cites Facebook, Google and ComScore which were found to have collected data on approximately a third of users, with Google topping the table having collected data on 78% of its users. The problem with this invasion of privacy is the information could potentially be used to discriminate against...
Dallas Hospital Sued by Ebola Nurse for HIPAA Privacy Violation
The Ebola epidemic raised questions about the privacy of individuals and when information about illnesses can be disclosed. There was considerable confusion about when Protected Health Information can be disclosed in emergency situations “for the public good.” In the case of an outbreak of a highly infectious – and potentially fatal – disease, disclosing information about the victims is a necessity if the disease is to be controlled. The release of information about the victims makes it easier to determine who that person may have come into contact with and is important to stop the spread of the disease. However, in some HIPAA violation cases, the disclosure of information has potential to lead to discrimination. Public knowledge of medical information about an individual can cause mental anguish as well as the victim to suffer financially. The most recent example comes from a nurse who served in a Dallas Hospital operated by the Texas Health Resources during the outbreak. Nina Pham, a 26-year old nurse, worked at the Texas Health Presbyterian Hospital Dallas and helped to treat a...



