Central Texas Clinic Notifies 8,700 of HIPAA Breach
A central Texas clinic, Lone Star Circle of Care of Georgetown, has learned that a backup file containing the personal information of 8,700 individuals has been available through the community health center’s website for a period of six months, during which time it was accessed on a number of occasions by unknown individuals. The file was created on 31st July 2014; however the data breach was not discovered until 9th January 2015. The breach has been attributed to the actions of an individual employed by a company tasked with designing, maintaining and securing the website. That person had accidentally generated a backup file which was subsequently placed in an unsecured folder accessible to the public via the Lone Star website. No direct link to the file was posted online, although the file was accessible through the website search facility and could be downloaded in full by anyone able to locate it. The file was not secured with a username or password and at this stage is not clear how many individuals were able to download the data. LSCC has confirmed that no medical information...
Wearable Devices Carry High Risk of Causing HIPAA Violations
Advances in technology have allowed wearable devices to be developed to monitor health and fitness, and while these gadgets, monitors and sensors have potential to greatly improve healthcare, they also carry a high risk of a causing a HIPAA violation. Over the past 12 months the number of devices in use has grown at a tremendous rate. In 2013 the market for wearable devices was estimated to be worth $1.4 billion and by 2024, sales of wearable devices are expected to generate $70 billion per year. High Risk of Data Exposure Wearable devices include fitness bands, such as those developed by Fitbit, which record detailed data during exercise and everyday living. In 2011, users of the devices discovered just how much personal information was saved, stored and unfortunately for many, also shared with the online community. Some discovered their exercise data had been indexed by Google and was publicly available. Not only was data from jogging, cycling and running sessions recorded, but also much more personal information including other forms of “exercise”. This included kissing,...
2015 Healthcare Cybersecurity Threats
The healthcare industry is facing an elevated threat of attacks by hackers and healthcare providers and insurers are being targeted for the data they hold on patients and plan members. The threat does not only come from cyberspace, as thieves are on the hunt for the laptops and mobile devices of healthcare professionals for the information they contain. Personal information and healthcare data carries a high value on the black market, and Social Security numbers, personal identifiers, ePHI and Medicare details are impossible for criminals to resist, especially when the databases storing that information contains tens of millions of individuals records and has substandard protections. Healthcare Data Privacy and Security Threats Healthcare organizations must fight a battle against cybercriminals on many fronts. HIPAA-covered entities must shore up defenses and thoroughly assess their organization for weaknesses, before implementing a plan to manage any potential security risks that are identified. Multi-level security systems must then be installed to ensure data is properly...
Analysts Suggest Link Between CHS and Anthem HIPAA Breaches
Anthem has started an investigation into the data breach which exposed the personal data of up to 80 million Americans and is attempting to determine how hackers gained access to its systems. The insurer has announced that the first attempt possibly dates back to 10th December, 2014; however some analysts believe the attackers may have first gained hold of the computer systems some nine months previously, with the system potentially having been compromised in April 2014. The report, published in Forbes, suggests that the “Cybercriminal infrastructure likely used to siphon 80 million Social Security numbers and other sensitive data” bears similarities to the techniques used by a known state-sponsored Chinese hacking group. The group, which operates under names such as Deep Panda, Group 72, and Axiom was responsible for a number of hacks on US companies. The breach has also been linked by some experts to the Heartbleed Bug, which first emerged in 2011. The fix for the bug was issued in April last year, yet in spite of the danger, many millions of websites have yet to have had the fix...
Should HIPAA be Expanded to Improve Defenses Against Hackers?
The recent massive data breach at Anthem Inc., has caused HIPAA Privacy and Security Rules to come under the spotlight, with many asking if the legislation – in its current format – goes far enough to protect the privacy of patients and health plan members. The Anthem breach could potentially have been avoided had the insurer used full data encryption along with the appropriate security controls to keep the security keys private. HIPAA Rules could certainly be tightened to improve data security, but that is no guarantee that healthcare organizations would comply promptly and implement those additional controls. HIPAA does not currently specify that an organization must use data encryption, only that the issue should be addressed. Data encryption is therefore voluntary and according to a Forrester Research report released in September 2014, only 59% of healthcare organizations had implemented full-disk encryption or partial encryption of healthcare data. Before covering the question of whether legislation needs to be tightened, here is a refresher of what legislation has been...



