Class Action Lawsuit Filed Against Anthem with Evidence of Harm
Three insurance agencies have been accused of failing to secure HIPAA-covered data and have been cited in a class action claim as a result of the Anthem data breach in February. Now the lawsuit has allegedly attracted three new plaintiffs, each of who claim to have suffered identity theft as a result of the security breach. There have been a slew of lawsuits filed in recent months since the Connecticut Supreme Court ruling that individuals can sue for data breaches that exposed their PHI. However many of these class action claims against insurance companies and healthcare providers have been thrown out by judges as plaintiffs have been unable to substantiate the claims for damages with evidence of actual loss or harm suffered. The Missouri class action against the insurers was filed in February in St. Louis County by one female breach victim; shortly after the data breach was announced. Each of the three new plaintiffs that have been signed up for the suit alleges that they suffered actual losses as a result of the breach. In December and January each of the three plaintiffs had...
HIMSS 2015: HIPAA Security: A Decade of Breaches
Cybersecurity is a hot topic the Healthcare Information and Management Systems Society conference (HIMSS 2015) in Chicago this week. There are a number of scheduled presentations relating to data security and the Health Insurance Portability Act (HIPAA), which are aimed at compliance officers and IT professionals who are trying to navigate HIPAA regulations and get their organizations fully compliant. On Monday 13, Marion Jenkins, Ph.D., FHIMSS, Chief Strategy Officer at 3t Systems, took a session entitled HIPAA Security: A Decade of Breaches in which he explained the current landscape and how the HIPAA Security Rule has changed over the past 10 years as well as covered entities (CEs) attitudes to the legislation. In the presentations, Jenkins presented some examples of the real causes behind the data breaches and suggested a number of easy – and not-so-easy – remedies that healthcare providers and other CEs can implement to reduce the risk of them being affected. Jenkins pointed out that in the past 6 years, there have been 1,189 reported breaches of HIPAA-classified data –...
Health IT Privacy and Security Guide Released by ONC
The government, via the Office of the National Coordinator for Health IT (ONC), has issued a new set of guidelines on Privacy and Security of Protected Health Information. The update to the guidance was made in the most part to facilitate the interoperable exchange of healthcare data but also to improve cybersecurity defenses and the understanding of HIPAA Rules, in addition to outlining the core objectives of Stage 2 of the Meaningful Use program. The guidelines set out to explain why PHI must be protected and convey that HIPAA compliance is a responsibility that is shared between everyone employed in the healthcare industry. Advice is provided on how compliance can be achieved under the Health Insurance Portability and Accountability Act and best practices are outlined that should be adopted by Medicare Eligible Professionals (EPs) and HIPAA –covered entities (CEs). The guidelines were last updated in 2011 so an update has been long overdue, especially in light of the 2014 EHR Certification Rule which, like the HIPAA Privacy Rule, allows patients the opportunity to access their...
Denton County Health Dept Reports HIPAA Data Breach
On February 13, 2015, an employee of the Denton County Health Department inadvertently violated the Health Insurance Portability and Accountability Act (HIPAA) when a USB drive was left at a printers shop. The drive contained a personal document that the employee wanted the shop staff to print. The drive also contained the unencrypted Personal Health Information (PHI) of 874 patients who had received medical services through Health Department’s tuberculosis (TB) clinic. The data included the names of patients along with their TB test results; addresses; dates of birth and other PHI. No Social Security numbers were stored on the drive, nor any financial information. Since Personal Identifiers and Health Information have potentially been exposed and the incident involved more than 500 patient records, Denton County Health Department is obliged to report the data breach to the Department of Health and Human Services’ Office for Civil Rights (OCR). The HIPAA Breach Notification Rule also requires Notification Letters to be sent to all affected individuals within 60 days of the...
Criticism of ONC’s EHR Interoperability Plan Builds
The Office of the National Coordinator for Health IT proposed an Interoperability Roadmap in January this year, to help the healthcare industry achieve the benefits that should come from moving over to electronic health record (EHR) systems. The ultimate aim of the plan is to create an environment where medical professionals can share data on patients and access medical information quickly and easily, which in turn should have an important impact on patient outcomes. After the issuing of the first draft, the ONC invited healthcare providers and other holders of healthcare data to read the roadmap and send in comments. That comment period ended on April 3, and many healthcare organizations took the opportunity to help the ONC achieve its goal. Criticism has been constructive and a number of concerns have been raised. Timescale for Critical Actions The Interoperability Roadmap calls for a number of actions to be taken by both stakeholders of healthcare organizations as well as industry regulators. These measures are critical to the overall success of the Interoperability Plan and are...



