HIPAA Violation Charge for ProMedica Bay Park Hospital Employee
Criminal prosecutions for HIPAA violations hospital employees are a relatively uncommon occurrence, although another case has recently resulted in legal action with a former employee of ProMedica Bay Park Hospital charged with HIPAA violations for inappropriately accessing 596 patient records. Jamie Knapp was indicted by a federal grand jury in Ohio for unlawfully viewing and obtaining protected identifiable healthcare data and for accessing of a protected computer without authorization. The penalty for these charges is a fine of up to $500,000 and a prison term up to 10 years if prosecutors determine that PHI was taken for personal gain. The inappropriate accessing of PHI is alleged to have occurred between April 1, 2013 and April 1, 2014. A police investigation was conducted last summer after the breach was discovered and Knapp was determined to be the employee responsible for the breach. The data compromised in the incident included patient names and dates of birth as well as Protected Health Information including hospital visit numbers, physician names, medications prescribed,...
American Hospital Association Advises ONC HIPAA is Sufficient
Critics of level of data security required under HIPAA legislation are calling for even greater demands to be placed on holders of Protected Health Information (PHI). Improved security and privacy controls would make it harder for cybercriminals – and other data thieves – from obtaining healthcare data. The Interoperability Roadmap of the Office of the National Coordinator is intended to help achieve nationwide secure health data exchange involving the EHR systems that have now been implemented by many healthcare organizations. The roadmap calls for changes to be made to the existing framework of rules and regulations to improve cybersecurity controls to help achieve interoperability. The American Hospital Association (AHA) disagrees. AHA Voices Opinion on the ONC Interoperability Roadmap The ONC published a draft of the Roadmap back in January and invited healthcare organizations to submit comments. It will assess the feedback it receives before releasing the final version of the Interoperability Roadmap. The ONC has received criticism from many quarters over the first draft, with...
Hacking: How Severe is the Threat to the Healthcare Industry?
Retail, financial, entertainment, healthcare. It would appear that no industry is safe from hackers. The volume of incidents reported over the past 12 months, and the sheer scale and complexity of some of the attacks indicate that the threat level is currently at critical. The healthcare industry in particular appears to be under attack. Two hacking incidents on health insurers resulted in the perpetrators obtaining 78.8 million records from Anthem and approximately 11 million records from Premera Blue Cross, the latter including healthcare data. There were numerous smaller incidents reported where hackers had gained access to PHI according to data from the Office for Civil Rights. The OCR requires all HIPAA-covered entities to report data breaches affecting more than 500-individuals within 60 days of discovery. Between March 1st 2014 and February 28th 2015, the OCR received 31 breach reports that were attributed to hacking/IT incidents. However, the data only includes hacking incidents involving data covered under HIPAA and in many cases data breaches are not noticed until...
Horizon Class Action Claim for HIPAA Breach Tossed
According to a report in the New Jersey Law Journal, a class-action claim for a HIPAA breach has been thrown out by a NJ judge. The claim was filed by four plaintiffs against New Jersey’s largest health insurer, Horizon Blue Cross Blue Shield (HBCBS). The incident that triggered the lawsuit was a breach of HIPAA data caused by the theft of two unencrypted laptop computers from the Newark office of the HBCBS back in November 2013. The breach exposed the data of approximately 840,000 of the insurer’s members in one of the largest data breaches to be reported that year. The quartet alleged that as a result of the breach they – and more than 830,000 other members – were placed at an elevated risk of suffering identity fraud because PHI had been obtained by thieves along with their Social Security numbers. There is no private right of action under HIPAA; however the Connecticut Supreme Court made the decision to allow individuals affected by data breaches to sue the organizations after data breaches, provided there is evidence of negligence. A class action lawsuit for a breach of...
How Can PHI be Shared Under HIPAA?
Under the Health Insurance Portability and Accountability Act, specifically the HIPAA Privacy Rule, Protected Health Information (PHI) cannot be shared with unauthorized individuals. Since the Omnibus Rule was introduced, covered entities (CE) are also not permitted to use PHI for marketing purposes, so how can PHI be shared under HIPAA? How Can PHI be Shared Under HIPAA? The sharing of Protected Health Information is not permitted under the Privacy Rule, so if a CE wants to share that data – for marketing purposes, research or any other reason – individual records must be de-identified. If it is not possible to identify an individual from the data, the information is not considered to be PHI. Therefore, if all personal identifiers are stripped from the data, the CE will be free to do with the data whatever they wish, as the data will no longer be considered to be PHI. Why De-identify Data? Healthcare providers may wish to conduct comparative drug effectiveness studies in order to check the effectiveness of different treatment methods on patient outcomes for example. Medical...



