Anthem Inc. Reeling After Behemoth 80M-Record HIPAA Breach
The Nation’s second largest health insurance provider, Anthem Inc, has been the target of a highly sophisticated cyberattack which has resulted in the theft of 78.8 million records, making this the largest ever data breach to affect the healthcare industry. The data breach is on a par with the Target data breaches of 2013 and 2014 which exposed a total of 110 Million confidential customer records and eclipses the Tricare Management Activity Data breach of 4.9 Million records in 2009 and the 1.9 million record breach of Health Net Inc. in 2011. The attack has reportedly exposed personal information including names, dates of birth, addresses and email addresses, along with Social Security numbers, Medical IDs, some income data and employment information, although no health data is believed to have been exposed and no credit card numbers were stored with the compromised data. Both employees and health plan members have been affected. The insurer discovered the data breach last week and notified the FBI of the attack. The agency is currently conducting an investigation, while Anthem is...
National Data Exchange Roadmap Released by ONC
The Meaningful Use program has helped encourage healthcare providers to make the move from paper files to electronic health records. Now the majority of organizations have moved to EHRs, the next step is for further policies and procedures to be developed to allow the healthcare industry to obtain the full benefits of digital record-keeping. Covered entities must continue to invest in technology to improve communication of data while also employing the appropriate safeguards to protect it from prying eyes. To help the industry achieve the main benefits of EHRs, while ensuring the data is properly protected, the Department of Health and Human Services’ Office of the National Coordinator for Health IT has been working on a roadmap. The ONC Interoperability Roadmap – A 10-Year Plan for EHRs The first draft of the roadmap has now been issued. The main aim of this new Interoperability Plan is to make it possible for physicians and other medical professionals to obtain quick access to EHRs and to be able to view and share patient data in a timely manner. Access to this information...
OCR to Clarify HIPAA Rules for Mobile Health Companies
The HHS has responded to a letter sent by Representative Peter DeFazio (D-OR) requesting clearer guidance on HIPAA Rules relating to the mobile health industry, and has confirmed that the OCR does intend to work more closely with the industry to ensure HIPAA Rules are being followed. In September last year, Representatives DeFazio and Tom Marino (R-PA) wrote to HHS Secretary, Sylvia Burwell, requesting much needed updates to HHS guidance on HIPAA. In the letter it was pointed out that the technical compliance guidelines had not been updated in the past 8 years, yet the pace of technology over the same period has been considerable, with the past 6 years having seen the market for mobile apps – including mobile health apps – grow into a $68 million industry. Burwell replied to the letter a month later in November, although her response has only just been made public. She confirmed that the HHS is aware of the rapid growth in the use of technology and that it understands there are a number of issues with HIPAA Privacy and Security Rule compliance and that the guidance it has...
FTC Calls for Greater Protection than HIPAA for Internet of Things
This week, the FTC published a new report calling for greater privacy and security controls to be implemented covering the Internet of Things (IoT). The growth of digital technology over the past few years has seen numerous new mobile devices come to market which can record and share detailed information about the owner’s health and lifestyle. Digital cameras can now take photos at the press of a button, while those images can just as easily be shared with others. Home automation systems similarly store data, while wearable devices such as fitness trackers and Smartwatches record health metrics and use GPS systems to track individuals. All of this highly detailed data is stored in the cloud, on the devices themselves, and potentially on the devices of friends, family and acquaintances. There is potential for this data to be shared with unauthorized individuals and controls must be put in place to reduce the risk of unauthorized disclosure. In an increasingly interconnected digital world, data privacy and security is of paramount importance. The FTC pointed out that six years ago...
Timeline of Important Events in the History of HIPAA
The Health Insurance Portability and Accountability Act of 1996 is widely accepted to be one of the most important pieces of healthcare legislation ever to be introduced in the United States. Next year will be the 20th Anniversary of the introduction of the act, and during that time there have been some major updates to that legislation. The legislation was originally introduced during Bill Clinton’s tenure as president, and was originally intended to improve the portability and accountability of health insurance coverage. The act promoted the use of medical savings accounts by introducing tax breaks and ensured coverage for employees with pre-existing medical conditions. It also ensured that coverage continued when individuals changed employer. Since the act was introduced, its scope has grown considerably and it has become a vehicle to encourage healthcare providers and other covered entities to make the change from paper files to electronic healthcare records, and along with that change, introduce a number of measures to ensure patient healthcare data is kept secure. When...



