Current Risk of Fraud from 2012 Philadelphia Ambulance HIPAA Breach
This week the Philadelphia Fire Department reported a data breach involving 750 individuals who had used the ambulance service in 2012. Three years ago an employee of Intermedix, the company it used to handle the Fire Department’s data needs, had been given access to records; however one employee used his data access privileges to steal financial data of patients. The data was stolen in order to file fraudulent tax returns according to an investigation launched soon after the discovery of the breach. The employee responsible is now in prison, and at the time it was deemed that the information had not been sold on or used inappropriately. However, earlier this year, law enforcement officers in Florida found a sheet of data in the possession of an individual which contained billing records of patients who had used the Philadelphia Ambulance Service. Upon investigation it was discovered that approximately 750 patients had their financial information exposed and potentially sold on. The persons affected were those who had used the service on April 1 or April 2, 2012. The Fire...
HIPAA Breach Report: January 2015
January 2015 HIPAA Breach Summary: The HIPAA Breach Notification Rule demands that Healthcare providers, health plans healthcare clearinghouses and Business Associates report data breaches involving more than 500 individuals to the Office for Civil Rights of the HHS within sixty days of the discovery of the breach. A summary of the HIPAA breaches reported to the OCR for the month of January, 2015 is detailed below: Major HIPAA Breaches in January 2015 Following the relatively quiet month of December when few HIPAA breathes were reported, data theft increased in January with 17 separate incidents being reported to the Office for Civil Rights via its breach reporting portal. The Tennessee Rural Health Improvement Association (TN) Health Plan recorded a major HIPAA breach in which 79,000 of its plan member records were potentially accessed and disclosed to unauthorized individuals. Aspire Indiana, Inc. (IN) reported the theft of a number of laptop computers which contained the Social Security numbers and personal identifiers of 43,890 of its employees and clients; although no...
Major Focus on Cybersecurity at HIMSS15
The HIMSS Annual Conference & Exhibition is a firm fixture in many healthcare IT professionals’ yearly work calendars. The conference showcases the latest healthcare technologies and highlights current trends in the industry, while keynote speakers share solutions in health IT. The move to EHRs has elevated risk of cybercrime and the massive data breaches to hit all industries over the past 12 months clearly demonstrate that the threat from hackers is a very real. Furthermore cybercriminals are targeting healthcare providers and health plans in search of the Protected Health Information (PHI) they hold. In February and March of this year, two massive hacking incidents were reported by health insurers which resulted in 89,800,000 confidential records being obtained by cyber criminals. 11 million of those records were reported to have contained sensitive PHI. This year, HIMSS has a strong cybersecurity focus to help the industry take proactive steps to improve defenses against hackers. There will be a new Cybersecurity Command Center at this year’s conference, which will allow...
Hattiesburg Clinic Notifies Patients of HIPAA Privacy Breach
The Hattiesburg Clinic, a physician-owned multi-specialty practice based in South Mississippi, has alerted its patients to an invasion of their privacy after an optometry provider used the clinic’s database to send out a mailing to patients advising them of his new employer. The breach was discovered by a patient who alerted 7WDAM about the potential HIPAA breach. Staff at 7WDAM contacted the clinic to advise them of the potential privacy breach, and an investigation into the incident was launched. The clinic sent Breach Notification letters to patients on March 20, 2015, alerting them to a potential breach of their privacy. The notification letter told patients that the clinic became aware of the breach on January 23, 2015. The clinic discovered that former optometrist, Dr. Scott Paladichuk, had accessed the clinic’s patient database on a number of occasions and had viewed and copied a number of records of patients, many of whom he had no treatment relationship with. The investigation determined that the records were accessed over a period of two weeks between December 11 and...
March Sees Massive Hike in Healthcare Data Hacking
The number of successful cyber attacks spiked in March, with 11 incidents reported to the Office for Civil Rights, although since HIPAA-covered entities have up to 60 days from the discovery of a data breach until a breach notification must be submitted, that figure may yet rise. In February, there was one reported hacking incident involving HIPAA-covered data, and just 2 reported in January. Last month, 11-milliion health plan records were exposed in the huge data breach at Premera Blue Cross; an incident potentially much more serious than the Anthem breach the month before due to the extent of data acquired by thieves. The Premera hack allo9wed the perpetrators to copy Social Security numbers, personal identifiers and healthcare data. There were also a number of other large scale breaches reported to the OCR in March. The Virginia Department of Medical Assistance Services (VA-DMAS) reported a network server hacking incident in which 697,586 plan member records were exposed and 151,626 records were compromised at Advantage Consolidated. Over 90,000 records were exposed in separate...



