HIPAA Audits May Give False Sense of Security
The news that Premera Blue Cross was audited just three weeks before hackers were able to infiltrate its computer systems has raised a number of questions regarding the effectiveness of HIPAA compliance audits. The U.S. Office of Personal Management performed an audit of the health insurer and identified a number of security vulnerabilities that it advised Premera to address, in particular the failure to install patches and software updates in a timely manner and the importance of developing a baseline configuration that would allow full audits of the insurer’s servers and databases to be conducted. It took the OPM six months to release its final report on the audit, during which time hackers were accessing and copying the PHI of Premera’s members. After the report was released, it took a further 2 months before the insurer was able to identify the HIPAA breach and shut down access, although that was too late to prevent the PHI of 11 million members from being obtained by the thieves. These issues, along with a handful of other observations, were not considered to be serious enough...
Cloud Security Adoption: Healthcare and Pharmaceutical Lead the Way
When it comes to Cloud Security adoption, the healthcare and pharmaceutical industries lead the way according to a recent survey by CipherCloud, an industry leading provider of secure cloud services. Both industries are required to implement safeguards – under the Health Insurance Portability and Accountability Act (HIPAA) – to ensure that Protected Health Information is kept private and confidential, which according to the report is the reason why cloud security adoption is so important and uptake has been so high in these industries. Healthcare and pharmaceuticals have been grouped together in the report, and account for 38% of companies which have chosen to store data securely in the cloud. The banking and finance industry is second, accounting for 25% of companies, with telecommunications third (16%) and the Government in fourth spot (9%). HIPAA does not demand that PHI is encrypted while at rest, although data encryption is an addressable area. If covered-organizations decide not to encrypt data, they must document the reasons why, along with the alternative safeguards...
5 Class-Action Lawsuits Filed Against Premera for HIPAA Breach
Following any healthcare data breach there are likely to be numerous lawsuits filed by victims seeking damages for having their data exposed to criminals and Premera Blue Cross, which reported an 11M-patient HIPAA data breach earlier this month, has now had 5 class-action filed against it in the past few days. The lawsuits argue that the insurer should be held financially responsible for the incident and must award damages and restitution, in addition to taking action to prevent future breaches and notifying all affected about the specific data that was compromised in the breach. Class Action Lawsuits Resulting from HIPAA Data Breaches It is almost a certainty that litigation will follow a data breach, although it is rare for class-action lawsuits to succeed. In order to successfully claim damages, there must be evidence of loss or damage caused as a result of the data breach. A victim may be placed at an increased risk of suffering medical or identity fraud, but it is unlikely that any damages will be awarded unless that individual can show that their identity has been stolen or...
Anthem 78.8 Million Breach Notification Letter Mailing Almost Finished
According to a recent statement issued by Anthem spokeswoman, Sarah Yeager, the insurer expects to have completed the arduous task of mailing 78.8 million past and present policyholders – and other individuals – to advise them that their data has been compromised and obtained by hackers. Under the Health Insurance Portability and Accountability Act – specifically the Breach Notification Rule – all covered entities (CEs) are required to send notification letters to all individuals affected by a data breach and to complete the process no later than 60 days following the discovery of the breach. It would appear that Anthem needed all of that time to complete such a monumental task. In spite of the scale of the attack, only 937,478 individuals have so far signed up for the credit monitoring services offered by the insurer through AllClear ID. That figure is almost certain to rise considerably over the coming weeks as all the letters are finally sent. According to an article in Hartford Courant, in spite of the scale of the attack and the number of individuals affected, the...
Investigations Mount into LifeWise HIPAA Breach
The LifeWise Health Plan of Oregon is being investigated by Washington State and Alaska in the wake of the huge HIPAA breach to affect its parent organization, Premera Blue Cross. Now the state of Oregon has decided to conduct an investigation into the breach after it was determined that approximately 250,000 state residents had been affected. The attack on Premera Blue Health and LifeWise Health Plan – which shared the same IT infrastructure for claims – first occurred in May 2014. Data going back to 2012 was potentially obtained by the thieves. However there was no evidence of data being copied leading experts to believe the attack was highly sophisticated in nature and that data access was somehow masked. The volume of data potentially exposed – and its detailed nature – make this hacking incident the largest ever reported and the most serious and by some distance. Last year 4.5 million records were exposed in a hacking incident at Community Health Systems and the Tricare data breach in 2009 exposed 4.9 million records. In total, 11 million records were exposed in the...



