CHIME Leader Says Healthcare Cybersecurity is Top Priority in 2015
Charles Christian, FCHIME, LCHIME, CHCIO, has the 2015 Trustees Chair at the College of Healthcare Information Management Executives (CHIME) and believes 2015 to be a year where positive changes will be made to improve cybersecurity in healthcare, although many challenges are faced. Just as new technology is being used – and exploited – by cybercriminals looking to gain access to the Protected Health Information of patients, healthcare providers can easily use technology to keep the data of their patients protected. The technology exists to prevent any external unauthorized third parties from gaining access to protected information and this must be used to ensure that data remains confidential and private. Evolving technologies are allowing greater protections to be placed on data, which can be effectively secured in motion and at rest. CHIME is committed to educating its members on new technology, how it can be used and implementing best practices to keep electronic Protected Health Information secure. Christian believes that positive patient identification and cybersecurity to be...
No Timetable for HIPAA Audits Provided by OCR Director
OCR Director Jocelyn Samuels has revealed the expected round of HIPAA audits are could still be some time off. In a Jan 13 media briefing the OCR Director refused to commit to a timescale for the next round of audits, which were originally expected to take place in the fall of 2014. The delay has previously been attributed to issues with the implementation of new technology to allow audit documents to be collected and processed. No reason was given for the continued delay to the audit program, other than the fact that the OCR still has plenty of work still to do before the audits program can be launched. The pilot audits first took place in 2012, with an initial 115 organizations assessed for compliance. KPMG conducted the audits and the procedures and protocols have needed to be revised to accommodate the changes made by the introduction of the Omnibus Final Rule in 2013. The delay gives healthcare organizations some more time to conduct risk assessments, review and revise business associate agreements and make sure all HIPAA regulations are being followed. Samuels confirmed that...
Safeway Fined $10 Million for Improper Disposal of Pharmacy Records and Waste
California prosecutors have reached a $9.87 million settlement with the grocery store chain Safeway for improperly disposing of pharmacy records and hazardous waste in dumpsters. The patient records contained private and confidential medical information and should have been destroyed or rendered unreadable according to California’s Confidentiality of Medical Information Act and the Health Insurance Portability and Accountability Act. Safeway had been disposing of waste and patient pharmacy records improperly for a period of over seven years according to prosecutors. The case relates to a series of waste inspections conducted by state regulators between 2012 and 2013. Inspectors checked the waste at dozens of stores operated by the grocery chain over a period of 18 months. The waste found in dumpster used by Safeway stores was destined for landfill sites. The inspections revealed that approximately 40% of the stores had violated state laws by failing to stop controlled items from being dumped along with regular waste. In a number of cases the inspectors found documents containing...
New Jersey Extends HIPAA: PHI Data Encryption Mandatory
New Jersey Governor, Chris Christie, signed a new law last week that extends the reach of HIPAA, calling for New Jersey healthcare providers to make greater efforts to keep the electronic health records of patients secure. The new law will go into effect in July this year and requires all covered entities to use data encryption software on all electronic devices that contain Protected Health Information. HIPAA does not currently require all health data to be encrypted. The legislation only states that the “encryption of healthcare data must be addressed”. The new law takes this further and mandates encryption. When the law comes into effect in the summer, all end user computer systems including laptop computers, desktop PCs, portable storage devices, tablets and Smartphones will require PHI to be encrypted. The new law states: “Health insurance carriers shall not compile or maintain computerized records that include personal information, unless that information is secured by encryption or by any other method or technology rendering the information unreadable, undecipherable,...
Error by BlueCross BlueShield of Tennessee Causes HIPAA Privacy Rule Violation
An error at BlueCross BlueShield of Tennessee (BCBST) has lead to the mailing of marketing information to 80,000 members of the TRH Health Plan, and in doing so has inadvertently violated HIPAA Privacy Rule. The healthcare provider has previously had to settle with the Office for Civil Rights for $1,500,000 for past HIPAA violations after 57 computer hard drives were stolen from its facilities; an incident which exposed the personal identifiers and ePHI of over 1 million individuals. The latest HIPAA breach came to light when a number of members of the TRH Health Plan, a not-for-profit service company of Farm Bureau, complained about receiving information from BCBST in the mail. TRH conducted an investigation and has now contacted all 80,000 members to advise them that their contact information may have been used for marketing purposes. The Tennessean was informed by a spokeswoman of BCBST that TRH members were contacted in error. “We made a mistake and included TRH members in a BlueCross Medicare Advantage mail marketing campaign,” she went on to say “The vendors have destroyed...



