Data Breach Security Bill Criticized for Lack of Privacy Safeguards
The Data Security and Breach Notification Act – commonly referred to as the Data Breach Security Bill – was announced by President Obama earlier this year at the State of the Nations address. Last week the new bill was introduced, with the Subcommittee on Commerce, Manufacturing, and Trade having held a meeting yesterday to discuss the new bill. The aim of the bill is to improve cybersecurity measures throughout the United States and introduce new standards to protect the privacy of consumers. The new legislation was deemed necessary, as while there are numerous pieces of legislation covering data privacy and security, according to Vice Chairman of the House Energy and Commerce Committee, Marsha Blackburn, and Rep. Peter Welch, the new bill will “”replace the current patchwork of laws” and introduce a single, national standard to protect the sensitive data of all consumers. According to a statement released by Blackburn, “This bill will help enhance the security of sensitive information and provide much needed clarity by creating a national standard and ensure that consumers are...
How To Strengthen Defenses Against HIPAA Data Hacking
The large scale data breaches that affected Anthem and Premera Blue Cross this year – and Community Health Systems in 2014 – are a sign of things to come. Healthcare providers, insurers, healthcare clearinghouses and healthcare business associates must face up to the fact that the game has now changed, and cyber attacks are now an inevitability, not just a possibility. Criminals have previously concentrated on obtaining credit card numbers to commit fraud, although following the major breaches of last year at Target and Home Depot; action is being taken by the retail industry to implement new safeguards and protect consumer data. As the $7 billion retail industry improves defenses, hackers are turning to other less protected industries and the healthcare sector is the prime target. Thieves are now concentrating on obtaining Social Security numbers to sell on the black market. These numbers, especially when accompanied by healthcare data and other personal identifiers, can be used to commit identity and medical fraud, allowing criminals to commit millions of dollars of identity...
Sacred Heart Health System Suffers Hacking HIPAA Breach
The Sacred Heart Health System, a regional health system serving north Florida and south Alabama, has reported that a hacker has infiltrated the e-mail account of a Business Associate and has potentially obtained the personally identifiable information and Protected Health Information of approximately 14,000 individuals. The security incident was caused when an employee of the Business Associate had their account username and password compromised in an “e-mail hacking attack”; reportedly a phishing campaign. In recent months hackers have successfully used phishing methods on a number of occasions to obtain user login details. Emails are sent to hospital employees that closely mimic those of individuals who would conceivably require login details to be provided. The users are fooled into revealing their login credentials and the hackers then use that information to access email accounts and PHI. On discovery of the breach the billing vendor immediately shut down the affected e-mail account. The breach was discovered on December 3, 2014, although it was not reported to Sacred Heart...
Advantage Dental HIPAA Breach Exposes More Than 150K Patient Records
Advantage Dental of Redmond, OR, has announced that hackers have successfully infiltrated its computer systems and have potentially accessed the records of over 151,000 of its patients, according to a report in the Portland Tribune. The Oregon-based company, which primarily provides dental services for low-income patients and operates more than 30 clinics throughout the state, discovered that hackers had gained access to its internal computer systems and patient database over a period of three days between Feb 23 and Feb 26, 2015. In accordance with HIPAA Security Rule Technical Safeguards, Advantage Dental had implemented a system that monitored access to the PHI of its patients, and that intrusion detection system identified individuals who had accessed the Protected Health Information of its patients. Access to the data was quickly shut down but the company determined that during that time, names, addresses, phone numbers, dates of birth, and Social Security numbers were accessed. No financial information, payment details, or healthcare data was exposed in the incident as this...
Up to 11M Affected By Premera Health HIPAA Breach
The healthcare industry has been hit hard by HIPAA breaches in recent months, with February’s data breach at Anthem the largest to date; however, news has just broken that another insurer, Premera Blue Cross, has also been hit by hackers, in what has been described as the largest ever breach of healthcare information. This successful hack potentially compromised the records of up to 11 million individuals. (The Anthem data breach of last month was the largest HIPAA breach ever recorded, although no health information was obtained by hackers in that incident.) The hack has been described as being highly sophisticated in nature, with the initial access to data now determined to have occurred on Mar 5, 2014. The data exposed includes personal identifiers, medical histories, and financial data, including plan member – and applicant – names, dates of birth, postal addresses, email addresses, Social Security numbers, bank account details, clinical information, and details of medical insurance claims; according to a news report from Reuters. The data that has potentially been compromised...



