2013 USPS Security Breach Exposed the Health Information of 485K Employees
The hacking of the United States Postal Office computer Network in September 2013 exposed the personal information of approximately 800,000 employees and included a database of 2.9 million customer complaints containing some personal information. The security breach was discovered on September, 11, 2013 when the Department of Homeland Security informed the USPS that its servers were sending unauthorized communications outside of the network, indicating its computer network had been compromised. An investigation was immediately launched which revealed 29 servers had been compromised and a large volume of data had been copied from the servers, including HR files containing the financial information of employees. An FBI investigation revealed the hack to be highly sophisticated in nature. The decision was taken not to close down the servers and alert the hackers, although access was finally shut off and security measures installed on Nov, 8 and 9, 2013. The public and all affected employees were advised of the breach the following day. While the breach was reported late last year,...
Fewer First Baby of the Year Announcements due to HIPAA
The first of January traditionally sees a flurry of announcements from hospitals around the country advising the public of the first babies to be born in the New Year; however 2015 has seen fewer hospitals making the announcements. Many healthcare providers have made the decision not to reveal details of newborn New Year’s babies and have extended the Health Portability and Insurance Act to include birth announcements. While the announcements may not have been made public, many have still celebrated the tradition internally, and in doing so, have mitigated any security risks that could result from the disclosure of personal information. Community Health Systems, sufferer of a major HIPAA security breach last year exposing 4.5 million patient records, operates 207 hospitals the length and breadth of the country. It is exercising extreme caution and has issued directions to its hospital administrators advising them to refrain from making public announcements of the first baby of 2015, citing security concerns. CHS Spokesperson, Tomi Galin, told the Associated Press “We know the birth...
New California Health Data Privacy Law Plugs Holes in HIPAA
The Confidential Health Information Act came into force in California on January 1st, 2015 and provides greater privacy protection for individuals who are covered by a health plan but are not the actual policy holder. Many individuals are covered by health insurance on a policy belonging to a parent or spouse; however when communications are sent out by the health plan operator, correspondence is usually addressed to the policy holder rather than the individual concerned. This could potentially result in the disclosure of Protected Health Information to the holder of the health plan policy. The new legislation amends the State’s Confidentiality of Medical Information Act and has been introduced to give individuals the right to determine to whom information is disclosed and to ensure that even non policy holders are given the right to keep their medical information private. The Health Insurance Portability and Accountability Act does cover these individuals and allows them to make a confidential information request to the provider of their health plan, although insurance companies...
Major HIPAA Data Breaches Make 2014 a Landmark Year
2014 has been a landmark year, although unfortunately for the healthcare industry, for the wrong reasons. This year has seen some of the largest recorded HIPAA data breaches ever to affect the healthcare industry, exposing the protected health data of millions of patients and costing the healthcare industry as a whole many tens of millions in fines and levies. The healthcare industry accounted for 42.3% of all data breaches recorded this year according to the Identity Theft Resource Center Report for 2014, and healthcare providers have been responsible for exposing the Protected Health Information of over 8 million Americans in 322 recorded breaches. Healthcare Industry Warned of Major Breach Risk The year had only just begun when the FBI released a stern warning to the healthcare industry that cybercriminals were likely to target the healthcare sector in the coming months, and that medical devices and hospital networks were under an elevated risk of a targeted attack. The FBI attributed the increased threat to the “mandatory transition from paper to electronic health records, lax...
Certificates of Creditable Coverage No Longer Required Under HIPAA
Certificates of Creditable Coverage were required by health plan providers and insurers under the Health Insurance Portability and Accountability Act (HIPAA); however the issuing of a final rule of the Affordable Care Act (ACA) has changed that requirement. As a result, Certificates of Creditable Coverage are no longer required for new health plans or any issued since January 1st, 2014. Continuous coverage is guaranteed by HIPAA legislation for retirees taking advantage of the Consolidated Omnibus Budget Reconciliation Act (COBRA) as well as individuals who change employment or health plan policy. To help offset a preexisting condition exclusion under a new health plan, administrators were required to issue a Certificate of Continuous Coverage 30 days prior to the end of coverage or 30 days before employment was left. From 1st January, 2014 until 31st December, 2014, health plan providers have not been able to impose pre-existing conditions exclusions on enrollees in health plans and as of 1st January 2015, Certificates of Creditable Coverage will no longer be required to be...



