Denver Medical Center Reports HIPAA Privacy Violation
The Medical Center of Aurora, Colo, has suffered a potential HIPAA violation that exposed the data of 20 of its patients, according to a recent Fox31 Denver news report. The incident involved paper records which were provided to a patient by mistake. Karen Billings was leaving the hospital after having received treatment, and in her discharge file was the paperwork of 20 other patients. She told reporters “I was shocked. I was mad. I was hurt that I had somebody else’s information,” The accidental disclosure of Protected Health Information (PHI) occurred on Nov 22, 2015; and since Billings was in the hospital at the time, the matter was swiftly dealt with. Or so it would seem. A nurse took the file from Billings and removed the sheets corresponding to other patients and handed back the file to Billings, who returned home. When she got back and checked her paperwork she found that she still had seven pages of medical information relating to 20 other patients. The data included in the paperwork included the name of the patient, their data of birth, the name of the procedure that was...
Patch and Update Computer Software or Face a HIPAA Sanction
In order to comply with Health Insurance Portability and Accountability Act regulations it is essential that all healthcare and health plan providers use appropriate safeguards to keep the personal and medical information of employees and patients private. There are many potential security risks when maintaining a database of patient medical records, whether the data is stored on in-house servers, managed by external contractors or hosted in the cloud. The only way it is possible to be certain that all vulnerabilities are identified is to conduct a comprehensive risk assessment of all IT systems, including any hardware and software that touches the PHI. Software quickly becomes outdated and needs to be regularly updated to maintain its functionality. As software engineers discover vulnerabilities, patches are developed and made available for download. It is essential that these patches and software updates are run on all terminals and mobiles running on the software to ensure the systems and data are unwittingly exposed to attack. Applying software patches is as important as...
Health Insurance Firms Focused on Big Data and Wearables
There has a lot of hype surrounding wearable technology in recent months and over the past two years the industry has seen an incredible amount of investment in new technology as big brands and startups develop new ways to monitor, track and record body metrics and health information. Many new Smartwatches have been released this year with 2015 expected to see the market flooded with new wearable devices. Smartwatches may not yet have become mainstream products, but surveys show the public is ready to embrace new fitness and health tracking devices. There has also been considerable interest in the devices from insurance companies, with some experts believing wearables could cause a massive shake up in the industry and change how insurance premiums are calculated and sold to customers. If insurance companies want to sell more policies, reducing premiums can certainly win more business. If customers are unlikely to ever make a claim there is no reason why they should not be rewarded with lower premiums. High risk clients naturally should pay more to cover their higher risk level. The...
Children’s Hospital Settles HIPAA Violations with Mass. Attorney General
Only a month has passed since Boston’s Beth Israel Deaconess Medical Center reached a settlement with the Massachusetts Attorney General for HIPAA violations after a laptop was stolen containing unencrypted PHI. Now Boston Children’s Hospital joins the list of Boston healthcare organizations to be fined for failing to safeguard electronic patient health records. Under the Security Rule, all entities covered by HIPAA must ensure appropriate controls are put in place to protect ePHI. Attorney Generals are permitted to take action against HIPAA covered entities within their jurisdictions following changes to HIPAA regulations, and the Mass. Attorney General’s office is vigorously pursuing healthcare providers that violate data privacy and security laws. In contrast to the Beth Israel data breach, the information exposed in the BCH breach was contained in an email attachment. Because the data was not stored on the hard drive the hospital was unable to determine whether it was actually accessible through the laptop. The physician in question believed he had taken the appropriate steps...
Countdown to the HIPAA Compliance Audits
The countdown to the HIPAA compliance audits has begun. The HHS’ Office for Civil Rights has now implemented its new breach reporting portal which means the planning of the second round of the audits can begin in earnest. The long-awaited compliance audits look set to take place in 2015 and all covered entities need to be prepared. Background to the HIPAA Compliance Audits The Department of Health and Human Services gave its Office for Civil Rights the role of enforcing the Health Insurance Portability and Accountability Act, with the Enforcement Rule giving the legislation teeth in 2006. Organizations failing to comply with HIPAA Rules have since faced financial consequences if privacy and data security policies are not introduced to the standards demanded by the legislation. Part of the OCR’s role in enforcing HIPAA regulations is to conduct compliance audits. These were conducted between 2011 and 2012 and 115 organizations were audited. The Omnibus Rule and Business Associates The introduction of the HIPAA Omnibus Rule extended the coverage of HIPAA to include Business...



