Malware Responsible for Reeve-Woods Eye Center HIPAA Breach
The Reeve-Woods Eye Center – an eye treatment clinic consisting of two centers in Chico, CA, and Paradise, CA – discovered on Wednesday, September 17, 2014, that malware had been installed on two of its computers. The malware was discovered by an IT consultant used by the clinic who established that the malware was taking screenshots of the computers; essentially making a digital photocopy of the data being viewed on the screen. As patient files were accessed, a snapshot was taken. This means that a wide range of data could potentially have been obtained by criminals responsible for the malicious software. The persons affected are those who have visited the center for treatment or otherwise have had their files accessed on either of the two computers on which the malware had been installed. The data potentially exposed includes names, addresses, contact telephone numbers, Social Security numbers, dates of birth, dates of service, medical insurance details, diagnosis and treatment codes, medical histories, Medi-Cal IDs and Medicare ID numbers, as well as any other data stored...
HIPAA Breach Report: September 2014
September 2014 HIPAA Breach Summary: The HIPAA Breach Notification Rule requires covered entities to report all data breaches involving HIPAA-covered data to the Department of Health and Human Services’ Office for Civil Rights. Breach reports must be submitted via its website portal, and CEs have 60 days from the discovery of the breach in order to do this. This report contains a summary of the breaches reported to the OCR during the month of September, 2014. Major HIPAA Breaches in September 2014 Large scale data breaches continue to plague the healthcare industry. Last month saw well over 4 million records exposed in hacking incidents, laptop thefts, improper access, disclosure and disposal or records. This month, while there were fewer incidents reported, most of which involved a few thousand records, Xerox State Healthcare, LLC (TX) reported a massive data breach in which approximately 2 million records were exposed. The incident was atypical for a HIPAA breach. Rather than records being exposed by hackers or the theft of computer equipment, this breach was caused following the...
Watch out for Wearables if you Want to Avoid a HIPAA Violation
Wearable devices are rising in popularity and now Google Glass has been made available to all in the USA and UK, Apple is launching a Smartwatch and other big influential brands are heavily investing in wearables, the next few years could see the devices become the norm and used throughout the healthcare industry. Currently more than 25% of adults in the United States own a fitness tracker or use a Smartphone fitness tracking application and a considerable amount of personal health data is being now recorded. A recent survey conducted by Juniper Research has predicted that the wearables market will grow ten-fold over the next 4-5 years and over 180 million devices will have been sold by 2018. Google Glass is stealing the headlines; however Apps and fitness bands are the most popular method of tracking health and wellness at the present time. The data recorded could revolutionize healthcare allowing preventative steps to be taken to help patients avoid illness and injury. Smart glasses such as Google Glass may not prove so popular for consumers, but the benefits to business are...
Sony Pictures Confirms Breach Potentially Exposed HIPAA Data
Sony Pictures has made an announcement confirming the protected health information of some employees could have been exposed in this month’s security breach. Employees were sent a breach notification letter earlier this week containing details of the data the company believes was exposed. While the written notification letters have only just been mailed, an E-mail was sent to all affected employees earlier this month alerting them to the security breach and stating that computer records had been compromised. In that E-mail Sony Pictures suggested that all affected persons sign up for credit monitoring services with AllClearID; the company being used by Sony Pictures to help mitigate any damage caused. The notification letter reiterated the need to sign up for credit monitoring services and provided additional details about the breach, including more information on the scale of the data exposure. Earlier this month some computers at Sony Pictures were hacked in what appears to be a targeted attempt to steal company and employee data. Some of the data has already been posted on...
Concern that Drug Company Use of Patient Data Circumvents HIPAA
Pharmaceutical companies are using patient PHI to market their products, even though they are not permitted to have access to this information under HIPAA regulations, according to a recent report on Bloomsberg News. HIPAA covered entities are not permitted to disclose patient information to third parties for the purposes of marketing, yet pharmaceutical companies are obtaining the data from a different source. Drug companies are now seeking assistance from online data agencies that can provide them with the data they require to directly market products to the persons most likely to use their drugs. Marketing data is invaluable to drug companies as it enables them to market their products more effectively. The market for a particular treatment may be very small in terms of penetration so using traditional advertising methods is unlikely to produce the required number of sales. However, if a drug company obtained a list of patients who had been diagnosed with a condition that their drug treats, the volume of sales from its direct marketing efforts would increase substantially....



