Amedisys Hospice to be Investigated for Potential HIPAA Violation
The discovery of documents containing the Protected Health Information of 17 patients of Amedisys Hospice, Tennessee has triggered an investigation over the potential HIPAA violation. Earlier this week, Sandra Rambo was walking with her daughter when she came across paperwork on the side of the highway. The pair noticed that the records contained information on patients, one of whom was the deceased husband of one of her neighbors. The information contained in the paper documents included private patient details such as identification numbers, medical conditions, information about previous hospice visits as well as personal details of patients who had visited the hospice according to a report on local radio station, WHHL. Rachel Seeger, Spokesperson for the US Department of Health and Human Services explained that in cases such as this, the DHHS works with the healthcare provider to resolve HIPAA violations and enters into a resolution agreement to ensure that the entity in question implements an action plan. That action plan must correct any privacy and security issues affecting...
Laptop Theft Causes HIPAA Breach Exposing Patient Data in Oregon
A new HIPAA breach has been announced affecting patients of an Oregon healthcare facility although the number of patients to be affected is currently unknown. The incident occurred in November when an employee of the Corvallis Clinic left a laptop computer in a vehicle while attending a work conference. The laptop was subsequently stolen from the car. The laptop contained unencrypted data of patients who had visited the clinic during the past two years, although the information was in a spreadsheet and the data it contained was limited and included patient names, dates of birth, name of the healthcare provider and the reason for the visit. The spreadsheet is not believed to have contained any Social Security numbers, driver’s license numbers or credit card details. There is no indication that the thieves have been able to access the data contained in the spreadsheet. The Clinic advised patients that the laptop was protected with a “highly secure” alpha numeric pass code and that it is improbable that the thieves would have been able to access the data. A notice has been posted on...
Highlands-Cashiers Hospital Reassures 25K Patients After Possible HIPAA Breach
Highlands-Cashiers Hospital of Macon County, North Carolina, has informed 25,000 patients of a security vulnerability that left the PHI of some of its patients unprotected for a period of four months, between May and September, 2014. The healthcare provider employed a business associate, TruBridge, to handle some of its healthcare information however the company made a configuration error which potentially exposed the health records of approximately 25,000 individuals. The vulnerability was discovered during routine security screening procedures on Sept 29. HCH identified information such as patient names, addresses, dates of birth, Social Security numbers, health insurance details, diagnoses and treatments were all potentially accessible and were not protected by the company’s firewall. Immediate action was taken and new firewalls were installed to correct the issue and the data has now been made secure and there is believed to be no further risk of exposure. The hospital hired a forensic investigation company to assess the extent of the data breach and the investigation found no...
5 Actions to Take to Secure Healthcare IT Systems and Prevent HIPAA Breaches
The publishing of data from the 2013 Survey on Medical Identity Theft by the Ponemon Institute has highlighted the prevalence of medical identity fraud and has shown the crime is becoming much more commonplace. Over the course of past 12 months the number of reported cases of medical identity fraud has risen by 20%. There are now believed to be over 1.84 million Americans now affected by medical identity fraud. The cost is colossal and is a huge drain on the economy, while the victims have had to cover over $12.3 billion in out of pocket expenses. Many of the victims have had their medical records exposed in data breaches at healthcare organizations. If data breaches result from violations of HIPAA regulations, healthcare organizations can be held accountable. The HHS Office for Civil Rights is issuing substantial fines for non-compliance and class action lawyers are keen to sign up victims of data breaches to claim damages. Even in cases where PHI has been accidentally exposed or been deliberately hacked, healthcare organizations can still face hefty fines. In extreme cases it is...
Long Island Radiologist Arrested over HIPAA Violation
The arrest of a Long Island radiologist on Dec 3, 2014 has prompted Nassau County District Attorney, Kathleen Rice, to call for changes to the state legislation to bring in stiffer penalties for doctors and healthcare professionals who abuse their positions and steal confidential data from their employers. Currently state laws do not permit criminal charges to be brought against individuals who are found to have obtained personal identification information relating to patients, in fact the current NY statutes do not even make it a crime to steal or maliciously disclose patient health information. Due to this loophole, Richard Kessler, M.D., will only be facing three misdemeanor charges for stealing the records of 97,000 patients from the Long Island medical practice where he worked. Current legislation allows him to be charged for petty larceny, unauthorized use of a computer and unlawful duplication of computer related material; charges which carry a maximum penalty of 1 year in prison if he is convicted. The theft of Protected Health Information (PHI) is covered under federal...



