HIPAA Settlement Reached for Dumpster PHI Exposure
Under Health Insurance Portability and Accountability Act (HIPAA) data privacy and security rules, Protected Health Information (PHI) must be secured at all times and when data is no longer required it must be destroyed to prevent accidental exposure. In May 2013, Midwest Women’s Healthcare Specialists disposed of a number of medical records of patients; however the files were placed in an open dumpster. While the material was destined to be destroyed, unauthorized individuals could have easily gained access to the information. The HIPAA violation would perhaps not have been identified had it not been a particularly windy day. However, the some of the paper PHI records were blown from the dumpster up the street and the medical records were dispersed over an area of several blocks. The data included in the files and notes included personal identifiable information, addresses, diagnoses, treatment details and test results. Many of the records also detailed the patient’s Social Security numbers. In total, the records of 1,532 female patients from Missouri were potentially exposed by...
Business Associates Account for 40 Percent of HIPAA Breaches
During the first quarter of 2013, 40% of all HIPAA breaches involving the exposure of PHI that affected more than 500 individuals were the result of the actions of business associates of HIPAA–covered entities. The problem appears to be growing, as over the previous four years BA’s caused 30% of all reported HIPAA security breaches. This fact has not been missed by the Department of Health and Human Services. New legislation has been introduced which makes business associates accountable for their actions – or lack of them – to maintain the security of Protected Health Information. Business associates and their subcontractors are now covered by the latest amendment to HIPAA; the Omnibus Rule. Under the new rule, the Office for Civil Rights has the power to investigate business associates for HIPAA compliance issues and BA’s are expected to be included in the upcoming HIPAA audits. If the OCR discovers HIPAA compliance issues, business associates will be held accountable regardless of whether or not there has been a data breach and fines will be issued directly by the OCR. Before...
Visionworks Reports Second Server HIPAA Breach in Less Than a Month
Visionworks has announced that it has suffered a second major security breach in less than a month, bringing the total number of patients affected over the past four weeks to 122,627 individuals. Visionworks sent breach notifications to 75,000 patients last month after a computer server was lost following a security upgrade. The missing server was believed to have been inadvertently dumped along with construction debris during the refurbishment of the Visionworks Jennifer Square, Annapolis, MD., facilities. The latest breach affects patients who had received services at its Florida store in the Mall of the Avenues, Jacksonville. The server had been upgraded; however the old server, which contained the Protected Health Information and personal details of approximately 48,000 patients, cannot be located. As with the previous server loss, the incident is being attributed to an employee who may have inadvertently dumped the server, although the breach letter did not confirm that this was definitely the case. The optical care services provider maintains the two incidents are not linked....
Xerox Reported for 2 Million Record HIPAA Breach by Texas HHSC
The dispute between Xerox and the Texas Health and Human Services Commission (THHSC) continues with the latter now having reported a 2 million-record HIPAA breach to the Department of Health and Human Services’ Office for Civil Rights for allegedly not returning PHI following the termination of the service provider’s contract. Xerox was a former Business Associate of THHSC and was contracted to provide administrative services for the Texas Medicaid program. However, THHSC took the decision in May to terminate the contract following allegations that Xerox had inappropriately given authorization for orthodontic braces to be given to thousands of Medicaid patients when the devices were not medically necessary. Three months later, once THHSC had replaced Xerox with a new Business Associate, it filed a lawsuit against Xerox claiming that the company had failed to return computer equipment and paper files after its contract was terminated. Stored on those computers and in those files was a large volume of confidential information including personal identifiers, Medicaid numbers and...
HIPAA Breach Due to Improper PHI Disposal Affects 1,778 Minn. Patients
Northfield Hospital & Clinics has recently issued a HIPAA breach notification to approximately 1,800 of its patients after their Protected Health Information (PHI) was potentially exposed to unauthorized individuals over an eight day period in October this year. The security breach only affected a small percentage of Northfield patients and no medical information is believed to have been accessed, although the matter is being treated with the utmost seriousness. The security breach occurred when a number of documents were disposed of in commercial dumpsters by mistake, rather than being destroyed as required by HIPAA data security and privacy rules. When Protected Health Information is no longer required it must be destroyed or rendered unusable, with the rules applying to paper records and all electronic data. Paper records containing PHI and other confidential information must be shredded, incinerated or rendered unreadable to ensure that patient health information is not accidentally disclosed. In the case of Northfield Hospital & Clinics, the records included some...



