Indiana Court Upholds $1.44M HIPAA Privacy Breach Award
Walgreen Co. has lost an appeal against the $1.44 million award for damages it was ordered to pay after a HIPAA Privacy Rule breach resulted in confidential patient PHI being shared with unauthorized individuals. This is the first time that the action of an employee has resulted in a healthcare provider being held liable for a violation of the Health Insurance Portability and Accountability Act. The Indiana appellate court decision could well set a legal precedent in cases where employees have violated HIPAA regulations and sensitive patient data has been shared with third parties. Walgreen Co. v. Abigail E. Hinchy In July 2013, a Marion Superior Court jury awarded $1.44M in damages to Abigail Hinchy after a Walgreen pharmacist shared PHI with a third party about a client who had dated her husband. A pharmacist at Walgreens at 6269 W. 38th St. in Indianapolis improperly accessed Hinchy’s prescription history. Hinchy had once dated her husband and had his child and the pharmacist knowingly accessed her prescription history and personal information and divulged that information. The...
Importance of Encryption for HIPAA Compliant Organizations
Recent cyberattacks on big corporations have demonstrated that no company is safe from cybercriminals. Individuals and groups of hackers will take advantage of easy targets, and even well known companies with considerable resources to allocate to cybersecurity have suffered highly damaging attacks. The security breach at Target in November 2013 cost the company the sum of $148 million. Investment in data encryption and other cybersecurity measures can therefore be considered money exceptionally well spent. Private and confidential data must be kept secure and one of the easiest methods to use is data encryption. Encrypted data is scrambled and indecipherable to unauthorized users. The theft of a device containing an encrypted database means loss of equipment not loss of data and the fines and lawsuits which that entails. Data Encryption Options It is possible to encrypt data stored on servers, hard drives, PCs and other devices but also of vital importance to secure data in transit between devices and over the internet to prevent interception. Encryption can be used for...
Congress Asked by Mobile Health App Industry to Amend HIPAA
Software companies and mobile phone application developers are concerned about HIPAA regulations and many believe the legislation is hampering innovation. The industry accepts the need for strict controls to ensure data is recorded, stored and transmitted securely, but that there is some way to go to strike a good balance between data security and product development. The App Association represents mobile phone app developers, with the organization communicating its concerns this month in a letter to congress. The letter was sent to U.S. Representative Thomas Marino (R-PA) who has already made an effort to help remove some of the barriers faced by the mHealth industry and mobile App developers. The mobile phone app industry is reportedly worth an estimated $68 billion and the App Association represents some 5000 members. It has voiced concern about key areas which require federal government intervention and has requested that regulations be updated to allow mobile health apps to be developed and for growth to be promoted in the sector. Several innovative applications have been...
Highmark Subsidiary Visionworks Hit by 75K HIPAA Breach
The Pennsylvania-based health Insurance company, Highmark Inc., has announced today that one of its subsidiaries, Visionworks, has lost a computer server containing the medical records of approximately 75,000 patients. The medical data stored on the server included details of patients’ visits to Visionworks optometrists, their lens prescriptions and names and addresses. The HIPAA breach is understood to have potentially exposed the data of patients who had previously visited its Jennifer Square, Annapolis, MD store. No patients of its other 650 nationwide vision care centers are believed to have been affected. All affected individuals are in the process of being notified of the data breach by post in accordance with the breach notification rules laid down in the Health Insurance Portability and Accountability Act and are being offered a year of free credit monitoring services through Equifax. The breach letter informs patients that the incident exposing patient data was actually part of the company´s efforts to improve privacy and security. A server was scheduled to be replaced as...
OCR Issues Guidance on HIPAA in Emergencies
The outbreak of Ebola has raised numerous issues of personal privacy and the information that should be disclosed in situations when there is a public health concern. Under HIPAA regulations, protected health information such as the diagnosis of a disease should remain private, and the disclosure of this information with the name of the patient can be a potential HIPAA violation. The issue of sharing private information in an emergency situation is not addressed in the HIPAA privacy rule, although the Privacy Rule does cover what information can be shared. In cases where the sharing of patient information can aid the treatment of the patient or other patients, medical information can be disclosed without authorization. The OCR explained that “Treatment includes the coordination or management of healthcare and related services by one or more healthcare providers and others, consultation between providers, and the referral of patients for treatment.” If an entity is covered by HIPAA it is permitted to submit medical information about a patient to public health authorities in cases...



