Connecticut Supreme Court to Allow HIPAA Negligence Claim
A recent ruling by the Connecticut Supreme Court could potentially pave the way for a wave of lawsuits from victims of theft and fraud who have had their protected health information disclosed and have suffered losses or harm as a result. The case of Emily Byrne vs. Avery Center for Obstetrics and Gynecology, was heard by the court after a patient’s medical records were provided to a third party when explicit instructions were provided to the contrary. While this is just one individual case, legal experts are now considering how this ruling will apply to data breaches involving millions of potential victims. HIPAA violations are investigated by the Office for Civil Rights of the Department of Health and Human Services and financial penalties are issued to organizations that breach regulations. HIPAA makes no provision for the private right of action to sue for loss and damage caused by non-compliance issues or data breaches, although a small number of cases have been heard by the courts where HIPAA has been allowed as the Standard of Care in negligence claims. It was not possible...
Connecticut Court Allows Claim for a Breach of HIPAA to Proceed
The Connecticut Supreme Court has ruled that a plaintiff can proceed with a claim for a breach of HIPAA after her private health details were released without her consent. Emily Byrne brought her claim for a breach of HIPAA after advising her doctor at the Avery Center for Obstetrics and Gynecology in Westport not to provide her protected health information to the father of the child to whom she was pregnant as their relationship had broken up – Andro Mendoza. However, after Mendoza had obtained a subpoena to support a paternity suit, the health center released Emily´s protected health information without telling Emily or fighting the subpoena in court. Emily´s former partner then used the information to launch “a campaign of harm, ridicule, embarrassment and extortion”. Emily took her claim for a breach of HIPAA to the Appellate Court – claiming that the Avery Center had been negligent in releasing her protected health information to Mendoza. The court decided that HIPAA preempted the negligence suit which meant that the health center could admit to a breach of HIPAA...
Healthcare Professionals Violate HIPAA with Personal Phones
There is a worrying practice taking place in healthcare centers across the country: The use of personal mobile phones for communicating with care teams and sending patient data. The practice is a clear HIPAA violation, yet text messages, attachments and even photographs and test results are being shared over insecure networks without data encryption, albeit with individuals permitted to view the data. Even if the recipient of the message or communication is authorized to have access to that information, sending of PHI over an insecure network without the protection of a firewall is a clear security risk. If messages are sent via the hospital’s password-protected WI-Fi network this may be permitted under the HIPAA Security Rule; the sending of text messages via an AT&T network for example, is not. The Department of Health and Human Services enforces HIPAA compliance via the OCR, which is issuing financial penalties for HIPAA violations and taking a particular interest in the use of mobile technologies and communication of PHI in healthcare centers and between healthcare...
How Safe are your Medical Records?
We would like to believe that our confidential medical records are kept under digital lock and key; however this is not always the case. The safety of patient data depends on the diligence of health care organizations and the cyber-security measures they implemented. Simple oversights and errors can result in private and confidential patient medical data being made available in the public domain, as recently happened for 7,000 patients in a diagnostic clinical laboratory in Huntsville, Al. The company, Diatherix Laboratories, was forced to notify its 7,016 patients that a HIPAA breach led to their data being made available in the public domain for a period of three years, and during that time outsiders had accessed that information. The problem occurred because the patient data was stored on a third party server and which had not been made secure. The breach occurred in September of 2011, yet the issue was not noticed until July 2014. This is far from an isolated incident. A Temple University doctor’s office recently reported a laptop theft from the premises with data of 3,780...
HIPAA Health Plan Identifiers Delayed Until Further Notice
The CMS introduced the rule that a national health plan identifier must be used for transactions, yet it appears to have had second thoughts on the issue and its HPID plans have now been “delayed until further notice”. The Office of E-Health Standards and Services of the CMS previously ruled in 2012 that it would require health plans to have a numerical identifier, while other covered entities would also be required to use them and would be covered in future mandates. The Health Insurance Portability and Accountability Act of 1996 uses HPIDs along with other identifiers to simplify administration. HIPAA provider IDs were first introduced in 2007, although plans for the introduction of a national patient identifier have been on hold since 2000 due to privacy and security concerns. The use of health plan identification numbers has not been met with praise by all in the healthcare industry and concern has been voiced that the use of these identifiers would just add granularity; over-complicating transactions unnecessarily. The purpose of HPIDs has also been questioned, in particular...



