Breakthrough in HIPAA-Compliant Remote Diabetes Care
The FDA-cleared Remote Patient Monitoring system from ALR Technologies’ (ALRT) has been hailed as a potential breakthrough in remote diabetes care. The system providing doctors and health care professionals with a method of being reimbursed for time spent providing remote treatment to long term diabetes sufferers and to receive recompense for the chronic care management services provided. The system – termed Health e-Connect – is an off-the-shelf software system that helps to connect diabetes patients with care providers, no matter where the team members are based in the country. Members of the care team are able to log on through a secure web portal and enter data and communicate with the entire team. Based on the payment system and schedule due to be decided on Nov 1, 2014, the Centers for Medicare and Medicaid Services (CMS) would issue doctors a monthly payment of $41.92 for the provision of up to 20 minutes remote care per patient. Once the system is implemented and ALRT begins invoicing for its services, the system could generate up to $2.3 million in monthly revenue...
Cybercriminals Target Health Care Organizations for Patient Medical Data
The value of patient’s confidential medical data has risen to ten times that of credit card numbers on the black market according to recent Reuters reports. Medical data can be used by cyber criminals to fraudulently obtain products and services – as with credit cards – although medical data theft has the advantage of being harder to detect than other cyber crime activities such as credit card phishing. Hackers are now targeting health organizations in an attempt to obtain confidential patient data and other personally identifiable information from their websites, databases and internal computer systems. The threat of attack has prompted the FBI to issue warnings to a wide range of organizations in the health care sector alerting them to the risk of cyber theft of data. The warning was issued following the theft of 4.5 million patients’ data by a group of hackers in an attack on Community Health Systems. The theft ranks as the biggest HIPAA data breach by hackers and the second largest data breach in history. In this case the data obtained was non-medical in nature,...
Pennsylvania Hospital Advises of Data Breach
Penn Highlands Brookville has issued a public notice confirming a recent “data security incident”, which the Pennsylvania Hospital says involved the data of 4,500 patients under the care of Barry J. Snyder, M.D. The statement was issued as a PHIprivacy press release. Penn Highlands Brookville is part of a quartet of Dubois, PA hospitals comprising Penn Highlands Healthcare, although this incident only affected one doctor’s patient database. On August 14, 2014 a server containing Barry J. Snyder’s patient database was found to have been compromised. A third party had gained access to the server on which the data was stored and potentially had access to protected health data of all of the doctor’s patients. It could not be determined whether the intruder had actually accessed any of the patient data. The data was held on a server belonging to an Ohio third party vendor under contract to maintain Dr. Snyder’s records. The data stored on the server included names, addresses, social security numbers, medical and insurance information, driver’s license numbers, telephone numbers and the...
Colorado Behavioral Health Patients Advised of HIPAA Breach
A recent postcard mailing by the Colorado Department of Health Care Policy and Financing has, albeit accidentally, disclosed protected health information on patients and is in breach of HIPAA regulations. The breach has now been made public and the patients concerned have been notified by mail. The HIPAA breach was due to a survey being mailed to approximately 15,000 patients, each of whom had received treatment through Medicaid or the Office of Behavioral Health belonging to the Department of Human Services. The HIPAA violation was not due to social security numbers and addresses being listed in the communication or any other information which could potentially be used by thieves or fraudsters. The HIPAA violation was for using a postcard rather than a sealed envelope for the survey. By using a postcard the name and the address of the recipient was clearly visible, while the survey identified them as being behavioral services patients. The survey contained questions about the behavioral health care services they had received and someone other than the intended recipient could...
HIPAA and Healthcare Data Compliance
Access to healthcare can be considered a basic human right, although many counties have different views on the services that are provided by the state, and to whom. Privacy is also important and can also be considered a basic human right, with the rights of individuals showing just as much variation. In the UK, British citizens have access to the National Health Service. Formed in 1948, the NHS provides universal healthcare to all but there is no common law right to privacy, although privacy issues can usually be resolved in court. Across the Atlantic in the United States, privacy laws affect how doctors can operate. If they want to assess how effective treatments are across the country for the treatment of a particular disease, privacy laws prevent them from having automatic access to data from any patient who is not their own. This is a problem, as sharing of patient data enables doctors to gain a better understanding of the treatments that are working the best. A way around this is for doctors to share some of their patient data using a service such as Sharepoint. Data can be...



