HIPAA Breach Due to Improper PHI Disposal Affects 1,778 Minn. Patients
Northfield Hospital & Clinics has recently issued a HIPAA breach notification to approximately 1,800 of its patients after their Protected Health Information (PHI) was potentially exposed to unauthorized individuals over an eight day period in October this year. The security breach only affected a small percentage of Northfield patients and no medical information is believed to have been accessed, although the matter is being treated with the utmost seriousness. The security breach occurred when a number of documents were disposed of in commercial dumpsters by mistake, rather than being destroyed as required by HIPAA data security and privacy rules. When Protected Health Information is no longer required it must be destroyed or rendered unusable, with the rules applying to paper records and all electronic data. Paper records containing PHI and other confidential information must be shredded, incinerated or rendered unreadable to ensure that patient health information is not accidentally disclosed. In the case of Northfield Hospital & Clinics, the records included some...
Detroit Thieves Use Stolen PHI to Commit Medical Identity Theft
Electronic devices are easy to steal and thieves sell on the hardware, although the value of the equipment pales into insignificance compared to the money that can be obtained from the patient data stored on the devices. PHI can be used to obtain products and medications which can be sold on the black market, although the data can also be used to submit false tax returns, obtain tax refunds and make bogus insurance claims. The theft of Protected Health Information from two Detroit hospitals earlier this year has highlighted how easy it is for thieves to steal PHI if adequate security measures are not implemented and how that data can be used to commit fraud and medical identity theft. The data breach involved two hospital employees; Markitta Washington who worked at Henry Ford West Bloomfield Hospital and Martez Lear from DMC Harper Hospital. The pair is alleged to have stolen the data of 1,400 patents from the hospital computer network in order to make bogus claims for tax refunds. Following the discovery of the theft at Detroit Medical Center the hospital conducted an...
Data Encryption May not Prevent a HIPAA violation
According to the Department of Health and Human Services’ HIPAA Security Rule, healthcare entities and their business associates must implement measures to protect private and confidential data of patients. Many healthcare organizations use data encryption services to protect PHI in the event that healthcare networks are infiltrated by hackers or electronic devices are lost or stolen. Encrypting patient data should ensure that an organization is covered and protected against HIPAA violation penalties; however this may not necessarily be the case. A recent data breach at Boston’s Brigham and Women’s Hospital has highlighted an issue faced by healthcare organizations who take the appropriate steps to protect PHI, only for those measures to prove insufficient. BHW announced on Monday 17th November that a mobile phone and laptop computer were stolen in a robbery in which a doctor was held at knife point, bound to a tree and was subsequently forced to hand over the equipment as well as the pass codes to access the data. The devices held the data of 999 patients,...
Postal Workers Union Files Charges over Post Office HIPAA Data Breach
Earlier this year the U.S Postal Service was targeted by cybercriminals who gained access to a database containing the confidential data of past and present post office workers, including social security numbers, names, addresses and telephone numbers. The HIPAA breach also affected a limited number of customers; those who contacted the postal service between Jan. 1 and Aug. 16, although no customer data was limited to telephone numbers, names and email addresses. The USPS started planning increased security measures after it was notified by the FBI about the breach, although action to protect the data was delayed according to the Washington Post, with measures to tackle the security issues only implemented in early November this year. In addition to facing potential fines from the OCR for the HIPAA breach, the USPS is now under the scrutiny of the American Postal Workers Union which filed for unfair labor practices last month following on from the breach and how the USPS responded. The charges were filed with the National Labor Relations Board with the Union believing that it...
Beth Israel Fined $100,000 for HIPAA Data Breach
A laptop computer was stolen from Beth Israel Deaconess Medical Center in May 2012. It was not being transported and was not left unattended in a car. The theft occurred inside the hospital with the laptop stolen from a physician’s desk. Data stored on the laptop included Protected Health Information of close to 4,000 patients and employees, including Social Security numbers, addresses, telephone numbers and other personal identifiable information. In total, 3,796 patients and employees of Beth Israel had confidential data exposed and potentially exposed to criminals. Beth Israel Deaconess Medical Center has now agreed to settle a complaint and pay $100,000 after the Massachusetts attorney general’s office alleged that the laptop theft could have been prevented had proper security measures been in place. There were two area of concern: General security at the hospital which facilitated the theft of the device and a failure to use data encryption to protect the PHI of patients. The Attorney General’s office claimed that the data security failures at Beth Israel broke the law and lax...



