The HIPAA Wall of Shame: Major Data Breaches of 2013
Healthcare organizations were hit hard by security breaches in 2013 and millions of Americans have had their health and personal data exposed, placing them at an elevated risk of suffering identity and medical fraud. According to the Identity Theft Resource Center (ITRC), 614 data breaches were reported in 2013; an increase of 30% from the previous year. 269 of these breaches – 43% – affected the healthcare industry, with 2013 being the first year since 2005 that healthcare has ranked higher than the business sector for data breaches. ITRC reported hacking to be the major cause of data breaches as a whole in 2013; however it was the loss of unencrypted portable devices that resulted in the largest exposures of patient health data. Many laptop computers were stolen from vehicles and medical facilities while hacking is a growing problem. ITRC reports the total number of individuals to be affected by healthcare data breaches to be close to 9 million, and had the Target hack – which exposed 70 million records – not have occurred; the healthcare sector would also top the...
Virginia HIPAA Breach Exposed Patient Data for 4 Years
A new HIPAA security breach has been uncovered in Virginia involving 919 patients from the Riverside Health System which operates five hospitals in Southeast Virginia. The data breach did not involve tens of thousands of patients although the security breach is one of the longest recorded to date, with ePHI data being accessible since September 2009 until the security breach was discovered on November 1 last year. The data was not accessed by outside entities as with other recent breaches, instead a single practice nurse employed at one of the hospitals accessed the records of nearly 1000 patients. The breach was uncovered in a random audit of the hospital’s IT systems. The nurse in question allegedly accessed the records of 919 patients, which included Social Security numbers and medical histories, although the reason for accessing the data was not provided. The nurse has since had her employment contract terminated and there is no ongoing security risk. Riverside Health System is currently taking all reasonable steps to contact patients and mitigate any damage or loss caused. An...
Office of Civil Rights Responds to OIG HIPAA Enforcement Criticisms
The Office of the Inspector General of the Department of Health and Human Services has recently issued a report stating that the Office for Civil Rights failed to meet all the federal requirements that it was set and specifically criticized it for not having overseen and enforced the HIPAA Security Rule to the required degree. According to the OIG, there were two key requirements under the Security Rule that the OCR had not met: OCR had not assessed the risks, established priorities, or implemented controls for its HITECH requirement to provide for periodic audits of covered entities to ensure their compliance with Security Rule requirements. OCR’s Security Rule investigation files did not contain required documentation supporting key decisions because its staff did not consistently follow OCR investigation procedures by sufficiently reviewing investigation case documentation. The OIG recommended immediate action is taken to address these failures including conducting periodic audits of covered entities to ensure that the amendments to HIPAA due to the HITECH Act are assessed. It...
Barry University Foot and Ankle Institute Suffers Potential HIPAA Breach
A laptop malware infection is believed to have exposed the data of an unspecified number of patients of the Barry University Foot and Ankle Institute in Florida according to an announcement made on Monday night by the healthcare provider. In the statement the university did not disclose the number of patients that were believed to have been affected, although the data only related to individuals who had received treatment at the Miami Shores School. All affected patients have been notified that a malware infection on a laptop belonging to the Miami Shores School contained a complex malware infection that potentially allowed access to be gained to the medical and personal information of a number of its patients. The malware was discovered on the laptop computer on May 14, 2013 and an expert IT forensics team was brought in to assess the exact nature of the infection and the extent of data that potentially could have been accessed. The malware has now been removed and the infected files have been restored and the hospital believes no further threat of exposure exists. The data...
How to Reduce Human Error and Prevent HIPAA Breaches
This year has seen a number of large data breaches which have exposed the Protected Health Information of millions of Americans, placing them at an increased risk of becoming victims of identity theft and medical fraud. While some deliberate attacks have infiltrated computer networks, in many cases it is human error that exposes patient data to unauthorized third parties. Misplaced or unguarded portable devices have resulted in massive data breaches and many simple errors and oversights have resulted in patient details being exposed. Healthcare organizations are now required to store an increasing volume of data in electronic format. While data security used to mean locked filing cabinets and a small security presence, the increased risks faced by today’s healthcare providers requires an increasingly technical array of security measures to be employed to keep patient data secure. Even when legislation is followed to the letter and all of the appropriate technical, physical and administrative safeguards are put in place, a simple mistake by a member of staff can easily cause a data...



