Plaintiffs HIPAA Privacy Case Against Advocate Health Dismissed
An Illinois circuit court in Kane County has dismissed a class action lawsuit that arose from the Massive HIPAA breach affecting the healthcare provider last August. The incident potentially exposed the data of approximately 4 million patients when four unencrypted computers were stolen from its Park Ridge facilities. The class action lawsuit was filed by two plaintiffs who alleged Advocate Health acted with negligence by failing to implement the appropriate safeguards to protect their data. The lawsuit also claims Advocate Health violated both the Illinois Personal Information Protection Act and the Illinois Consumer Fraud Act in addition to the incident causing an invasion of privacy. The court ruled in favor of Advocate Health & Hospitals because the case lacked standing. While there was no doubt that the PHI of the patients had been potentially exposed, the plaintiffs were unable to offer enough evidence to confirm that the data had actually been viewed by an unauthorized individual. Without this proof it was not possible to establish whether any harm or damage had actually...
Parkview Health System Receives $800K HIPAA Privacy Rule Fine
The financial penalties for violations of HIPAA can be severe, as was discovered by Indiana-based Parkview Healthcare System recently when it was ordered to pay $800,000 in fines as a settlement for violation of the HIPAA Privacy Rule. The incident for which the fine has been issued dates back to 2009 when a data security complaint was filed by a patient of one if its doctors. The doctor was retiring and received a delivery of 71 boxes of medical files containing up to 8,000 patient records; however the delivery was made and the boxes were left on the doctor’s driveway while he was out of the house. The confidential patient records could have been accessed by any number of individuals as the boxes were left unattended in a “highly trafficked” area for a considerable period of time. The complaint was made against Parkview Health as it was responsible for the paper records and should have taken greater care to protect the confidentiality of its patients. Acting Deputy Director of Health Information Privacy at OCR, Christina Heide, issued a statement regarding the incident and...
Self Regional Healthcare Announces HIPAA Data Breach
Self Regional Healthcare (SRH), a healthcare provider based in South Carolina, has announced that a laptop computer was stolen from one of its facilities on May 25, 2014. That laptop contained unencrypted Protected Health Information of nearly 40,000 of its patients. The data included highly sensitive information which could potentially be used by criminals to commit identity fraud, insurance fraud, credit card fraud and enable them to make false Medicaid/Medicare claims. Social Security numbers; drivers license numbers; financial account numbers; physician names; payment card information; insurance policy details; diagnosis and procedure information and patient names – possibly addresses – were stored on the laptop. SRH learned of the break-in and theft on May 27, 2014. Law enforcement officers were alerted and were able to apprehend two individuals believed to have illegally entered the property. One person admitted to stealing the laptop, but according to the report “he destroyed it and disposed of it in a lake,” after an attack of remorse. He also claimed not to...
PRN Medical Services Notifies 2,200 of HIPAA Data Theft
According to a breach report issued to the Department of Health and Human Services’ Office for Civil Rights, PRN Medical Services, LLC – under the name Symbius Medical LLC – has suffered a HIPAA breach after five members of staff were identified as having accessed and stolen confidential and private records. The information is believed to have been accessed, copied, and disclosed to a third party; a competitor of PRN Medical Services where the employees went to work. According to a statement issued by Symbius Medical, as reported by PHIPrivacy, the information is believed to have been stolen “in the weeks leading up to their resignations.” The staff in question were former sales representatives and Symbius believes that the information was intended to be used, and may still be, to contact patients to attempt to sell them medical supplies. The data is not believed to have been taken for the purposes of committing medical or financial fraud, and is instead a case of sales representatives taking contacts with them when they change employer. That said, this is theft of PHI and the...
Unencrypted Hospital Communications are HIPAA Violations
Text messages may be a quick and convenient method of communication for doctors and healthcare professionals; however two medical professionals from North Carolina have recently discovered that the use of unsecured text messages to transmit medical data is a HIPAA violation. For the professionals concerned, the action was innocent and believed to be in the best interest of the patient. A doctor was visiting a patient at a nursing home and requested that a nurse send the patient’s laboratory results via text message. The message was sent and only two people viewed the patient data, both of whom were authorized to access the records. However by sending the data over an unencrypted and insecure connection, the records could potentially have exposed to a third party. Text messages can be used in healthcare, but in order to be HIPAA compliant data has been encrypted. The nursing facility was given an e-class deficiency by The Centers for Medicare & Medicaid Services (CMS) which resulted in a 10-point Directed Plan of Correction (DPOC) which must be implemented within 15 days. The...



