Los Angeles Times Article Results in $275000 HIPAA Privacy Rule Fine
An article published in the L.A Times started a sequence of events that has now resulted in Shasta Regional Medical Center (SRMC) agreeing to a settlement of $275,000 for its violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule. The HIPAA Privacy Rule forbids covered entities – and their employees and business associates – from disclosing health information of patients to unauthorized persons. Whenever there is suspicion that regulations are not being followed the HHS Office for Civil Rights (OCR) conducts an investigation and compliance review. The U.S. Department of Health and Human Services (HHS) was tipped off to potential Privacy Rule violations after two senior SRMC leaders met with the media and provided details of medical procedures performed on a specific patient. This unauthorized disclosure of the patient’s protected health information to the media was a direct violation of the Privacy Rule. Patient consent must be obtained in writing before any PHI can be disclosed to a third party and this was not the case at SRMC. The...
Stanford University Suffers 5th Large HIPAA Security Breach
Stanford University has now suffered its 5th large data breach in four years following the theft of a laptop from the Lucile Packard Children’s Hospital. The latest breach may not be the largest to date – or even the largest to affect the University – but it could potentially see the University having to pay a large settlement to the OCR for failing to secure its patients’ PHI. The latest security breach involved close to 13,000 patients, with the data that was exposed containing personal identifiers including patient’s names and contact information. The data stored on the stolen laptop also included medical diagnoses, medical record numbers, surgical procedures performed and the names of the treating physicians. No Social Security numbers were present in the data set, although the hospital is still required to notify each of the 13,000 patients affected. Victims of data breaches must be alerted to the possibility that their PHI may be used to enable them to take action to mitigate any damage or losses caused. The laptop was stolen from a private area of the hospital...
Healthcare BYOD Schemes Here to Stay Says Ovum
IT Research firm, Ovum, has released details of a study conducted on full time IT workers’ participation in Bring Your Own Device (BYOD) schemes, and for the second year running participation has remained steady at around 60%. Healthcare professionals are using Smartphones and mobile devices at home, and they the preferred mode of communication for many physicians. They offer speed, convenience, practicality and they are familiar; as well as allowing the user to be in touch around the clock. However, being made to leave the devices at home or in lockers when coming to work, and instead being forced to use outdated modes of communication – such as pagers – is not something that all workers agree with. Many ignore company policies and bring their own devices to work anyway, even when BOYD schemes are not in place. The study showed that 15.4% of employees who owned their own Smartphone took it to work and used it and did not report use of the device to their IT department, while 20.4% said their employers were anti-BYOD yet they still took their devices to work and used them. If a...
Breach Penalty Highlights Easily Overlooked HIPAA Security Issues
The Department of Health and Human Services’ Office for Civil Rights has recently issued a large fine to Idaho State University for the accidental disclosure of electronic Protected Health Information stored on one of its servers. Unbeknown to the University, a server holding data on one of its HIPAA-covered clinics accidentally had the firewall disabled causing a 10-month data security breach. The OCR investigation highlighted three main areas of non-compliance: A HIPAA Risk Analysis had clearly not been conducted, as if that had been the case, the deactivated server would have been identified. There was no risk management process in place which also could have identified the problem and thirdly, an Information System Activity Review had not been conducted. The HIPAA Security Rule demands all three of these procedures be made policy at a healthcare organization in order to be HIPAA-compliant. It was clear that ISU had, albeit unwittingly, violated HIPAA regulations without the OCR having to perform a full compliance assessment. HIPAA compliance is an ongoing process “Risk...
Idaho State University Ordered to Pay $400K Settlement for HIPAA Breach
Violating HIPAA regulations can incur harsh penalties, as discovered by Idaho State University this month. The institution has recently been forced to settle with the Department of Health and Human Services’ Office of Civil Rights for alleged violations of the HIPAA Privacy Rule. Fines were issued for HIPAA non-compliance issues relating to network security; inadequacies which exposed sensitive patient health information to third parties. ISU had implemented the required control measures to prevent health data from being accessible by unauthorized personnel, although it failed to perform checks to ensure that the security measures it had implemented had remained in place. The security breach occurred when the Pocatello Family Medicine Clinic disabled the firewall that was protecting a server containing medical health records of 17,500 its patients. The firewall was inactive for a period of 10 months leaving the data exposed and potentially accessible to unauthorized third parties for an unacceptable period of time. According to the HHS, ISU operates 29 outpatient clinics and is...



