Using Windows XP will be a HIPAA Violation
Microsoft Windows XP was one of the most liked and most used software platforms released by the Software giant. The platform became the standard operating system in use around the world and it was installed on the majority of PC’s and laptops in the healthcare industry. Microsoft sold millions of copies of its software, yet when Vista and subsequent products were released, many healthcare organizations did not upgrade. Programs had been written to be compatible with Windows XP, issues would arise with hardware and the sheer cost of upgrading software and buying new licenses for all laptops and PCs in use in an organization was deemed by many to be a cost to be put off indefinitely. Unfortunately the time has now come when the decision to upgrade computer operating system can be put off no longer, as Microsoft is finally pulling the plug on Windows XP. It will stop writing software patches and issuing security updates in less than 12 months. Microsoft stopped selling Windows XP five years ago and it has been allowed to fade away; however, while Microsoft is willing to let that...
Hearing Clarifies Rules on Disclose of PHI under HIPAA
One of the main aims of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) – and its five subsequent rule amendments – was to create a national standard to protect medical records and other Personal Health Information and keep the data private and confidential. The HIPAA Privacy Rule, one of the five amendments to the original legislation, was introduced specifically to address electronic PHI and ensure that healthcare organizations implemented the necessary technical, administrative and physical safeguards to maintain data security. All entities covered by HIPAA were required to comply with this rule by 2003, and since the rule came into effect, the OCR has been policing healthcare organizations and ensuring that the new rules are adhered to. The Privacy Rule defines and limits the circumstances under which an individual’s protected heath information may be used or disclosed by covered entities. Although the introduced rules have tried to simplify HIPAA policies and help healthcare organizations to put them into action, there are circumstances under...
Lawsuit Alleges IRS Violated HIPAA with Seizure of 60M Patient Medical Records
A class action lawsuit alleges the IRS violated HIPAA regulations when agents seized 60 million private and confidential health records relating to 10 million American individuals. The case is being filed by a healthcare provider – that wishes to remain anonymous – against the IRS and fifteen of its agents who were not named. The case is being filed with the complainant alleging the IRS breached HIPAA regulations and illegally seized 60 million personal medical records when the warrant allowed only access the financial data of one individual. The incident occurred on March 11, 2011 when the IRS gained a search warrant to access specific records relating to one individual who had previously worked for the company filing the suit. The IRS agents allegedly seized the data which included financial and medical records and made no attempt to abide by HIPAA regulations and only take the data relating to their investigation. Unrelated medical records of 10 million patients were included with the record they wanted to access. The data contains highly sensitive medical information such as...
Dent Neurologic Clerk Violates HIPAA by Emailing PHI to Patients
The theft of mobile devices may be one of the leading causes of HIPAA breaches, although human error can easily lead to patient health data being disclosed, with Dent Neurologic the latest healthcare organization to suffer a major HIPAA breach as a result of the actions of an employee. Dent Neurologic, a neurologic institute serving Buffalo and West New York, accidentally distributed a spreadsheet containing PHI to 200 patients in a routine email. The spreadsheet contained data relating to 10,200 patients and was attached by accident to an email by a clerk in the DNI administration office. The data did not contain information relating to treatment and diagnoses, nor Social Security numbers or dates of birth. However, patient names, email and home addresses, last appointment dates and the name of the treating doctor were all detailed in the spreadsheet. Dent Neurologic CEO, Joseph V. Fritz, issued a news release explaining the error, which has been attributed to a mistake made by the clerk. Fritz stated that “We are very sorry this happened, and we deeply apologize to all of our...
Hospital X-Ray Scam Provides Thieves with PHI of 17K Patients
When the Raleigh Orthopedic Clinic arranged for its X-ray films to be modernized and transferred to digital media, the healthcare organization naturally sought external assistance. A third party vendor was located that could offer the service and the X-ray films were sent for conversion. The contract was arranged in January of this year and the films were dispatched; however when the clinic failed to receive the electronic copies of the data suspicions were aroused. An investigation was conducted into the matter in the first week of March and it was determined that the clinic had been involved in a scam. In contrast to other security breaches where thieves deliberately set out to steal ePHI to commit fraud, in this case the thieves wanted the x-ray film for the silver it contained. Raleigh Ortho discovered that its X-rays had been sold on to a recycling company based in Ohio which offers a service to recycle X-ray films. It is understood that the unspecified company used by the hospital obtained the X-rays fraudulently with a view to selling the silver. X-ray films contain...



