HIPAA Data Breach Affects 13.5K United Homecare Services Patients
United HomeCare Services had been diligently implementing policies and procedures to protect the PHI of its patients which included installing software to encrypt the data on all of its laptop computers. Upgrading data security measures can take some time, and while laptops had been scheduled for data encryption some devices only employed password protection to protect the data. On January 8, 2013 a billing manager at the hospital returned home with a laptop computer which she was authorized to take off the premises. On the way home from the hospital the employee made a stop to visit a friend who was ill. She left the laptop on the front seat of the car, locked the doors and entered her friend’s house. Despite the visit only lasting 10 minutes, this was enough time for thieves to smash her car window and steal the laptop. United HomeCare Services was made aware of the incident and the local authorities were notified of the theft. UHCS reported the theft to the OCR the following day, and while it was known that the laptop had some patient data stored on the hard drive, it was not...
HIPAA Omnibus Rule Comes into Force
The HIPAA Omnibus Rule was published on Jan 25, 2013 by the Department of Health and Human Services (HHS) as an amendment to the Health Insurance Portability and Accountability Act (HIPAA). The new rule came into force on March 26, 2013 and modifies existing HIPAA regulations to provide greater protection of patient data; extending the reach of HIPAA and modifying regulations to bring them in line with the Health Information Technology for Economic and Clinical Health (HITECH) Act. The HIPAA Omnibus Rule contains many amendments, although it introduces four new rules: The HIPAA Privacy, Security and Enforcement regulations have been updated as follows: Liability for HIPAA compliance extended to include business associates and subcontractors Sale of PHI prohibited without authorization and the use of PHI for marketing or fundraising has been prohibited. Greater powers for patients allowing them access to their electronic medical and health data, while restricting information which must be disclosed to a health plan if treatment has been paid in full by the patient. Notices of...
Pittsburgh 911 Dispatch Center Investigated for HIPAA Violation
A 911 dispatch center in Monroeville, Pittsburgh is being investigated for a potential violation of the Health Insurance Portability and Accountability Act (HIPAA) after failing to safeguard protected health information. The Office for Civil Rights of the U.S. Department of Health and Human Services received a complaint in August 2012 relating to the dispatch center after a former police chief was sent protected health information via E-mail, which violates HIPAA regulations. While the electronic communications violate HIPAA, the complaint also highlighted another potential HIPAA-compliance issue. Generic user names and passwords were created to ‘protect’ a database of 911 callers’ medical information, potentially exposing confidential information to anyone with the login details. Users with those credentials would be able to log into the database and access all of the information held in the database. The complaint was made by Assistant Police Chief Steven Pascarella after the discovery that communications were still being sent via E-mail to a former police chief. Even though...
How HIPAA Applies to Text messages and Emails Sent by Healthcare Professionals
It was not long ago that doctors were required to carry pagers and call in when their pockets started to bleep. Today, pagers have been replaced by Smartphones with communications and notifications sent via text messages, Email or telephone calls. A number of healthcare centers and doctors have discovered that sending a quick text message can cause a HIPAA violation. If text messages or Emails are to be used, the appropriate technical safeguards must be put in place to protect the PHI of patients. When data is sent over the internet or mobile phone networks, it must be encrypted. A failure to implement these safeguards can result in huge fines being issued by the OCR. When HIPAA regulations were first drafted the internet was still in its infancy and mobile phones, tablets and multimedia SMS messages did not exist. However, over the years, the use of electronic communication has become commonplace. Back in 2001, 258.2 million text messages were being sent every month according to data from CTIA, while just 3 years ago, that number had risen to 193.1 billion per month in the U.S...
Rensselaer County Jail Implicated in Teen Girl HIPAA Violation
Protected Health Information of patients must be stored securely and unauthorized access to that data must prevented, although in the case of one Melrose family this was not the case. The family was recently alerted about the unauthorized disclosure of their teenage daughter’s medical information. The HIPAA breach allegedly occurred when employees from Rensselaer County jail gained access to the medical records of their 11-year old daughter. The father of the girl, Dominic Pasinella, was notified when he received a letter from Northeast Health which manages the Samaritan Hospital on behalf of St. Peter’s Health Partners. The letter stated that there had been a potential HIPAA breach at the hospital where his 11 year old daughter was sent for treatment following a dog bite. The incident was described as “private” by Mr. Pasinella, yet it has now become a public matter and the issue is now subject to a criminal investigation which he discovered had been ongoing for a number of months. Mr. Pasinella received the breach notification – a requirement under HIPAA regulations – which...



