Pre-Audit HIPAA Compliance Survey Finalized by OCR
The Office for Civil Rights has set the wheels in motion for its upcoming HIPAA compliance auditing program by filing an information collection request in the Federal Register, which post-Omnibus Rule now includes Business Associates as well as entities previously covered by HIPAA. No schedule for the audits has been announced, nor was an announcement expected. The collection request is just the first step in the process and the audits are not expected to take place until the fall of this year. The request is to allow it to conduct a pre-screening survey which will permit it to contact up to 1,200 covered entities and Business Associates, in part to gain an understanding of each organization’s readiness for audit and also to “assess the size, complexity, and fitness of a respondent for an audit.” The information the OCR plans to collect relates to recent activities in relation to HIPAA regulations laid down by the Omnibus Rule and Privacy Rule in particular. It will require information to be provided on the use of electronic patient health records which are to be the major...
Inspira Health Network Alerts 1,411 Patients of Potential HIPAA Breach
The theft of two personal computers from Inspira Health Network’s Vineland Medical Center in December 2013 has potentially exposed health data of 1,411 New Jersey patients. All affected individuals are in the process of being notified that some of their data has potentially been compromised, although the risk to individuals is considered to be low. In December, 2013, a former employee at the Vineland center took two computers from storage facilities in the center’s radiology department. The filing room where the computers were being stored was unlocked and unsecured. Christopher McCourt of Port Norris took the computers and sold them to a local recycling center. The computers, reportedly worth $2,800 each, were sold for just $14. According to a Vineland Police Department statement, McCourt committed the crime to obtain gas money. This was not the first time McCourt had taken a computer. He also admitted to another theft, although the incident had gone unreported. McCourt has now been charged with burglary and theft and is being held in Cumberland County Jail. Inspira Health was...
HIPAA Breach Report: November 2013
November 2013 HIPAA Breach Summary: The Health Insurance Portability and Accountability Act requires all covered entities – including Business Associates – to report all data breaches affecting more than 500 individuals. The reports must be made via the DHHS’ Office for Civil Rights (OCR) breach notification portal and covered entities have up to 60 days from the date of discovery of the breach to notify the OCR. This report contains a summary of the breaches reported to the OCR during the month of November, 2013. Major HIPAA Breaches in November 2013 November saw a dramatic drop in the number of victims from data breaches. There were 24 HIPAA breaches reported for the month – five less than in October – with the number of victims falling by 75%. UW Medicine (WA) recorded the largest breach, in which 76,183 patient records were exposed in a hacking incident. The Kaiser Foundation Hospital in Orange County (CA) potentially exposed 49,000 patient records after a portable device containing unencrypted PHI was lost. An unauthorized disclosure of PHI at Triple S Salud...
138 Percent Annual Increase in Reported HIPAA Data Breaches
A new data security report released by healthcare IT security company Redspin suggests the number of data breaches reported to the U.S. Department of Health and Human Services has increased by 138% over the course of the past 12 months. The figures are likely to be higher still, as the report only details data breaches which have been reported by HIPAA-covered organizations that have affected more than 500 individuals (incidents involving data being compromised where under 500 individuals are affected do not need to be a matter of public record and are therefore not included in the report). Even with the strict reporting requirements under the HIPAA Security Rule, many incidents involving data breaches go unreported according to industry officials. The total number of people affected by data breaches is currently estimated to be approximately 29.3 million, although it is highly probable that the actual number of victims is far higher. The Director of Privacy and Security at HIMSS calculated the actual number of victims to be in the region of 40 and 45 million back in 2012. Even...
Texas Healthcare System Suffers 405K-Patient HIPAA Security Breach
A Texas healthcare system has been targeted by an international team of hackers who were able to access a server containing the Protected Healthcare Information of over 405,000 patients. This is the third largest security breach reported to the Office of Civil Rights of the Department of Health and Human Services. The hackers gained access to a computer server used by the St. Joseph Health System in Bryan, Texas for a period of three days in December 2013. The health center announced the breach on February 4th, although the data was accessed over a 48 hour period between December 16 and 18, 2013. During this time hackers were able to access data containing Social Security numbers, patient contact details and medical information. Patients’ full medical histories were not stored on the server, only information such as registration data and details and test results. The data contained patient information from hospitals operated by the St. Joseph Health System: The St. Joseph Center in Madison; St. Joseph Health Center in Grimes and Bryan as well as the St. Joseph Rehabilitation...



