Sutter Health Sued for 4.24M HIPAA Mega Breach
Two class action lawsuits have now been filed against the Sutter Health hospital system in Northern California after a burglary at its administrative offices in Sacramento potentially exposed the Protected Health Information of 4.24 million patients. Over the weekend of Oct 15-16 thieves gained access to the offices by throwing a rock through the window. Once inside they cleared the office of electrical equipment including a PC, mouse and computer monitors. The PC contained data relating to 3.3 million former and current patients of Sutter Physician Services (SPS) with the records dating back to 1995. Social Security numbers were not included in the data although some personally identifiable information could potentially have been accessed by the thieves. The data included names, dates of births, addresses, phone numbers and some email addresses. The breach also exposed the medical records of 943,000 patients from the Placer, Sacramento, Solano, Sutter, Yolo and Yuba counties who had been treated by Sutter Medical Foundation doctors from January 2005 to the present. One of the...
Lapse in Business Associate Security Causes 20K Patient HIPAA Breach
According a New York Times report published this week, the medical records of 20,000 patients of Stanford University Hospital in Palo Alto, Calif., have been posted online and accessible to the public for close to a year after an error was made by one of the hospital’s business associates. The hospital and its contractor – Multi-Specialty Collection Services of Los Angeles (MSCS) – confirmed that a spreadsheet containing the medical data of 20,000 patients had been accidentally sent to a job prospect who in turn posted the data on a tutoring website as part of a job skills test. The data was posted on Dec. 9, 2010 and remained accessible until a patient discovered it and brought it to the attention of the hospital on Aug. 22, 2011. MSCS explained how the incident occurred in an email sent to affected patients, according to the NYT report. MSCS President, Anthony Reyna, told the patient that a marketing vendor had been sent patient health information directly from Stanford Hospital. After converting the data to a different format it was inadvertently given to a job applicant...
HIPAA Sees Meritus Medical Center Stop Media Announcements
Meritus Medical Center is one of a number of hospitals that has stopped issuing information about patient conditions to the media. The hospital announced on September 22 that this courtesy would be stopped. The Health Insurance Portability and Accountability Act places certain restrictions on the disclosure of Protected Health Information to third parties, including the media. Just a few years ago, reporters would be able to call a healthcare provider to make an enquiry about the health status of a patient. The hospital staff would provide general information about a particular patient’s condition if they were asked about a patient by name. The information disclosed would be restricted, so reporters would be advised for instance, that a patient was good, fair, stable or in critical condition. Under HIPAA Rules this information may be disclosed to the media; however it is not mandatory for a hospital or healthcare provider to give out any information, except when it is in the public health interest to do so or if required by law enforcement officers to assist with an investigation....
Texas Expands HIPAA Privacy Laws to Bolster EHR Security
Governor of Texas, Rick Perry, has signed a new law to give Texas residents even greater protection than required by the Health Insurance Portability and Accountability Act and has increased penalties for healthcare organizations that fail to implement the appropriate security measures to protect the health data of patients. Under the Health Information Technology for Economic and Clinical Health Act (HITECH), covered entities have a number of responsibilities including reporting data breaches to the Office for Civil Rights (OCR). Data breaches are reportable to the OCR, either in an end of year report or after an investigation, depending on the number of individuals affected. HIPAA places a number of restrictions on how ePHI is used and stored, and all covered entities are required to conduct a full risk analysis to assess systems for security vulnerabilities to allow risk to be managed. It also lays down the procedures that must be followed after a data breach, such as notifying potential victims. Covered organizations are also required to conduct an investigation into how a...
HIPAA Privacy Complaint Results in Federal Criminal Prosecution for First Time
For the first time, a HIPAA privacy complaint filed with the Department of Health and Human Services’ Office for Civil Rights (OCR) has resulted in federal criminal prosecution. A complaint was filed with OCR over an impermissible disclosure of a patient’s protected health information by a doctor. The doctor, Richard Alan Kaye of Suffolk, Va., was alleged to have shared PHI with the patient’s employer without consent from the patient – A violation of the HIPAA Privacy Rule. The case against Kaye has been referred to the Department of Justice, which has pressed charges. While OCR has referred more than 500 HIPAA violation cases in the past, this if the first time that an investigation of a privacy complaint has resulted in criminal prosecution. Kaye had previously worked at Sentara Obici Hospital in Suffolk, Va., as Medical Director of its Psychiatric Care Center. The patient had been enrolled in a mental health treatment program at the hospital and Kaye treated and subsequently discharged the patient. On discharge, Kaye stated that the patient was not a threat to the public....



