VA Nurse Charged for Unlawfully Accessing a Patient’s Medical Records
A Michigan Nurse at the U.S. Department of Veteran Affairs has been charged with unlawfully accessing and obtaining the medical records of a patient. Jessica Nicole Pitcher, 41, of Shelbyville, is alleged to have accessed and copied the medical records of a patient of the Veterans Affairs Medical Center in Battle Creek, Michigan, without authorization on or around November 27, 2023. The Health Insurance Portability and Accountability Act (HIPAA) sets standards covering the privacy and security of healthcare information, termed protected health information or PHI under HIPAA. There are strict rules concerning uses and disclosures of PHI, which may only be used or disclosed for purposes expressly permitted by the HIPAA Privacy Rule unless authorization is received from a patient. Healthcare professionals must abide by the HIPAA Rules and are not permitted to access the medical records of patients unless they have a valid work reason for doing so. The HIPAA Privacy Rule permits access to medical records for purposes related to treatment, payment, and healthcare operations. Nurses are...
OCR Phishing Investigation Uncovers HIPAA Training Failure; Children’s Hospital Colorado Fined $548,265
The HHS’ Office for Civil Rights (OCR) has announced another civil monetary penalty for a HIPAA-regulated entity to address non-compliance with the HIPAA Rules, its 7th of the year and the 15th enforcement action of 2024 to result in a financial penalty. The latest fine was imposed on Children’s Hospital Colorado Health System, a not-for-profit provider of healthcare services for children and young individuals at its main healthcare facility in Aurora, CO, and 22 other facilities in the Anschutz Medical Campus and throughout the State of Colorado. Children’s Hospital Colorado also has agreements with nursing schools and provides clinical opportunities for nursing students. On July 11, 2017, an unauthorized individual accessed a physician’s email account following a response to a phishing email. The email account contained the electronic protected health information (ePHI) of 3,370 patients. The email account was previously protected with 2-factor authentication; however, it was deactivated by the IT help desk and was not reactivated. The breach was reported to OCR, and an...
Mount Nittany Health Agrees $1.8 Million Settlement for Using Website Tracking Technologies
Mount Nittany Health in Pennsylvania has agreed to pay $1.8 million to resolve a class action lawsuit that alleged sensitive patient data was shared with third parties such as Meta and Google without the knowledge or consent of patients. The plaintiffs alleged that Mount Nittany Health added tracking technologies such as pixels to its website and patient portal, which collected information about website visitors based on their interactions, such as the pages viewed and options chosen in forms. That information, which included identifiers such as IP addresses, was transferred to tech companies for marketing and advertising purposes without first obtaining user consent. The lawsuit alleged that the information collected by the tracking tools could be tied to individuals and it could be inferred they were patients of Mount Nittany Health and had or were being treated for a specific medical condition. The lawsuit alleged that around 74,000 patients had used the website and/or patient portal since 2007 and potentially had their sensitive information disclosed to third parties without...
FTC Takes Action Against Two Data Brokers For Unlawfully Selling Consumers’ Precise Geolocation Data
The Federal Trade Commission has taken action against two data brokers for alleged FTC Act violations related to the collection, use, and sale of sensitive geolocation data without user consent. Gravy Analytics Inc. and its subsidiary Venntel Inc. are alleged to have engaged in the unlawful tracking and sale of consumers’ sensitive location data, including visits to healthcare facilities, places of worship, correctional facilities, schools/childcare facilities, military installations, and other sensitive locations. According to the FTC’s complaint, both companies are alleged to have violated the FTC Act by collecting and using consumers’ geolocation data without verifiable user consent for commercial and government uses, and unfairly selling sensitive consumer location data. Most Americans own a mobile phone and have it on their person or close by at all times. Since these devices usually precisely track the user’s location, records are generated of the user’s movements and location throughout the day and night. Geolocation data reveals the places a person visits regularly,...
Which Situations Allow a Medical Professional to Release Information?
The situations when a medical professional can release information vary depending on who is releasing the information, what information is being released, when it is being released, and where it is being released. It is fair to say there is a fair amount of misunderstanding both within and outside the healthcare industry about which situations allow a medical professional to release information. To find evidence supporting this statement, you only have to look at stories covered by mainstream news channels in which patients and their families have been denied their HIPAA rights by medical professionals, or in which politicians have failed to grasp the basics of health information privacy. To find further evidence supporting this statement, you need only visit the Enforcement Highlights page on the Department of Health and Human Services (HHS) website. The page reveals that, since 2003, the agency has received more than 300,000 complaints alleging violations of HIPAA. Of those 300,000 complaints, more than 200,000 have been rejected because “the complaint did not present an...



