Humana Reports Mailing Errors Affecting More than 10,000 Members
Three mailing error incidents have resulted in the impermissible disclosure of the PHI of more than 10,000 Humana members. Data breaches have also recently occurred at KMJ Health Solutions, Jewish Home Lifecare, and Lake of the Woods County Social Services. Insurance ACE/Humana Inc. The Kentucky-based health insurance provider Humana Inc. has recently disclosed three separate mailing error incidents that have resulted in the impermissible disclosure of the protected health information of 10,688 of its members. On December 8, 2023, a programming error resulted in Explanation of Payment documents intended for providers being sent to an incorrect address. The documents included first and last names, Humana ID numbers, provider names, dates of service, and claim payment information. On December 14, 2023, large print/braille health plan communications were mailed to incorrect recipients. An error was made when fixing an unrelated coding issue that added a date/time stamp to the naming convention, which was not a unique identifier. As a result, the system began overwriting files as...
HHS-OIG Agrees $49,000 Settlement with North Carolina Hospital to Resolve Alleged EMTALA Violation
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has agreed to a settlement with UNC Health Chatham Hospital that resolves an alleged violation of the Emergency Medical Treatment and Labor Act (EMTALA). EMTALA was enacted in 1986 to ensure public access to emergency services regardless of an individual’s ability to pay, and EMTALA applies to all hospitals that offer emergency services through a dedicated department. There are also specific obligations for hospitals that participate in Medicare and offer emergency services, including the requirement to provide a medical screening examination (MSE) when a request is made for examination or treatment for an emergency medical condition. Organizations found to have violated EMTALA can face stiff financial penalties and, potentially, exclusion from federally funded healthcare programs. On January 16, 2022, a 62-year-old patient presented to Chatham’s Emergency Department (ED) via emergency medical services (EMS). Before arriving at the hospital, EMS called in a report about the patient’s condition to the...
Data Breaches Reported by Rebound Orthopedics, CCM Health, BCBST & Orsini Pharmaceutical Services
Data breaches have recently been reported by Rebound Orthopedics & Neurosurgery, CCM Health, BlueCare Plus Tennessee, and Orsini Pharmaceutical Services. Rebound Orthopedics & Neurosurgery Rebound Orthopedics & Neurosurgery in Vancouver, WA, has recently announced that it fell victim to a cyberattack on February 2, 2024. The attack was detected on February 3 when its computer systems went offline, including its patient and scheduling portals, and the outage lasted for more than 2 weeks. Computer forensics specialists were engaged to investigate the incident and confirmed that an unknown and unauthorized actor had accessed its network and viewed or copied files that were stored on its systems. A detailed review has been conducted of those files which confirmed that they contained patient information although no evidence was found to indicate any information in those files has been misused. It is currently unclear what information was involved, as that information was not present in the sample notice provided to the Montana Attorney General. The incident has yet to appear...
White House Meets with Healthcare Community to Discuss Change Healthcare Ransomware Attack Mitigations
On March 12, White House officials met with UnitedHealth Group, leaders at the Department of Health and Human Services, and industry groups to discuss the cyberattack at UHG-owned Change Healthcare, the disruption to healthcare services over the past 3 weeks, and mitigations to help patients and providers. The Change Healthcare cyberattack was detected on February 21 – the timeline of events can be viewed here – and caused an outage that lasted for three weeks. The Blackcat ransomware group claimed responsibility for the attack. The attack caused massive disruption with providers unable to verify coverage, submit prior authorization requests, exchange clinical records, and be reimbursed for services. UHG set up a financial assistance program to help providers who receive payments processed by Change Healthcare, who could apply for temporary funding through Optum Financial Services, and the Centers for Medicare and Medicaid Services (CMS) introduced flexibilities to help ease the financial strain on providers, including applications for advanced payment. Last week, 2 weeks after the...
OCR Opens HIPAA Compliance Investigation of Change Healthcare
The HHS’ Office for Civil Rights has opened an investigation of Change Healthcare following its February 21, 2024, cyberattack, just three weeks after the attack occurred. Typically, OCR’s investigations of cyberattacks and data breaches are initiated several months after the breach is reported, which may even be years after the breach occurred. In this case, the incident has not even been reported to OCR as it is still under investigation. Change Healthcare has only just brought its systems back online – 99% of pharmacy and payment platforms are now up and running according to a recent statement – and there are still 5 weeks before the HIPAA Breach Notification Rule’s deadline for reporting breaches is reached. The rapidly initiated investigation is in response to the magnitude of the incident, which is disrupting health care and billing information systems nationwide and has been estimated to be costing providers well over a billion in reimbursement losses per day due to Change Healthcare’s systems being unavailable. The disruption caused to providers that use Change...



