April 2023 Healthcare Data Breach Report
There was a 17.5% month-over-month fall in the number of reported healthcare data HIPAA compliance breaches with 52 breaches of 500 or more records reported to the HHS’ Office for Civil Rights (OCR) – less than the 12-month average of 58 breaches per month, and one less than in April 2022. One of the largest healthcare data breaches of the year was reported in April, but there was still a significant month-over-month reduction in breached records, which fell by 30.7% to 4,425,891 records. The total is less than the 12-month average of 4.9 million records a month, although more than twice the number of records that were breached in April 2022. Largest Healthcare Data Breaches Reported in April 2023 As previously mentioned, April saw a major data breach reported that affected 3,037,303 individuals – The third largest breach to be reported by a single HIPAA-covered entity so far this year, and the 19th largest breach to be reported by a single HIPAA-regulated entity to date. The breach occurred at the HIPAA business associate, NationsBenefits Holdings, and was a data theft and...
Updated Pennsylvania Breach of Personal Information Notification Act Now in Effect
the 2022 update to the Pennsylvania Breach of Personal Information Notification Act (BPINA) is now in effect. The update broadened the definition of personal information to include medical information, health insurance information, and usernames in combination with a password or security question/answer that allows an account to be accessed. The update to BPINA was signed into law on November 3, 2022, and took effect on May 2, 2023. Medical information is defined as any individually identifiable information contained in an individual’s current or historical record of medical history or medical treatment or diagnosis created by a health care professional. Health insurance information is defined as a health insurance policy number or subscriber identification number in combination with an access code or other medical information that permits misuse of an individual’s health insurance benefits. The updated BPINA applies to state agencies, political subdivisions of the Commonwealth, and individuals or businesses that do business in the Commonwealth of Pennsylvania. A state agency...
Apria Healthcare Breach Affects Up to 1.8 Million Individuals
Apria Healthcare LLC, an Indianapolis-based provider of home medical equipment for sleep apnea, has recently sent notifications to individuals about a historic data breach. Apria was alerted about unauthorized access to some of its systems on September 1, 2021. According to the breach notification letters, steps were immediately taken to mitigate the incident, and Apria worked with a third-party forensics team and the Federal Bureau of Investigation. The investigation confirmed its systems were accessed by an unauthorized individual between April 5, 2019, and May 7, 2019, and again from August 27, 2021, to October 10, 2021. The investigation determined that access was gained to its systems primarily to obtain funds from Apria, rather than to obtain the personal information of patients or employees. While the investigation confirmed that some files containing protected health information were accessed, no evidence of data theft was found; however, data theft could not be ruled out. According to the breach notification sent to the Maine Attorney General, the files on its system that...
Bipartisan Legislation Introduced to Address Rural Hospital Cybersecurity Skill Gaps
New bipartisan legislation has recently been introduced to help address the current shortage of cybersecurity skills at rural hospitals. The Rural Hospital Cybersecurity Enhancement Act was introduced by Sen. Gary Peters (D-MI), chair of the Senate Homeland Security and Governmental Affairs Committee, and Sen. Josh Hawley (R-MO), committee member. Cyberattacks on healthcare organizations have increased significantly over the past few years. These attacks cause considerable disruption to patient care and can put lives at risk and while health systems have increased investment in cybersecurity, many small and rural hospitals lack the necessary resources and struggle to hire skilled cybersecurity professionals. At a recent Senate Homeland Security and Governmental Affairs Committee hearing, cybersecurity experts testified about the current healthcare cybersecurity challenges. Kate Pierce, former CIO and CISO at North County Hospital in Vermont and executive at Fortified Health Security said cybercriminals have shifted their focus and are now actively targeting small and rural...
FTC Proposes Changes to Modernize the Health Breach Notification Rule
The Federal Trade Commission (FTC) has proposed changes to the Health Breach Notification Rule to strengthen the applicability of the Rule to health apps and other emerging direct-to-consumer technologies that collect, store, and transmit identifiable health data. There has been an explosion of health apps and connected devices that collect health data, and those apps and devices are collecting vast amounts of health data. There are also incentives for companies that collect health data to disclose that information to third parties for advertising and other purposes. The Health Insurance Portability and Accountability Act (HIPAA) requires health data to be safeguarded, places restrictions on uses and disclosures of health data, and if a data breach occurs, the HIPAA Breach Notification Rule requires notifications to be issued. While health apps and connected devices may collect health data that would be classed as Protected Health Information under HIPAA if collected by a HIPAA-regulated entity, most health apps and connected devices are not covered under HIPAA. The FTC Health...



