Online Alcohol Counseling Service Provider Reports 109K-record Tracking Tool Data Breach
Monument Inc., a New York-based online alcohol addiction and treatment service provider, has recently notified almost 109,000 individuals about an impermissible disclosure of some of their personal and protected health information. The disclosure occurred due to the use of tracking code on its websites. Monument explained in its breach notification letters that an internal review was conducted in late 2022 into the use of website tracking tools after guidance was issued by the HHS’ Office for Civil Rights on pixels and other tracking tools and how they may violate the HIPAA Rules. The internal review was completed on or around February 6, 2023, and it was determined that the tools on its websites potentially transferred identifiable protected health information to third parties who were unauthorized to receive the information, as consent to disclose that information was not obtained and there were no business associate agreements with the companies that provided the tools. The tracking tools were provided by Google, Facebook (Meta), Pinterest, and Bing, and while present on the...
ILS Data Breach Affects Almost 21K Iowan Medicaid Recipients
The Iowa Department of Health and Human Services (DHHS) has confirmed a HIPAA compliance breach where the personal information of 20,815 Iowans who receive Medicaid was exposed in a cyberattack at a subcontractor of one of its business associates between June 30, 2022, and July 5, 2022. Telligen performs annual assessments on Medicaid recipients for the Iowa DHSS. Telligen subcontracted part of the work to Independent Living Systems (ILS), and it was the systems of ILS that were breached. While ILS discovered the breach in July 2022, it took until February 14, 2023, for Telligen to be notified about the breach. Telligen notified the Iowa DHSS three days later on February 17, 2023. The DHSS will be sending notification letters to the affected individuals over the next few days. Independent Living Systems reported the breach to the HHS’ Office for Civil Rights using a 501 placeholder until the number of affected individuals is determined; however, the breach was reported to the Maine Attorney General as affecting more than 4 million individuals. You can read more about the...
Revised American Data Privacy and Protection Act Due to be Released
Last month, the U.S. House of Representatives’ Committee on Energy and Commerce held the third of three scheduled meetings ahead of a release of a new draft of the American Data Privacy and Protection Act (ADPPA), which is edging closer to being the first, comprehensive federal privacy legislation to be signed into law in the United States. There is a clear need for greater privacy protections for Americans. Big tech firms are collecting huge volumes of sensitive data on Americans and there are few restrictions on how consumer data can be collected, used, and shared. There is mounting concern over the collection and use of the data of minors, the serving of targeted advertisements to children and teenagers based on the personal data collected by tech firms, and the sheer volume of data that is being collected on all Americans. Currently, privacy regulations are implemented at the state level, and they can vary vastly across the country. ADPPA seeks to address this by placing restrictions on the collection and use of consumer data at the federal level and replacing the current...
Insight Global Settles Class Action Data Breach Lawsuit
Insight Global LLC has agreed to settle a class action lawsuit that was filed in response to an April 2021 data breach that exposed the contact tracing data of more than 76,000 Pennsylvania residents. Insight Global was appointed the administrator of Pennsylvania’s contact tracing program during the pandemic. Performing the contracted duties required Insight Global to collect a range of sensitive information including names, telephone numbers, email addresses, sexual orientation, family size, health data, indications of exposure to COVID-19, and whether individuals required any support services. Several Insight Global employees created Google accounts to share information, including documents and spreadsheets containing contact tracing data. When the unauthorized accounts were discovered, Insight Global instructed its employees to stop using the accounts and ensure information was secured. The issue with using unauthorized Google accounts was sensitive data was sent to servers that were outside the control of Insight Global and could potentially be accessed by unauthorized...
Unlimited Care and Nonstop Administration and Insurance Services Confirm PHI Exposure
The White Plains, NY-based home healthcare provider, Unlimited Care Inc., was the victim of a cyberattack that caused disruption to its network on February 16, 2023. Unlimited Care engaged a third-party cybersecurity firm to assist with the investigation and determine the nature and scope of the incident. The investigation is ongoing, but around March 21, 2023, it was determined that unauthorized individuals had access to parts of its network that contained sensitive data, and that information may have been viewed or acquired by the attackers. The information confirmed as exposed includes employee names, addresses, birth dates, and Social Security numbers. The breach was reported to the Maine Attorney General as affecting up to 29,066 individuals. Complimentary identity theft protection services have been offered to those individuals. The breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 8,453 individuals. Unlimited Care said it initiated a global password reset, has deployed the Carbon Black endpoint detection and...



