Update: CorrectCare Integrated Health Data Breach Affects Hundreds of Thousands of Inmates
The medical claims processor, CorrectCare Integrated Health, has recently notified its clients that the protected health information of some of their patients was accidentally exposed over the Internet and may have been accessed by unauthorized individuals. On July 6, 2022, CorrectCare discovered two file directories on its web server had been misconfigured and could be accessed over the Internet without authentication. The breach has affected patients treated by Mediko, Inc. – the largest provider of health care services to individuals in correctional facilities in Virginia. Mediko has reported the HIPAA breach to the HHS’ Office for Civil Rights (OCR) as affecting 2,809 individuals. Sacramento County Adult Correctional Health says 5,372 individuals have been affected, and the Louisiana Department of Public Safety and Corrections says 85,466 individuals incarcerated in facilities in the state have been affected. Health Net Federal Services (HNFS) in California, a business associate of the California Correctional Health Care Services (CCHCS)/ California Department of...
Pennsylvania Updates Data Breach Notification Law
The Governor of Pennsylvania, Tom Wolf, has signed Senate Bill 696 into law, which expands the definition of personal information under the Breach of Personal Information Notification Act that warrants individual notifications to be issued in the event of a data breach. The updated law will take effect on May 2, 2023. The updated definition of personal information now includes medical information, health insurance information, and usernames and passwords. Notifications must be issued if any of that information is breached along with the name of a state resident. Medical information is classed as individually identifiable information related to an individual’s current or past medical condition, diagnosis, or treatment that has been created by a healthcare professional. Health insurance information includes a health insurance policy number or subscriber number, combined with an access code or other information that would allow the misuse of an individual’s insurance benefits. Breaches of usernames also require notifications, if the password is also compromised or any other...
Five Former Tennessee Hospital Employees Charged with Criminal HIPAA Violations
Five former employees of Methodist Hospital in Tennessee have been indicted by a federal grand jury in Memphis for criminal violations of the Health Insurance Portability and Accountability Act (HIPAA) for impermissibly accessing the protected health information of patients and providing that information to another individual for financial gain. According to the indictment, between November 2017 and December 2020, Roderick Harvey, 40, conspired with five former hospital employees and paid them to provide him with the names and telephone numbers of patients who had been involved in motor vehicle accidents. Harvey then sold that information to third parties such as personal injury lawyers and chiropractors. The former Methodist Hospital employees – Kirby Dandridge, 38, Sylvia Taylor, 43, Kara Thompson, 30, Melanie Russell, 41, and Adrianna Taber, 26 – and Harvey were charged with conspiracy to obtain patient information with the intent to sell, transfer or use such information for personal gain, the maximum penalty for which is five years in jail, three years of supervised...
New York Provider of Administrative Anesthesiology Services Facing Multiple Class Action Data Breach Lawsuits
A New York-based physician-owned provider of administrative services to anesthesiology firms is facing several class action lawsuits over a cyberattack and data breach that has affected at least 24 entities and involved the exposure and potential theft of the protected health information of more than 450,000 patients. Anesthesiology firms started reporting data breaches to the Department of Health and Human Services’ Office for Civil Rights in September 2022, with the notification letters to patients indicating there had been a data breach at their anesthesia management services organization. The notification letters failed to name that company. According to the notification letters, the management services organization detected the cyberattack on or around July 11, 2022, or July 15, 2022 – two templates were used by the affected firms that had different dates. The forensic investigation determined the attackers had access to parts of its system that contained the protected health information of patients, including names, Social Security numbers, dates of birth, driver’s license...
CISA Releases Decision Tree Methodology for Assessing and Remediating Software Vulnerabilities
CISA has issued a decision tree methodology that can be adopted by healthcare organizations to help them develop an efficient and effective vulnerability management program. The Importance of an Efficient Patch Management Program When it comes to vulnerability management, the best practice is to patch promptly. When software updates and patches are released, they should be applied as soon as possible to prevent bad actors from exploiting the flaws. In practice, promptly patching all vulnerabilities can be a major challenge due to the sheer number of patches and software updates that are being released, and nor is it wise, as vulnerabilities are not all equal. Some are much more likely to be exploited than others and the impact of the successful exploitation of vulnerabilities can vary considerably. When it comes to vulnerability management, IT teams need to prioritize patching and deal with critical and actively exploited vulnerabilities first. Healthcare organizations with mature vulnerability management programs are more likely to have efficient processes for vulnerability...



