Wisconsin Department of Health Services Reports Breach of 12,000 Records
A round-up of healthcare data breaches that have recently been reported to the HHS’ Office for Civil Rights, state attorneys general, and the media. Wisconsin Department of Health Services: Accidental Disclosure of PHI via Email The Wisconsin Department of Health Services (DHS) has recently confirmed that there has been an accidental disclosure of protected health information via email. According to the breach notice, a presentation was emailed to the DHS Children’s Long-Term Support Council in April 2021 that contained protected health information. The presentation was then forwarded by the Council to employees working for certain county government agencies and the presentation was posted to the DHS website as part of the meeting minutes. The error was detected on August 8, 2022, and the file was removed from the meeting minutes and replaced with a file that did not provide access to PHI. Steps were also taken to recover all distributed copies of the presentation. The presentation contained the following types of information: first and last names, date of birth, gender, county...
How Does HIPAA Improve Healthcare?
Questions are often sent to HIPAA Journal about the Health Insurance Portability and Accountability Act, one of which is how HIPAA has improved healthcare. In this article, I explain some of the main ways that healthcare has been improved by HIPAA for healthcare providers, health plans, and patients. How Does HIPAA Improve Healthcare? There has been a lot of criticism about HIPAA in the past and it continues to be a pain point for many healthcare providers. Compliance with the HIPAA Rules can be challenging, and healthcare professionals may feel that HIPAA unnecessarily limits their ability to deliver healthcare efficiently. While the HIPAA Rules may be a cause of frustration and seem overly restrictive is some respects, HIPAA has done a great deal to improve healthcare. To appreciate some of the key benefits of this landmark piece of healthcare legislation, you need to cast your mind back to before HIPAA was signed into law in 1996 – Several years prior to the introduction of the HIPAA Privacy and Security Rules, for which HIPAA is now best known. HIPAA Made Health Insurance...
Email Breach at CSI Laboratories Impacts Almost 245,000 Patients
Cytometry Specialists, Inc., doing business as CSI Laboratories in Alpharetta, GA, has recently announced that the email account of an employee has been accessed by an unauthorized individual, who may have viewed or obtained the protected health information of 244,850 patients. CSI Laboratories is a leading cancer testing and diagnostics laboratory that serves pathologists, oncologists, and community hospitals throughout the U.S. The email account breach was detected on July 8, 2022, and the account was immediately secured. The investigation into the incident indicates the purpose of the attack was to use the email account in a business email compromise (BEC) attack to redirect CSI customer health care provider payments to an account under the control of the attacker by posing as CSI using a fictitious email address, rather than to obtain patient information; however, the breach investigation confirmed on July 15, 2022, that certain files had been copied from the employee’s mailbox that contained patient information. The files related to invoices sent to CSI Health Care provider...
PHI Exposed in Data Incidents at Anthem, WellMed Medical Management and CareOregon
Anthem has confirmed that the protected health information of certain plan members has been compromised in a data breach at its vendor, Choice Health. Choice Health was provided with the data of plan members to perform its contracted duties. On August 5, 2022, Anthem discovered that an unauthorized individual had gained access to a database and downloaded files containing plan members’ protected health information, including names, addresses, dates of birth, phone numbers, email addresses, Medicare ID numbers, and Medicaid ID numbers. The database was accessible over the Internet due to a misconfiguration by a third-party service provider and was accessed and downloaded on May 7, 2022. Choice Health confirmed that the database has now been secured and that steps have been taken to improve its data security measures to prevent similar incidents in the future, including implementing multi-factor authentication for access to database files. Affected individuals have been offered complimentary credit monitoring services. The breach affected several Choice Health clients,...
Netwalker Ransomware Affiliate Sentenced to 20 Years in Jail
An affiliate of the infamous Netwalker ransomware gang has been sentenced to serve 20 years in jail for his role in ransomware attacks on entities in the United States. Netwalker is a ransomware-as-a-service (RaaS) operation where affiliates are recruited to conduct attacks and deploy ransomware in exchange for a cut of the ransom payments they generate, typically receiving up to 75% of any ransoms paid. After gaining access to a victim’s network, sensitive data would be identified and exfiltrated and used as leverage to pressure victims into paying. Threats were then issued to publish or sell the data if the ransom is not paid. Ransom demands ranged from hundreds of thousands to millions of dollars. While some RaaS operations ban their affiliates from conducting attacks on healthcare organizations, that was not the case with Netwalker, which actively targeted healthcare organizations around the world. The gang also stepped up attacks on the sector during the COVID-19 pandemic. Victims included the Champaign-Urbana Public Health District and the University of California San...



