Health Share of Oregon Notifies 654,000 Members About Business Associate Data Breach
Oregon’s Medicaid coordinated-care organization, Health Share of Oregon, is notifying approximately 654,000 current and former members that some of their protected health information (PHI) was stored on a laptop computer stolen from its transportation vendor, GridWorks. GridWorks was contracted to manage Health Share’s Ride to Care program, through which Health Share provided non-emergent transportation for its members. Health Share’s HIPAA compliance policies require business associates to use encryption on all portable devices containing patient information but, for reasons unknown, the GridWorks laptop was not encrypted. PHI stored on the laptop computer included names, addresses, contact telephone numbers, birth dates, Health Share ID numbers, Medicaid numbers, and Social Security numbers. The laptop was stolen in a burglary at GridWorks’ office in November 2019. GridWorks notified Health Share about the laptop theft on January 2, 2020. Health Share started sending notification letters on February 5 to all individuals whose PHI was stored on the laptop. Affected individuals...
Medtronic Issues Patches for CareLink Programmers and Implanted Cardiac Devices
The medical device manufacturer Medtronic has issued patches to correct flaws in its CareLink 2090 and CareLink Encore 29901 programmers, implantable cardioverter defibrillators (ICDs), and cardiac resynchronization therapy defibrillators (CRT-Ds). The vulnerabilities were first identified by security researchers in 2018 and 2019. When Medtronic was informed about the vulnerabilities, mitigations were quickly published to reduce the risk of exploitation of the vulnerabilities and allow customers to continue to use the affected products safely. The development and release of patches for these complex and safety-critical devices has taken a long time due to the required regulatory approval process. “Development and validation can take a significant amount of time and also includes a required regulatory review process before we can distribute updates to products. Medtronic worked to develop security remediations quickly while also ensuring the patches continue to maintain comprehensive safety and functionality,” explained Medtronic. In 2018, Security researchers Billy Rios and...
Annual Cost of Insider Cybersecurity Incidents Has Risen 31% in 2 Years
The frequency of cybersecurity incidents caused by insiders has increased by 47% in the past two years and the average annual global cost of those cybersecurity incidents has increased by 31% over the same period, according to new research conducted by the Ponemon Institute. The average annual cost of insider incidents is now $11.45 million. The research was conducted for the 2020 Cost of Insider Threats study on behalf of the Proofpoint company, ObserveIT. 964 IT and security professionals at 204 organizations in North America, Europe, Africa, the Middle East and Asia-Pacific were surveyed for the study. Insider incidents were divided into three categories: Incidents that resulted from mistakes made by employees (negligent insiders); incidents deliberately caused by employees and contractors to harm the company (criminal insiders); and incidents involving the use of insiders’ login details to gain access to applications, systems, and data (credential insiders). In the past 12 months, 4,716 insider incidents occurred. Incidents caused by credential insiders were the costliest to...
Florida Clinic Worker Facing 22 Years in Jail for Wire Fraud and Aggravated Identity Theft
A former medical clinic worker in Florida who impermissibly accessed the HIPAA protected health information of patients and sold the information to identity thieves has pleaded guilty to wire fraud and aggravated identity theft. Stacey Lavette Hendricks, 49, of Leesburg, FL, had previously been employed as an administrative worker at several state medical clinics in Florida. Her role gave her access to the protected health information of patients. Hendrinks used her access to steal patient information from the unnamed medical clinics, including names, dates of birth, and Social Security numbers. That information was sold to identity thieves for cash and was also used to defraud businesses. The United States Secret Service investigated the case. Hendricks was apprehended after she attempted to sell stolen patient information to an undercover law enforcement officer. A warrant was obtained to search her home and car and law enforcement officers found patient information stolen from the clinics related to 113 different patients. Hendricks was charged in the United States District...
HHS Issues Final Rule Requiring Pharmacies to Track Partially Filled Prescriptions of Schedule II Drugs
The Department of Health and Human Services has issued a final rule modifying the HIPAA National Council for Prescription Drug Programs (NCPDP) D.0 Telecommunication Standard that requires pharmacies to track partially filled prescriptions for Schedule II drugs. The modification is part of HHS efforts to curb opioid abuse in the United States and will provide a greater quantum of data that may help prevent impermissible refills of Schedule II drugs. The final rule takes effect on March 24, 2020. The compliance date is September 21, 2020. By September 21, 2020, pharmacies will be required to use the Quantity Prescribed (460-ET) field for retail pharmacy transactions for all Schedule II drugs. Pharmacies must distinguish in retail pharmacy transactions whether the full prescribed amount of a Schedule II drug has been dispensed in a refill, or if the prescription has only been partially filled. Background The NCPDP Telecommunication Standard was adopted by the Secretary of the HHS in January 2009 for pharmacy transactions (health care claims or equivalent encounter information,...



