Allscripts Proposes $145 Million Settlement to Resolve DOJ HIPAA and HITECH Act Case
A preliminary settlement has been proposed by Allscripts Healthcare Solutions to resolve alleged violations of HIPAA, the HITECH Act’s electronic health record (EHR) incentive program, and the Anti-Kickback Statute related to the electronic health record (EHR) company Practice Fusion, which was acquired by Allscripts in 2018. Prior to the acquisition, Practice Fusion has been investigated by the Attorney’s Office for the District of Vermont in March 2017 and had provided documentation and information. Between April 2018 and January 2019, the company received further requests for documents and information through civil investigative demands and HIPAA subpoenas. Then in March 2019, the company received a grand jury subpoena over a Department of Justice (DOJ) investigation into the business practices of Practice Fusion, potential violations of the Anti-Kickback Statute, HIPAA, and the payments received under the HHS EHR incentive program. Scant information has been released about the nature of the alleged violations by Practice Fusion. The proposed settlement will see Allscripts pay...
Email Security Breaches Expose PHI of Seattle Community Psychiatric Clinic Patients
Community Psychiatric Clinic in Seattle, WA, a provider of accredited outpatient, mental health treatment, and counselling services, has experienced two security breaches in which patient information may have been compromised. In both cases, an unauthorized individual gained access to an employee’s Microsoft Office 365 account. The first security breach was detected on March 12, 2019 when an employee’s account was subjected to unauthorized access. The affected account was immediately secured, passwords were changed, and the employee’s hard drive was restored. The email account also had additional protections added to prevent similar breaches from occurring in the future. The investigation did not uncover any evidence to suggest that patient data had been stolen. Around two months later on May 8, 2019, a second email account was discovered to have been compromised in a separate attack. The attacker used the email account to send a fraudulent wire transfer request to another member of staff. The transfer was executed, but due to the fast response of the clinic, it was possible to...
UnityPoint Health Data Breach Lawsuit Partially Dismissed by Federal Judge
A class-action data breach lawsuit filed against UnityPoint Health has been partially dismissed by the US District Court for the Western District of Wisconsin. The lawsuit stems from a phishing attack on UnityPoint Health in February 2018. As a result of employees falling for phishing emails, the attackers were able to gain access to email accounts containing the protected health information (PHI) of 16,429 patients. The investigation into the breach showed access to patient data was first gained on November 1, 2017 and further email accounts were compromised up to February 7, 2018. The types of PHI in the compromised email accounts included names, contact information, diagnoses, medications, lab test results, and surgical information. Some patients also had their driver’s license number and/or Social Security number exposed. One month after the data breach was announced, four patients filed a lawsuit against UnityPoint Health claiming the company had mishandled the breach. The lawsuit also alleged UnityPoint Health had unnecessarily delayed the issuing of breach notification...
PHI of Tens of Thousands of Patients Exposed Online Due to Database Misconfiguration
A database containing the personal information of individuals who had expressed an interest in Amarin Pharma’s cholesterol drug Vascepa® has been exposed online. The database was maintained by a third-party vendor and contained information such as full names, addresses, telephone numbers, email addresses, medications, and interest in a copay card for Vascepa®. Amarin learned of the breach via media reports of an exposed database containing information about Amarin customers and immediately launched an investigation. The company quickly determined which database had been exposed and took steps to suspend active data feeds and the database was secured the same day. The vendor’s investigation revealed a database misconfiguration had occurred which rendered the database accessible online between May 2, 2018, and June 20, 2019. An investigation by the vendor confirmed that the database had been subjected to unauthorized access by a third party between May 29, 2019, and June 20, 2019, and during that time data had been copied. Amarin and its vendor are continuing to investigate the...
Further 185,000 Individuals Affected by AMCA Data Breach
Three more healthcare organizations have announced they have been affected by the data breach at American Medical Collection Agency (AMCA): West Hills Hospital & Medical Center in California, Inform Diagnostics, and CompuNet Clinical Laboratories. The AMCA data breach was first announced more than two months ago. Most of the companies impacted by the breach were notified by AMCA in May/June that some of their patients’ data had potentially been compromised, but it has taken several weeks for those companies to be provided with sufficient information to make announcements and sent notification letters. The breach at AMCA occurred between August 1, 2018 and March 30, 2019. During that period, an unauthorized individual had access to a web payment page, through which it was possible to obtain personal and financial information. Affected individuals had had their information passed to AMCA to collect outstanding bills for medical services. The latest announcements bring the total number of companies known to have been affected to 21. It is not yet known how many patients of West...



