The HIPAA Journal is the leading provider of news, updates, and independent advice for HIPAA compliance

Montefiore Medical Center Fires Employee for Unauthorized Record Access

Montefiore Medical Center has discovered another employee has accessed patient information with no legitimate work reason for doing so.

The New York hospital announced in February 2020 that an employee had been discovered to have accessed medical records without authorization for 5 months in 2020, and another employee was found to have obtained the PHI of approximately 4,000 patients between January 2018 and July 2020.

The latest discovery involved an employee accessing the records of patients without authorization for more than a year. The breach was identified by Montefiore’s FairWarning software, which monitors records for inappropriate access.

When unauthorized medical record access was discovered, the employee was suspended pending an investigation. A review of record access confirmed that the employee had accessed records with no legitimate work reason for doing so between January 2020 and February 2021.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The types of information accessed varied from patient to patient and included first and last names, medical record numbers, addresses, emails, dates of birth, and the last 4-digits of Social Security numbers. Montefiore found no evidence that financial information or clinical information was accessed.

The unauthorized record access violated Montefiore’s policies and HIPAA. The employee was fired, and the matter was referred to law enforcement for possible criminal prosecution. The OCR breach portal indicates 943 individuals were affected.

Belden Facing Class Action Lawsuit Over November 2020 Data Breach

Belden, a U.S. vendor of networking equipment, is facing a class action lawsuit over a November 12, 2020 data breach in which the personal information of current and former employees was compromised. Hackers gained access to a limited number of file servers and exfiltrated employee data and information about some of its business partners.

The breach has recently been reported to the HHS’ Office for Civil Rights as involving the protected health information of 6,348 individuals. Names, Social Security numbers, tax identification numbers, financial account numbers, home addresses, email addresses, dates of birth and other employment-related information were stolen. Belden announced the breach on November 24, 2020 and started notifying affected individuals on December 14, 2020.

The lawsuit, Edke v. Belden Inc., alleges the plaintiff and class members have been harmed as a result of the breach and had to wait several weeks before being notified that their personal information had been stolen. They allege the data breach has placed them at “significant risk of identity theft and various other forms of personal, social, and financial harm.” The lawsuit alleges Belden was careless and negligent, and security failures at the company allowed patient data to be stolen.

Author: Steve Alder is the editor-in-chief of HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist