Showing posts with label Civil Rights. Show all posts
Showing posts with label Civil Rights. Show all posts

Tuesday, June 20, 2017

Washington State University experiences a major breach of PHI

The health and wellness services division of Washington State University in Seattle has faced a huge breach of protected health information, but the extent of the tragedy isn’t yet clear.

Local media, involving KUOW a National Public Radio station, have reported the breach affects 1 million people, but the HHS Office for Civil Rights, which enforces the HIPAA privacy and security rules, hasn’t publicly confirmed that number.

On the day of April 21, the Washington State University discovered that a hard drive was stolen from a locked safe. The hard drive held back-up files from a server utilized by the Social and Economic Sciences Research Center, which involved a health survey that collected PHI.

Breached data from the health and wellness services division covered data of sufferers of medical and dental clinics, vision clinics, behavioral health organizations and local pharmacies.

Compromised data included Social Security numbers, names and undisclosed personal health information. Entities giving the information included school districts and community colleges, along with other undisclosed customers.

Washington State University is providing affected individuals one year of credit monitoring and identity theft protection services. Notification letters were mailed on the day of June 9, and the university is inquiring individuals who believe they may have been affected and have not got a letter by June 30 to call a dedicated hot line.

“As president of Washington State University, I deeply regret that this tragedy occurred and am truly sorry for any concern it might cause our community,” Kirk H. Schulz claimed in the notification letters. He pledged to strengthen IT operations through a comprehensive assessment of IT practices and policies, as well as improving security awareness training of employees.

The university refused to give additional information on the incident.

 

Wednesday, May 24, 2017

Medical device theft at SSM Health Orthopedics affects the data of 836 patients

A medical device that records physiological information was stolen on the day of April 12 from SSM Health Orthopedics, which operates out of SSM Health-owned DePaul Hospital in St. Louis, potentially impacting the data of 836 sufferers.

The agency said the medical device, which looks similar to a laptop computer, contained in its memory certain physiological data as well as protected health information from sufferers who participated in a study between the time period of 2002 and 2017. The agency notified the sufferers that some of their protected health information has been compromised.

These sufferers had one of 2 electro diagnostic studies, called EMG or NCS, and the electromyography medical device recorded electrical activity in muscle tissue to assess health of the muscles and corresponding nerve cells. Compromised information involved first and last names, dates of birth, medical record numbers and chief complaints. No financial, address, phone or Social Security information was compromised. SSM Health privacy specialist Mackenzie Schlotz said in a letter sent to patients that the organization does not believe patients are at risk for identity theft deployed on the limited data on the device.

“It is likely that the intention of the theft was to steal the medical device, which resembles a laptop computer, and not health data,” Schlotz added. “There is no proof to recommend that the limited health information contained on the medical device has been misused in any manner.”

SSM Health Orthopedics has instituted new controls, and will conduct further training of staff and management on the managing of patient information.

The agency has 2 previous major data breaches listed on the HHS Office for Civil Rights breach web site. In the year of October 2013, the theft of a laptop at Janesville Hospital in Wisconsin affected 631 sufferers. In the year of October 2015, an unauthorized access to paper or films at SSM Health Cancer Care in Missouri affected 643 patients.

SSM Health Orthopedics refused to provide more information on the most recent incident, however it did corroborate the information it sent out to affected patients by letter.

 

Tuesday, May 23, 2017

Organizations informing data breaches faster to federal agencies

The Department of Health and Human Services’ OCR (Office for Civil Rights) is cracking down on providers that don’t report data breaches of protected health information in a basic timely manner. OCR in the month of March initiated to fine agencies that don’t notify federal agencies of breaches within sixty days as required. The effect has been dramatic—average reporting times for breaches were merely 45 days in the month of March and 59 in the month of April, compared with 478 days in February, in accordance to Protenus, a vendor that offers a cloud platform to monitor and secure the security of hospital electronic health records (EHRs).

“It is complex to know for sure with limited information, but we might recommend 2 reasons for this trend of reduced breach reporting time,” claims Robert Lord, co-founder and CEO at Protenus. “One potential reason is that initiating earlier this year, HHS has arguably stepped up enforcement on healthcare agencies that don’t report breaches within the required 60-day window. Organizations are informing data breaches faster to federal agencies.

“An extra potential reason is that healthcare agencies are becoming more diligent in their analysis and reporting of breaches, as awareness of the significance of reporting grows,” Lord continues. “While these tragedies are unfortunate, they can be utilized as a learning experience to educate other covered entities on best practices.”

The number of days between when a breach occurred and when it was discovered in the month of April ranged from almost instantly to 228 days. Organizations are informing data breaches faster to federal agencies.

In April, 16 hacking tragedies accounted for 47% of all breaches. Additionally, another 29% were caused by insiders; 15% involved lost or stolen information and 9% by unknown means. The total number of records breached in the April attacks for which Protenus has numbers includes 171,268 patients.

The kinds of breaches reported last month involve providers (79% of all incidents), health insurers (5.8%), business associates or vendors (5.8%) and other (8.8%). Data from the monthly Protenus Breach Barometer report comes from DataBreaches.net.

 

Thursday, May 11, 2017

Memorial Hermann Health System to pay $2.4M Fine for HIPAA violations

Memorial Hermann Health System in the region of Texas will pay a fine of $2.4 million and enter into a 2-year corrective action plan after revealing a sufferer’s protected health information without the patient’s authorization.

In the year of September 2015 a sufferer at a MHHS clinic presented a fraudulent identification card to office staff, which contacted police, and the sufferer was arrested.

MHHS released multiple press releases to fifteen media outlets on the incident and added the sufferer’s name in the title of the release; it also revealed the sufferer’s protected information during 3 meetings with an advocacy group, state representatives and a state senator, as well as on its website.

Moreover, the HHS Office for Civil Rights found during an investigation that the agency also failed to document in a timely manner the sanctioning of workforce members that revealed the patient’s name.

“Senior management should have known that revealing a sufferer’s name on the title of a press release was a clear privacy violation that would induce a swift OCR response,” OCR Director Roger Severino claimed in a statement. “This case reminds us that agency can readily cooperate with law enforcement without violating HIPAA, but that they must nevertheless sustain to secure patient privacy when making statements to the public and elsewhere.”

Among other requirements, the corrective action plan, available here, needs all MHHS facilities to attest their understanding of permissible uses and disclosures of protected health information, involving disclosures to the media.

Memorial Hermann Health System refused to comment.

 

Tuesday, April 25, 2017

Cardiology vendor pays $2.5M Fine for HIPAA violation

CardioNet, a cardiology vendor of ambulatory cardiac monitoring products, has paid a fine of $2.5 million and will execute a two-year corrective action plan under a settlement agreement with the Office for Civil Rights of the Department of Health and Human Services, which implements the HIPAA privacy and security rules.

The sanction follows the 2012 theft of a laptop from a worker’s car that compromised the security of electronic protected health information for 1,391 people.

OCR’s inquiry, in accordance to the agency, discovered that Cardiology vendor had poor risk analysis and risk management procedures in place at the time of the theft; policies and procedures to comply with the security rule still were in draft form and hadn’t been implemented, the enforcement agency asserts.

In its inquiry, OCR further learned that CardioNet, now a part of BioTelemetry, had no final policies or procedures to execute safeguards for protected information, involving those for mobile devices.

“CardioNet failed to enforce the specifications needed to develop a security management process to stop, detect, contain and correct security violations,” OCR pointed out in the resolution agreement.

The company, OCR added, didn’t have procedures governing receipt and removal of media containing electronic protected health information, encryption and movement of these items within its facilities until the year of March 2015. That means CardioNet didn’t take action until it was in trouble, a situation that is usually happening when OCR investigates breaches.

Representatives of CardioNet or BioTelemetry didn’t respond to a request for extra information. The corrective action plan is available here.

 

Friday, April 14, 2017

Feds punishes Metro community provider network with $400,000 Fine for HIPAA violations

Unsuccessful to undertook a risk analysis and establish a risk management plan as required under the HIPAA privacy and security rules has landed a provider agency in trouble with the HHS Office for Civil Rights, leading to a $400,000 fine and imposition of a 3-year corrective action plan. Metro Community Provider Network is a huge federally qualified health center with 21 clinics serving 43,000 primarily poor sufferers in 5 counties throughout the Denver region. Its services involve primary care, pharmacy, dental, social work and behavioral health.

In the month of January 2012, Metro Community Provider Network informed OCR that a hacker accessed workers’ email accounts through a phishing attack and gained electronic protected health information on 3,200 people. “OCR’s investigation disclosed that MCPN took important corrective action related to the phishing tragedy; although, the investigation also unveiled that MCPN failed to conduct a risk analysis until the year of mid-February 2012,” the agency asserts in a statement.

When MCPN ultimately conducted a risk analysis, it and subsequent risk analyses weren’t enough to meet HIPAA security rule requirements, in accordance to OCR.

OCR has now levied huge sanctions against almost 50 HIPAA covered entities. Although, starting in the year of 2016, OCR has ramped up HIPAA enforcement actions and is levying considerably higher fines, concentrating on covered entities’ requirement to have viable risk assessment programs in place. Fines levied against providers in the year of 2016 and 2017 have ranged from $2.14 million to $5.55 million.

However, in the declaration of sanctions against Metro Community Provider Network, OCR appeared to provide the organization a financial break due to the nature of the work it does. “With this settlement amount, OCR considered MCPN’s status as a federally qualified health center when balancing the importance of the violation with MCPN’s capability to maintain sufficient financial standing to make sure the provision of ongoing care.”

In response to an appeal for comment, Metro Community Provider Network released the following statement:

“In the year of 2011, Metro Community Provider Network (MCPN) had a phishing tragedy which was reported to Health and Human Services and the Office for Civil Rights. Since that time, the agency has worked with these entities to assure HIPAA compliance, involving reaching an agreed upon settlement of $400,000. MCPN is happy with the work that has been done and continues to assure that sufferer privacy is protected.”

The resolution agreement and corrective action plan are available here.

Wednesday, December 14, 2016

Breach: Quest Diagnostics breach impacts 34,000 individuals’ info

Quest Diagnostics, a famous nationwide healthcare laboratory chain that also sells a suite of information management systems, has informed 34,000 people about Quest Diagnostics breach that few of their protected health information was compromised after an internet application on its network was suddenly hacked.


The impacted application was MyQuest, a patient portal enabling people to access health information and test results from Quest Diagnostics. The app also enables people to schedule an appointment, share health information, and it helps in offering tracking and reminders on medication.


Accessed data involved patient names, lab results, birth dates and few telephone numbers, in accordance to a statement from the company. Social Security numbers, credit card numbers, insurance data and financial data weren’t impacted. Evaluation of information systems sustains to be ongoing.


“There is no prove that information of people has been misused in any way,” the company claimed in a statement. The company is not providing credit and/or identity theft protection services, in accordance to a spokesperson, but sufferers with key concerns are encouraged to call Quest at 888-320-9970.


This tragedy, which will be posted on the HHS Office for Civil Rights web site of breaches impacting 500 or more people, is the 1st major breach for Quest as Quest Diagnostics breach.


 

Tuesday, November 29, 2016

UMass agrees to pay fine of $650,000 for exposing electronic health records

The University of Massachusetts Amherst (UMass) has accepted to pay the federal government a fine of $650,000 to settle a 3-year-old healthcare privacy violation of exposing electronic health records that resulted from a malware infection. That’s why it has agreed to pay fine of $650,000 for exposing electronic health records.


In the year of June 2013, the center of university for language, speech and hearing reported a malware infection to the U.S. Department of Health and Human Services Office for Civil Rights that resulted in the unauthorized disclosure of the personal health and financial data of over 1,670 people. The malware infection had resulted in the unauthorized exposure of a host of sensitive information involving sufferer names, addresses, Social Security numbers, and dates of birth, health insurance information, diagnoses and procedure codes.


Few details about the malware attack are vague, like how many unauthorized users had access to the sufferer information and for how long. The University of Massachusetts Amherst claims that the information breach happened due to a Trojan horse attack, a kind of malware that is mostly disguised as legitimate software.


The federal government levied the fine in huge measure because at the time period the University of Massachusetts Amherst did not have a firewall in place securing the electronic health records at its center for language, speech and hearing. “UMass failed to execute technical security measures at the Center to guard against unauthorized access to electronic protected health information transmitted over an electronic communications network by ensuring that firewalls were in place,” in accordance to a statement from the Office for Civil Rights, the branch of the federal government that enforces The Health Insurance Portability and Accountability Act of 1996, or HIPAA, a law that targets to ensure the confidentiality of sufferer medical records.


The Office for Civil Rights determined that in hindsight University of Massachusetts Amherst should have implemented a better job ensuring that the center for language, speech and hearing was part of a protective electronic health network that complied with HIPAA and had adequate firewalls in place to stop the unauthorized approach. The federal government also fined the University for not performing a precise and thorough risk analysis until the month of September 2015 and was enabled of exposing electronic health records.


In addition to the monetary settlement, the UMass has accepted to a corrective action plan that needs it to perform an enterprise-wide risk analysis and establish and implement a risk management plan, claims the Office for Civil Rights.


The UMass also has been needed to revise its policies and processes and train its staff on the HIPAA safeguards being put in place. “HIPAA’s security needs are a significant tool for securing both patient information and business operations against threats like malware,” claims Office for Civil Rights director Jocelyn Samuels.



 

Thursday, November 24, 2016

UMass Amherst Agrees to Pay $650,000 HIPAA suit Fine

The Institute of University of Massachusetts Amherst has accepted to pay $650,000 to settle potential violations of the Health Insurance Portability and Accountability Act.


The fine is lower than it might have been and the $650,000 settlement depicts the fact that the university operated at a financial loss in the year of 2015, in accordance to a statement from the Office for Civil Rights, which oversees HIPAA enforcement.


The breach happened on June 18, 2013, when a workstation in the university’s Center for Language, Speech, and Hearing was infected with a malware program. This resulted in the impermissible disclosure of electronic protected health information of 1,670 people, involving names, addresses, social security numbers, dates of birth, health insurance information, diagnoses and procedure codes.


In this situation, the malware was a generic remote access Trojan that infiltrated the system, the university evaluated. It gave impermissible access to ePHI, because UMass didn’t have a firewall in place.

Monday, July 25, 2016

U-Miss Medical Center receives $2.75M fine for HIPAA breaches

The HHS Office for Civil Rights is continuing its frustrating attempt of sanctioning covered entities and business associates who’ve run afoul of HIPAA security principles, this time taking target at University of Mississippi Medical Center.


UMMC will pay a $2.75 million penalty and stepped into the resolution compliance and corrective action policy after an OCR inquiry determined the hospital was aware of susceptibilities to protected health data since at least the month of April 2005—the compliance information of the HIPAA Security Principle. The agency asserts that the agency took no meaningful action to reduce threat until after the theft of a laptop in the year of 2013. While the computer was password secured, it wasn’t encrypted.


OCR also referred the fact that, while the hospital gave notice of the violation on its web site and to regional media, it didn’t notify sufferers whose data was on the stolen laptop.


“OCR’s inquiry disclosed that ePHI stored on a UMMC network drive was susceptible to unauthorized approach through UMMC’s wireless network because consumers could access an active directory consisting of 67,000 files after giving a generic username and password,” in accordance to an OCR statement. “The directory involved 328 files consisting of the ePHI of an assumed 10,000 sufferers dating back to the year of 2008.”


In the resolution compliance, OCR claimed the hospital failed to execute suitable policies and procedures to comply with HIPAA and protect information. UMMC got agreed to the resolution agreement, but pointed out that the acceptance isn’t an admission of liability.


OCR charged that UMMC had not executed security steps enough decrease the threats and susceptibilities to reasonable and suitable levels; failed to execute safeguards for all workstations approaching ePHI; failed to allocate a distinctive username or number for recognizing and detecting users; permitted workers to access ePHI on a shared department network drive through a generic account that stopped tracking; and failed “to notify each person whose unprotected ePHI was reasonably considered to have been accessed, acquired, utilized or revealed as an outcome of the violation” after the discovery of the violation.


In a 3-year corrective action policy, UMMC commits to designate a qualified worker to be the internal monitor of agreement with the plan, with at least 46 particular milestones of agreement hoped to be completed.


In a statement, UMMC notes it has began substantial improvements in data security in recent years. Improvements involve encryption of entire laptops; remaking of the role and reporting relationships of the chief information security officer; and executing an external assessment and overhaul of its information technology security program.


“Our sufferers should never have to doubt that their security or privacy is a divine trust that we’re devoted to securing as part of our primary ethical values,” claims LouAnn Woodward, MD, vice chancellor for health affairs, in the statement. “We’ve learned from this experience and are working hard to make sure that our data security program meets or exceeds the largest standard.”

Monday, April 25, 2016

NYP punished with $2.2M fine for HIPAA breach in filming TV series

New York-Presbyterian Hospital has been punished with $2.2 million under sanctions given by the HHS Office for Civil Rights and has stepped into a corrective action policy for unauthorized filming of 2 sufferers while engaging in the “NY Med” television series.


It was the 2nd HIPAA violation for the New York-Presbyterian Hospital (NYP), which 2 years ago paid $3.3 million and Columbia University paid $1.5 million following a 2010 violation in which protected health data on a shared data network was discovered to be approachable on Google and other various Internet search engines.


The HHS Office for Civil Rights claimed the greatest violation was an outcome of errors in NYP’s judgment in permitting filming of the TV series.


 “In specific, OCR discovered that NYP permitted the ABC crew to film someone who was dying and another person in important distress, even after a medical expert emphasized the crew to stop,” an agency stated.


Overall, OCR discovered that NYP offered the network “virtually unfettered approach to its healthcare facility,” which made an atmosphere where PHI could not be secured. “This case sends a significant message that OCR won’t allow covered entities to compromise their sufferers’ privacy by permitting news or TV crews to film the sufferers without their authorization,” OCR Director Jocelyn Samuels claimed in the announcement.


Under a proposed resolution agreement with OCR, the hospital has stepped into a two-year corrective action policy that involves establishing the new policies and processes to make sure that photography, video or audio recordings—for purposes not regarded to the provision of medical care—can just be done with authorization from a sufferer or the patient’s personal representative.


A range of other compulsory policies and processes will govern various problem regarded to such recordings. Particular workforce HIPAA privacy training policies also are spelled out.


NYP released the following statement on the regulatory sanctions:


“New York-Presbyterian reached agreement with the Office for Civil Rights in case to bring closure to OCR’s review procedure.


“Our involvement in the ABC News documentary program “NY Med” was proposed to educate the public and give insight into the complications of medical care and the regular challenges confronted by our dedicated and compassionate medical professionals. This program, and others that preceded it, garnered much acclaim, and raised the public’s consciousness of significant public health problems, involving organ transplantation and donation. It also vividly expressed how our emergency department medical team operates tirelessly each day to save sufferers’ lives. The hospital sustains to maintain that the filming of this documentary program didn’t violate the HIPAA Privacy Rule.”


 

Monday, March 14, 2016

Bizmatics discloses the secret that it was hacked

Unknown figures of contributors are affected after the hacking of Bizmatics Inc., a popular vendor of ambulatory care software and revenue cycle management services.


Bizmatics, in business for more than fifteen years and facilitating 15,000 medical experts in accordance to its Web site, offers regionally hosted and cloud-hosted systems.


Complete Family Foot Care in the Lincoln, Neb., is believed to be one of the victims and has mailed a pervious notice to sufferers—with a proposed formal HIPAA notice now being mailed—and is providing 1 year of identity protection services from the IdentityForce.


Bizmatics and the practice performed an investigation to evaluate which sufferers may have been impacted, but they yet do not really know, the notice from the foot care practice elaborates.


“Regrettably, we can’t determine at this period which, if any, of our sufferers’ files might have been approached. Bizmatics’ servers consists of a huge number of patient files from a great number of healthcare providers; it may well be that none of our sufferers’ files were approached or compromised in any way. Nonetheless, because of the threat that your data might have been checked, we consider that it is significant that you are informed regarding the tragedy.”


Compromised protected health data may have involved names, addresses, Social Security numbers, health insurance numbers, diagnoses and treatments. Credit/debit cards and financial data were not impacted at Complete Family Foot Care. The breach happened sometime in the year 2015, and the practice was notified in the month of January 2016.


It is not yet obvious if all sufferers possibly affected by the Bizmatics breach will get protective services, or merely those who consider they have become a victim of ID theft. Bizmatics and Complete Family Foot Care didn’t instantly response to an appeal for extra data. The HHS Office for Civil Rights also didn’t respond to an appeal for data.


Thursday, February 25, 2016

Office for Civil Rights issues crosswalk between HIPAA, NIST Cybersecurity Plan

Targeting to assist HIPAA covered entities strengthen their cybersecurity preparedness, HHS Office for Civil Rights have issued a crosswalk recognizing mappings between NIST's Framework for Improving Critical Infrastructure Cybersecurity and the HIPAA Security Rule.


Established in partnership with NIST and ONC, the crosswalk also involves mappings to other commonly utilized security frameworks, officials stated.


In the month of February 2014, NIST issued the framework to help agencies better understand and handle cybersecurity risks. Many agencies in healthcare and other industries voluntarily depend on detailed security guidance and particular standards published by NIST.


Entities bound by HIPAA, meanwhile, are needed to implement powerful data security safeguards to comply with the HIPAA Security Rule and secure the health data they make, receive, maintain or transmit.