Showing posts with label Attorney General Office. Show all posts
Showing posts with label Attorney General Office. Show all posts

Sunday, June 11, 2017

Medicaid Claim Resolution Worksheet documents with patient information found in dumpster

The North Dakota Department of Human Services has reported the breach of patient information contained on Medicaid claim resolution worksheet documents, impacting the data of almost 2,500 individuals.

The agency reported that one of its workers was supposed to have properly disposed of the forms in secure onsite receptacles that a contractor picks up for shredding. Rather, the Medicaid claim resolution worksheet documents were found on the day of May 10 in a dumpster in Bismarck by a citizen who notified the agency, which retrieved the materials.

Now, NDDHS is notifying 2,452 affected people, offering 1 year of credit and identity theft monitoring services from CSIdentity and has taken “suitable disciplinary action against the responsible workforce member,” according to the patient notification letter.

Protected information at risk was extensive but didn’t involve the most sensitive information about recipients, like addresses, financial information and Social Security numbers.

The compromised information involved recipient names, dates of birth, Medicaid provider numbers, first two characters of providers’ names, recipient Medicaid ID numbers, two-digit code of recipients’ counties, recipients’ internal NDDHS identification numbers, dates of service, amounts billed and allowed, amounts covered by insurance, diagnosis codes, HCPCS/CPT procedure codes and details on dental work.

In the sufferer letter, the agency said it has no evidence of PHI being inadequately used or revealed and believes the risk for disclosure is low.

The North Dakota Department of Human Services is emphasizing affected individuals to review credit reports, request a free fraud alert be placed on credit files and to contact the state Attorney General Office if they become a victim of identity theft.

As is common in breach notifications, the agency apologized for the tragedy and will retain workers and review policies and procedures to ignore another similar incident.

 

Thursday, March 10, 2016

AG: Healthcare Accounted for 16 percent of CA Data Violaions in 2015

Healthcare contributors accounted for 16 percent of all data violations in California previous year and almost one-quarter were the result of hacking and malware, in accordance to a new report released in the month of February.


The 2016 California Data Breach Report from the state Attorney General's Office discovered the healthcare sector was 3rd only to retail (25%) and finance (18%) as the most susceptible to breaches. The healthcare sector was also cited as doing a worst job of encrypting data that is often stolen in physical violations, although it has made better its security in the past 2 years.


"The [healthcare] industry appears to be making better on its utilization of encryption to secure data on laptops and other portable devices, but there is still a long way to go in dealing this preventable kind of breach," wrote state Attorney General Kamala Harris.


Physical breaches, like lost or stolen computers and drives, were still the dominant type of breach in healthcare, accounting for 39 percent of all healthcare breaches in the year 2015 compared to just 13 percent in other business sectors. The report notes that "physical breaches have denied in healthcare the past 2 years," from a high of 72 percent of all healthcare sector breaches in the year 2013.


But the refusal in physical breaches previous year was offset by an increase in malware attacks and hacking, which accounted for 21 percent of data breaches in healthcare in the year 2015 compared to just 5 percent in the year 2013. The report recommends the trend is likely to sustain as the healthcare industry transitions to EHRs and the use of wireless portable devices.