Tuesday, August 1, 2017
Contractor breach impacts data of 18,500 Anthem Medicare members
LaunchPoint Ventures, which gives insurance coordination services to Anthem, learned in the month of April that a worker likely was engaged in identity theft activities. The contractor then employed a forensic firm to assess suspicious incidents.
In the month of late May, LaunchPoint learned that the employee might have accessed data of other LaunchPoint customers, in addition to that of Anthem. The inquiry further determined that the worker emailed a file with information on Anthem members to his personal address in the month of July 2016; the inquiry couldn’t determine if the employee had a legitimate work-related reason for doing so.
LaunchPoint says the worker has since been terminated and is now being held by law enforcement on charges that are unrelated to the Anthem breach.
In June, LaunchPoint was capable to confirm that the Anthem data emailed by the worker contained protected health information of Anthem Medicare members. There is not yet evidence the data was misused. Compromised member information includes Medicare ID numbers including Social Security numbers, health plan ID numbers, Medicare contract numbers, dates of enrollment, and a restricted number of last names and dates of birth.
LaunchPoint is now reinforcing policies and protocols, and evaluating additional safeguards. The company is providing affected individuals 2 years of free credit monitoring and identity theft services with AllClear ID.
Anthem refused to comment on the incident, and executives didn’t say whether it will continue to use LaunchPoint’s services.
Monday, March 14, 2016
Bizmatics discloses the secret that it was hacked
Unknown figures of contributors are affected after the hacking of Bizmatics Inc., a popular vendor of ambulatory care software and revenue cycle management services.
Bizmatics, in business for more than fifteen years and facilitating 15,000 medical experts in accordance to its Web site, offers regionally hosted and cloud-hosted systems.
Complete Family Foot Care in the Lincoln, Neb., is believed to be one of the victims and has mailed a pervious notice to sufferers—with a proposed formal HIPAA notice now being mailed—and is providing 1 year of identity protection services from the IdentityForce.
Bizmatics and the practice performed an investigation to evaluate which sufferers may have been impacted, but they yet do not really know, the notice from the foot care practice elaborates.
“Regrettably, we can’t determine at this period which, if any, of our sufferers’ files might have been approached. Bizmatics’ servers consists of a huge number of patient files from a great number of healthcare providers; it may well be that none of our sufferers’ files were approached or compromised in any way. Nonetheless, because of the threat that your data might have been checked, we consider that it is significant that you are informed regarding the tragedy.”
Compromised protected health data may have involved names, addresses, Social Security numbers, health insurance numbers, diagnoses and treatments. Credit/debit cards and financial data were not impacted at Complete Family Foot Care. The breach happened sometime in the year 2015, and the practice was notified in the month of January 2016.
It is not yet obvious if all sufferers possibly affected by the Bizmatics breach will get protective services, or merely those who consider they have become a victim of ID theft. Bizmatics and Complete Family Foot Care didn’t instantly response to an appeal for extra data. The HHS Office for Civil Rights also didn’t respond to an appeal for data.
Friday, February 19, 2016
Healthcare data breaches lead more sufferers to withhold data from doctors
As the year 2015 slides into the cybersecurity history books as “the year of the healthcare breach” I chose to examine 1 aspect of medical information privacy that is sometimes overlooked: the effect of breaches on patient-doctor data exchange. Particularly, I am concerned that high profile healthcare-related Information Technology security violation may lead more persons to withhold sensitive data from their doctor because of fears that it will be exposed because of weak privacy protection or weak security controls.
That such fears exist is all too obvious and clear when you talk to persons about the huge healthcare data breaches of 2015, the 6 largest of which compromised more than 100 million records. I have spoken to several people whose information was exposed in those attacks and who subsequently experienced 1 or more forms of attempted identity theft.
Of course, it is difficult to get direct evidence that ties a particular violation of your data to a particular instance of identity theft. But if the theft comes soon after a violation at Company A, of which you are a consumer, you will probably suspect that specific violation is the cause of your issue. When an entire string of breaches occur in a short span of time, there is plenty of blame to go around. Even if you are Company A and you are certain that your violation did not result in ID theft, you may get blamed anyway.
The Withholding Issue
The requirement for doctors to keep patient data confidential is as old as the practice of medicine itself. (In the genuine version of Hippocratic Oath a doctor would vow to hold sufferer data “sacred and secret within my own breast”.) Simply put, doctors can’t offer safe and effective care to sufferers if those sufferers do not share with them all of the relevant data. Of course, there are various reasons why a person might select not to tell their doctor everything. Few reasons predate computers and are as old as society itself, involving shame, embarrassment, and fear of censure.
Although, fears about unauthorized approach to, and abuse of, electronically stored personal health data were voiced as soon as database technologies started to emerge in the latter half of the last century. In fact, the US government agency that was then called as the Department of Health, Education, and Welfare (HEW) prompted few of the 1st critical thinking about the effect of computer databases on society. A 1973 document commissioned by that agency and subsequently called as the HEW Report, examined the numerous fears raised by the increasing growing computerization of personal data.
Monday, February 6, 2012
CMS Has Updated the EHR Information Center with New Self-Service Options
- Obtain registration status
- Acquire attestation status
- Review payment information
- Check progress towards meeting the $24,000 threshold amount
- Begin by dialing (888) 734 6433
- Press 3 for Self Service
- Enter the authentication elements
(Please note that General Information and Self-Service options may be reached via IVR 24 hours a day, except during periods of planned system maintenance or upgrades).
Supplementary information on the program may also be viewed by visiting the FAQs section of the EHR Incentive Programs website, where users can search for any questions they have about the Medicare or Medicaid EHR Incentive Programs.
Sunday, January 9, 2011
Some Healthcare Scams you should know about...
Health fraud
Health care scams cost Americans billions of dollars each year. Taxpayer-funded programs such as Medicare, Medicaid and others are among the biggest victims. This makes health-care fraud one of America's largest taxpayer ripoffs.
Organized crime rings hatch many schemes. Hospital chains, individual employees and even patients also can be involved — as victims or perpetrators.
The scams
Most medical providers are honest and ethical. But here are just some of the health care scams you should know about...
Phantom treatments. Dishonest medical providers will bill health insurers for expensive treatments, tests or equipment you never received — and for illnesses or injuries you don't even have.
Double billing. Unethical providers may double or triple bill health insurers for the same treatments, hoping the insurer won't discover the overruns in the big stack of bills.
Shoddy care. You might receive shoddy or substandard treatment for real and urgent medical problems. One eye doctor shined pen lights into patients' eyes and said he'd performed cataract surgery. Surgeons have used defective pacemakers and catheters during heart surgeries, which have killed patients or required more surgeries to correct the problems.
Unneeded care. You might receive dangerous and even life-threatening treatment you don't need. One surgeon performed heart surgery on patients who didn't need it.
Bogus insurers. Insurance agents or brokers sell you low-cost health coverage from fake insurance companies. Then they take your premiums and disappear. You're left without vital health coverage, and don't even know it until you make a claim.
Identity theft. Cheaters steal your medical ID number, then use it to bill health programs tens of thousands of dollars for phantom treatment. Crooks steal your health info from dumpsters behind medical clinics, break into doctor offices and steal files, and hack into computer databases containing your records.
Rolling labs. Mobile diagnostic labs give needless or fake tests or physical exams to consumers, then bill health insurers for expensive procedures.
Runners. A person hired by a medical provider to drum up business trolls through neighborhoods, often low-income areas, enticing people to come to a clinic for tests. These runners will even roundup children for unneeded tests and procedures.
The price you pay
Coverage drained. Your coverage limits might be drained by worthless and unnecessary treatments.
Financial disaster. Inflated or phantom medical bills can increase your co-payment, beyond your ability to pay. This could force you into collections and damage your credit rating. And if you bought health insurance that ends up completely fake, you could face financial disaster if you must pay large medical bills with your life savings because your policy's worthless.
False medical record. Your medical record contains false information about illnesses, diseases, injuries or other problems you never had. Your information is available to insurers, so you could be denied health coverage or pay higher premiums because of a trumped-up medical record.
Premiums rise. Your health premiums rise because insurers pass the cost of fraud onto policyholders. High health premiums discourage employers from offering this needed employee benefit.
Personal distress. You receive bogus or needless treatments that are painful, distressing, can threaten your health — and even kill you.
Taxpayer ripoff. Billions of your tax dollars pay for fraudulent claims against Medicare, Medicaid and other taxpayer-funded health programs every year. These are your tax dollars being stolen.
Fight Back
- Keep detailed records of treatments you receive. Include all dates, locations, who provided the treatments, what services you received, and what medicine, supplies or equipment were provided.
- Carefully review the billing and summary statements you receive after treatment. Are the treatment dates, doctor name(s), facility locations and medical services the same as you remember? Know what medical equipment and supplies your provider ordered, as well.
- Never sign blank insurance claim forms.
- Ask your medical providers what price they charge, and what you'll pay out-of-pocket.
- Avoid door-to-door or telephone salespeople who offer you free medical services or equipment.
- Never give strangers your policy number, insurance ID number, Medicare claim number or other info, especially if they offer you cash or free gifts, treatments or equipment.
- Know what your medical benefits are — what's covered and what isn't.
- Back off if someone says they can bill your health program to pay for an uncovered treatment or equipment. You're being pulled into an illegal scheme. You could lose your health coverage, be arrested, fined, thrown into jail, and live with a conviction record that disrupts your life for years to come.
- Never pay your health premiums in cash, and be wary if the health insurer asks you to pay a full year's premium upfront.
- Be careful if medical providers say they're connected with the federal government, Medicare, Medicaid or other health programs.
- Watch out if the insurer offers you health coverage for "just pennies a day," or sells coverage at a price far lower than others.
- Check with your state insurance department to make sure the health insurance company is licensed to do business in your state.
- See if the health insurer has a history of consumer complaints, bankruptcy, fraud convictions or other problems. Your state insurance department and consumer protection agency, and Better Business Bureau are good places to start.
- Question your health provider and ask for clarification if you see problems or inconsistencies on your bills.
Who to contact
If you think you've discovered a healthcare scam, contact:
- The insurer that paid the claim (the name, address and phone are on the explanation of benefits you receive in the mail).
If you think the scam victimizes Medicare, Medicaid or another public health program:
- Phone: the U.S. Department of Health and Human Services toll-free: 1-800-HHS-TIPS (1-800-447-8477) OR...
- Write: Office of Inspector General
Department of Health and Human Services
ATTN: HOTLINE
330 Independence Ave., SW
Washington, DC 20201
Fax: 1-800-223-8164
e-mail: HTIPS@os.dhhs.gov - Contact your state fraud bureau.
Be prepared
Make sure you include this information when you contact the authorities:
- provider's name and identifying number
- item or service you're questioning
- date(s) you supposedly received the item or service
- amount approved and paid
- date of the explanation of benefits
- name and Medicare number of the person who supposedly received the item or service
- why you believe Medicare shouldn't have paid
- other information that might be helpful.
Want to know More about Scams??? Go to Scamming Alerts
Friday, March 5, 2010
Medical identity theft: Nearly 1.5 million Americans have been victims
Medical identity theft is an alarming and often undetected offense affecting today’s consumers, according to a recent survey conducted by The Ponemon Institute and sponsored by ProtectMyID.com™, Experian’s multilayered identity theft detection, protection and fraud resolution product. According to the study, nearly 1.5 million Americans have been victims of medical identity theft. For many, the notion of identity theft is both upsetting and daunting, but few individuals realize the specific severity and potential repercussions of medical identity fraud. It is estimated that the costs associated with this type of theft total about $28.6 billion — or approximately $20,000 per victim. Not only is resolution of medical fraud an especially arduous endeavor, but the difficulty of recognition and the potential associated costs also make it particularly dangerous.
“We are proud to sponsor this groundbreaking study because when people are informed, we find that they are empowered to take steps to protect all their valuable information.”
“We are pleased to work with Experian’s ProtectMyID.com for this first-of-its-kind study,” said Dr. Larry Ponemon, chairman and founder of Ponemon Institute. “This is the first empirical study that attempts to measure the size and scope of the medical identity theft, and our results underscore the importance of informing the public why the protection of their medical records is of the utmost importance. This study confirms that there is not only a significant financial impact to medical identity theft, but that there is a very real danger of erroneous diagnosis and treatment because of medical records that contain false information. All this adds up to the need for urgency on the part of consumers to self-educate and take the proper steps to ensure the integrity of their medical identity.”
One of the most common instances of medical identity theft is the use of a stolen insurance ID card in order to receive medical services. The main problem in combating the theft is the time it takes to recognize that it has occurred. According to the study, more than 50 percent of consumers didn’t discover that they had been victimized until at least a year after the incident or incidents had occurred. Only 6 percent received a timely notification that their medical records had been breached. These unsettling figures indicate that a significant number of consumers are currently and unknowingly being targeted by medical identity thieves.
Adding to the number of those affected are the individuals who choose not to report wrongdoings to the authorities. In fact, 46 percent of respondents elected not to report incidents to law enforcement officials or other legal authorities. Within this group, the predominant reasoning for withholding such information is even more surprising: 49 percent of those surveyed said that they were close to the thief and did not wish to subject him or her to legal trouble. With so many unreported cases of medical identity theft, it is clear that the reach of such fraud goes far beyond the total number of documented incidents.
“The difficulty in detecting medical identity theft makes it a particularly dangerous form of fraud,” said Jennifer Leuer, general manager of ProtectMyID.com. “Arming yourself with the tools provided by a fraud protection product such as ProtectMyID.com can prove invaluable in early detection and resolution, especially knowing that if something does happen you won’t be alone in getting the matter resolved.”
The potential consequences of medical identity theft have proved to be extremely damaging. Forty-eight percent of respondents said they lost their health care coverage completely, and 32 percent noted an increase in their insurance premiums. Of those surveyed, nearly 80 percent suffered negative ramifications as a result of the theft.
In order to combat these risks, ProtectMyID.com offers coverage specifically designed to aid consumers who are victims of medical identity theft. The following features will be available this month:
- Ongoing and daily monitoring for identity theft using insurance policy numbers. This will flag suspicious Internet activity involving personal medical information and keep customers informed along the way.
- Dedicated resolution agents who are trained to notify and work with health care providers on behalf of customers to resolve any theft-related issue. This removes the mystery and uncertainty from dealing with providers and delegates the responsibility to a trained agent.
- A lost wallet feature allows the consumer to make one call to a trained agent and receive assistance in the cancellation and reordering of lost wallet items, including credit cards and medical and dental insurance cards.
- Alerts inform members when medically related collection actions occur.
Compounding the effects of medical identity theft is the reality that resolution is extremely difficult. Of those surveyed, only 9 percent of victims reported that they have completely resolved the crimes against them and restored their identity. In contrast, an overwhelming 40 percent of respondents had not reached resolution at the time of the study. As a result of the situation, 55 percent of victims lost confidence in their health care organizations. According to the study, medical identity theft is a pervasive issue that frequently goes untreated and often unnoticed by consumers.
“At ProtectMyID.com, we want to educate consumers about the risks associated with medical identity theft and give them the tools to better protect themselves against this crime,” said Leuer. “We are proud to sponsor this groundbreaking study because when people are informed, we find that they are empowered to take steps to protect all their valuable information.”
Source The Ponemon Institute®
