Main menu

Pages

Recent incidents of hacking, malware and device theft affect 208,000 people

A roundup of data breaches that have recently been reported to the HHS Civil Rights Office and state attorneys general.

California EHR Provider Reports Violation of 77,652 Records

Further information has been obtained regarding a data breach reported to the HHS Civil Rights Office on June 2, 2022 by Clinivate, a Pasadena, Calif.-based provider of EHR solutions for behavioral health agencies and schools.

According to a breach notification to the California Attorney General, unusual activity was detected in his digital environment on March 23, 2022. A forensic investigation confirmed that an unauthorized third party gained access to his network, and on May 25 2022, it was determined that the files containing the individuals’ protected health information were accessed by this third party between March 12, 2022 and March 21, 2022.

The files included the protected health information of 77,652 people, including names, medical record numbers, health plan beneficiary numbers, treatment information, diagnostic information, other medical information and payment information for medical services.

Clinivate notified affected individuals and said it has additional security measures in place to prevent further data breaches.

McLaren Port Huron Hospital confirms private health insurance for 49,000 people compromised in cyberattack at MCG Health

McLaren Port Huron Hospital said some patients’ protected health information was compromised in a cyberattack at one of its former associates, MCG Health. MCG Health provides patient care guidelines to many health plans and nearly 2,600 hospitals in the United States. On March 25, 2022, MCG Health discovered that an unauthorized third party had obtained data from its network that included data elements such as names, social security numbers, medical codes, mailing addresses, phone numbers , e-mail addresses, dates of birth and gender. Many MCG Health customers were affected by the incident.

McLaren Port Huron Hospital said it was notified of the breach on June 9, 2022 and that the delay in notification meant it had not conducted its own investigation to determine the likelihood of an actual compromise of the patient data, but had sent notifications to everyone involved. people to alert them to the possibility that their PSRs have been stolen. McLaren Port Huron Hospital discontinued using MCG Health in 2019.

The data breach was reported to the HHS Civil Rights Office as affecting 48,957 patients at McLaren Port Huron Hospital. Those affected were offered free credit monitoring and identity theft protection services for 24 months.

Kaiser Permanente reports stolen iPad containing PHI

Kaiser Permanente began notifying some people that some of their protected health information was stored on an iPad that was stolen from a locked storage area at Kaiser Permanente Los Angeles Medical Center. A stranger broke into the storage area and stole the iPad, and also got the password to access the device.

The device was used at a Kaiser Permanente COVID-19 testing site and included photographs of COVID-19 sample labels and protected health information such as names, medical record numbers, dates of birth and service dates and locations. The theft was discovered the same day and Kaiser Permanente remotely deleted the data from the device, including all photographs.

Kaiser Permanente said it moved devices containing PHI to a safer location and strengthened its internal practices and procedures. Kaiser Permanente said the iPad contained the protected health information of approximately 75,000 health plan members.

Blue Cross and Blue Shield of Massachusetts Report Third-Party Data Breach

Blue Cross and Blue Shield of Massachusetts (BCBSofMA) recently confirmed that a data breach at an associate exposed the protected health information of some of its health plan members. The breach occurred at LifeWorks US Inc, which provides services related to the administration of the retirement income trust, which includes making payments to pension beneficiaries.

Around June 20, 2022, a former LifeWorks employee emailed spreadsheets to a personal email account and copied the email to another former LifeWorks employee’s personal email account. The spreadsheets contained the protected health information of those eligible for or receiving BCBSofMA benefits.

Former employees argued that the spreadsheets were sent to preserve the formula used and that attempts were made to remove all protected health information in the spreadsheets; however, some PHI remained. The former employees said they did not further disclose the information in the spreadsheets and have now deleted the spreadsheets from their personal email accounts. The information that remained in the spreadsheets was limited to names, addresses, social security numbers and some retirement benefit information.

BCBSofMA reported that the breach affected 4,855 people and offered 24 months of free identity theft and credit monitoring services to those affected. LifeWorks said it was taking steps to prevent any recurrence of incidents like this.

Business associate ransomware attack affects Blue Shield of California health plan members

A contractor for a vendor used by Blue Shield of California (BSofC) suffered a ransomware attack in which the protected health information of BSofC and BSofC Promise Health Plan members may have been accessed or obtained. The ransomware attack was detected on April 28, 2022 by OneTouchPoint (OTP), which was a contractor used by business associate Matrix Medical Network.

OTP said it immediately terminated unauthorized access to the network and launched an investigation into the breach. Although it was not possible to confirm whether files containing protected health information about members of the health care plan were accessed or obtained, the possibility cannot be ruled out. Files potentially viewed included names, subscriber ID numbers, diagnoses, medications, patient addresses, birth dates, gender, physician demographic information, advance directives, family history, social history, allergies, vital signs, vaccinations, encounter data, assessment ID numbers, and assessment dates.

The data breach was reported to the HHS Civil Rights Office as affecting 1,506 health plan members. Those affected were offered a free 12-month subscription to a credit monitoring and identity theft protection service.