Information Security News mailing list archives

New HIPAA breach details remain vague


From: InfoSec News <alerts () infosecnews org>
Date: Wed, 27 Aug 2014 16:35:09 +0000 (UTC)

http://www.healthcareitnews.com/news/new-hipaa-breach-details-remain-vague

By Erin McCann
Associate Editor
Healthcare IT News
August 26, 2014

Cedars-Sinai Health System is notifying its patients of a HIPAA breach, after an unencrypted hospital laptop containing patient medical data and Social Security numbers was stolen from an employee's home.

Despite saying they were mailing breach notification letters this week, hospital officials said they didn't know how many patients were affected by the June 23 HIPAA breach. CS officials launched an investigation into the theft more than two months ago. Multiple requests for the number have been unsuccessful.

The laptop stolen contained patient diagnoses, treatment data, lab tests, Social Security numbers in many cases, patient ID numbers and other personal information.

According to Cedars-Sinai officials, the employee used the unencrypted laptop to troubleshoot software and worked outside of normal business hours, which was why the laptop was taken home.

[...]



--
Evident.io - Continuous Cloud Security for AWS.
Identify and mitigate risks in 5 minutes or less.
Sign up for a free trial @ https://evident.io/


Current thread: