DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

The curious case of Alex Rodriguez and his stolen medical records

Posted on August 5, 2013 by Dissent

Update of December 12: See the update/follow-up here.

Several months ago, I was contacted by a reader who asked me about the Alex Rodriguez case and whether there was a HIPAA breach.  I responded, via e-mail, that I didn’t know as the clinic was no longer in operation and I didn’t have any information on them. Over the weekend, a story appeared on The Bent Corner in that says, in part:

The evidence against A-Rod is based on stolen medical records obtained from Porter Fischer, an ex-employee of Biogenesis of America, an anti-aging clinic in Coral Gables, Florida. The clinic has since closed. Reportedly, MLB paid Fischer for the records. Fischer stole the medical records from Biogenesis of America because he believed the clinic owed him some money, $4,000 to be exact.

What’s worse, using PEDs or stealing someone’s medical records?

Biogenesis of America was owned and operated by Tony Bosch, a man who at least pretended to be a medical doctor. It would stand to reason that anyone partaking of the ant-aging services of Biogenesis of America, whether they be a retired postal worker or a guy playing third base for the New York Yankees, had the expectation that what they were doing was confidential and protected by doctor-patient privilege.

As I noted in my discussion of a case involving blood donors, not all entities are HIPAA-covered entities, even if they employ doctors or have a medical component. Was Biogenesis of America ever a HIPAA-covered entity? I don’t know. They listed a medical doctor as their medical director in their Florida business incorporation papers, but again, that doesn’t make them a HIPAA-covered entity.  So that’s one question: was there a reportable privacy breach under HIPAA or not?

As a second question: can Major League Baseball purchase records stolen from a clinic and use them against a player? I don’t think they should be able to do so, but I don’t know if that’s really what they did, and besides, I am not a lawyer and do not know what the law says about such conduct.

But the public perception is what I want to address. The fact that the public may have an expectation of privacy when there may be no HIPAA protection or state law protection is problematic and needs to be addressed. Whether it’s an anti-aging clinic, a weight loss clinic, or anything other than a medical practice that hands you a copy of their HIPAA policies and/or privacy practices, ask whether they are HIPAA-covered and ask for a copy of their privacy policies.

Update: The case is even more confusing, as some sources say it was not MLB but Rodriguez himself who purchased his clinic records, presumably to destroy them. I have no idea whether either story is accurate.

Category: Uncategorized

Post navigation

← MO HealthNet notifying 1,357 of breach
Boxes with personal info found in trash →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ireland’s Data Protection Commission publishes 2024 Annual Report
  • The headlines suggested Freedman Healthcare suffered a ransomware attack that affected patient data. The reality was quite different.
  • Runsafe report: Medical device cyberattacks threaten patient care, strain budgets, top concern for healthcare sector
  • Ryuk ransomware’s initial access expert extradited to the U.S. from Ukraine
  • Alleged Geisinger hacker will defend himself pro se.
  • Tallahassee Memorial Healthcare reveals it was also impacted by Cerner/Legacy Oracle cyberattack
  • Hospital cyberattack investigation complete, no formal review needed (1)
  • Largest Ever Seizure of Funds Related to Crypto Confidence Scams
  • IMPACT: 170 patients harmed as a result of Qilin’s ransomware attack on NHS vendor Synnovis
  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • US Judge Invalidates Biden Rule Protecting Privacy for Abortions
  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • 23andMe fined £2.31 million for failing to protect UK users’ genetic data
  • DOJ Seeks More Time on Tower Dumps
  • Your household smart products must respect your privacy – including your air fryer
  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.