DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Sony Pictures admits HIPAA data might have been compromised during breach

Posted on December 15, 2014 by Dissent

Steve Ragan reports:

In a breach notification letter sent to employees this week, Sony Pictures outlines the full scope of data that was compromised by attackers shortly before the Thanksgiving holiday.

[…]

“In addition, unauthorized individuals may have obtained (ix) HIPAA protected health information, such as name, Social Security Number, claims, appeals information you submitted to SPE (including diagnosis and disability code), date of birth, home address, and member ID number to the extent that you and/or your dependents participated in SPE health plans, and (x) health/medical information that you provided to us outside of SPE health plans.”

 So HIPAA protections were supposed to be in place for some data, and this breach should be reported to HHS.
Read more on CSO.  Sony’s notification to SPE employees is available on the web site of the California Attorney General’s Office (pdf).

No related posts.

Category: Business SectorHackHealth DataOf NoteU.S.

Post navigation

← Sony Pictures admits HIPAA data might have been compromised during breach
IL: Clay County Hospital Notifies Patients After Receiving Extortion Demand (updated) →

7 thoughts on “Sony Pictures admits HIPAA data might have been compromised during breach”

  1. David says:
    December 16, 2014 at 5:22 pm

    Unfortunately, unless Sony Pictures, Inc., is a “covered entity” … a healthcare provider, or insurance company, or PHI data processor … I don’t see how HIPAA applies to their breach. Unless DrOz is offering office visits and writing scrips!

    Unforgivable for them to even have the information … can’t imagine what their justification would be … but the HR office should have none of this data, nor should anyone within the company. Watching this unravel will be very interesting.

    1. Dissent says:
      December 16, 2014 at 6:35 pm

      Actually, they seem to administer their own health plan for employees, and their own letter says the data are HIPAA-covered.

      1. David says:
        December 17, 2014 at 9:43 am

        Thank you for pointing out the letter, and yes, their self-admission may indicate that they carry their own coverage and are indeed CEs by law, subject to fine and even jail time.

        At the same time, that clarity isn’t yet assured… a quick morning review shows one legal opinion Yea (http://abovethelaw.com/2014/12/celebrities-health-information-compromised-by-sony-hacking/); one Nay (http://www.wired.co.uk/news/archive/2014-12/17/former-employees-sue-sony); and a third suggests “While the industry debates whether Sony and all other employers are covered entities under HIPAA…” (http://www.healthleadersmedia.com/content/TEC-311345/In-2015-Target-Online-Security-or-Be-a-Target).

        Also pertinent is the recent Connecticut SC decision to allow HIPAA negligence standards to serve as the standard for private right of action.

        I do know that many companies make assumptions that they are covered entities when indeed, they are not … and while I would hope Sony’s breach letter writer wasn’t redefining their role accidentally, you cannot overestimate the raw corporate stupidity running throughout this case. ‘Twere written as a movie script, it would get laughed out of the offices!

        1. Dissent says:
          December 17, 2014 at 9:47 am

          Thanks for your thoughtful reply. I’m waiting to see if this gets reported to HHS and what/how HHS responds, but it will be quite a while before we know either.

          Regardless of whether this falls under HIPAA, I think employees will face the same “standing” issues in any litigation as we have seen in most lawsuits. Can they demonstrate actual harm or “impending” harm and not just “potential” harm or injury.

          I also would like to know what federal agency – if any – can go after Sony on data security. Neither FTC nor the NLRB replied to my tweeted inquiries asking whether they have statutory authority to do so. I may email them. 🙂

        2. Dissent says:
          December 17, 2014 at 11:34 am

          Located Sony Pictures Entertainment Inc.’s self-insured group health plans (the “HIPAA Plans”) Notice of Privacy Practices (pdf)

          1. David says:
            December 17, 2014 at 12:13 pm

            You wizard of the web, you! Thanks for this.
            In response to your other post and the replies it generated, no, you’re not the only one to find this activity a major crossing of a line in human relations … and it is dismaying to see how quickly the conversation degenerated into a “Kemoy/Matsu” debate irrelevant to the point made. But please know that your efforts are remarkable, and well appreciated by privacy champions, rare as the breed appears.

          2. Dissent says:
            December 17, 2014 at 12:37 pm

            Thanks, David. There are those who have suggested I’m asking for trouble by publicly appealing to hackers or criticizing them if they put people at risk of harm, but at least I’m consistent, huh? 🙂

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Kentfield Hospital victim of cyberattack by World Leaks, patient data involved
  • India’s Max Financial says hacker accessed customer data from its insurance unit
  • Brazil’s central bank service provider hacked, $140M stolen
  • Iranian and Pro-Regime Cyberattacks Against Americans (2011-Present)
  • Nigerian National Pleads Guilty to International Fraud Scheme that Defrauded Elderly U.S. Victims
  • Nova Scotia Power Data Breach Exposed Information of 280,000 Customers
  • No need to hack when it’s leaking: Brandt Kettwick Defense edition
  • SK Telecom to be fined for late data breach report, ordered to waive cancellation fees, criminal investigation into them launched
  • Louis Vuitton Korea suffers cyberattack as customer data leaked
  • Hunters International to provide free decryptors for all victims as they shut down (2)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • German court awards Facebook user €5,000 for data protection violations
  • Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher
  • Ninth Circuit Reviews Website Tracking Class Actions and the Reach of California’s Privacy Law
  • US healthcare offshoring: Navigating patient data privacy laws and regulations
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • Google Trackers: What You Can Actually Escape And What You Can’t
  • Oregon Amends Its Comprehensive Privacy Statute

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.