DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Sony Pictures admits HIPAA data might have been compromised during breach

Posted on December 15, 2014 by Dissent

Steve Ragan reports:

In a breach notification letter sent to employees this week, Sony Pictures outlines the full scope of data that was compromised by attackers shortly before the Thanksgiving holiday.

[…]

“In addition, unauthorized individuals may have obtained (ix) HIPAA protected health information, such as name, Social Security Number, claims, appeals information you submitted to SPE (including diagnosis and disability code), date of birth, home address, and member ID number to the extent that you and/or your dependents participated in SPE health plans, and (x) health/medical information that you provided to us outside of SPE health plans.”

 So HIPAA protections were supposed to be in place for some data, and this breach should be reported to HHS.
Read more on CSO.  Sony’s notification to SPE employees is available on the web site of the California Attorney General’s Office (pdf).
Category: Business SectorHackHealth DataOf NoteU.S.

Post navigation

← Sony Pictures admits HIPAA data might have been compromised during breach
IL: Clay County Hospital Notifies Patients After Receiving Extortion Demand (updated) →

7 thoughts on “Sony Pictures admits HIPAA data might have been compromised during breach”

  1. David says:
    December 16, 2014 at 5:22 pm

    Unfortunately, unless Sony Pictures, Inc., is a “covered entity” … a healthcare provider, or insurance company, or PHI data processor … I don’t see how HIPAA applies to their breach. Unless DrOz is offering office visits and writing scrips!

    Unforgivable for them to even have the information … can’t imagine what their justification would be … but the HR office should have none of this data, nor should anyone within the company. Watching this unravel will be very interesting.

    1. Dissent says:
      December 16, 2014 at 6:35 pm

      Actually, they seem to administer their own health plan for employees, and their own letter says the data are HIPAA-covered.

      1. David says:
        December 17, 2014 at 9:43 am

        Thank you for pointing out the letter, and yes, their self-admission may indicate that they carry their own coverage and are indeed CEs by law, subject to fine and even jail time.

        At the same time, that clarity isn’t yet assured… a quick morning review shows one legal opinion Yea (http://abovethelaw.com/2014/12/celebrities-health-information-compromised-by-sony-hacking/); one Nay (http://www.wired.co.uk/news/archive/2014-12/17/former-employees-sue-sony); and a third suggests “While the industry debates whether Sony and all other employers are covered entities under HIPAA…” (http://www.healthleadersmedia.com/content/TEC-311345/In-2015-Target-Online-Security-or-Be-a-Target).

        Also pertinent is the recent Connecticut SC decision to allow HIPAA negligence standards to serve as the standard for private right of action.

        I do know that many companies make assumptions that they are covered entities when indeed, they are not … and while I would hope Sony’s breach letter writer wasn’t redefining their role accidentally, you cannot overestimate the raw corporate stupidity running throughout this case. ‘Twere written as a movie script, it would get laughed out of the offices!

        1. Dissent says:
          December 17, 2014 at 9:47 am

          Thanks for your thoughtful reply. I’m waiting to see if this gets reported to HHS and what/how HHS responds, but it will be quite a while before we know either.

          Regardless of whether this falls under HIPAA, I think employees will face the same “standing” issues in any litigation as we have seen in most lawsuits. Can they demonstrate actual harm or “impending” harm and not just “potential” harm or injury.

          I also would like to know what federal agency – if any – can go after Sony on data security. Neither FTC nor the NLRB replied to my tweeted inquiries asking whether they have statutory authority to do so. I may email them. 🙂

        2. Dissent says:
          December 17, 2014 at 11:34 am

          Located Sony Pictures Entertainment Inc.’s self-insured group health plans (the “HIPAA Plans”) Notice of Privacy Practices (pdf)

          1. David says:
            December 17, 2014 at 12:13 pm

            You wizard of the web, you! Thanks for this.
            In response to your other post and the replies it generated, no, you’re not the only one to find this activity a major crossing of a line in human relations … and it is dismaying to see how quickly the conversation degenerated into a “Kemoy/Matsu” debate irrelevant to the point made. But please know that your efforts are remarkable, and well appreciated by privacy champions, rare as the breed appears.

          2. Dissent says:
            December 17, 2014 at 12:37 pm

            Thanks, David. There are those who have suggested I’m asking for trouble by publicly appealing to hackers or criticizing them if they put people at risk of harm, but at least I’m consistent, huh? 🙂

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • 16 Defendants Federally Charged in Connection with DanaBot Malware Scheme That Infected Computers Worldwide
  • Russian national and leader of Qakbot malware conspiracy indicted in long-running global ransomware scheme
  • Texas Doctor Who Falsely Diagnosed Patients as Part of Insurance Fraud Scheme Sentenced to 10 Years’ Imprisonment
  • VanHelsing ransomware builder leaked on hacking forum
  • Hack of Opexus Was at Root of Massive Federal Data Breach
  • ‘Deep concern’ for domestic abuse survivors as cybercriminals expected to publish confidential abuse survivors’ addresses
  • Western intelligence agencies unite to expose Russian hacking campaign against logistics and tech firms
  • Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime tool
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • Privilege Under Fire: Protecting Forensic Reports in the Wake of a Data Breach

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Widow of slain Saudi journalist can’t pursue surveillance claims against Israeli spyware firm
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • GDPR is cracking: Brussels rewrites its prized privacy law
  • Telegram Gave Authorities Data on More than 20,000 Users
  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.