DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Sony Pictures admits HIPAA data might have been compromised during breach

Posted on December 15, 2014 by Dissent

Steve Ragan reports:

In a breach notification letter sent to employees this week, Sony Pictures outlines the full scope of data that was compromised by attackers shortly before the Thanksgiving holiday.

[…]

“In addition, unauthorized individuals may have obtained (ix) HIPAA protected health information, such as name, Social Security Number, claims, appeals information you submitted to SPE (including diagnosis and disability code), date of birth, home address, and member ID number to the extent that you and/or your dependents participated in SPE health plans, and (x) health/medical information that you provided to us outside of SPE health plans.”

 So HIPAA protections were supposed to be in place for some data, and this breach should be reported to HHS.
Read more on CSO.  Sony’s notification to SPE employees is available on the web site of the California Attorney General’s Office (pdf).
Category: Business SectorHackHealth DataOf NoteU.S.

Post navigation

← Sony Pictures admits HIPAA data might have been compromised during breach
IL: Clay County Hospital Notifies Patients After Receiving Extortion Demand (updated) →

7 thoughts on “Sony Pictures admits HIPAA data might have been compromised during breach”

  1. David says:
    December 16, 2014 at 5:22 pm

    Unfortunately, unless Sony Pictures, Inc., is a “covered entity” … a healthcare provider, or insurance company, or PHI data processor … I don’t see how HIPAA applies to their breach. Unless DrOz is offering office visits and writing scrips!

    Unforgivable for them to even have the information … can’t imagine what their justification would be … but the HR office should have none of this data, nor should anyone within the company. Watching this unravel will be very interesting.

    1. Dissent says:
      December 16, 2014 at 6:35 pm

      Actually, they seem to administer their own health plan for employees, and their own letter says the data are HIPAA-covered.

      1. David says:
        December 17, 2014 at 9:43 am

        Thank you for pointing out the letter, and yes, their self-admission may indicate that they carry their own coverage and are indeed CEs by law, subject to fine and even jail time.

        At the same time, that clarity isn’t yet assured… a quick morning review shows one legal opinion Yea (http://abovethelaw.com/2014/12/celebrities-health-information-compromised-by-sony-hacking/); one Nay (http://www.wired.co.uk/news/archive/2014-12/17/former-employees-sue-sony); and a third suggests “While the industry debates whether Sony and all other employers are covered entities under HIPAA…” (http://www.healthleadersmedia.com/content/TEC-311345/In-2015-Target-Online-Security-or-Be-a-Target).

        Also pertinent is the recent Connecticut SC decision to allow HIPAA negligence standards to serve as the standard for private right of action.

        I do know that many companies make assumptions that they are covered entities when indeed, they are not … and while I would hope Sony’s breach letter writer wasn’t redefining their role accidentally, you cannot overestimate the raw corporate stupidity running throughout this case. ‘Twere written as a movie script, it would get laughed out of the offices!

        1. Dissent says:
          December 17, 2014 at 9:47 am

          Thanks for your thoughtful reply. I’m waiting to see if this gets reported to HHS and what/how HHS responds, but it will be quite a while before we know either.

          Regardless of whether this falls under HIPAA, I think employees will face the same “standing” issues in any litigation as we have seen in most lawsuits. Can they demonstrate actual harm or “impending” harm and not just “potential” harm or injury.

          I also would like to know what federal agency – if any – can go after Sony on data security. Neither FTC nor the NLRB replied to my tweeted inquiries asking whether they have statutory authority to do so. I may email them. 🙂

        2. Dissent says:
          December 17, 2014 at 11:34 am

          Located Sony Pictures Entertainment Inc.’s self-insured group health plans (the “HIPAA Plans”) Notice of Privacy Practices (pdf)

          1. David says:
            December 17, 2014 at 12:13 pm

            You wizard of the web, you! Thanks for this.
            In response to your other post and the replies it generated, no, you’re not the only one to find this activity a major crossing of a line in human relations … and it is dismaying to see how quickly the conversation degenerated into a “Kemoy/Matsu” debate irrelevant to the point made. But please know that your efforts are remarkable, and well appreciated by privacy champions, rare as the breed appears.

          2. Dissent says:
            December 17, 2014 at 12:37 pm

            Thanks, David. There are those who have suggested I’m asking for trouble by publicly appealing to hackers or criticizing them if they put people at risk of harm, but at least I’m consistent, huh? 🙂

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Resource: State Data Breach Notification Laws – June 2025
  • WestJet investigates cyberattack disrupting internal systems
  • Plastic surgeons often store nude photos of patients with their identity information. When would we call that “negligent?”
  • India: Servers of two city hospitals hacked; police register FIR
  • Ph: Coop Hospital confirms probe into reported cyberattack
  • Slapped wrists for Financial Conduct Authority staff who emailed work data home
  • School Districts Unaware BoardDocs Software Published Their Private Files
  • A guilty plea in the PowerSchool case still leaves unanswered questions
  • Brussels Parliament hit by cyber-attack
  • Sweden under cyberattack: Prime minister sounds the alarm

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.