DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Update: HHS opens investigation into Monroeville 911 dispatch center for possible violations of privacy and security rules

Posted on March 27, 2013 by Dissent

Back in October, I commented on a complaint filed with HHS by the Monroeville, Pennsylvania Assistant Chief of Police.   In August 2012, Chief Pascarella alleged that the town’s emergency dispatch service had been disclosing what should have been confidential information to his former boss, who, having retired, should no longer have been receiving copies of emergency dispatches on his cell phone.  It appears that when he retired, the town never removed him from the notification system.  The town’s lawyer didn’t see a problem, but Chief Pascarella did, and so did I.

What wasn’t clear to me, however, was whether the dispatch service was a HIPAA covered entity or not.  To the extent that medical information was transmitted over an emergency dispatch system like fire department or police scanners that anyone and everyone could monitor, the transmissions wouldn’t be protected, but if they were transmitting to electronic devices such as individual’s cell phones or email accounts, then…?

Since October, I have been in communication with an interested party in Monroeville, who tipped me that the breach  wasn’t confined to just one person. According to my correspondent, the town’s failure to ensure it kept an updated and need-to-know list with appropriate access controls may have exposed hundreds of thousands of records to people who should not have received them or access to them.  According to this source, each fire company had its own login to the dispatch system’s database, and the logins were only one digit apart. Basically, then, pretty much anyone who knew any of the logins could access the entire database of emergency medical records. And it wasn’t just the fire department/EMS that had access to the database, as the police also had access to it.

When my correspondent attempted to learn what, if anything, HHS was doing with Chief Pascarella’s complaint, he was reportedly told that HHS had not opened an investigation (yet).  I pointed out to him that HHS may have been viewing this as N=1 complaint or case instead of an N=400,000 systemic case (the 400,000 was just a guestimate on my correspondent’s part as to how many records might have been vulnerable to improper access).

Today, Annie Siebert of the Pittsburgh Post-Gazette reports that HHS has opened an investigation into the alleged breach:

Monroeville’s 911 dispatch center covers Monroeville, Pitcairn and Wilmerding.

“Anyone who has called the police, called the fire department, used our [emergency medical service]” or was transferred to or from a Monroeville hospital could be affected by the breach, Monroeville manager Lynette McKinney said. Monroeville police Chief Steven Pascarella said the leaks likely started sometime in late 2011 and continued until he discovered them in August 2012.

The breach first surfaced last year after then-Assistant Chief Pascarella filed the complaint, alleging ambulance dispatches were being sent to former Monroeville police Chief George Polnar, who retired in January 2010 and is now employed as the manager of security and parking at UPMC East in Monroeville.

But Ms. McKinney said the breach was wider than that.

“The magnitude of this investigation is well beyond the leaking of one resident’s private information to a former chief of police,” she said on Tuesday.

Read more on the Pittsburgh Post-Gazette.  And kudos to Chief Pascarella and concerned citizens in Monroeville who have pursued getting this situation investigated.

Update: Then-Monroeville Manager Jeffrey Silka informed the town that he was opening an investigation into the allegations back in October 2012.  On November 29, 2012, he announced that he would have the investigation “wrapped up soon.”  It is not known to me whether any report was ever issued following that investigation, but Mr. Silka’s successor, Lynette McKinney, has made it clear that she intends to carefully investigate the problem and allegations.

Update2: In response to a freedom of information request I filed with Monroeville requesting the final investigative report issued by Mr. Silka, my request was denied on two grounds. The first is probably more relevant here: “Mr. Silka never completed a final investigative report on this matter.”

Category: Health Data

Post navigation

← Recent Oregon Health & Science University breach was their fourth breach involving unencrypted information
Class action lawsuit filed against hospital, former staff and Fleming College →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Mysterious leaker GangExposed outs Conti kingpins in massive ransomware data dump
  • Resource: HoganLovells Asia-Pacific Data, Privacy and Cybersecurity Guide 2025
  • Class action settlement following ransomware attack will cost Fred Hutchinson Cancer Center about $52 million
  • Comstar LLC agrees to corrective action plan and fine to settle HHS OCR charges
  • Australian ransomware victims now must tell the government if they pay up
  • U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams
  • Victoria’s Secret takes down website after security incident
  • U.S. Government Employee Arrested for Attempting to Provide Classified Information to Foreign Government
  • St. Cloud Provides Update on Ransomware Attack in 2024
  • Bradford Health Systems detected abnormal network activity in December 2023. They first sent out breach notices this week.

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Resource: HoganLovells Asia-Pacific Data, Privacy and Cybersecurity Guide 2025
  • She Got an Abortion. So A Texas Cop Used 83,000 Cameras to Track Her Down.
  • Why AI May Be Listening In on Your Next Doctor’s Appointment
  • Watch out for activist judges trying to deprive us of our rights to safe reproductive healthcare
  • Nebraska Bans Minor Social Media Accounts Without Parental Consent
  • Trump Taps Palantir to Compile Data on Americans
  • The US Is Storing Migrant Children’s DNA in a Criminal Database

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.