Purna Nemani reports: A shark-bite victim claims a Honolulu hospital violated his privacy by photographing and posting on the Internet a picture of his “gaping leg wound,” without his consent, “while he was completely helpless, undraped, and in a life-threatening and traumatic shock condition.” Todd Murashige claims The Queen’s Medical Center violated HIPAA protections and…
Category: Health Data
OH: Resident reports theft of laptop computer to UA police
From the Upper Arlington Police Beat: A laptop computer containing personal information and confidential medical records was reported lost and presumed stolen after its owner accidentally left it at a business on the 3200 block of Tremont Road on Aug. 25, according to Upper Arlington police reports. The owner has contacted the credit bureau about…
Triplets' Parents Sue Hospital & Media
Dan McCue reports on a case in Illinois: Surrogate parents of newborn triplets claim a hospital and major media outlets violated medical privacy laws and subjected them to “humiliation, embarrassment and emotional distress” by publishing photos and stories about their newborns. The parents say they never gave Advocate Christ Medical Center permission to release personal…
Scottish ministers told to “get a grip” on data security
Ben Borland of the Express reports on previously undisclosed breaches involving PII and/or PHI, but I note that BBC provides slightly different coverage. I’ve indicated the BBC’s statements in italics, below. More than 200 electronic items were stolen or lost in the first six months of the year, including PCs, laptops, phones and Blackberries. The…
Ca: RMC patient info might have been compromised
Gene Zaleski reports: The Regional Medical Center has offered identity theft coverage to about 200 patients after discovering a possible breach of its computer system. RMC President Tom Dandridge said the hospital’s auditor found an former employee’s password may have been used to access medical records. “We could not determine whether there had a been…
Connecticut Insurance Commissioner Announces Data Breach Notification Mandate
Joseph Lazzarotti of Jackson Lewis writes: On August 18, 2010, the Connecticut Insurance Commissioner issued Bulletin IC-25 which mandates that entities within its jurisdiction notify the Department of Insurance of any “information security incident.” This post provides a brief summary of this new requirement. […] What is an “information security incident”? Under this Bulletin, an…