I have been following this case from the beginning and wondering why the heck HHS didn’t come down on Walgreens like they did on their competitors CVS and RiteAid. And now we learn that OCR just closed the case with no penalty? Seriously? So CVS and RiteAid get clobbered by both the FTC and HHS/OCR, and Walgreens…….
Category: Exposure
Personal information for hundreds of people found along CLE roadside
NewsNet5 in Cleveland reports: The City of Cleveland is trying to determine who dumped the personal information of hundreds of northeast Ohio residents along the roadside on Train Avenue. The personal information was strewn along a mile stretch of roadway, at five different dumping sites, and included; tax returns, mortgage information, canceled checks, addresses, social…
UK: Domestic abuse privacy breach: Greater Manchester Police pays victim
BBC reports: A domestic abuse victim has received £75,000 from a police force after it revealed details of her treatment by a former boyfriend without her consent. The unnamed woman had agreed Greater Manchester Police (GMP) could refer to her experience in a training session providing she remained anonymous. However, she later learned her identity…
UK: Medical data leak: Doctors hit with £40,000 fine from UK watchdog
Jennifer Baker reports: A doctor’s surgery in Hertfordshire has been fined £40,000 by the UK’s privacy watchdog for giving out personal medical information in breach of data law. Regal Chambers gave information about a woman and her family to her estranged ex-partner, despite staff at the practice being warned that this might happen. Read more on…
What HHS may not do, a state might
Back in June, 2014, this site noted two breaches disclosed by Rady Children’s Hospital in San Diego that involved patient data being disclosed to job applicants. Later that month, we learned that in the process of investigating the two known breaches, Rady uncovered two more such breaches. Rady duly notified HHS in June, 2014. More than two years later, there…
More details emerge on Jefferson Medical Associates incidents
So there’s a bit more to the incidents recently disclosed by Jefferson Medical Associates that I had reported here. Now WDAM reports that it was Chris Vickery who had discovered a misconfigured database and had alerted JMA. For their part, JMA is pretty much accusing Vickery of hacking them. Here we go again…. From WDAM’s…