Bonnie Eslinger reports: The University of California, Los Angeles Health System was not responsible for the unauthorized release of a woman’s medical records by a romantic rival, a California jury decided Thursday, rejecting her lawyer’s arguments that the victim was due $1.25 million for emotional harm caused by the breach. Read more on Law360 (subscription…
Category: Health Data
Cancer Care Group settles HHS charges over “widespread noncompliance” with HIPAA Security Rule; $750,000 fine and corrective action plan
In August 2012, I noted a breach involving the theft of backup media from an unattended vehicle of a Cancer Care Group employee. The backup contained information on 55,000 patients and employees. Now, more than three years later, HHS has announced a settlement with CCG over the breach. As seems to be their style, they…
UK: London clinic accidentally exposes HIV status of 780 patients
Joseph Patrick McCormick reports that 780 patients at the 56 Dean Street sexual health clinic in London had their names, HIV status, and contact details exposed to one another. The breach occurred when an employee sent out an email newsletter but put the mailing list in the “To:” field instead of the “bcc” field. The clinic…
UCLA Health notifying patients of stolen laptop containing personal health information; third breach report in as many months?
Hard to believe, but UCLA Health is notifying patients of yet another data breach. From a notice issued today: UCLA Health is sending notification letters to 1,242 individuals about the theft of a laptop computer containing patient names, medical record numbers, and health information used to help prepare patient treatment plans. No social security numbers,…
Ca: Hospital clerk pleads guilty to stealing, selling patient records
An update from Marco Chown Oved on the Rouge Valley Hospital insider breach reported last year: A former Rouge Valley Hospital clerk has pleaded guilty to stealing thousands of patient records and selling them to financial brokers over the course of more than a decade. Shaida Bandali, 61, who worked at Rouge Valley from 1995-2014,…
Boston University notifies medical research participants after server compromise
When a Boston University server was used to launch attacks against a system in Nova Scotia in May, the Nova Scotia network administrator contacted BU to alert them. BU’s month-long investigation revealed that one of its servers had been compromised – possibly by a hacker in Russia – in March 2015. Of note, the compromise…