Jeremy Kirk reports: A new study from Microsoft researchers warns that many types of databases used for electronic medical records are vulnerable to leaking information despite the use of encryption. The paper, due to be presented at the ACM Conference on Computer and Communications Security next month, shows how sensitive medical information on patients could be…
Category: Of Note
Calif. Jury Clears UCLA In $1.25M Medical Data Breach Suit
Bonnie Eslinger reports: The University of California, Los Angeles Health System was not responsible for the unauthorized release of a woman’s medical records by a romantic rival, a California jury decided Thursday, rejecting her lawyer’s arguments that the victim was due $1.25 million for emotional harm caused by the breach. Read more on Law360 (subscription…
Cancer Care Group settles HHS charges over “widespread noncompliance” with HIPAA Security Rule; $750,000 fine and corrective action plan
In August 2012, I noted a breach involving the theft of backup media from an unattended vehicle of a Cancer Care Group employee. The backup contained information on 55,000 patients and employees. Now, more than three years later, HHS has announced a settlement with CCG over the breach. As seems to be their style, they…
Meanwhile, back at the OPM breach….
Victims of the breach still have not been notified. OPM will start sending postal laters “later this month.” The government will spend $133 million on identity theft protection services. With options, it could go up to $330 million. ID Experts (Identity Theft Guard Solutions LLC) got the gig to provide the service, which will provide…
UCLA Health notifying patients of stolen laptop containing personal health information; third breach report in as many months?
Hard to believe, but UCLA Health is notifying patients of yet another data breach. From a notice issued today: UCLA Health is sending notification letters to 1,242 individuals about the theft of a laptop computer containing patient names, medical record numbers, and health information used to help prepare patient treatment plans. No social security numbers,…
South Korea: KCC introduces ‘strong incentive’ for breach reporting
Oh, this is an intriguing approach. Alice Marini reports: The Korean Communications Commission (KCC) announced, on 21 August 2015, the implementation of a new penalty scheme, which allows companies, that have voluntarily reported a data breach to the KCC, to receive a reduction on the total administrative fine prescribed of up to the 30% (‘the…