Adam Greenberg reports: Illinois-based Heartland Dental is notifying an undisclosed number of individuals that unauthorized access was gained to a limited portion of its IT systems, and that personal data may have been compromised. How many victims? Undisclosed. What type of personal information? Names, addresses, phone numbers, Social Security numbers, email addresses, certain information related to income and…
Category: U.S.
St. Martin Parish School Based Health Centers breach
As I’ve often noted on PogoWasRight.org, student health records are generally covered under FERPA, not HIPAA. When a school district provides a health center, however, the student’s health records may be covered by HIPAA, as seems to be the case with the St. Martin Parish School Based Health Centers in Louisiana. They notified HHS last…
NY: Montefiore Health System employee stole 12,517 patients’ information
From their web site: Montefiore Health System is notifying certain patients about a security incident involving information that was stolen by a former employee. The employee compromised the information of 12,517 patients, which included names, addresses, dates of birth, Social Security numbers, next of kin information, and health insurance details. The theft occurred between January 2013…
Seek and ye shall find: CareFirst notifies brokers and members of 2014 breach
Sometimes doing the right thing can be costly. In the wake of increasing attacks on health insurers (e.g., Anthem, Premera), CareFirst BlueCross BlueShield retained Mandiant to do an end-to-end assessment of their information security environment. The assessment included multiple scans to determine if there was any evidence of any attack. On April 21, 2015, Mandiant uncovered evidence…
FL: Tax Fraudster Receives 27-Year Prison Sentence; Scheme Used Stolen Patient Information
Some of the breaches mentioned in this press release had been covered on PHIprivacy.net. Tampa, Florida – U.S. District Judge Charlene Honeywell has sentenced James Lee Cobb, III (27, Tampa) to 27 years in federal prison, followed by 5 years of supervised release, for conspiracy to commit mail and wire fraud, wire fraud, aggravated identity…
No private info exposed in 2nd Lewisburg Area School District breach
Marcia Moore reports: A second computer breach in the Lewisburg Area School District in March did not expose any personal student or staff information, Superintendent Mark DiRocco said. Unlike the October incident in which the FBI was called to assist the Buffalo Valley Regional Police investigating a Lewisburg student who twice hacked a school cafeteria…