Skip to content Skip to navigation

Indiana Medical Clinic and Long Beach Health Plan Report Data Security Incidents

August 29, 2016
by Heather Landi
| Reprints

Orleans Medical Clinic located in southern Indiana reported that it was recently the victim of a hacking incident of its network server resulting in inappropriate access to the protected health information about 6,800 patients.

In a separate incident, Scan Health Plan, a health insurance company based in Long Beach, California, reported a data privacy incident on its website that resulted in unauthorized access to patient information.

In the Orleans Medical Clinic incident, a breach report filed with the U.S. Department of Health and Human Services Office for Civil Rights (OCR) and publicly reported on the OCR’s breach portal indicated that 6,890 individuals were potentially affected by the server hacking incident. A notice posted on the medical practice’s website reported that on or about April 17, 2016, the clinic became aware of suspicious activity involving one of its computer servers. The clinic initiated an investigation and learned that its computer server that contained electronic health record data had been left unsecured after the server was upgraded.

“As a result, computer hackers gained access to the server over a period of time from April 5, 2016 until April 17, 2016. On July 21, 2016, we received confirmation of the individuals and information potentially affected by the breach,” according to a statement from the practice.

The practice stated that its investigation did not definitively conclude whether the hackers actually accessed or obtained a particular individual’s information. “It would have been possible for the hackers to access and obtain patient information about all of our current and former patients, including medical records and demographic information such as date of birth and social security number,” the practice stated.

Orleans Medical Clinic is offering all 6,890 patients one year of identity theft protection at no cost to patients through Equifax Personal Solutions.

Scan Health Plan posted a notice on its website stating that it is working with AllClear ID, an identity protection provider, to offer a year of identity protection services to plan members impacted by the data security incident.

On June 27, 2016, Scan Health Plan learned a person without authorization accessed contact sheets kept in a system used for sales purposes. “We immediately began an investigation and brought in outside experts. We determined the unauthorized access occurred between March and June 2016,” the health plan stated in it is notice. Scan Health also stated that there is no indication that the information in this system has been used fraudulently.

According to an article in the Long Beach Press Telegram, Scan Health Plan has about 170,000 members.

“The information on the contact sheets that were exposed included name, address, and phone number. For some people it also included date of birth and limited health notes, such as a doctor name, health condition, or medication name. For a small number of individuals it may have also included social security number,” the health plan stated.

Get the latest information on Cybersecurity and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

Healthcare Data Breaches: A Year in Review

The latest year-in-review Breach Barometer report from Protenus paints a stark picture—2016 average at least one health data breach per day, affecting more than 27 million patient records.

Healthcare Industry Could Save $9.4B with Full Adoption of Electronic Transactions

The healthcare industry continues to make modest progress toward full adoption of electronic business transactions, but significant gaps remain, representing an opportunity for $9.4 billion in savings, according to new data from the 2016 CAQH Index.

ONC Announces Phase 2 Winners of Consumer, Provider App Challenges

ONC today announced the Phase 2 winners for the Consumer Health Data Aggregator Challenge and the Provider User Experience Challenge.

Health Affairs: ACOs with High Numbers of Minority Patients Struggle in Quality

Accountable care organizations (ACOs) that have a high proportion of minority patients were associated with low scores on about three-fourths of Medicare quality performance measures, according to new research published in Health Affairs.

Trump Taps David Shulkin, an Obama Appointee, for VA Secretary

President-elect Donald Trump announced yesterday that David Shulkin, M.D.—an Obama administration appointee and current VA undersecretary—will lead the Department of Veterans Affairs.

NIST Publishes Draft Update to Cybersecurity Framework

The National Institute of Standards and Technology (NIST) has published proposed updates to the Framework for Improving Critical Infrastructure Cybersecurity—also known as the Cybersecurity Framework.