Breach Report 2013.Pdf
Total Page:16
File Type:pdf, Size:1020Kb
Report Date: Identity Theft Resource Center 8/9/2013 2013 Breach List: Breaches: 360 Exposed: 7,534,496 Page 1 of 72 How is this report produced? What are the rules? See last page of report for details. ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-13 Northrop Grumman Retiree VA Paper Data Medical/Healthcare Yes - Published # 4,305 Health Plan other - paper Attribution 1 Publication: hhs.gov Author: Date Published: Article Title: Northrop Grumman Retiree Health Plan Article URL: http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-12 Med-El NC Electronic Medical/Healthcare Yes - Published # 609 other - email Attribution 1 Publication: hhs.gov / phiprivacy.net Author: Date Published: Article Title: Med-El Article URL: http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-11 Medtronic MN Paper Data Medical/Healthcare Yes - Published # 2,764 In early July, the manufacturer notified patients about a box of training records that had gone missing from a facility in Minnesota, Resman said. Most of the documents and records in the box dated back to 2008 and were connected with training in the use of insulin pumps or continuous glucose monitoring devices. Attribution 1 Publication: phiprivacy.net / hhs.gov Author: Date Published: Article Title: Medtronic Article URL: http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-10 Aflac GA Electronic Medical/Healthcare Yes - Published # 679 theft of laptop Attribution 1 Publication: hhs.gov Author: Date Published: Article Title: Aflac Article URL: http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-09 Sheet Metal Local 36 Welfare MO Electronic Medical/Healthcare Yes - Published # 4,560 Fund unauthorized access/disclosure - other Attribution 1 Publication: hhs.gov Author: Date Published: Article Title: Sheet Metal Local 36 Welfare Fund Article URL: http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-08 South Florida Neurology FL Electronic Medical/Healthcare Yes - Published # 900 Associates, P.A. theft of laptop Attribution 1 Publication: hhs.gov Author: Date Published: Article Title: South Florida Neurology Associates, P.A. Article URL: http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html Copyright 2013 Identity Theft Resource Center Report Date: Identity Theft Resource Center 8/9/2013 2013 Breach List: Breaches: 360 Exposed: 7,534,496 Page 2 of 72 How is this report produced? What are the rules? See last page of report for details. ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-07 Samaritan Regional Health OH Paper Data Medical/Healthcare Yes - Published # 2,203 System paper breach Attribution 1 Publication: hhs.gov Author: Date Published: Article Title: Samaritan Regional Health System Article URL: http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-06 Jacksonville Spine Center FL Paper Data Medical/Healthcare Yes - Published # 5,200 unauthorized access/disclosure - paper Attribution 1 Publication: hhs.gov Author: Date Published: Article Title: Jacksonville Spine Center Article URL: http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-05 Lone Star Circle of Care TX Electronic Medical/Healthcare Yes - Published # 1,955 theft of laptop Attribution 1 Publication: phiprivacy.net / hhs.gov / LSCC website Author: Date Published: Article Title: Lone Star Circle of Care Article URL: http://www.lscctx.org/security/ ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-04 Cogent Healthcare, Inc. TN Electronic Medical/Healthcare Yes - Published # 32,000 The protected health information of some 32,000 patients across 48 states has been compromised after a health IT vendor's firewall was down for more than a month, allowing, in some cases, for patient data to be indexed by Google, officials announced Thursday. Attribution 1 Publication: healthcareitnews.com Author: Date Published: Article Title: Site flaw puts patient data on Google Article URL: http://www.healthcareitnews.com/news/site-flaw-puts-patient-data-google ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-03 Office of Dr. James Fosnaugh NE Electronic Medical/Healthcare Yes - Published # 2,125 Somehow, somewhere, sometime in May, a computer chip containing medical records for more than 2,000 of a Lincoln doctor's patients went missing — likely having slipped from the thumb drive Dr. James Fosnaugh wore on a lanyard around his neck. Attribution 1 Publication: JournalStar.com Author: Date Published: Article Title: Lost piece of thumb drive contained thousands of patient records Article URL: http://journalstar.com/news/local/lost-piece-of-thumb-drive-contained-thousands-of-patient-records/article_d3d422ab-e ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-02 Missouri HealthNet MO Electronic Medical/Healthcare Yes - Published # 1,357 MO HealthNet is in the process of notifying 1,357 individuals that some of their personal information was mailed to an incorrect address by one of its contractors, Infocrossing, Inc. The disclosure was caused by a software programming error. Attribution 1 Publication: KRCG13 / PHIPrivacy.net Author: Date Published: Article Title: MO HealthNet notifies consumers of HIPAA disclosure Article URL: http://www.connectmidmissouri.com/news/story.aspx?id=930103 - .UgUeZ53n_mc Copyright 2013 Identity Theft Resource Center Report Date: Identity Theft Resource Center 8/9/2013 2013 Breach List: Breaches: 360 Exposed: 7,534,496 Page 3 of 72 How is this report produced? What are the rules? See last page of report for details. ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130809-01 Retinal Consultants Medical CA Electronic Medical/Healthcare Yes - Unknown # 0 Group On June 7, 2013, it was discovered that a laptop computer, which was a component of a diagnostic imaging machine, was stolen sometime after our office closed on June 5, 2013. The laptop computer contained the following types of unsecured PHI: names, dates of birth, gender, race, and OCT (optical coherence tomography) images. Please be assured that information such as your Social Security Number, Driver’s License, and address was not on the laptop. Attribution 1 Publication: eSecurity Planet - RCMG Notification let Author: Jeff Goldman Date Published: Article Title: Retinal Consultants Medical Group Admits Security Breach Article URL: http://www.esecurityplanet.com/network-security/retinal-consultants-medical-group-admits-security-breach.html ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130808-04 Auburn University AL Electronic Educational Yes - Unknown # 0 We represent Auburn University, 316 Leach Science Center, Alabama 36849 ("Auburn University") and are writing to notify you of a data event that may affect the security of personal information of two (2) New Hampshire residents. Auburn University's investigation into this event is ongoing, and this notice will be supplemented with any new significant facts learned subsequent to its submission. By providing this notice, Auburn University does not waive any rights or defenses under New Hampshire law. Attribution 1 Publication: databreaches.net / NH AG's office Author: Date Published: Article Title: Auburn University Article URL: http://doj.nh.gov/consumer/security-breaches/documents/auburn-university-20130802.pdf ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20130808-03 Rocky Mountain Spine Clinic CO Electronic Medical/Healthcare Yes - Published # 532 Rocky Mountain Spine Clinic announced Wednesday that a former employee misappropriated and stole protected health information from some of the clinic's patients. The employee, who worked for RMSC's billing department, created a document containing the information of 532 patients and then sent the document to her personal email account, according to a news release. Attribution 1 Publication: Denver Post / datalossdb.org Author: Matthew Payne Date Published: Article Title: Former Rocky Mountain Spine Clinic employee stole patient information Article URL: http://www.denverpost.com/breakingnews/ci_23769928/former-rocky-mountain-spine-clinic-employee-stole-patient