Skip to main content

Large Patient Information Breaches Skyrocket

 |  By dnicastro@hcpro.com  
   April 16, 2010

The number of entities reporting breaches of unsecured PHI affecting 500 or more individuals has doubled since the agency that enforces the HIPAA privacy and security rules first posted them on its Web site two months ago.

The Office for Civil Rights (OCR) in February posted a list of 32 entities that since September 22, 2009, had reported the egregious breaches to OCR. On Friday, that number climbed to 64.

HITECH requires OCR to make public any breaches of 500 or more. OCR said on the site it will continue to update the page as it receives new reports of breaches of unsecured PHI.

The requirement is included in the interim final rule on breach notification, which became effective on September 23, 2009.

Those regulations require:

  • Notice to patients alerting them to breaches "without unreasonable delay," but no later than 60 days after discovery of the breach

  • Notice to covered entities (CE) by business associates (BA) when BAs discover a breach

  • Notice to the secretary of HHS and prominent media outlets about breaches involving more than 500 patient records

  • Notice to next of kin about breaches involving patients who are deceased

  • Notices to include what happened, the details of the unsecured PHI that was breached, steps to help mitigate harm to the patient, and the CE's response

  • Annual notice to the secretary of HHS 60 days before the end of the calendar year about unsecure PHI breaches involving fewer than 500 patient records

Frank Ruelas, director of compliance and risk management at Maryvale Hospital in Phoenix, AZ, and principal of HIPAA Boot Camp in Casa Grande, AZ, released a report to HealthLeaders Media that breaks down the types of breaches posted on the OCR Web site.

Highlights include:

  • 27% involve laptops

  • 19% involve paper records

  • 17% involve desktop computers

Of the 64 breaches of unsecured PHI, 11 involved business associates. Eight of the entities on the Web site are listed as "private practice." OCR says it cannot list the names of sole practitioners who do not give it consent, per the Privacy Act of 1974.

The breach affecting the most individuals remains the Blue Cross Blue Shield of Tennessee incident that involved theft of hard drives Oct. 2, 2009.

Filling out the top five breaches are:

Providence Hospital
State: Michigan
Approximate number of individuals affected: 83,945
Date of breach: Feb. 4, 2010
Type of breach: Other
Location of breached information: Hard drive

Universal American, Inc.
State: New York
Business associate involved: Democracy Data & Communications, LLC
Approximate number of individuals affected: 83,000
Date of breach: Nov. 12, 2009
Type of breach: Incorrect mailing
Location of breached information: Postcards

"Private Practice"

City and state: San Antonio, Texas
Approximate number of individuals affected: 21,000
Date of breach: Feb. 20, 2010
Type of breach: Theft
Location of breached information: Portable electronic device

Shands at UF
State: Florida
Approximate number of individuals affected: 12,580
Date of breach: Jan. 27, 2010
Type of breach: Theft
Location of breached information: Laptop

Dom Nicastro is a contributing writer. He edits the Medical Records Briefings newsletter and manages the HIPAA Update Blog.

Tagged Under:


Get the latest on healthcare leadership in your inbox.