91K affected by improper Wash. state employee data exchange

Apple Health, Washington state's Medicaid program, has reported a breach affecting the protected health information (PHI) of more than 91,000 individuals.

According to the notification from the Washington State Health Care Authority, two state employees in different agencies exchanged Apple Health client files in a manner not compliant with HIPAA. Both employees said they exchanged the information because an HCA employee needed assistance with spreadsheets containing PHI, and the data was not used for any unauthorized purposes.

"While we have no indication that the client files went beyond the two individuals involved, important privacy laws were violated, and we are exercising caution and due diligence given the nature of the information," said Steve Dotson, HCA risk manager.

However, they are not able to confirm that the data stayed within the state's system.

Apple Health learned of the incident through a whistleblower investigation into misuse of state resources, according to the notification.

The compromised spreadsheets include client Social Security numbers, birth dates and Apple Health ID numbers.

Beth Walsh,

Editor

Editor Beth earned a bachelor’s degree in journalism and master’s in health communication. She has worked in hospital, academic and publishing settings over the past 20 years. Beth joined TriMed in 2005, as editor of CMIO and Clinical Innovation + Technology. When not covering all things related to health IT, she spends time with her husband and three children.

Trimed Popup
Trimed Popup