HHS publicly posts list of data breach notifications
A list of the covered entities that have reported health information data breaches impacting more than 500 people now has been posted by the Office of Civil Rights of the Department of Health and Human Services on its Web site.
HHS is required by section 13402(e)(4) of the HITECT Act to post the list, which includes the covered entity’s name, the nature of the breach and the number of individuals affected.
The list includes 36 breaches dating from Sept. 22, 2009--when entities were first required to start reporting the breaches--to as recently as Jan. 18, 2010.
The biggest breaches involved:
- Blue Cross Blue Shield of Tennessee in a case that affected 500,000 persons;
- AvMed in a situation in Florida impacting 359,000 persons due to a stolen laptop; and
- Universal American in a breach that affected 83,000 persons because of an incorrect mailing of postcards.
Most of the cases involved the loss or theft of stolen devices such as laptops and in the vast majority of cases the number of persons affected was less than 10,000. Eleven of the breaches impacted fewer than 1,000 persons.
To see the entire list click here.