HHS publicly posts list of data breach notifications

  

A list of the covered entities that have reported health information data breaches impacting more than 500 people now has been posted by the Office of Civil Rights of the Department of Health and Human Services on its Web site.

HHS is required by section 13402(e)(4) of the HITECT Act to post the list, which includes the covered entity’s name, the nature of the breach and the number of individuals affected.

The list includes 36 breaches dating from Sept. 22, 2009--when entities were first required to start reporting the breaches--to as recently as Jan. 18, 2010.

The biggest breaches involved:

  • Blue Cross Blue Shield of Tennessee in a case that affected 500,000 persons;
  • AvMed in a situation in Florida impacting 359,000 persons due to a stolen laptop; and
  • Universal American in a breach that affected 83,000 persons because of an incorrect mailing of postcards.

Most of the cases involved the loss or theft of stolen devices such as laptops and in the vast majority of cases the number of persons affected was less than 10,000. Eleven of the breaches impacted fewer than 1,000 persons.

To see the entire list click here.
 

Michael Bassett,

Contributor

Around the web

The American College of Cardiology has shared its perspective on new CMS payment policies, highlighting revenue concerns while providing key details for cardiologists and other cardiology professionals. 

As debate simmers over how best to regulate AI, experts continue to offer guidance on where to start, how to proceed and what to emphasize. A new resource models its recommendations on what its authors call the “SETO Loop.”

FDA Commissioner Robert Califf, MD, said the clinical community needs to combat health misinformation at a grassroots level. He warned that patients are immersed in a "sea of misinformation without a compass."

Trimed Popup
Trimed Popup