Ind. breach impacts almost 200,000

The Indiana Family and Social Services Administration (FSSA) is in the process of notifying almost 200,000 clients that some of their personal information may have been accidently disclosed to other clients, according to a statement from the organization.

The accidental disclosures may have occurred when RCR Technology Corporation (RCR), a contractor for FSSA, made a computer programming error to a document management system the company supports on behalf of FSSA. This error caused an undetermined number of documents being sent to clients to be duplicated and also inserted with documents sent to other clients. Some clients may have received documents belonging to other clients along with their own documents.

The programming error was made on April 6, and affected correspondence sent between April 6 and May 21. The error was discovered on May 10. RCR determined the root cause of the programming error and it was corrected on May 21.

In compliance with federal and state privacy law, FSSA has sent written notices to the 187,533 potentially impacted FSSA clients informing them that some of their personal information may have been disclosed.

Information that may have been disclosed includes name, address, case number, date of birth, gender, race, telephone number, email address, types of benefits received, monthly benefit amount, employer information, some financial information such as monthly income and expenses, bank balances and other assets, and certain medical information such as provider name, whether the client receives disability benefits and medical status or condition, and certain information about the client’s household members like name, gender and date of birth. Of the 187,533 clients, 3,926 may have had their Social Security numbers disclosed. 

This is the second HIPAA breach for the Indiana FSSA. In 2012, the agency reported the theft of a company laptop containing the protected health information of 757 clients.

Beth Walsh,

Editor

Editor Beth earned a bachelor’s degree in journalism and master’s in health communication. She has worked in hospital, academic and publishing settings over the past 20 years. Beth joined TriMed in 2005, as editor of CMIO and Clinical Innovation + Technology. When not covering all things related to health IT, she spends time with her husband and three children.

Around the web

The American College of Cardiology has shared its perspective on new CMS payment policies, highlighting revenue concerns while providing key details for cardiologists and other cardiology professionals. 

As debate simmers over how best to regulate AI, experts continue to offer guidance on where to start, how to proceed and what to emphasize. A new resource models its recommendations on what its authors call the “SETO Loop.”

FDA Commissioner Robert Califf, MD, said the clinical community needs to combat health misinformation at a grassroots level. He warned that patients are immersed in a "sea of misinformation without a compass."