Healthcare IT NewsHealthcare IT News
  • Home
  • Sections
    • Industry News
    • Hospitals & IDNs
    • Physician Practices & Ambulatory Care
    • Payers
    • Vendors
    • International
  • Issues
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • Sept. 2009
  • Resource Central
    • All Resources
    • Research
    • White Papers
    • Web Seminars
    • Videos
    • Podcasts
  • Blog
  • Events
  • Jobs
  • About
  • Subscribe
  • Advertise
  • Newsletters
  • RSS
  • Twitter
  • LinkedIn
  • Solutions Series
Select Your Homepage
Search eConnect
Login | Register
Home » News » Industry News

E-mail to a FriendPrint
Social Bookmarking
  • Delicious Delicious
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Reddit Reddit
  • Newsvine Newsvine
  • Furl Furl
  • Facebook Facebook
  • Google Google
  • Yahoo Yahoo
Hacker says he stole confidential medical data on 8 million Virginia residents

Hacker says he stole confidential medical data on 8 million Virginia residents

May 06, 2009 | Molly Merrill, Associate Editor and Chip Means, New Media Manager

Related Links

  • Wikileaks story
  • Transcript of full ransom note
  • Virginia Department of Health Professions Web site

Suggested Content

  • Virginia group launches Web site to promote e-prescribing
  • Advocacy organization calls for improved protection of online health data
  • Web News Briefs
  • Warner: Feds should do more to push HIT adoption

RICHMOND, VA – A Virginia government Web site was replaced last week with a ransom note from a hacker claiming he stole 8.3 million patients' personal and prescription drug information. The hacker says he wants $10 million for the safe return of the information.

The Virginia Prescription Monitoring Program's site tracks prescription drug abuse and contains 35.5 million prescriptions in addition to enrollees' personal information, such as names, social security numbers and addresses.

According to Wikileaks.org, an online clearinghouse for leaked documents, on April 30 the secure site for the Virginia Prescription Monitoring Program was replaced with the following ransom demand:

"Attention Virginia! I have your [expletive]! In *my* possession, right now, are 8,257,378 patient records and a total of 35,548,087 prescriptions. Also, I made an encrypted backup and deleted the original. Unfortunately for Virginia, their backups seem to have gone missing, too. Uhoh :( For $10 million, I will gladly send along the password." (See sidebar for link to full note).

The hacker, who taunts the FBI and lists his own email address as "hackingforprofit@yahoo.com," claims the database of prescriptions has been bundled into an encrypted, password-protected file.

The Virginia Department of Health Professions Web site has been temporarily disabled and now features a notice saying the site is "experiencing technical difficulties which affect computer and email systems." According to the department's director, Sandra Whitley Ryals, the breach is under federal investigation.

Speculation has risen about whether or not the Virginia Department of Health Professions has back-ups of the patient database.

"It is possible that they do have back-up, but they fear the massive damage if patients data is used for identity theft," says Deborah C. Peel, MD, founder of Patient Privacy Rights.

"This is a lesson for all health systems," she says. "Providence hospital system spent $8-9 million fending off lawsuits for a breach... You have to prove you can be trusted, especially in the wake of a disaster. And why not announce the actions they are taking - more specifics about who is investigating and more details as they are known," she added. "Treat the public not as an enemy but as the ones that deserve to know, the ones who hired them in the first place to care for residents of the state."

Robert Coffield, a healthcare lawyer practicing at Flaherty, Sensabaugh & Bonasso, PLLC and author of the Health Care Law Blog, says often times you don't want to disclose too much information or it may compromise the investigation. Coffield points out that this could be a hoax.

"There is indication that this is a real situation but it is too early to speculate at this point what has occurred is truthful," he says. "We have to remember that this is a pretty technical and difficult process to go through."

The alleged breach has also caused questions about whether under the HIPAA privacy rule, the Virginia Department of Health Professions is required to notify individuals impacted by the breach.

Coffield says that it does not. "However, when I have assisted clients with these types of data breach situations in the past I typically discuss with the client whether it is good practice to provide notification. The HIPAA privacy rule provisions do contain a requirement that a covered entity should mitigate potential harm to patients/individuals when there is a violation of the privacy rule. My interpretation is that this might, under certain circumstances, include providing notice to such individuals whose data has been compromised. Handling these situations is very fact specific and depends upon a number of factors."
 
One such factor is if Virginia was the only state involved. "The Virginia Department of Health Professions will likely have to assess the Virginia Data Breach Act (state-by-state survey of state breach laws by the National Conference of State Legislatures) to see whether notification or other action is required under state law."

Nancy Glasheen of the Virginia Health Commissioner's Office said the office knew of the data breaches but that most of the department's resources have been devoted to managing issues surrounding swine flu. "Everyone right now is heavily involved in H1N1, so a lot of our senior management is unavailable," she said.

Virginia Gov. Tim Kaine's (D) press secretary, Gordon Hickey, said there would be no official statements from the Governor's office while the investigation is still open. When asked to comment on the potential effects the data hijacking could have on Virginia's citizens, Hickey said, "That's the whole point of the investigation - to find out what's going on."

 

Lock photo by jimaand obtained under Creative Commons license.

Related Topics:
  • Deborah C. Peel
  • drug abuse
  • RICHMOND
  • Robert Coffield
  • Virginia
  • Virginia Gov

Reader Comments (0)Login to Post a Comment

receive news by email

Most Popular

Latest Headlines
Most Popular
  • Five healthcare IT decisions to avoid
  • Blumenthal: EHRs will become 'an absolute requisite' for docs
  • Video program puts docs at bedside 24/7 at MassGeneral
  • FCC to promote mobile health apps
  • Spheris bankruptcy could spark bidding war, with MedQuist in the lead
  • North Carolina group offers help with ARRA
  • New Hampshire hospital pulls its data together
  • KLAS questions vendor claims on HIEs
  • Terso expands to Germany
  • SunCrest Healthcare contracts with Philips for telehealth monitors

Resource Central

  • White Papers
    St. Francis Care Uses Leading Edge Technology to Deliver First Class Healthcare Services
  • White Papers
    Six Things Hospitals Need to Know About Replacing Pagers With Smartphones
  • Web Seminars
    On-Demand--Integrated, Real-time Decision Making – A Prescription for Improving Patient Outcomes and Your Bottom Line
  • Web Seminars
    On-Demand--Part II-The Crystal Clear Healthcare Provider: How Cleveland Clinic Delivers Transparency to Stakeholders with Business Intelligence
  • White Papers
    Validation process and compliance support with IBM Maximo Asset Management in regulated industries
More Resources
Syndicate content

HEALTHCARE IT JOB SPOT

  • Software Engineer - GE Healthcare - Boston, MA
  • Lead Software Engineer - GE Healthcare - Boston, MA
  • Conversion Analyst - GE Healthcare - WA
  • Show Site Director - GE Healthcare - North Carolina
  • Health Information Manager - Center for Spinal Surgery - Nashville, TN
more jobs

  • Destination HIMSS

    Going to HIMSS this year? Then you can't afford to miss our Destination HIMSS site and newsletter. 

  • EHRWatch.com

    EHRWatch.com offers news, commentary and community participation on the developments in electronic health records.

  • Priming the Pump

    Priming the Pump provides practical news on the stimulus package and the incentives that it offers to healthcare providers.

  • Facebook

    Join Healthcare IT News on Facebook to connect with other readers!

  • NHINWatch

    Visit NHINWatch.com for coverage of the Nationwide Health Information Network.

  • Mobile Health Watch

    Stay up to date on the latest mobility news at Mobile Health Watch.

  • MedTech Publishing

    Visit our company Web page to learn more about MedTech Publishing.

  • LinkedIn

    Join our LinkedIn group to connect with other readers. Click here to join the group.

     

  • Healthcare IT Job Spot

    Check out the latest open positions at Healthcare IT Job Spot.

Marketplace

  • Home
  • Issues
  • Resource Central
  • Blog
  • Events
  • Subscribe
  • Advertise
  • About Us
  • Site Map
  • Privacy Policy
Healthcare IT News is a publication of MedTech Publishing Company LLC.
For more information about MedTech Publishing Company and its publications, please visit medtechpublishing.com.
©2009 MedTech Publishing
Powered by Phase2 Technology.