Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Hacker says he stole confidential medical data on 8 million Virginia residents

May 06, 2009 | Molly Merrill, Associate Editor and Chip Means, New Media Manager

Related Links

  • Wikileaks story
  • Transcript of full ransom note
  • Virginia Department of Health Professions Web site

Suggested Content

  • Automation key to getting a grip on absences
  • Bon Secours gets to the heart of IT
  • BCBS Virginia aims to cut unneeded ER visits
  • InnerWireless antennas keep things mobile at VCU
  • Virginia group launches Web site to promote e-prescribing
  • Advocacy organization calls for improved protection of online health data
  • Web News Briefs
  • Warner: Feds should do more to push HIT adoption

RICHMOND, VA – A Virginia government Web site was replaced last week with a ransom note from a hacker claiming he stole 8.3 million patients' personal and prescription drug information. The hacker says he wants $10 million for the safe return of the information.

The Virginia Prescription Monitoring Program's site tracks prescription drug abuse and contains 35.5 million prescriptions in addition to enrollees' personal information, such as names, social security numbers and addresses.

According to Wikileaks.org, an online clearinghouse for leaked documents, on April 30 the secure site for the Virginia Prescription Monitoring Program was replaced with the following ransom demand:

"Attention Virginia! I have your [expletive]! In *my* possession, right now, are 8,257,378 patient records and a total of 35,548,087 prescriptions. Also, I made an encrypted backup and deleted the original. Unfortunately for Virginia, their backups seem to have gone missing, too. Uhoh :( For $10 million, I will gladly send along the password." (See sidebar for link to full note).

The hacker, who taunts the FBI and lists his own email address as "hackingforprofit@yahoo.com," claims the database of prescriptions has been bundled into an encrypted, password-protected file.

The Virginia Department of Health Professions Web site has been temporarily disabled and now features a notice saying the site is "experiencing technical difficulties which affect computer and email systems." According to the department's director, Sandra Whitley Ryals, the breach is under federal investigation.

Speculation has risen about whether or not the Virginia Department of Health Professions has back-ups of the patient database.

"It is possible that they do have back-up, but they fear the massive damage if patients data is used for identity theft," says Deborah C. Peel, MD, founder of Patient Privacy Rights.

"This is a lesson for all health systems," she says. "Providence hospital system spent $8-9 million fending off lawsuits for a breach... You have to prove you can be trusted, especially in the wake of a disaster. And why not announce the actions they are taking - more specifics about who is investigating and more details as they are known," she added. "Treat the public not as an enemy but as the ones that deserve to know, the ones who hired them in the first place to care for residents of the state."

Robert Coffield, a healthcare lawyer practicing at Flaherty, Sensabaugh & Bonasso, PLLC and author of the Health Care Law Blog, says often times you don't want to disclose too much information or it may compromise the investigation. Coffield points out that this could be a hoax.

"There is indication that this is a real situation but it is too early to speculate at this point what has occurred is truthful," he says. "We have to remember that this is a pretty technical and difficult process to go through."

The alleged breach has also caused questions about whether under the HIPAA privacy rule, the Virginia Department of Health Professions is required to notify individuals impacted by the breach.

Coffield says that it does not. "However, when I have assisted clients with these types of data breach situations in the past I typically discuss with the client whether it is good practice to provide notification. The HIPAA privacy rule provisions do contain a requirement that a covered entity should mitigate potential harm to patients/individuals when there is a violation of the privacy rule. My interpretation is that this might, under certain circumstances, include providing notice to such individuals whose data has been compromised. Handling these situations is very fact specific and depends upon a number of factors."
 
One such factor is if Virginia was the only state involved. "The Virginia Department of Health Professions will likely have to assess the Virginia Data Breach Act (state-by-state survey of state breach laws by the National Conference of State Legislatures) to see whether notification or other action is required under state law."

Nancy Glasheen of the Virginia Health Commissioner's Office said the office knew of the data breaches but that most of the department's resources have been devoted to managing issues surrounding swine flu. "Everyone right now is heavily involved in H1N1, so a lot of our senior management is unavailable," she said.

Virginia Gov. Tim Kaine's (D) press secretary, Gordon Hickey, said there would be no official statements from the Governor's office while the investigation is still open. When asked to comment on the potential effects the data hijacking could have on Virginia's citizens, Hickey said, "That's the whole point of the investigation - to find out what's going on."

 

Lock photo by jimaand obtained under Creative Commons license.

Related Topics:
  • Deborah C. Peel
  • drug abuse
  • RICHMOND
  • Robert Coffield
  • Virginia
  • Virginia Gov

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • Analytics and the future of healthcare
  • CNIO position on the rise
  • Health data breaches up 97 percent in 2011
  • Docs use iPads, but don't see them as game-changers
  • Greenway set for IPO
  • HIT figures prominently in GOP primary battle for Nevada
  • Mostashari expects big year ahead for data exchange
  • AMA, AHIMA at odds on ICD-10
  • Minnesota: A healthy appreciation for HIT
  • 5 issues affecting cloud service quality and performance

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Driving Meaningful Use of Enterprise Content Management
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
More Resources
Syndicate content

HIMSS JOBMINE

  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
  • Vice President - Tower Strategies - Remote
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy