Showing posts with label identify theft. Show all posts
Showing posts with label identify theft. Show all posts

Tuesday, February 11, 2014

Medical identity theft increasing; survey says 43% of leaks involve medical records

Modern technology has brought about an increase in identity theft and lately in a particularly dangerous form: medical identity theft. According to a survey conducted by the Identity Theft Resource Center, 43 percent of all record breaches in personal information in 2013 involved health records . That's more than those involved with banking and finance, education, the government and the military, Michael Ollove writes for Stateline.

Medical identity theft is deceptively obtaining another person's personal information—such as name, Social Security number and health-insurance number—to get medical services, reimbursements or prescription drugs. "Medical identity theft is a growing and dangerous crime that leaves its victims with little to no recourse for recovery," said Pam Dixon, World Privacy Forum's founder and executive director. "Victims often experience financial repercussions and worse yet, they frequently discover erroneous information has been added to their personal medical files due to the thief's activities."

The Patient Protection and Affordable Care Act has caused even more concern about the privacy of medical information. Some people worry that online marketplaces could compromise confidentiality, and with the increased push for digitized medical records comes questions about the level of security of the computer networks. "Edward Snowden, the former National Security Agency contractor who has disclosed the agency's activities to the media, says the NSA has cracked the encryption used to protect the medical records of millions of Americans," Ollove writes.

According to Sam Imandoust of the Identity Theft Resource Center, thieves can obtain medical information by stealing laptops or hacking into computer networks. "With a click of a few buttons, you might have access to the records of 10,000 patients. Each bit of information can be sold for $10 to $20," he said. Over half of the security breaches result from a stolen electronic device, 20 percent result from a person's obtaining unauthorized access to information or giving it to someone who shouldn't have it and 14 percent result from hacking.

The Health Insurance Portability and Accountability Act and the Health Information Technology Act are the two federal laws that mandate the confidentiality of medical records. A business, institution or provider can be charged between $100 and $50,000 for failing to meet privacy standards, and a person who violates HIPAA could be charged a fine of $50,000 and serve up to a year in prison.

Even if the breach is discovered, that doesn't undo all the damage, Ollove writes. "It's almost impossible to clear up a medical record once medical identity theft has occurred," said James Pyles, a Washington, D.C., lawyer who has dealt with health issues for more than 40 years. "If someone is getting false information into your file, theirs gets laced with yours, and it's impossible to segregate what information is about you and what is about them." The U.S. has "a regulated industry that is saddled with laws with so many loopholes that they don't know what they are responsible for and a public that doesn't believe their health information is being protected." (Read more)

Friday, October 4, 2013

Beware of identity thieves exploiting the Patient Protection and Affordable Care Act to get personal information

As if buying health insurance isn't confusing enough, the Better Business Bureau has sent out a series of releases warning people to beware of scam artists posing as callers claiming to be from the federal government. The scam is mostly targeting small business owners, and people who are 65 and older or have disabilities.

The caller informs you that you've been selected to receive insurance cards through the Patient Protection and Affordable Care Act, but before the card can be mailed, they need your personal information, such as a credit card, Social Security number or Medicare ID. The callers may seem credible, often possessing personal information, such as a bank account number or routing number.

If someone gets such a call, they should immediately hang up, the BBB says. Don't press any buttons and don't return voice mails. The government usually communicates through mail, but if they call, they will already have all the necessary personal information. (Read more)

Tuesday, January 31, 2012

Medical records of 1,018 patients stolen at Lexington Clinic, but no apparent identity theft

One of the fears of electronic health records is that personal information can be stolen en masse, a possibility that became a reality when a laptop computer was stolen at the Lexington Clinic.

The machine was taken Dec. 7 from the clinic's neurology department at the St. Joseph Office Park. Letters were sent to the 1,018 affected patients last week about the theft, Mary Meehan of the Lexington Herald-Leader reports.

The laptop contained the names, contact information and diagnoses from patients from as long as five years go. Not among the data were Social Security numbers, credit card or bank account numbers. So far, there is no sign of identify theft. 

The clinic said it took six weeks to informing patients because it took time to "pinpoint exactly what information was on the laptop, which was used in conjunction with the clinic's electromyography machine," Meehan reports.

Another theft happened at UK HealthCare in June, when the medical records of 3,000 patients were taken from the Department of Pediatrics' newborn screening program. Patients were not informed of that breach until two months later. (Read more)