Volume 16, Issue 1
SPRING 2019
Security Shredding News Serving the Security Shredding & Records Storage Markets
Visit us online at www.SecurityShreddingNews.com
HIPAA Reports Record Number of Enforcements in 2018
E
By Ken McEntee
nforcement actions for violations of the Health Insurance Portability and Accountability Act (HIPAA) set a record last year, according to the U.S Department of Health and Human Services Office for Civil Rights (OCR) concluded an all‑time record year in enforcement activity. In 2018, OCR settled 10 cases - including a case involving a defunct record storage company - and was granted summary judgment in a case before an administrative law judge, together totaling $28.7 million from enforcement actions. This total surpassed the previous record of $23.5 million, set in 2016, by 22 percent. In addition, OCR also achieved a $16 million settlement with Anthem Inc., the largest individual HIPAA settlement ever. The settlement was almost three times larger than the previous record of $5.5 million reached in 2016. “Our record year underscores the need for covered entities to be proactive about data security if they want to avoid being on the wrong end of an enforcement action,” said OCR Director Roger Severino. OCR’s final settlement of 2018 occurred in December, when Cottage Health, of Santa Barbara, Calif., agreed to pay $3 million to OCR and to adopt a substantial corrective action plan to settle potential violations of the HIPAA rules. Cottage Health operates Santa Barbara Cottage Hospital, Santa Ynez Cottage Hospital, Goleta Valley Cottage Hospital and Cottage Rehabilitation Hospital, all in California. OCR received two notifications from Cottage Health regarding breaches of unsecured electronic protected health information (ePHI) affecting more than 62,500 individuals, one in December 2013 and another in December 2015. OCR said the first breach arose when ePHI on a Cottage Health server was accessible from the internet. OCR’s investigation determined that security configuration settings of the Windows operating system permitted access to files containing ePHI without requiring a username and password. As a result, patient names, addresses, dates of birth, diagnoses, conditions, lab results and other treatment
information were available to anyone with access to Cottage Health’s server. The second breach occurred when a server was misconfigured following an IT response to a troubleshooting ticket, exposing unsecured ePHI over the internet. This ePHI included patient names, addresses, dates of birth, social security numbers, diagnoses, conditions, and other treatment information. OCR’s investigation revealed that Cottage Health failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the ePHI; failed to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level; failed to perform periodic technical and non-technical evaluations in response to environmental or operational changes affecting the security of ePHI; and failed to obtain a written business associate agreement with a contractor that maintained ePHI on its behalf. “The Cottage settlement reminds us that information security is a dynamic process and the risks to ePHI may arise before, during and after implementation covered entity makes system changes,” Severino said. In addition to the $3 million settlement, Cottage will undertake a robust corrective action plan to comply with the HIPAA Rules. Here are OCR’s other settlements and judgements from 2018:
Filefax Inc.
I
n January 2018, OCR settled for $100,000 with Filefax Inc., a now-closed medical records maintenance, storage and delivery services provider based in Northbrook, Ill. OCR’s investigation found that Filefax impermissibly disclosed protected health information (PHI) of about 2,150 people by leaving the PHI in an unlocked truck in the Filefax parking lot, or by granting permission to an unauthorized person to remove the PHI from Filefax and leaving the PHI unsecured outside the Filefax facility. Consequences for HIPAA violations don’t stop when a business closes, OCR said. In February, 2018, a receiver appointed to liquidate the assets of Filefax agreed to pay $ 100,000 out of the receivership estate to the OCR to settle the HIPAA violations. Although Filefax shut its doors during the course of OCR’s investigation into alleged HIPAA violations, it could not escape its obligations under the law, OCR said. On February 10, 2015, OCR received an anonymous complaint alleging that an individual transported medical records obtained from Filefax to a shredding and recycling facility to sell on February 6 and 9, 2015. OCR opened an investigation, which confirmed that an individual had the left medical records of about 2,150 patients at the shredding and recycling facility, and that these medical records contained Continued on page 3
Have you started shredding hard drives and SSD’s yet?
The future is here. Everything needs to be destroyed. No better time than now to create new revenue stream for your business
A
LLEGHENY MANUFACTURES a complete line of powerful hard drive shredders, providing everything from 3 HP shredders for those companies just entering into this thriving business, to 20 HP fully automated E-scrap destruction systems. All of our Hard Drive Shredders can be equipped for mobile on-site shredding, giving you the option to shred at your place…or theirs!
Securely Shred SSDs and Rotary HDs
well as cell phones, USB drives, CD’s, and many other e-scrap products to be destroyed on the SAME machine.
We’ll help get you started!
Don’t fall behind the times! Our experts will help you launch your own hard drive destruction service right away, so you can reap the benefits of this growing and critical niche in information destruction.
Don’t forget about Allegheny’s SelecShred™ Hard Drive Shredder! Manufactured with a split head cutting assembly, this shredder allows for solid state drives and rotary hard drives, as
call us today
800-245-2497
alleghenyshredders.com
12HD20 SELECSHREDTM HARD DRIVE SHREDDER
© 2017 Allegheny Paper Shredders Corporation
Old William Penn Hwy E, Delmont, PA 15626 ■ 800-245-2497 toll free alleghenyshredders.com Old William Penn Hwy East, Delmont PA 15626 ■
©2016 Allegheny Paper Shredders Corporation www.alleghenyshredders.com alleghenyshredders.com 800-245-2497
2 Security Shredding News Spring 2019
Security Shredding News
HIPAA Reports Record Number of Enforcements in 2018 Continued from page 1
patients’ protected health information. “The careless handling of PHI is never acceptable,” Severino said. “Covered entities and business associates need to be aware that OCR is committed to enforcing HIPAA regardless of whether a covered entity is opening its doors or closing them. HIPAA still applies.”
Fresenius Medical Care
I
n January 2018, OCR settled for $3.5 million with Fresenius Medical Care North America
PUBLICATION STAFF Publisher / Editor Rick Downing Contributing Editors / Writers Ken McEntee • Bob Johnson Sandy Woodthorpe Production / Layout Barb Fontanelle • Christine Mantush Advertising Sales Rick Downing Subscription / Circulation Donna Downing Editorial, Circulation & Advertising Office 6075 Hopkins Rd., Mentor, OH 44060 Ph: 440-257-6453 • Fax: 440-257-6459 Email: downassoc2@oh.rr.com www.securityshreddingnews.com For subscription information, please call 440-257-6453 Security Shredding News (ISSN #15498654) is published bimonthly by Downing & Associates. Reproductions or transmission of Security Shredding News, in whole or in part, without written permission of the publisher is prohibited. Annual subscription rate U.S. is $19.95. Outside of the U.S. add $10.00 ($29.95). Contact our main office, or mail-in the subscription form with payment.
©Copyright 2019 by Downing & Associates Printed on Post-Consumer Recycled Paper
(FMCNA), a Waltham, Mass.-based provider of products and services for people with chronic kidney failure. OCR said FMCNA filed five breach reports for separate incidents occurring between February 23 and July 18, 2012, implicating the ePHI of five FMCNAowned covered entities. OCR’s investigation revealed that FMCNA failed to conduct an accurate and thorough risk analysis of potential risks and vulnerabilities to the confidentiality, integrity and availability of all of its ePHI. Additional potential violations included failure to implement policies and procedures and failure to implement a mechanism to encrypt and decrypt ePHI, when it was reasonable and appropriate to do so under the circumstances.
Anderson Cancer Center
I
n June 2018, an HHS administrative law judge ruled in favor of OCR and required the University of Texas MD Anderson Cancer Center, a Houston-based cancer center, to pay $4.3 million in civil money penalties for HIPAA violations. OCR said it investigated MD Anderson following three separate data breach reports in 2012 and 2013 involving the theft of an unencrypted laptop from the residence of an MD Anderson employee and the loss of two unencrypted USB thumb drives containing the unencrypted ePHI of more than 33,500 individuals. OCR’s investigation found that MD Anderson had written encryption policies going back to 2006 and that MD Anderson’s own risk analyses had found that the lack of device-level encryption posed a high risk to the security of ePHI. Despite the encryption policies and high risk findings, MD Anderson did not begin to adopt an enterprise-wide solution to encrypt ePHI until 2011, and even then it failed to encrypt its inventory of electronic devices containing ePHI between March 24, 2011 and January 25, 2013, OCR said. This matter is under appeal with the HHS Departmental Appeals Board.
Boston Hospitals
I
n September 2018, OCR said that it reached separate settlements totaling $999,000, with Boston Medical Center, Brigham and Women’s Hospital and Massachusetts General Hospital all of Boston - for compromising the privacy of patients’ PHI by inviting film crews on premises to film an ABC television network documentary series without first obtaining authorization from patients.
Advanced Care Hospitalists
A
lso in September 2018, OCR settled with Advanced Care Hospitalists (ACH), a contractor physician group in Lakeland, Fla., for $500,000. ACH filed a breach report confirming that ACH patient information was viewable on a medical billing services’ website. OCR said its investigation revealed that ACH never had a business associate agreement with the individual providing medical billing services to ACH, and failed to adopt any policy requiring business associate agreements until April 2014. Although ACH had been in operation since 2005, it had not conducted a risk analysis or implemented security measures or any other written HIPAA policies or procedures before 2014, OCR said.
Allergy Associates
I
n October 2018, OCR settled with Allergy Associates, a Hartford, Ct.-based health care practice that specializes in treating individuals with allergies, for $125,000. In February 2015, a patient of Allergy Associates contacted a local television station to speak about a dispute that had occurred between the patient and an Allergy Associates’ doctor. OCR’s investigation found that the reporter subsequently contacted the doctor for comment and the doctor impermissibly disclosed the patient’s PHI to the reporter.
Anthem Inc.
I
n October 2018, Anthem paid $16 million to OCR and agreed to take substantial corrective action to settle potential violations of the HIPAA rules after a series of cyber attacks led to the largest U.S. health data breach in history. “The largest health data breach in U.S. history fully merits the largest HIPAA settlement in history,” Severino said. “Unfortunately, Anthem failed to implement appropriate measures for detecting hackers who had gained access to their system to harvest passwords and steal people’s private information.” Anthem is one of the nation’s largest health benefits companies, providing medical care coverage to one in eight Americans through its affiliated health plans. Its breach affected ePHI that Anthem maintained for its affiliated health plans and any other covered entity health plans. Anthem filed a breach report after discovering cyber-attackers had gained access Continued on page 4
Security Shredding News Spring 2019
3
Security Shredding News
i-SIGMA Emerging as a Community for All RIM Services By Bob Johnson
O
n July 1, 2018, PRISM International and NAID official merged to become i-SIGMA, creating the largest trade association of information management and security service providers in the world. And while big (or bigger) is not always better, after eight months of assimilation the benefits of merger are already apparent. And what is more, i-SIGMA is show signs it will emerge from the merger as a global community of vendors who are better able to promote the high ethics and operating standards and help clients use members’ services to meet their compliance and security requirements. According to i-SIGMA Co-President Angie Singer Keating, creating i-SIGMA would have been impossible if not for the quality of its building blocks. “PRISM International brought a respected and enviable 38-year track record in records and information management to the equation,” said Keating. “While NAID came to the table with a proven ability to develop successful programs and an ambitious management team. It’s why the early results of the merger point so clearly to its early success.” The decision to use i-SIGMA as an umbrella organization, keeping NAID and PRISM International as the outward facing brands help speed up integration and execution. According to Christopher Jones, the other i-SIGMA Co-President, it was important the branding be more than cosmetic. “We knew from the start the both PRISM International and NAID needed to have service providers dedicated to meaningful representation,” said Jones. “To ensure that, each division has a Leadership Committee responsible to make sure the larger organization remains focused on the needs of its constituents we wrote the requirement into the bylaws.”
With the support of the i-SIGMA board and clear vision for what we wanted to achieve, the new organization hit the ground running. Added Subject Matter Expertise: In October, Gail Bisbee was selected from a short list of highly-regarded professionals to bring records management services expertise into the i-SIGMA management team. As a result, PRISM International members now have one of the world foremost authorities in records and information management to guide the association and address their questions. Formed PRISM PRIVACY+ Certification Committee: The first step in advancing PRISM’s PRIVACY+ Certification, the division took a page from NAID by creating a committee specifically focused on improving and advancing the program. The change comes amid signs that recognition for the program is already growing. In the past 6 months, PRIVACY+ Certifications has added a half dozen members to its ranks, including locations in India and Saudi Arabia. Local and Global Advocacy: It’s been said that “timing is everything.” It just so happens that the merger creating i-SIGMA coincided with the wave of data protection regulations across the U.S. and around the world. There is no doubt that the combined resources of NAID and PRISM International, not to mention the combined brain-power, will allow the organization to better represent members’ interests. As a result, the future of RIM service and data destruction have a bright future and will factor heavily in upcoming legislation. Folding the Data Protection Association (DPA) into i-SIGMA: There could be no better testimony to the viability and benefits of the i-SIGMA community of service providers, than the decision by the Data Protection
Continued on next page
HIPAA Reports Record Number of Enforcements in 2018 Continued from page 3
to its IT system via an undetected continuous and targeted cyber attack for the apparent purpose of extracting data, otherwise known as an advanced persistent threat attack. After filing its breach report, Anthem discovered cyber-attackers had infiltrated its system through spear phishing emails sent to an Anthem subsidiary after at least one employee responded to the malicious email and opened the door to further attacks. OCR’s investigation revealed that between December 2, 2014 and January 27, 2015, the cyber attackers stole the ePHI of almost 79 million individuals, including names, social security numbers, medical identification numbers, addresses, dates of birth, email addresses and employment information. “We know that large health care entities are attractive targets for hackers, which is why they are expected to have strong password policies and to monitor and respond to security incidents in a timely fashion or risk enforcement by OCR,” Severino said. In addition to the impermissible disclosure of ePHI, OCR’s investigation revealed that Anthem failed to conduct an enterprise-wide risk analysis, had insufficient procedures to regularly review information system activity, failed to identify and respond to suspected or known security
incidents and failed to implement adequate minimum access controls to prevent the cyber-attackers from accessing sensitive ePHI beginning as early as February 18, 2014. In addition to the $16 million settlement, Anthem said it will undertake a robust corrective action plan to comply with the HIPAA Rules.
Pagosa Springs Medical Center
I
n November 2018, Pagosa Springs Medical Center, a critical access hospital in Pagosa Springs, Colo., paid $111,400 to OCR to resolve potential violations concerning a former PSMC employee who continued to have remote access to PSMC’s web-based scheduling calendar after separation of employment. The calendar contained patients’ ePHI. OCR’s investigation revealed that PSMC impermissibly disclosed the ePHI of 557 individuals to its former employee. Ken McEntee is the publisher and editor of The Paper Stock Report, providing market intelligence for the paper recycling industry.Visit paperstockreport. com.
Visit us online at www.SecurityShreddingNews.com 4 Security Shredding News Spring 2019
Security Shredding News Continued from previous page Association Board of Directors to roll into the new organization. More than the added resources and more than the added numbers, it indicates the appeal of an organization with the resources and credibility to project a united front to customers and regulators, and the power and credibility that comes with it. Exciting Future Of course, the real test of the merger’s success is how it resonates with service providers. Here the news is good too. The organizations’ respective memberships and certifications continue to grow. The upcoming 2019 Conference and Expo in Denver on pace to be among the largest in the organization’s history. At this point in time, close to 200 member representatives actively participate in the various boards and committees that make it run. Only time will tell if i-SIGMA realizes its full potential. Luckily, all the early signs clearly point to the fact that it will. Bob Johnson is the CEO of i-SIGMA. He can be reached at rjohnson@isigmaonline.org. 2019
Redishred Buys Proshred and Secure e-Cycle in Deals Totaling $7.5 Million
M
ississauga, Ontario — Redishred Capital Corp. is positioned to expand its on-site and plant-based shredding business through its latest acquisitions, Proshred Kansas City and Secure e-Cycle, according to a company statement released in February and published on Digital Journal. Both ProShred and Secure e-Cycle have been operated by the same franchisee. The total purchase price for these acquisitions was approximately USD$7.5 million in cash, earnout and vendor take back. Redishred’s statement says the latest assets to add on-site paper shredding trucks, plant-based shredding and baling equipment, client relationships and other capabilities used in the shredding and electronics recycling businesses. The businesses are expected to substantially increase Redishred’s cash flows and earnings per share. Redishred Capital Corp. is the owner of the PROSHRED® trademarks and intellectual property in the United States and Internationally. PROSHRED® shreds and recycles confidential documents and proprietary materials currently services over 40 markets in the United States in all industry sectors. The company has ISO 9001:2015 certification. Redishred Capital Corp. grants PROSHRED® franchise businesses in the United States and by way of license arrangement in the Middle East. Redishred Capital Corp. also operates eight corporate shredding businesses directly. Secure e-Cycle provides data destruction & removal, including data sanitization and physical destruction, responsible e-waste recycling, remarketing & resale of surplus equipment and detailed results reporting. Redishred’s plan, according to its news release, is to continue growing through franchising and buying/operating document destruction businesses that generate stable and recurring cash flow through regularly schedule service contracts, ongoing paper recycling and as-needed shredding service.
Security Shreddiong & Storage News Combo Half Horizontal - 8-3/8” x 5-1/8”
Advertise in all 4 issues of Security Shredding News and $AVE !! For more information, contact Rick Downing at 440-257-6453 or email rickdowning@oh.rr.com.
INDUSTRIAL PAPER SHREDDERS MOBILE SHREDDING SYSTEMS CDL • NON-CDL • PIERCE-&-TEAR • SINGLE-SHAFT
(336) 285-0021 • 5708 UwHARRIE ROAD, ARCHDALE, NC 27263 • www.vECOPLANLLC.COM Security Shredding News Spring 2019
5
www.paperstockindustries.org 6 Security Shredding News Spring 2019
PSI@isri.org
Security Shredding News
New Report Urges Focus on E-Waste Reduction Policymaking
T
he World Business Council for Sustainable Development is promoting a new initiative to reduce electronics waste (e-waste), reports. Announced at the World Economic Forum in Davos in January, the group wants to stimulate a “circular economy” that hinges on improved repairability and reusability. Called PACE, the Platform for Accelerating the Circular Economy shared its first report entitled at Davos. The volume of e-waste has been increasing steadily and has many industry observers and sustainability groups, as well as policymakers, concerns. A report puts electronics raw materials at $62.5 billion. PACE puts discarded devices at 48.5 million tonnes. The PACE report authors urge designers, manufacturers, investors, traders, miners, raw material producers, recyclers, consumers, policymakers and others to innovate. A Right to Repair initiative can cut e-waste now, they say. As of last year, 17 states have introduced bills that would reduce repair costs by requiring manufacturers to make parts and tools accessible to independent repair shops. Manufacturers tend to balk at such requirements. A recent example of an environmentally unfriendly design from Apple is the MacBook Pro. Internet-based repair guide website, iFixit, says the unit’s “stage light fault,” a display problem, should be a $6 cable fix. By contrast, the manufacturer charges $600 to replace the entire display. On the positive side, Apple shows support by accepting recyclable devices of any brand at its in-store collection sites. The free discard service is in addition to Apple’s trade-in program for credit toward new devices. Last year, Apple unveiled its new Daisy iPhone disassembly robot (a successor to Liam) to recycle and salvage parts from nine different iPhone models and also hit 100 percent sustainable energy for all of its operations. Meanwhile, PACE’s report projects that e-waste will more than double to 120 million tonnes by 2050.
Access Acquires Docu-Depot
W
oburn, MA — Records and information management services provider, Access, has acquired Docu-Depot, according to a company statement released in February. Woburn, Massachusetts based Access, a portfolio company of Berkshire Partners and GI Partners, is the largest privately-held records and information management services provider worldwide, with operations across the United States, Canada, Central and South America. Headquartered in Montreal, Docu-Depot provides document management, destruction and storage services to businesses in Montreal and Quebec City. With the Docu-Depot acquisition, Access expands its services to 58 Canadian markets and now has four locations in Quebec City and Montreal. Access operates coast to coast in Canada, including in Vancouver, Edmonton, Calgary, Saskatoon, Regina, Winnipeg, Ottawa, Toronto, Montreal, Quebec, St. John and St. John’s. In the last year, Access has acquired 10 companies in Canada covering nine provinces. Access provides transformative services, expertise, and technologies to make organizations more efficient and more compliant. Access helps companies manage and activate their critical business information through offsite storage and information governance services, scanning and digital transformation solutions, document management software including CartaHR, and secure destruction services. The DocuDepot purchase extends the company’s information management services to businesses of all sizes across all North America. In April 2018, Access acquired Innovative Records Systems Corp., expanding its Canadian operations into nine provinces. Access was acquired by Berkshire Partners in October 2014. In September 2017, GI Partners joined Berkshire Partners as co-lead investor.
www.keithwalkingfloor.com
Security Shredding News Spring 2019
7
Security Shredding News
Lynx Equity Limited Acquires Alpine Shredders
T
oronto, Ontario — In a move to expand into mobile shredding equipment business, Lynx Equity Limited acquired Alpine Shredders in February, according to a statement by the company released in February. Alpine Shredders designs and builds premium quality, purpose-built mobile shredding trucks. The company’s president, George Doerr, will remain with the company, which has been in the shredding industry since 1985 and in the transportation equipment industry as far back as 1942. With sales in excess of $400M CAD (about $298 million USD) Lynx Equity Limited is a Toronto-based diversified private equity firm focused on acquiring small and medium-sized businesses from owners looking to retire. Lynx targets acquisitions of companies with EBITDA between $750K and $2M USD and utilizes a buy and hold strategy. Financial terms of the sale were not disclosed.
Bengal Machine Acquires FloridaBased Tire Shredding Business
B
uffalo, NY — In a move to secure a big share of the size-reduction equipment market, Bengal Machine has acquired CM Recycling Equipment Solutions, according to a Buffalo News article. Bengal Machine is the parent company of Schutte Hammermill and CM Shredder. CM Recycling Solutions is Columbus McKinnon’s tire-shredding business located in Florida. Schutte’s size-reduction equipment includes hammer mills, crushers, lump breaking products and pelletizing machinery. Adding the CM Shredders business will expand the company’s market into tire shredders and industrial shredders, a spokesperson told the press. Last July, Columbus McKinnon announced plans to sell its CM Recycling Equipment Solutions business as part of a plan to divest three of its smaller business units. Schutte-Buffalo has about 30 employees currently.
Issue Brief: Risky Business? Sharing Data with Entities Not Covered by HIPAA
W
riting in a 10-page Manatt, Phelps & Phillips issue brief, attorney Robert D. Belfort advises healthcare organizations to consider the complicated issues of privacy in the age of wearable devices, mobile computing - and the nifty applications developed for those technologies. Belfort, who specializes in regulatory compliance and transactional matters, illuminates some of the complicated issues faced by application developers and business associates under the Health Insurance Portability and Accountability Act (HIPAA). “Current privacy laws were not created during the age of the internet, big data and mobile healthcare,” Belfort writes. “One of the most critical pieces of privacy legislation enacted during a time when healthcare providers and payers maintained health information using paper-based medical records instead of electronic health records (EHRs).” Today, a significant amount of health data is being generated from apps and consumer devices that are outside the scope of HIPAA regulation, Belfort writes. Although HIPAA was amended in the 2009 Health Information Technology for Economic and Clinical Health (HITECH) Act, there is considerable confusion about what constitutes a covered or non-covered HIPAA entity and how to determine when an app developer, vendor or some other party handling protected information is a business associate under HIPAA. “For example, if a provider contracts with an app developer for patient management services— including remote patient health counseling; monitoring of patients’ food and exercise; patient messaging; EHR integration; and application interfaces that involve creating, receiving, maintaining, and transmitting PHI—and the app is a means for providing those services, the app developer is likely a business associate and a business associate agreement is required. In this scenario, the patient downloads the health app to his or her phone at the direction of the provider, and information the patient enters is automatically incorporated into the EHR.” The Manatt issue brief provides helpful definitions and discusses covered vs. non-covered HIPAA entities, determining who is a business associate, federal guidance and regulations for covered entities and app developers, general data protection and regulation (GDPR-European Union), California’s Consumer Privacy Act and the most recent policy on genomic security.
www.creweb.com/secure
Visit us online at www.SecurityShreddingNews.com
8 Security Shredding News Spring 2019
Security Shredding News
Business Associate Agreements May Extend Farther Than You Think
W
riting in a commentary published on Law.com, health law attorney, Vasilios J. Kalogredis, emphasizes the mandatory and far-reaching nature of the business associate agreement (BAA), which is required under the Health Insurance Portability and Accountability Act (HIPAA). As chairman of Lamb McErlane’s health law department, Kalogredis represents many medical and dental groups and thousands of individual physicians and dentists. In his article for The Legal Intelligencer he emphasizes the need for all covered entities to have business agreements in place with any contractors and subcontractors who have access to protected health information (PHI). Kalogredis advises covered entities and their business associates closely examine how PHI is handled to ensure that all security precautions are taken to prevent breaches. The HIPAA regulations at 45 C.F.R. Section 314 set forth the various requirements of a BAA, including reporting security incidents, complying with the HIPAA regulations applicable to HIPAA-covered entities, and implementing administrative, physical and technical safeguards. “PHI handling requirements may extend from a covered entity to a business associate of covered entity and a covered entity may grant permission to a noncovered entity (i.e., a business associate) to ‘create, receive, maintain, or transmit’ PHI on the covered entity’s behalf (45 C.F.R. §164.308(b)(2), grants that same right to business associates working with subcontracted business associates),” Kalogredis writes. “Covered entities are held to a higher standard than business associates with regard to PHI protection (e.g., the privacy rule under HIPAA applies to covered entities),” he explains. “The disparity in standards applicable to business associates and covered entities may jeopardize patient privacy when covered entities need assistance from third party business associates. The BAA seeks to address this disparity.”
www.paperstockreport.com
ken@paperstockreport.com
We’re in Your Corner There’s more to NAID than its widelyrecognized data destruction operational certification. Revenue from annual dues, its successful conference, and global certification program are used to:
We are Member-Owned & Member-Accountable. Association Dollars are Controlled and Spent to Benefit Members & the Industry.
• Engage in Regulatory Advocacy for Laws that Promote and Protect Secure Data Destruction Services
• Conduct Research to Help Members and
Join NAID today! Let us fight for you too!
• Educate Organizations on the
www.naidonline.org
Customers Make Better Decisions
Importance of Using a Service Provider
Security Shredding News Spring 2019
9
Security Shredding News
Community Health System to Pay $4.5m in HIPAA Breach Lawsuit
B
irmingham, AL — A class action lawsuit brought against Community Health System (CHS) for a 2014 breach has resulted in a $4.5 million settlement, according to a BizJournals.com article. The HIPAA breach lawsuit was settled in The United States District Court Northern District of Alabama in December 2018. The case was brought by 40 named patients from 24 states. The breach affected approximately 4.5 million individuals who received services from CHS-affiliated physicians in the previous five years and was the second-largest health care data breach at the time. Names, dates of birth, addresses, telephone numbers and Social Security Numbers were vulnerable during a malware attack. Forensic investigators believed the attack originated in China. According to CHS, most of its patients were not affected by the breach, and no credit card information or medical records were taken. The cyber-attack, which took place in April and June of 2014, but was not confirmed until July and not reported to the SEC until August of that year “deprived millions of former patients of critical time to protect themselves from identity theft,” according to the court filing. CHS’s total payout for claims related to the case is not to exceed $3.1 million. Affected patients will be eligible for up to $5,000 each in reimbursements for losses related to the breach. Patients have until Aug. 1 to make a claim and until May 18 to opt out of the settlement, according to the filing. The court has preliminarily approved the settlement but will hold a hearing on Aug. 13 to enter a final judgement. CHS operates 206 hospitals in 29 states. Since the attack, CHS has taken recommendations from forensic investigators to improve security in the future. Those improvements include implementing additional audit and surveillance technology to detect intrusions, adopting advanced encryption technology and requiring users to change their access passwords.
Tri-Cities Waste Closes Recycling Plant, Impacts TN and VA Communities
K
ingsport, TN — Tri-Cities Waste Paper is another of many recycling operations shutting down because of high costs, reports WTOP. com In March, the company stopped handling recycling for Sullivan County in Tennessee and Washington County in Virginia. The Kingsport plant’s parent company, Asheville Waste Paper had closed another local plant in Bristol, TN earlier this year. Bristol-based Reclaimed Resources closed in December 2018, citing depressed prices for baled cardboard and contamination, particularly with the residential waste collection. The company’s owner estimated that about 30 to 40 percent of the products received in a load would be “unusable.” Reclaimed Resources picked up waste from municipal recycling centers at no charge. Now, it can no longer afford to do that. In an interview with media, the owner hinted at plans to bring a $250 million state-of-the-art plastic recycling center in Tri-Cities within the next few years. Sullivan County has stopped taking plastic waste; Bristol, Virginia, has suspended paper and plastic recycling; Washington County, Virginia, has suspended recycling for all but cardboard and aluminum cans; and Abingdon has removed all of its recycling drop-off stations. In Tennessee, Unicoi and Johnson counties and Elizabethton currently take all their paper and plastic to Carter County. Carter County may also start taking waste from Washington County, Virginia. The closest plants that take both paper and plastic are located in Knoxville. Out of state locations include Roanoke, Virginia and Asheville, North Carolina. Transportation costs and logistics are apt to pose a problem, however. A one-way trip from Southwest Virginia or Northeast Tennessee could take from around 90 minutes to 2 1/2 hours.
ShredWise Whistleblower Tips Off Media About Unsecured Personal Papers
S www.bomaccarts.com sales@bomaccarts.com
10 Security Shredding News Spring 2019
urrey, BC, Canada — A cache of confidential documents being kept in an unsecured parking lot owned by mobile shredding contractor, ShredWise, has led to investigations, reports . A whistleblower employed by ShredWise contacted News 1140 about the papers, which include VISA documents, scanned copies of passports and SIN cards, biopsy results, blood tests, uncashed cheques, credit card statements and insurance records, as well as medical records and prescription bottle labels. The documents were supposed to have been destroyed by the mobile shredding company, but instead, were stored in an unlocked area. The whistleblower blames lax company practices, saying employees have stored the sensitive papers at the site when they got behind in shredding. Company management told media the whistleblower is a disgruntled employee. ShredWise is under investigation by The Office of the Information and Privacy Commissioner of B.C. and industry group, the National Association for Information Destruction (NAID). The company uses trucks with onboard shredding equipment that make regular pick-ups of documents from government offices, banks, doctor’s offices, pharmacies, and legal offices. ShredWise’s CEO told media the privacy breach on “an employee issue” and is conducting an internal investigation of the breach, which it calls “an isolated issue.” Although the company is not certified by NAID, it is a member of the organization and company’s CEO is on NAID’s board of directors. The CEO has been put on administrative leave by the board until the investigations are complete.
Est. 1991
YOU BUY IT, WE’LL HELP YOU FINANCE IT
WE PROVIDE A CONVENIENT AND COST-EFFECTIVE SOLUTION! Lease or Loan Financing Simple Application Process Low Initial Investment
Financing new or pre-owned equipment Serving the US & Canada Competitive Rate Structure
FINANCING THE WORLD OF TRANSPORTATION TERRY LEE
DOUG FERRANTE
Eastern States 303-301-7651 tlee@transleaseinc.com
Western States 509-389-1267 doug.ferrante@transleaseinc.com
WWW.TRANSLEASEINC.COM www.transleaseinc.com Security Shredding News Spring 2019 11
PRSRT STD U.S. Postage
PAID
Cleveland, OH Permit #1737
6075 Hopkins Rd • Mentor, OH 44060 • Ph: 440-257-6453 • Fx: 440-257-6459 • Email: downassoc2@oh.rr.com
Inside This Issue
VOL. 16 NO. 1
spring 2019
HIPAA Reports Record Number of Enforcements in 2018 PAGE 1 Business Associate Agreements May Extend Farther Than You Think PAGE4 New Report Urges Focus on E-Waste Reduction Policymaking PAGE 7 Issue Brief: Risky Business? Sharing Data with Entities Not Covered by HIPAA PAGE 8 ShredWise Whistleblower Tips Off Media About Unsecured Personal Papers PAGE 10
www.shred-tech.com