Wednesday, February 08, 2006

Brigham hospital has been faxing women's personal health information to investment bank

Yet Another Faxing Foul Up.

This time, the well-known Brigham and Women's hospital has been regularly sending a Boston-area investment bank personal health information about recently dicharged maternity patients. The information includes name, address, social security number, religion, attending physician and whether the woman/baby tested positive for STDs. The faxed forms apparently are for billing purposes:

BostonHerald.com - Local / Regional News: Brigham sent bank new moms' records

The faxed data was patient billing information. Hospitals typically send this type of information to medical supply companies for products for patients. The information is used to bill the patient’s insurance company.

While the accidental faxes are the bigger issue, perhaps someone can tell me why a billing form has to include the patient's religion, social security number and STD status? That makes two serious privacy issues.

Read more at BostonHerald.com. Thanks to HIPAA Blog for the link.

Technorati tags: :: :: :: :: ::

Chilliwack plan to require ID for hydroponics purchases on hold

The City Council for Chilliwack, in British Columbia's lower mainland, has put a controversial bylaw on hold, pending a review from the Information and Privacy Commissioner of BC. The bylaw, if passed, would require stores to demand photo ID from purchasers of hydroponic equipment. In addition, the purchaser's personal information would be entered into a database with the Royal Canadian Mounted Police. Not surprisingly, some have voiced concerns with the initiative. Check out: globeandmail.com : Hydroponics bylaw on hold in Chilliwack.

Also check out:

City of Chilliwack - Notices - City Government:

Public Notice is given that City Council intends to adopt 'Hydroponics and Drug Paraphernalia Bylaw 2006, No. 3223' to regular Hydroponics Equipment and Drug Paraphernalia Dealsers. A Public Information Meeting is scheduled for 7:00 p.m. on Monday, February 6, 2006.

Technorati tags: :: :: :: .

Incident: Insurer accidentally prints SSNs on mailing labels

According to Computerworld, an insurer in North Carolina has accidentally printed social security numbers on mailing labels of customers who sought information on a new insurance program. The incident was caused by "human error" and despite the fact that the insurer has replaced SSNs as customer identifiers. See: 'Human error' exposes patients' Social Security numbers in N.C. - Computerworld.

Technorati tags: :: :: ::

Tuesday, February 07, 2006

Correction: Information stolen from Providence Health System employee used fraudulently

I blogged early this morning about an incident being reported by KATU2 of Portland: (The Canadian Privacy Law Blog: Incident: Employee may have stolen personal information from Providence Health System - Original post deleted) Unfortunately, I mis-read the article and reported on this blog that the information in question was stolen by an employee of Providence Health Systems. That apparently was not the case. The personal information in question was stolen from the employee's vehicle on December 31, 2005 and some of it appears to have been used in fraudulent transactions since then. The investgation is still ongoing.

Technorati tags: :: :: ::

Columnist calls for national credit freeze laws

I've linked to Anita Ramasastry's Findlaw columns before, but this one is a must read: FindLaw's Writ - Ramasastry: Whose Credit Report is it, Anyway? It's Time for States to Pass Credit Freeze Laws that Give Consumers Control Over their Credit Profiles. Anita provides an overview of the problem of identity theft and advocates the use of credit freezes to give consumers additional tools to protect their financial well-being. Thanks to beSpacific for the link.

Technorati tags: :: ::

Incident: Computer security breach compromises personal info of California State University Employees

According to the Associated Press and the Oroville Mercury Register a suspected break-in of a computer server on the California State University at East Bay may have compromised the personal information, including social security numbers, of up to 700 faculty and 1600 staff members. It is unclear whether the information was actually obtained in the course of the security breach, but the university has notified the affected employees and has called in the California Office of Information Privacy.

See the report from the Oroville Mercury Register here.

Technorati tags: :: :: :: .

Monday, February 06, 2006

Incident: Faxes about American patients accidentally sent to Canadian company ... for 15 months

Most Canadians with any interest in privacy are well aware of the very high-profile CIBC faxing fiasco that resulted in hundreds of confidential faxes being sent from dozens of bank branches to one particular junk yard in the United States. When the story broke, it was front-page news and continued making headlines for weeks. It has even spawned a class action lawsuit against the bank, alleging that the failure to notify the indivuduals concerned caused them increased risk of identity theft.

Now there's a similar story coming from the US about hundreds of faxes being accidentally sent to a Canadian manufacturer of herbal remedies. According to Computerworld, a large number of people have trying to send Prudential Financial Inc.'s insurance arm faxes containing confidential patient information. Unfortunately, hundreds went to a company called North Regent RX in Manitoba, Canada. The two toll-free fax numbers only differ by one digit. This is likely to be labeled outrageous, but compounding the situation is that it apparently has gone unchecked for fifteen months.

The company apparently notified Prudential in October 2004 but months passed without any response. Now, Prudential is reported to say that that it is not their problem. They have no responsibility for others who incorrectly fax information. That may be true, but I am sure Prudential will face a storm of criticism asking what it did to protect its customers' information. The Manitoba company offered to sell its toll-free fax number of Prudential, which declined. They simply asked that misdirected faxes be mailed to Prudential as they came in. North Regent had intially contacted the senders, but quickly found they did not have the time and resources to continue to do so.

Legally, Prudential may have no responsibility for the misdirected faxes, but it will still face criticism that might have been avoided had they simply bought the fax number.

Check out Computerworld for the full story: Confidential patient data sent to wrong company -- for 15 months - Computerworld.

Technorati tags: :: :: :: ::

Must see TV ...

Thanks to Michael Fitzgibbon for passing this teaser along from NBC News:

The Daily Nightly - MSNBC.com:

"She was sure someone had stolen her social security number, but nobody -- not her bank or her credit companies -- would give her any information. Then, she got a new ATM card in the mail... with the thief's picture on it! It's an incredible story of identity theft, tonight on NBC Nightly News."

Technorati tags: :: :: ::

Law enforcement and others go after ISP data

The New York Times continues to lead the pack on reporting on privacy and security issues. On Saturday, the NYT ran an article on the increasing frequency with which law enforcement are seeking information from internet service providers in connection with investigations of all kinds: Increasingly, Internet's Data Trail Leads to Court - New York Times.

As I have said here, if you don't need the data, don't keep it. That data can be stolen, compromised or you could find yourself an information collector for law enforcement and others. Responding to privacy incidents is costly and dealing with subpoenas is also expensive. Check out: The Canadian Privacy Law Blog: Don't keep the data that you don't need.

Technorati tags: :: :: :: :: :: .

Sunday, February 05, 2006

Incident: Vehicle full of medical records stolen in British Columbia

The Information and Privacy Commissioner of BC (and hopefully the police) are investigating the theft of a courier vehicle full of medical records that was left idling and unlocked outside a medical facility in the Vancouver suburb of Langley, BC. See: Medical Records Stolen: CNG Portals Page

Technorati tags: :: :: ::