The Delaware Division of Developmental Disabilities Services Data Breach
DOVER (Oct. 21, 2022) – The Delaware Division of Developmental
Disabilities Services is announcing today that it is mailing letters to
service recipients and legal guardians who were impacted by a recent
data breach incident and is providing information to the public
regarding the incident.
On August 23, 2022, staff within the Division of Developmental
Disabilities Services (DDDS) discovered that in the process of creating
new user accounts in the division’s client database, DDDS staff
inadvertently provided access to individual records of 7074 individuals.
As a result of these actions, 159 new users had potential access to
service recipients’ personal, identifiable information and protected
health information as well as potential access to more detailed
information through accessed accounts.
A thorough investigation of the incident was conducted. Using
forensic analysis available through the software’s vendor, the division
has been able to determine how many users accessed information not
intended for their use, and which service recipient records were opened
and viewed. While the division has determined that only 12 detailed
records were actively accessed, certain personal, identifiable
information and protected health information was passively available to
any user with the erroneous access level. The software vendor is unable
to determine who may have passively viewed this information.
Based on this internal investigation and consultation with the
software vendor, the division is taking corrective measures to tighten
security and protection of the personal health information of its
service recipients. DDDS has:
- Reviewed and reinforced its Health Insurance Portability and Accountability Act (HIPAA)-related policies and procedures.
- Established new guidelines for the creation of user accounts and a tightened approval process for accessing records.
- Worked with its vendor to institute technology checks on providing access.
The division will incorporate lessons from this analysis into the
design and implementation of its new client data management system
scheduled for transition in 2023.
As required by HIPAA and state law, the Delaware Division of
Developmental Disabilities Services has reported this breach to the U.S.
Department of Health and Human Services and to the Delaware Department
of Justice.
The Division of Developmental Disabilities Services is also
establishing a dedicated call center independently staffed by a
contracted company to answer any questions about this incident. Call
center representatives have been fully versed on the incident and can
answer questions or concerns individuals may have regarding protection
of their personal information. Additionally, the division will be
offering free access to credit monitoring to all impacted parties for a
period of one year.
| Issued by: Office for Civil Rights (OCR) What if a HIPAA covered entity (or business associate) uses a CSP to maintain ePHI without first executing a business associate agreement with that CSP? Answer: If a covered entity (or business associate) uses a CSP to maintain (e.g., to process or store) electronic protected health information (ePHI) without entering into a BAA with the CSP, the covered entity (or business associate) is in violation of the HIPAA Rules. 45 C.F.R §§164.308(b)(1) and §164.502(e). OCR has entered into a resolution agreement and corrective action plan with a covered entity that OCR determined ...read more |
| Radiologist Revises Process for Workers Compensation Disclosures Covered Entity: Health Care Provider Issue: Impermissible Uses and Disclosures A radiology practice that interpreted a hospital patient’s imaging tests submitted a worker’s compensation claim to the patient’s employer. The claim included the patient’s test results. However, the patient was not covered by worker’s compensation and had not identified worker’s compensation as responsible for payment. OCR’s investigation revealed that the radiology practice had relied upon incorrect billing information from the treating hospital in submitting the claim. Among other corrective actions to resolve the specific issues in the case, the practice apologized to ...read more |
| Physician Revises Faxing Procedures to Safeguard PHI Covered Entity: Health Care Provider Issue: Safeguards A doctor's office disclosed a patient's HIV status when the office mistakenly faxed medical records to the patient's place of employment instead of to the patient's new health care provider. The employee responsible for the disclosure received a written disciplinary warning, and both the employee and the physician apologized to the patient. To resolve this matter, OCR also required the practice to revise the office's fax cover page to underscore a confidential communication for the intended recipient. The office informed all its employees of the ...read more |
| Tuesday, November 1, 2022 Modernizing Medicine Inc. (ModMed), an electronic health record (EHR) technology vendor located in Boca Raton, Florida, has agreed to pay $45 million to resolve allegations that it violated the False Claims Act (FCA) by accepting and providing unlawful remuneration in exchange for referrals and by causing its users to report inaccurate information in connection with claims for federal incentive payments. The Anti-Kickback Statute prohibits anyone from offering or paying, directly or indirectly, any remuneration — which includes money or any other thing of value — to induce referrals of items or services covered by Medicare, ...read more |
|
September 2026
| Su | Mo | Tu | We | Th | Fr | Sa |
| | 1 | 2 | 3 | 4 | 5 |
| 6 | 7 | 8 | 9 | 10 | 11 | 12 |
| 13 | 14 | 15 | 16 | 17 | 18 | 19 |
| 20 | 21 | 22 | 23 | 24 | 25 | 26 |
| 27 | 28 | 29 | 30 |
Blog Home
Newest Blog Entries
1/21/25 Understanding Business Associate Agreements
11/12/22 Modernizing Medicine Agrees to Pay $45 Million to Resolve Allegations of Accepting and Paying Illegal Kickbacks and Causing False Claims
11/12/22 Indian National Charged in $8 Million COVID-19 Relief Fraud Scheme
11/12/22 Former Hospital Employee Pleads Guilty To Criminal HIPPA Charges
11/12/22 Covered entities and those persons rendered accountable by general principles of corporate criminal liability may be prosecuted directly under 42 U.S.C. § 1320d-6
11/12/22 The Delaware Division of Developmental Disabilities Services Data Breach
11/12/22 OCR Settles Three Cases with Dental Practices for Patient Right of Access under HIPAA
11/12/22 HHS Issues Guidance on HIPAA and Audio-Only Telehealth
11/12/22 Five Former Methodist Hospital Employees Charged with HIPAA Violations
11/12/22 May a covered entity use or disclose protected health information for litigation?
11/12/22 When does the Privacy Rule allow covered entities to disclose protected health information to law enforcement officials?
Blog Archives
January 2025 (1) November 2022 (54)
Blog Labels
HIPAA (2) BAA (4) HIPAA Enforcement (3) Telehealth (1) Data Breach (1) PPP Fraud (1) Covered Entity (40) ePHI (2) EHR Fraud (1)
|