WASHINGTON – A health care privacy breach involving about 528 people at Brown University covered by Blue Cross & Blue Shield of Rhode Island is among more than 40 incidents reported on a new federal Web page set up under the American Recovery and Reinvestment Act of 2009.
The page, part of the U.S. Department of Health and Human Services Web site, lists every breach involving 500 or more people reported to HHS since last September.
Under the new law, all entities covered by the Health Insurance Portability and Accountability Act of 1996 must notify individuals whose protected health information may have been improperly accessed, used or disclosed.
If the incident affects 500 or more patients, the covered entities also are required to notify HHS and the media, and HHS must post the details on its Web site.
The Brown/Blue Cross breach involved unauthorized access to paper records on Dec. 11, the report shows. It’s the only large HIPAA breach reported in Rhode Island.
Also that day, a portable electronic device stolen from a private practice in Stoughton, Mass., exposed the medical records of 1,860 individuals. A previous theft, on Nov. 10 at the Massachusetts Eye and Ear Infirmary, exposed 1,076 patients’ records.
Nationwide, most of the reported breaches involved a few hundred or at most, a few thousand people, with two major exceptions: On Oct. 2, hard drives were stolen from Blue Cross Blue Shield of Tennessee, exposing 500,000 people’s data. And on Dec. 10, a laptop stolen from vMed Inc., in Florida, exposed 359,000 people’s health care information.
Theft was by far the most common reason for HIPAA breaches, cited in almost three-quarters of the cases (including six in a single day in California). Only one case involved a hacker, and another a phishing scam.
No posts to display
Sign in
Welcome! Log into your account
Forgot your password? Get help
Privacy Policy
Password recovery
Recover your password
A password will be e-mailed to you.












