A Stolen Health Insurer’s Laptop With PII Is Not Necessarily A HIPAA Violation

While scanning the news blurb summaries today, the statement, “This is a violation of HIPAA.” caught my eye. Hmm…let’s see what this is about…
This statement was actually within the reader comments to the story, “Blue Cross reports theft of computer.”


New Jersey’s “largest health insurance company,” Blue Cross/Blue Shield, reported a laptop computer containing the personally identifiable information (PII) of over 300,000 of its members (insureds) was stolen from an employee “while it was being taken home” on January 5.

“Horizon Blue Cross/Blue Shield says the risk of identity theft is small because the data was protected by password. Also, the computer was programmed to automatically destroy the information on Jan. 23.
The laptop contained names, Social Security numbers and other personal information for about 10 percent of the insurer’s 3.3 million customers in New Jersey. Medical information was not included.”

The statement that the New Jersey BC/BS made about the password protection is very troubling; a password is just a speedbump on a criminal’s path to the PII and subsequently using PII for fraud and other crimes. Hopefully this was not a statement from the Privacy or Information Security office!
An independent audit of the situation would reveal whether or not this was truly a violation of HIPAA; the report does not give enough details to determine this. However, names and SSNs are defined as protected health information (PHI) under HIPAA.
The comments for the report are very revealing and should demonstrate to business leaders that the public…their customers…expect organizations, to whom customers entrust their PII, to unequivocally and effectively safeguard their PII.
* Do not allow databases of PII to be stored on mobile computers and storage devices.
* If PII must be stored on mobile computers or storage devices, then strongly encrypt it.
* Provide training and ongoing awareness communications to all personnel with access to PII.

Tags: , , , , , , , , , , , , , , , ,

Leave a Reply

A Stolen Health Insurer’s Laptop With PII Is Not Necessarily A HIPAA Violation

While scanning the news blurb summaries today, the statement, “This is a violation of HIPAA.” caught my eye. Hmm…let’s see what this is about…
This statement was actually within the reader comments to the story, “Blue Cross reports theft of computer.”

Read the rest of this entry »

Tags: , , , , , , , , , , , , , , , ,

Leave a Reply