Skip to main content

Security Shredding News Fall/Winter 2018

Page 1

Volume 15, Issue 3

FALL/WINTER 2018

Security Shredding News Serving the Security Shredding & Records Storage Markets

Visit us online at www.SecurityShreddingNews.com

“While this law (AB 375) just covers California currently, large companies will soon have to offer similar rights to all Americans.”

Sweeping California Privacy Law Could Spark Federal Legislation By P.J. Heller

T

he California Consumer Privacy Act, a sweeping new privacy law signed into law earlier this year by Gov. Jerry Brown, could prompt similar legislation by other states or move Congress to enact a tough nationwide consumer online privacy policy. California‘s Assembly Bill 375, described as the most stringent in the nation, is scheduled to go into effect in 2020. In the meantime, amendments are expected (a so-called “cleanup” bill has already passed) and companies worldwide that meet certain requirements and that collect, use, disclose or receive personal information of California residents will be working to come into compliance. The California bill was unanimously passed in the wake of major data breaches, including the Cambridge Analytica case that involved improper data collection from tens of millions of Facebook users and the Equifax breach that compromised the identity of more than 140 million people. AB 375 was approved shortly after passage of the European Union’s General Data Protection Regulation (GDPR) that gives individuals control over their personal data. Both measures share some general features but concerns have been raised about how companies will meet the different compliance regulations and address varying privacy laws from state to state. Rather than have the privacy measure put to California voters in a November 2018 ballot initiative, legislators scrambled to pass the state law in June to give consumers more control over how companies collect and manage their personal information. It includes provisions that

allow consumers to see the actual data collected, the right to have that data deleted and the ability to opt out of having the information sold. AB 375 “puts the focus on giving choice back to the consumer, a choice which is sorely needed,” said Alastair Mactaggart, chair of Californians for Consumer Privacy which led the privacy effort. James P. Steyer, chief executive officer and founder of Common Sense Media, a major supporter of the measure, called passage of the bill a “huge win.” “The personal information and private data of Americans are routinely collected and used without our knowledge, and our well-being, as well as the health of our democracy, have suffered as a result,” he said. “This is the right first step toward ensuring that Americans have strong data privacy protections. “The state that pioneered the tech revolution is now, rightly, a pioneer in consumer privacy safeguards, and we expect many additional states to follow suit,” Steyer added. He said AB 375 gives consumer privacy advocates a “blueprint for success.” “We look forward to working together with lawmakers across the nation to ensure robust data privacy protections for all Americans,” Steyer said. Not everyone was enamored with the California legislation. Nicole Ozer, technology and civil liberties director for the ACLU of California, said the measure “utterly fails to provide the privacy protections the public has demanded and deserves. Nobody should be fooled to think AB 375 properly protects Californians’ privacy. “This measure was hastily drafted and needs

to be fixed,” Ozer said. “When that happens next year, effective privacy protections must be included that actually protect against rampant misuse of personal information, make sure that companies cannot retaliate against Californians who exercise their privacy rights, and ensure that Californians can actually enforce their personal privacy rights.” Robert Callahan, vice president of state government affairs for the Internet Association, also criticized the measure. “It is critical going forward that policymakers work to correct the inevitable, negative policy and compliance ramifications this last-minute deal will create for California’s consumers and businesses alike,” Callahan said. Others are looking to Congress to pass privacy legislation rather than having a possible hodgepodge of state regulations. “While this law (AB 375) just covers California currently, large companies will soon have to offer similar rights to all Americans,” said Mactaggart, the chief proponent of the California Consumer Privacy Act. “How on earth are they going to tell a New Yorker or a Texan that what’s good for a California consumer is out of reach for another state’s residents? It’s time for these companies to provide transparency and choice to all consumers, and if Congress is considering a national law, then California’s must be the minimum standard.” Thomas C. Donahue, president and chief executive officer of the U.S. Chamber of Commerce, said his organization is working on a legislative proposal for Congress “to prevent a patchwork of state rules that would pose a nightmare for businesses that operate across Continued on page 3


®

Specialist in Mobile Shred Truck Financing • LOW INITIAL INVESTMENT • LEASE OR LOAN FINANCING • FINANCING NEW OR PRE-OWNED EQUIPMENT

• SIMPLE APPLICATION PROCESS • SERVING THE U.S. & CANADA • COMPETITIVE RATE STRUCTURE

We Provide a Convenient and Cost-Effective Solution!

Financing The World Of Transportation For a Quote or More Information Contact: Eastern States Western States Terry Lee Cassie Bergo Direct: 303-301-7651 | Cell: 937-620-9400 Direct: 303-301-7685 | Cell: 303-324-8340 tlee@transleaseinc.com cbergo@transleaseinc.com

www.transleaseinc.com WWW.TRANSLEASEINC.COM 2 Security Shredding News Fall/Winter 2018


Security Shredding News

Sweeping California Privacy Law Could Spark Federal Legislation Continued from page 1

PUBLICATION STAFF Publisher / Editor Rick Downing

Contributing Editors / Writers P.J. Heller Sandy Woodthorpe

Production / Layout Barb Fontanelle Christine Mantush

Advertising Sales Rick Downing

Subscription / Circulation Donna Downing Editorial, Circulation & Advertising Office 6075 Hopkins Road Mentor, OH 44060 Ph: 440-257-6453 Fax: 440-257-6459 Email: downassoc2@oh.rr.com www.securityshreddingnews.com

For subscription information, please call 440-257-6453 Security Shredding News (ISSN #1549-8654) is published bimonthly b y D o w n i n g & A s s o c i at e s. Reproductions or transmission of Security Shredding News, in whole or in part, without written permission of the publisher is prohibited. Annual subscription rate U.S. is $19.95. Outside of the U.S. add $10.00 ($29.95). Contact our main office, or mail-in the subscription form with payment.  ©Copyright 2018 by Downing & Associates. Printed on Post-Consumer Recycled Paper

White House spokesman said in a statement. state lines. In today’s interconnected world, data “We look forward to working with Congress knows no boundaries and requires a federal on a legislative solution consistent with our framework. overarching policy.” “The Chamber is not only concerned about Cameron Kerry, former acting secretary in a patchwork of state laws in our country, but the Commerce Department during the Obama a patchwork of international requirements Administration and who led a task force that that present similar challenges for businesses developed the Consumer Privacy Bill of Rights operating around the world,” Donahue added. issued by the White House in 2012, said that David F. Grimaldi, executive vice president document, which never went anywhere, could at the Interactive Advertising Bureau, which serve as a starting point for represents more than 650 companies that account “The fundamental need federal legislation. “A s p o l i c y m a ke r s for the vast majority of for baseline privacy consider how the rules might online advertising sold in the legislation in America change, the Consumer United States, agreed that Privacy Bill of Rights we Congress needs to step up. is to ensure that developed in the Obama “A unifor m federal individuals can trust administration has taken privacy standard could that data about them on new life as a model,” provide clarity, market Kerry wrote in an article will be used, stored, certainty, and add fuel to published on the Brookings future innovation, while and shared in ways Institution website. preserving the value that are consistent with “One thing should be and benefit that online their interests and the clear, even though we live advertising brings to the internet ecosystem,” he said. circumstances in which in a world in which we share personal information more Some of the largest it was collected.” freely than in the past, we tech companies, including must reject the conclusion that privacy is an Alphabet Inc.’s Google, have indicated they outmoded value,” Obama said in the report would support a federal bill that would take Consumer Data Privacy in a Networked World: precedence over California’s privacy law. A Framework for Protecting Privacy and After the Cambridge Analytica scandal, Promoting Innovation in the Global Digital Facebook CEO Mark Zuckerburg told CNN, Economy. “It has been at the heart of our “I’m not sure we shouldn’t be regulated.” democracy from its inception, and we need it More recently, Zuckerburg, Tim Cook, now more than ever.” chief executive at Apple, and Google CEO “The fundamental need for baseline Sundar Pichai, all expressed support for privacy privacy legislation in America is to ensure that legislation. “It is time for the rest of the world, including Continued on page 4 my home country, to follow your lead,” Cook said in a keynote speech to an international conference in Brussels on data privacy. “We at Now Even More Options for Customers Apple are in full support of a comprehensive Who Want Their Own Key Codes! federal privacy law in the United States. Lock America Adds More New Key Codes “Our own information — from the every day for Padlocks and Console Locks. to the deeply personal — is being weaponized • Give your drivers and customers a single key against us with military efficiency,” Cook said. that fits all the locks at a site. “This is surveillance. And these stockpiles of • Ask your console or bin supplier for new available personal data serve only to enrich the companies key codes, or contact Lock America directly. that collect them. This should make us very uncomfortable. It should unsettle us.” The Commerce Department reportedly was working this summer on a proposal to protect One Key Can Now Operate All Your Locks! online privacy. It was expected to be released this fall. “Through the White House National Economic Council, the Trump Administration aims to craft a consumer privacy protection Tel: (951) 277-5180 9168 Stellar Court policy that is the appropriate balance between Fax: (951) 277-5170 Corona, CA 92883 www.laigroup.com sales@laigroup.com privacy and prosperity,” Lindsay Walters, a

800-422-2866

Security Shredding News Fall/Winter 2018

3


Security Shredding News

Sweeping California Privacy Law Could Spark Federal Legislation Continued from page 3

individuals can trust that data about them will be used, stored, and shared in coordination, and important commerce.” ways that are consistent with their interests and the circumstances in which While California’s privacy legislation is somewhat similar to Europe’s it was collected,” Kerry said in the Brookings article. “This should hold General Data Protection Regulation rules, Mactaggart noted there are regardless of how the data is collected, who receives it, or the uses it is differences. put to. If it is personal data, it should have enduring protection.” “The most obvious difference is in who is a covered entity: Mactaggart and Kerry both agreed that challenges in Europe, all entities of any size are subject to GDPR, remain to implementing a nationwide online privacy whereas CCPA only covers businesses with over $25 policy. million in revenue, and data brokers selling large “We do not have a “There will certainly be a battle in the coming amounts of personal information,” he explained clear understanding of years, either in the California Legislature or in written testimony to Congress. “The second in Congress, as companies seek to return to a big difference is in the European approach of what is required to comply. world free of any limitations on what they can requiring user consent before any processing do with consumer’s personal information,” That could disrupt transatlantic can take place.” Mactaggart said. Under GDPR, a corporation must obtain cooperation on financial “Trade-offs to get consistent federal a consumer’s approval before collecting and rules that preempt some strong state laws processing his or her data. The California law regulation, medical research, and remedies will be difficult, but with a gives consumers the right to know what personal strong enough federal baseline, action can be information is being collected about them and to emergency management achievable,” Kerry predicted. opt out of the sale of their personal data. People coordination, and important 16 years and under must give permission or opt Kerry added that while the EU‘s General Data Protection Regulation had “a lot of good in in to allow the sale of their personal information. commerce.” it . . . it is not the right model for America.” Mactaggart said AB 375 “represents one step Commerce Secretary Wilbur Ross also expressed towards damming the flow of this river of information, concerns about the EU privacy regulation, saying it could from consumer towards giant, multinational corporation, hurt trade with the U.S. and thence out to an entire ocean of companies the consumer “GDPR creates serious, unclear legal obligations for both private and has never heard of, and would never choose to do business with. public sector entities, including the US government,” Ross wrote in an “The 5th largest economy in the world now has meaningful privacy op-ed in The Financial Times. “We do not have a clear understanding of protections for the first time in history,” he said. “We will not only defend what is required to comply. That could disrupt transatlantic cooperation the historic gains we’ve made this year, but will continue our work to on financial regulation, medical research, emergency management expand these rights to all consumers.”

Congress Turns Down Substance Abuse Treatment Privacy Amendment

D

espite efforts of the policy advocacy group, Partnership to Amend 42 CFR Part 2, Congress decided not to allow providers expanded access to patients’ substance abuse records, according to an article on www.HealthITSecurity.com. The Overdose Prevention and Patient Safety Act (HR 6082), which passed the House in June, was finalized September by members of both the House and Senate with 42 CFR Part 2 intact. The resulting legislative package permits the disclosure of substance abuse treatment on a patient’s medical record with the patient’s explicit consent. The amendment to 42 CFR Part 2, which was intended to facilitate coordination between providers to improve patient care, would have permitted sharing the information without the patient’s consent. The biggest opposition to the amendment came from the American Medical Association (AMA), whose members argued that amending 42 CFR Part 2 would discourage addicted individuals from seeking treatment. The Partnership to Amend 42 CFR Part 2 is a coalition of more than 40 national health care organizations representing a wide range of health care stakeholders, including patients, clinicians, hospitals, biopharmaceuticals, the mental health community, pharmacists, electronic health record vendors, and payers. Its members include the American Hospital Association, American Health Information Management Association, American Psychiatric Association, College of Healthcare Information Management Executives, and major health insurers.

4 Security Shredding News Fall/Winter 2018

New Survey Shows Complacency About Identity Protection

D

espite the impact of the massive Equifax security breach affecting 147.9 million Americans, and overall rise in identity theft, experts and surveys show that Americans are less concerned rather than more so, reports a www.MoneyTips.com article. • Overall, the percentage of online households with privacy and security concerns dropped from 84 percent in 2015 to 73 percent in 2017. Only 16 percent of online households refuse to buy goods or services online in 2017, compared to 26 percent in 2015. Close to sixty million Americans have been victims of identity theft at some point in their lives, according to a 2018 Harris Poll. According to Javelin Strategy and Research, approximately 16.7 million people were victims of identity theft in 2017, accounting for $16.8 billion in losses. While those who have been affected by breaches tend to be more cautious, the growing threat is not driving the majority of Americans offline. A 2017 survey conducted by the U.S. Commerce Department’s National Telecommunications and Information Administration (NTIA) showed that 57 percent of households with online activities were concerned about identity theft, compared to 63 percent in the 2015 survey. The NTIA data suggests that if you haven’t experienced a data breach yet, you’re more likely to assume it won’t happen to you. In both the 2015 and 2017 surveys, 70 percent of households affected by security breaches listed identity theft as a concern – but in the 2017 survey, only 54 percent of households who hadn’t suffered a breach called it a concern. •


www.keithwalkingfloor.com

Security Shredding News Fall/Winter 2018

5


Security Shredding News

Anthem Pays OCR $16 million in Record HIPAA Settlement Following Largest U.S. Health Data Breach in History

A

cyber-attackers had gained access to their IT system via an undetected continuous and targeted cyberattack for the apparent purpose of extracting data, otherwise known as an advanced persistent threat attack. After filing their breach report, Anthem discovered cyber-attackers had infiltrated their system through seemingly official (spear phishing) emails sent to an Anthem subsidiary. Investigation revealed that at least one employee responded to the malicious email and opened the door to further attacks. OCR’s investigation revealed that between Dec. 2, 2014 and Jan. 27, 2015, the cyber-attackers stole the ePHI of almost 79 million individuals, including names, social security numbers, medical identification numbers, addresses, dates of birth, email addresses, and employment information. In addition to the ePHI breach, OCR’s investigation revealed that Anthem failed to conduct an enterprise-wide risk analysis, had insufficient procedures to regularly review information system activity, failed to identify and respond to suspected or known security incidents, and failed to implement adequate minimum access controls to prevent the cyberattackers from accessing sensitive ePHI, beginning as early as Feb. 18, 2014. OCR ordered Anthem to develop and submit a corrective action plan to comply with the HIPAA Rules.

nthem, Inc. has agreed to pay $16 million to the U.S. Department of Health and Human Services, Office for Civil Rights (OCR) for the largest U.S. health data breach in history, the agency said in an official statement issued in October. The $16 million settlement eclipses the previous high of $5.55 million paid to OCR in 2016. The Anthem breach exposed the electronic protected health information of almost 79 million people. In addition to the fine, the medical insurer must take substantial corrective action to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules cyberattacks. Anthem is an independent licensee of the Blue Cross and Blue Shield Association operating throughout the United States and is one of the nation’s largest health benefits companies, providing medical care coverage to one in eight Americans through its affiliated health plans. This breach affected electronic protected health information (ePHI) that Anthem, Inc. maintained for its affiliated health plans and any other covered entity health plans. On March 13, 2015, Anthem filed a breach report with the HHS Office for Civil Rights detailing that, on Jan. 29, 2015, they discovered

Advertise in all 4 issues of Security Shredding News and $AVE !! For more information, contact Rick Downing at 440-257-6453 or email rickdowning@oh.rr.com.

Data Destruction by the Book Finally, a book that tells the customer what reputable data destruction service providers have always wanted to say. • • • • •

How to pick a service provider What do regulations require Risk management best practices What to include in an RFP or contract Includes forms, policies & templates

Order your copy today! www.naidonline.org halfpg ShreddingNews317.indd 1 6Disposition Security Shredding News Fall/Winter 2018

This is the book your customers will soon be reading. 3/17/17 10:22 AM


Security Shredding News

OCR Says Next Round of HIPAA Audits Will Focus on Enforcements Office for Civil Rights Director announces intention to use harsher investigative tools to hold bad actors accountable

S

anta Monica, CA – In 2011, The Department of Health and Human Services’ Office for Civil Rights (OCR) began auditing healthcare providers and business associates to determine overall compliance with HIPAA’s privacy and security laws. At a recent HIPAA security conference, OCR Director Roger Severino announced that the next round of examinations will be focused on enforcement and the upcoming audits will use harsher investigative tools to hold bad actors accountable. Enforcement for noncompliant offenders m ay i n c l u d e s u b p o e n a s, l e g a l a c t i o n , reimbursements to victims, penalties, and more. Additionally, Bloomberg Law recently reported

that OCR has been ratcheting up enforcement actions over the past three years, and as random HIPAA audits occur, increased penalties will most likely result. Jeff Broudy, CEO of PCIHIPAA states, “Overall we see less than 20% of all practices and business associates have implemented the safeguards required under HIPAA. In preparation for the next wave of HIPAA audits, we are providing all healthcare providers and their business associates complimentary risk assessments and reviews so they clearly understand what is required, and to help identify the right actions to take in case of an audit.” Under the HIPAA Notification Rule, covered entities that experience a HIPAA data

breach must self-report the breach to HHS. Some practices aren’t aware of the rules, so audits will help with compliance and overall enforcement. Penalties are no longer immaterial. Average fines range from $100 to $50,000 per HIPAA violation, and are capped at $1.5 million per year. HIPAA compliance must be addressed continuously. It’s not a checkbox or a “one and done” process. Also, the same HIPAA safeguards required by a hospital or a health plan also apply to dentists, doctors, and their business associates. Anthem’s recent $16 million dollar HIPAA fine, and Mr. Severino’s position above, should be a warning to all healthcare providers and business associates.

HIPAA Changes Expected for 2019

T

he latest Department of Health and Human Services (HHS) semi-annual regulatory agenda signals significant changes to HIPAA regulations and other health care privacy rules, according to an article on www.natlawreview.com. HHS will revisit a proposal regarding sharing penalty money with individuals affected by data breaches. Currently, no clear methodology exists for determining at what point an individual is harmed by a data breach and how much money any one individual would deserve for the resulting harm. Making this type of determination is extremely difficult in large data breaches involving hundreds or thousands of unspecified victims whose information may have been left vulnerable but not actually exploited. Another area HHS will be looking into is whether HIPAA regulations are stalling progress toward increased care coordination and valuebased payment systems, both of which require sharing of patient information. As providers are encouraged to work together more to improve patient outcomes and decrease costs, the flow of information between them can be restricted due to HIPAA concerns. With some stakeholders pushing for greater coordination to enable “whole person” health care, the impact of 42 CFR Part 2 is a key issue at the agency. In March of 2019, HHS will commence the rulemaking on the alignment of 42 CFR Part 2 with HIPAA, to clarify what information providers may share about patients for the purpose of treatment, payment and operations. In September, Congress voted against adding an amendment to the final version of the Overdose Prevention and Patient Safety Act (HR 6082) that would have allowed sharing of information without patient consent.

www.paperstockreport.com

ken@paperstockreport.com

Security Shredding News Fall/Winter 2018

7


Security Shredding News

States Step Up Breach Settlement Activity

I

f the enforcement actions taken in 2018 represent a trend, states may be taking the lead in HIPAA settlements, according to an article on www.CareersInfoSecurity.com. So far this year, the Health and Human Services Office of Civil Rights has levied penalties on three organizations totaling less than $8 million. In 2017, OCR issued 10 enforcement actions totaling $19.4 million in settlements and fines, and 13 actions in 2016, totaling $23.5 million. The New York attorney general’s office issued several high-profile breach actions this year: a $200,000 HIPAA settlement and corrective action plan for The Arc of Erie County; a $1.15 million settlement with health plan Aetna; and a $575,000 settlement with Emblem Health. In April, the state of New Jersey fined Virtua Medical Group $418,000 for a 2016 breach affecting 1,600 patients. California has enacted one of the nation’s strictest privacy laws, which goes into effect in 2020. Other states, including Colorado, have also been strengthening their privacy and/or breach notification laws. So far in 2018, HHS has issued three HIPAA enforcement actions: • A $4.3 million civil monetary penalty issued in April by an HHS administrative law judge against the University of Texas MD Anderson Cancer Center in a case involving three breaches that occurred in 2012 and 2013 • A $100,000 settlement in February with Filefax, a now-defunct Illinois-based medical records storage company at the center of a 2015 “dumpster diver” breach affecting more than 2,000 patients • A $3.5 million settlement in February with Massachusetts-based healthcare organization Fresenius Medical Care North America in a case involving five small health data breaches in 2012 involving lost or stolen unencrypted computing devices Under the HITECH Act of 2009, state attorneys general have the authority to bring civil actions and obtain damages on behalf of state residents for violations of the HIPAA privacy and security rules.

California Privacy Law Amended to Exempt HIPAA-Covered Information and Entities

B

eginning Jan. 1, 2020, the California Consumer Privacy Act (CCPA) will give consumers, including healthcare consumers, the right to find out what personal information commercial businesses collect about them. The law spells out types of businesses from which consumer information is collected or with which it is shared and requires businesses to inform consumers why they are collecting or selling the information. In August, the California state senate passed SB 1121, an amendment to the CCPA that clarifies exemptions for data already covered by the Health Insurance Portability and Accountability Act (HIPAA), among other privacy acts. All HIPAA-covered data are exempt from the CCPA, as are HIPAA-covered entities. The rules also apply to any information collected as part of a clinical trial. SB 1121 also removed the requirement that a plaintiff first notify the California Attorney General before filing a lawsuit pursuant to the CCPA, which would have provided the Attorney General the opportunity to order a plaintiff not to proceed. Under CCPA, consumers must be notified of any sale or identity of third parties to which the information was sold or disclosed. Consumers may opt out of the sale of personal information by a business and to request that their personal information is deleted. Businesses may not sell the personal information of consumers under 16 years of age, unless affirmatively authorized, as specified, to be referred to as the right to opt in. Criteria for commercial businesses that must comply with the CCPA: • Annual gross revenues in excess of $25 million • Annually buy, receive for the business’ commercial purposes, sell or share for commercial purposes, alone or in combination, the personal information of 50,000 or more consumers, households or devices • Derive 50 percent or more of annual revenues from selling consumers’ personal information The law provides that any person, business, or service provider that intentionally violates a provision of the law is liable for a civil penalty up to $7,500 for each violation. Fines go into the newly created Consumer Privacy Fund in the General Fund to be applied to support the purposes of the bill and its enforcement. Businesses must provide two methods for consumers to make requests related to their information. This may include a toll-free telephone number and, if applicable, a Web site address. Businesses must disclose and deliver the requested information, free of charge to the consumer within 45 days of the request no more than twice a year to a single consumer.

8 Security Shredding News Fall/Winter 2018

Consumer Complaints on Potential HIPAA Issues Are Increasing, HHS Official Says

C

omplaints about misuse of protected health information are on the rise, according to an official within Health and Human Services Office for Civil Rights, reports an article on HealthDataManagement. com. HHS reports a steep escalation in complaints – approaching 27,000 to 28,000 this year, according to Nicholas Heesters, an OCR HIPAA compliance and enforcement official. The figures are adjusted upward from what Heesters predicted earlier this year in a February report on HIPAA compliance issues. Speaking this fall at the American Health Information Management Association conference in Miami, Heesters noted that the vast majority of the complaints are resolved quickly, and providers generally are not found to be at fault. Failure to comply with HIPAA requirements can result in civil and criminal penalties, as well as progressive disciplinary actions. These civil and criminal penalties can apply to both covered entities and individuals. Civil monetary penalties for misuse of protected health information: • Covered entity or individual did not know (and by exercising reasonable diligence would not have known) the act was a HIPAA violation. • $100-$50,000 for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year • The HIPAA violation had a reasonable cause and was not due to willful neglect. • $1,000-$50,000 for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year • The HIPAA violation was due to willful neglect, but the violation was corrected within the required time period. • $10,000-$50,000 for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year • The HIPAA violation was due to willful neglect and was not corrected. • $50,000 or more for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year Criminal penalties for misuse of protected health information: Unknowingly or with reasonable cause • Up to one year Under false pretenses • Up to five years For personal gain or malicious reasons • Up to ten years


Security Shredding News

Unauthorized Disclosure of Patients’ Protected Health Information During ABC Television Filming Results in Multiple HIPAA Settlements Totaling $999,000

I

n September, the Department of Health and Human Services Office for Civil Rights (OCR) announced that it reached separate settlements with Boston Medical Center (BMC), Brigham and Women’s Hospital (BWH), and Massachusetts General Hospital (MGH). The cases involved compromising the privacy of patients’ protected health information (PHI) by inviting film crews on premises to film an ABC television network documentary series, without first obtaining authorization from patients. Collectively, the three entities paid OCR $999,000 to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule. This is the second HIPAA case involving an ABC medical documentary television series, the previous being OCR’s April 16, 2016 settlement with New York-Presbyterian Hospital in association with the filming of “NY Med.” To resolve potential HIPAA violations, BMC has paid OCR $100,000, BWH has paid OCR $384,000, and MGH has paid OCR $515,000. Each entity will provide workforce training as part of a corrective action plan that will include OCR’s guidance on disclosures to film and media, including:

• • • • • •

a specific prohibition on filming patients without written authorization a process for evaluating and approving any requests from the media to film at the hospital identification of agents or representatives’ employees could contact regarding HIPAA compliance in relation to media related activities requirement that a hospital employee monitor all photography or filming of patients outside generally accessible areas internal reporting procedures to report and promptly investigate violations of these policies application of sanctions against employees that violate this policy.

The hospitals must provide an implementation report containing the following elements within 120 days of HHS giving final approval of the newly created policies and procedures summarizing their efforts to comply with their respective CAPs. HHS media guidelines can be found at: http://www.hhs.gov/hipaa/for-professionals/faq/2023/film-and-media/ index.html.

Advertise here and reach over 3,000 businesses involved in ...

Document & Product Destruction • Records & Media Storage • Medical / Pharmaceutical Waste Transporting For more information, contact Rick at 440-257-6453 or email rickdowning@oh.rr.com.

www.shred-tech.com

Security Shredding News Fall/Winter 2018

9


Security Shredding News

Subject Matter Expert Hired to Lead PRISM International

P

RISM International recently hired Gail Bisbee to serve as its Records and Information Management (RIM) Subject Matter Expert (SME). The association’s Board of Directors approved Bisbee and is excited for the extended benefits that a SME will afford to PRISM International members. According to i-SIGMA co-President Christopher Jones the ability to hire a RIM industry expert to lead PRISM International was among the most important reasons for the recent merger with the National Association for Information Destruction (NAID) and a top priority for the newly formed i-SIGMA Board of Directors. “By merging, PRISM International inherited a well-established and highly-competent back office,” said Jones. “With that in place, the combined resources of the new organization allowed us to add the type of in-house expertise we sorely needed. That was the commitment we made to our members when we proposed the merger, and I am happy to say we have delivered beyond our expectations.” According to i-SIGMA CEO Bob Johnson, Bisbee is a well-known and highly-regarded figure within the industry. “She brings with her the years of first-hand business experience and knowledge that will help us take PRISM International to the next level.” Bisbee is the former CEO of North Carolina-based Confidential Records Management, Inc. She is also a past member of the PRISM Board of Directors and has made numerous appearances speaking at association events over the years. PRISM International is a division of the International Secure Information Governance and Management Association™ (i-SIGMA™) and focuses on records information management, including physical record storage and management, data protection services, imaging and conversion services, and confidential destruction services (www.prismintl.org).

PSI Chapter Showcases Its Strengths in Rebranding Campaign

W

ashington, DC – The Paper Stock Industries (PSI) Chapter, a national chapter of the Institute of Scrap Recycling Industries, Inc., has launched a multimedia rebranding campaign that promotes its key strengths and reaffirms its position as a leading forum for scrap paper processors, MRFs, brokers, and consumers. The campaign focuses on PSI’s four key strengths of providing advocacy, standards, training, and networking. The chapter is promoting those key messages through PSA-type print ads in industry trade publications, digital banner ads on its website and other online outlets, a signature e-mail banner for PSI members, and printed fliers distributed at industry events. PSI will introduce the various parts of the campaign in stages over several months. “PSI offers invaluable benefits to its members, and this campaign tells prospects how PSI can give them a competitive edge to help them achieve even greater success,” says PSI Communications Committee Chair Nancy Womack of Caraustar (Austell, Ga.). “PSI already has a strong brand and a great reputation for serving all participants in the paper recycling chain,” says PSI Chapter President Leonard Zeid of Midland Davis Corp. (St. Louis), “but this new campaign will help it reach an even larger audience to note the value-added proposition PSI and ISRI offer recycling companies.”

Redishred Capital Corp. Announces Acquisition of Safe Shredding in North New Jersey

M

www.bomaccarts.com

sales@bomaccarts.com

10 Security Shredding News Fall/Winter 2018

ississauga, Ontario – Redishred Capital Corp has completed an asset acquisition of the Safe Shredding business located in North New Jersey. The acquisition includes on-site paper shredding trucks, client relationships and other equipment used in the business. Pursuant to an agreement with a private arms’-length vendor, the Company, through its wholly-owned subsidiary, acquired the assets for a total purchase of approximately CAD$6.4 million (US$5 million). The purchase is to be paid as follows (amounts are approximate and based on current foreign exchange rates): (i) CAD$4.034 million cash (subject to certain customary adjustments) from cash reserves; (ii) issuance of a promissory note in the amount of CAD$704,000 and a vehicle financing contract in the amount of CAD$373,000 by Redishred’s subsidiary; (iii) a holdback amount of CAD$192,000; (iv) the issuance of 671,434 common shares of the Company at a deemed price of $0.68 per common share, valued at CAD$457,000; and (v) up to CAD$640,000 paid as an earn out (subject to certain conditions set out in the Agreement). The common shares of the Company are to be issued after closing conditional upon regulatory approval and will be subject to a four month hold period in Canada from the date of issuance. Redishred views this acquisition as accretive to the Company’s operating income and earnings per share. Mr. Jeffrey Hasham, CEO of Redishred, had the following comments on the acquisition, “We are very pleased to welcome the Safe Shredding Team to PROSHRED®. Safe Shredding’s management, Adam Reitman and Joe Coletta, have done a tremendous job building a great business in North and Central New Jersey, and we at PROSHRED® are looking forward to continuing to deliver the fine client service that Safe Shredding has given to their many clients over the years. We are additionally excited to have Joe Coletta join us as our Manager of Performance and Operations for the region, a role he has excelled at with Safe Shredding for the last 12 plus years.”


SERVING THE PAPER RECYCLING INDUSTRY SINCE 1962.

Advocacy Standards Training Networking As a national chapter of the Institute of Scrap Recycling Industries (ISRI), PSI offers the support and information you need to succeed in today’s marketplace.

Give your company the competitive advantage: join the PSI today.

PaperStockIndustries.org www.PaperStockIndustries.org | Email: PSI@isri.org Security Shredding News Fall/Winter 2018 11


PRSRT STD U.S. Postage

PAID

Cleveland, OH Permit #1737

6075 Hopkins Rd • Mentor, OH 44060 • Ph: 440-257-6453 • Fx: 440-257-6459 • Email: downassoc2@oh.rr.com

Inside This Issue

VOL. 15 NO. 3 FALL/WINTER 2018 Sweeping California Privacy Law Could Spark Federal Legislation PAGE 1 Congress Turns Down Substance Abuse Treatment Privacy Amendment PAGE 4 Anthem Pays OCR $16 million in Record HIPAA Settlement Following Largest U.S. Health Data Breach in History PAGE 6 Unauthorized Disclosure of Patients’ Protected Health Information During ABC Television Filming Results in Multiple HIPAA Settlements Totaling $999,000 2018 PAGE 9 Security Shredding & Storage News, Plant Based 1/2 page, 4C

INDUSTRIAL PAPER SHREDDERS (336) 285-0021 • 5708 Uwharrie road, archdale, Nc 27263 • www.vecoplaNllc.com


Turn static files into dynamic content formats.

Create a flipbook
Security Shredding News Fall/Winter 2018 by Downing and Associates - Issuu