On April 12, 2018, Polk County Health Services, Inc submitted a HIPAA Email Breach to the U.S. Department of Health and Human Services (HHS). Located in Des Moines, Iowa, Polk County's email breach affected 1071 individuals’ protected health information. Polk County Health Services, Inc is classified as a Health Plan.
According to Polk County's press release: …
There was a breach in personal information related to some Polk County social work assessments. There are 2,042 individuals whose information was included in the breach, which happened during the assessment period of some child and dependent adult abuse cases. Letters were mailed this week notifying these Iowans of the breach. This occurred when two workers used personal email accounts, personal online storage accounts and personal electronic devices for work purposes. That caused confidential data to be transmitted outside the DHS secure network. The incidents happened over a 5-year period starting in 2008. “There are no reports that any of the information was misused before it was deleted,” said Pat Penning, service area manager for the region including Polk County. “We’ve sent notification to individuals whose information was transmitted outside the secure network.” The types of information involved included name, mailing address, Social Security number, state identification number, date of birth, health information and incident information. The department began an internal investigation on January 17, 2014, once the issue was identified by a social work supervisor. Officials found that the workers did not follow DHS policy, which prohibits use of personal devices and transmitting information outside of the agency’s network. Appropriate personnel action was taken. “The chance that this information was accessed through these password-protected accounts and devices was small,” said Penning, “but we realize the Iowans involved in these cases may wish to take steps to be sure their information wasn’t misused.” DHS is taking further action including blocking access to online file storage sites, providing updated materials to staff on the department’s information technology policy and standard operating procedures, and continuing to require yearly cyber-security training for all employees.
HHS Wall of Shame
The HHS Wall of Shame is a website under the jurisdiction of HHS that lists all HIPAA breaches reported within the last 24 months. The Wall of Shame displays breaches that are currently under investigation by the Office for Civil Rights. As part of section 13402(e)(4) of the HITECH Act, the HHS Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.
HIPAA Breach Report
The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame.