HMG Healthcare discloses a data breach

HMG Healthcare discloses a data breach


HMG Healthcare from Texas has disclosed a data breach resulting in the theft of personally identifiable information and medical records.

Back in November 2023, the breach was detected, and subsequent investigation resulted in the discovery of the first of gaining access in August 2023.

Advertisements

The incident involved hackers gaining access to an HMG Healthcare server and stealing unencrypted files. The files on the server contained medical records and personal information, including names, dates of birth, contact information, general health information, information regarding medical treatment, Social Security numbers and employment records.

In general, any organization should tick off a standard breach response list — hiring a third-party cybersecurity company, informing law enforcement, and offering credit monitoring. But strangely, none of those is in the HMG Healthcare disclosure.

The claim that the breach was “quickly” identified denies the fact that it’s only disclosing it now. It was discovered in November and then found to have occurred in August. That’s not only not quick, given the legal requirements around breach disclosures, it’s possibly legally liable.

Advertisements

The HIPAA Breach Notification Rule 45 CFR §§ 164.400-414 requires HIPPA covered entities and their business associates to provide notification following a breach of unsecured protected health information without unreasonable delay and in no case later than 60 days following the discovery of the breach. Depending on when it discovered the breach in November, HMG Healthcare may have scraped under the 60-day requirement, but it’s arguable whether sitting on the news for nearly two months constitutes an unreasonable delay.

1 Comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.