Department of Veterans Affairs Medicare Data Breach
Affected Social Workers Received Notices
Social workers have reported receiving notices dated the week of May 7 – 11, 2007 regarding a significant data breach by the Department of Veterans Affairs (VA), potentially affecting a large number of NASW members and social workers across the country. The VA has reported that data such as dates of birth and social security numbers for 1.3 million health care providers and 250,000 patients may have been breached by the loss of an employee’s portable hard drive. The loss was reported on January 22, 2007 and affected providers were sent a letter from the VA in May notifying them of the breach.
The data breach occurred in connection with the Birmingham VA Medical Center and included data obtained from the Centers for Medicare and Medicaid Services (CMS) for health research purposes. The VA has taken several steps to mitigate the possible harm done. The loss has been investigated by local and federal authorities and a reward has been offered for the return of the hard drive.
The VA has reported that it intends to offer one year of free credit reporting for the affected individuals and suggests contacting the Federal Trade Commission to place a “fraud alert” on credit accounts. This number is 1-877-438-4338 or consumers may visit the web site at www.ftc.gov.
In addition the VA has established an information call center regarding the data loss: 1-877-894-2600.
NASW Contacts VA and CMS with Concerns
NASW Executive Director Betsy Clark sent a letter to Department of Veteran Affairs Secretary R. James Nicholson detailing social workers’ concerns about the data breach and the VA’s delayed response and requesting dialogue on this matter. (See NASW Letter to VA). NASW also contacted the Centers for Medicare & Medicaid Services (CMS) highlighting social workers’ concerns about the lack of protection for health care providers’ personally-identifiable data and requesting more information about the standards applied by CMS to disclosures to external entities, such as the VA. (See NASW Letter to CMS).
Next Steps
The VA has indicated that affected providers will receive a second notice informing them of the one year free credit monitoring service, and information about how to activate that service. NASW will keep chapters and members informed as to the responses from the federal agencies involved in the breach and engage in advocacy for the protection of client and health care provider data.
Resources
-
- Department of Veterans Affairs Press Release (February 2, 2007)
http://www1.va.gov/opa/pressrel/pressrelease.cfm?id=1287
- Department of Veterans Affairs Press Release (February 10, 2007)
http://www1.va.gov/opa/pressrel/pressrelease.cfm?id=1294
- Department of Veterans Affairs Information Call Center: 1-877-894-2600
- Federal Trade Commission (for fraud alert on credit accounts) 1-877-438-4338 www.ftc.gov
- Letter from NASW to Department of Veterans Affairs [word document]
- Letter from NASW to Centers for Medicare & Medicaid Services[word document]
|