Risk
4/30/2008
01:50 PM
Connect Directly
RSS
E-Mail
50%
50%

Former UCLA Health Employee Charged With Selling Celeb Records To Media

The U.S. District Court indictment against a former administrative assistant does not appear related to leaks of Britney Spears' health information this year.

Prosecutors have accused an administrative assistant of illegally accessing UCLA Medical Center patients' health records and selling celebrities' private health information to a national media outlet.

The accusations appeared in an indictment that was unsealed Tuesday in U.S. District Court in Los Angeles.

The indictment states that the former employee, Lawanda Jackson, 49, accessed and transferred the protected information in May 2007 in exchange for at least $4,600 worth of checks that were made out to her husband. The document does not state whose information was breached or which media outlet paid for the information.

The Los Angeles Times linked the indictment to stolen records on Maria Shriver and Farrah Fawcett. The hospital has said that 61 celebrities' records have been illegally accessed and that it fired 13 employees because of the problem. Another six employees faced discipline and six doctors were under investigation. The hospital also said it strengthened its privacy protection practices in light of breaches.

"We are deeply troubled that a former employee may have illegally received payments from a news organization in exchange for providing personal medical information," Dr. David T. Feinberg, CEO and interim vice chancellor of the UCLA Hospital System, said in a news announcement. "We welcome the U.S. Attorney's investigation and stand ready to cooperate in achieving a swift and fair outcome. Meanwhile, we continue to take steps to improve our staff training and information systems to further strengthen the confidentiality of patient records."

It does not appear that the indictment is directly related to the leaking of Britney Spears' health information. Media outlets around the country reported on Spears' behavior and condition while she was held in the hospital for a psychiatric evaluation. Those reports came out long after Jackson quit working at the hospital. Hospital administrators have said subsequent leaks were discovered due to improved auditing systems.

The Health Insurance Portability and Accountability Act (HIPAA) protects people's private medical records and allows for civil and criminal penalties -- including imprisonment and hundreds of thousands of dollars in fines -- for healthcare information breaches.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2963
Published: 2014-07-10
Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X EE, and 6.2.X EE allow remote attackers to inject arbitrary web script or HTML via the (1) _2_firstName, (2) _2_lastName, or (3) _2_middleName parameter.

CVE-2014-3310
Published: 2014-07-10
The File Transfer feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center does not verify that a requested file was an offered file, which allows remote attackers to read arbitrary files via a modified request, aka Bug IDs CSCup62442 and CSCup58463.

CVE-2014-3311
Published: 2014-07-10
Heap-based buffer overflow in the file-sharing feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center allows remote attackers to execute arbitrary code via crafted data, aka Bug IDs CSCup62463 and CSCup58467.

CVE-2014-3315
Published: 2014-07-10
Cross-site scripting (XSS) vulnerability in viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCup76308.

CVE-2014-3316
Published: 2014-07-10
The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypass intended upload restrictions via a crafted parameter, aka Bug ID CSCup76297.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.