What is a privacy data spill?
A “privacy data spill” is the storage on, or transmission of, any information about an individual mentioned by the agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and information that can be used to distinguish or trace an individual’s identity (such as a person’s name, social security number, date and place of birth, mother’s maiden name, biometric records, etc., including any other personal information that is linked or linkable to an individual) over a system or network not approved for such information. One of the primary objectives of the Health Insurance Portability and Accountability Act (HIPAA), was to protect a patient’s Personally Identifiable Information (PII), as well as, establishing regulations for the use and disclosure of Protected Health Information (PHI). PHI is any information about health status, provision of health care, or payment for health care that can be linked to an individual. The