Raleigh Orthopedic Clinic arranged for its X-ray films to be brought up to date and converted to digital media, the healthcare organization sought external assistance from a third party vendor.
After locating a supplier that could offer the service and the selected X-ray films were sent for conversion.
The contract was agreed in January of this year and the films were sent; however when the clinic did not receive the electronic copies of the data, suspicions arose at the clinic. An review was conducted into the matter in the first week of March and it was found that the clinic had been involved in a scam.
In contrast to other security violations where thieves deliberately set out to obtain ePHI to commit fraud, in this case the thieves needed the x-ray film for the silver it contained. Raleigh Ortho found that its X-rays had been sold on for profit to a recycling company based in Ohio which offers a service to recycle X-ray films.
It is believed that the unnamed company used by the hospital obtained the X-rays fraudulently with a view to selling the silver. X-ray films contain around 2% silver and thieves are able to sell the metal for as much as $24.50 per ounce according to the News & Observer.
This is not the first instance where a healthcare company has been tricked into giving thieves valuable X-rays. In 2012, police arrested two men from South Carolina who had managed to steal X-rays from 38 healthcare facilities by posing as employees of a recycling company.
Raleigh Orthopedic Clinic has stated that while it understands the X-rays were taken for their silver content and the X-rays have now been terminated, patients should be extra careful and review their credit card and bank accounts closely over the next few months in case the thieves also duplicated the data.
The X-rays held PHI of 17,000 patients, although the information was limited to full names, dates of birth and any medical issues shown by the x-ray films. The clinic is in the process of advising those affected to warn them about the security breach in accordance with HIPAA breach notification regulations.