Archive for January, 2010

Best practices for mobile device data encryption at HIPAA covered entitites

Patient data was copied for 2,900 patients to an employee's thumb drive at BIDMC. The employee left that organization and went to a new one (UCSF). The employee loaded that data onto a laptop at the new organization to demonstrate quality improvement reporting. That laptop was stolen. Both organizations have potential HIPAA violations to worry about based on this person's actions. Some best practices:

  1. Policies should require that all mobile storage devices be secured
  2. Encrypt all mobile devices including laptops
  3. Educate employees on how to protect privacy
  4. Sanction employees who violate policies
  5. Implement technologies that find transfers of medical data (especially in an unencrypted form). This should include both transfers across the network and via physical devices such as USB thumb drives, iPods, etc.

Read more...

Be the first to comment - What do you think?  Posted by Waynerino - January 28, 2010 at 9:45 am

Categories: Healthcare   Tags: , , , ,

Dental clerk gets 5+ years: stealing identity of patients

Brownsville dental clerk gets fiver years and nine months for embezzlement and stealing identifies of patients to open credit cards.

  • Plead guilty to fraudulent identification and identity theft
  • She also pocketed some cash payments
  • Dentist says his reputation had been destroyed by this employee
  • Had to pay the credit card company back for fraudulent charges
  • $110,000 dollars in restitution

Read more...

Be the first to comment - What do you think?  Posted by Waynerino - January 25, 2010 at 10:16 am

Categories: Healthcare   Tags: , , ,

United Health Group’s takeover of HealthNet of the Northeast may be hampered by HIPAA privacy concerns

United Health Group's takeover of HealthNet of the Northeast may be hampered by HIPAA privacy concerns. Connecticut's largest physician's lobby has requested that the attorney generals office investigate to see if the deal would violate HIPAA. The AG's office is currently suing HealthNet for potential HIPAA violations. There are worries that United Health could use HealthNet records to decide who to cover and at what price.

Read more...

Be the first to comment - What do you think?  Posted by Waynerino - January 22, 2010 at 7:50 am

Categories: Healthcare   Tags: , , ,

Secure Medical Data Transport – Standards Smorgasbord

Great blog entry on secure transport of medical data by Dr. Halamka. Different standards used include:

NHIN FHA connect - SOAP 1.2
Type of dataProtocol used
Electronic prescriptionsSOAP 1.2
AdministrativeSMTP (CAQH) and SMTP (WEDI)
LabMLLP and TCP/IP
Personal Health RecordsREST
Federal agencies

Read more...

Be the first to comment - What do you think?  Posted by Waynerino - January 20, 2010 at 7:31 am

Categories: Healthcare   Tags: , ,

External drive containing thousands of patient records stolen from a Kaiser Permanente’s employee’s vehicle

External drive containing thousands of patient records stolen from a Kaiser Permanente's employee's vehicle. Control of external media is a tricky balance of usability and security (including security budgets)

  • 15,500 patients from Northern California potentially effected
  • Data included patient name and medical record number
  • Drive was not encrypted
  • Device was personal property
  • Employee was fired
  • Patients effected were notified by mail

Read more...

Be the first to comment - What do you think?  Posted by Waynerino - January 18, 2010 at 1:32 pm

Categories: Healthcare   Tags: ,

Release of the National Health Security Strategy by HHS – no direct mention of network security?

Release of the National Health Security Strategy by Health and Human Services

  • Protecting health during an emergency
  • Preparation for bioterrorism and natural disasters
  • Implementation guide with 10 objectives
Interesting that there is no direct mention of how the Internet and network security impact this plan

Read more...

Be the first to comment - What do you think?  Posted by Waynerino - January 16, 2010 at 3:20 pm

Categories: Healthcare   Tags: ,

Goldmine of identity theft in healthcare

Great article from CNN Money.

  • Healthcare identify theft dominated all other crimes in the sector last year
  • Insiders selling information to organized criminal groups
  • Medicare system a top target
  • Selling medical information to uninsured who need care
  • Fly by night shell billing companies
  • Can put health at risk via tampering of medical records
  • In 2008, $19,000 per incident of health care fraud, four fold larger than overall identify theft
  • Prime target areas are those with large numbers of Medicare recipients (Miami, Detroit, etc)

Read more...

Be the first to comment - What do you think?  Posted by Waynerino - January 14, 2010 at 8:25 am

Categories: Healthcare   Tags: ,

The HIPAA Song

Song about HIPAA privacy from some college students

Read more...

Be the first to comment - What do you think?  Posted by Waynerino - January 12, 2010 at 12:45 pm

Categories: Healthcare   Tags:

Next Page »