Best practices for mobile device data encryption at HIPAA covered entitites
Patient data was copied for 2,900 patients to an employee's thumb drive at BIDMC. The employee left that organization and went to a new one (UCSF). The employee loaded that data onto a laptop at the new organization to demonstrate quality improvement reporting. That laptop was stolen. Both organizations have potential HIPAA violations to worry about based on this person's actions. Some best practices:
- Policies should require that all mobile storage devices be secured
- Encrypt all mobile devices including laptops
- Educate employees on how to protect privacy
- Sanction employees who violate policies
- Implement technologies that find transfers of medical data (especially in an unencrypted form). This should include both transfers across the network and via physical devices such as USB thumb drives, iPods, etc.
Categories: Healthcare Tags: Encryption, HIPAA, Mobile, Stolen laptop, USB lost
Secure Medical Data Transport – Standards Smorgasbord
Great blog entry on secure transport of medical data by Dr. Halamka. Different standards used include:
| Type of data | Protocol used |
| Electronic prescriptions | SOAP 1.2 |
| Administrative | SMTP (CAQH) and SMTP (WEDI) |
| Lab | MLLP and TCP/IP |
| Personal Health Records | REST |
| Federal agencies | NHIN FHA connect - SOAP 1.2 |
Categories: Healthcare Tags: Encryption, REST, Standards
Health Net : 1.5 million records
Security breach may have affected 1.5 million patient records
- California based Health Net
- Lost an external hard drive six months ago that was not encrypted
- Patient records from multiple states include New York, Connecticut, Arizona and New Jersey.
- Attorney General is investigating, including the time it took to report the incident
- Free credit monitoring for two years will be offered to those effected
Full article: Health Net healthcare data breach affects1.5 million
Categories: Healthcare, Uncategorized Tags: Arizona, Connecticut, Credit Monitoring, Encryption, Hard drive lost, HIPAA, HITECH Act, New Jersey, New York
