Posts Tagged ‘USB lost’

Best practices for mobile device data encryption at HIPAA covered entitites

Patient data was copied for 2,900 patients to an employee's thumb drive at BIDMC. The employee left that organization and went to a new one (UCSF). The employee loaded that data onto a laptop at the new organization to demonstrate quality improvement reporting. That laptop was stolen. Both organizations have potential HIPAA violations to worry about based on this person's actions. Some best practices:

  1. Policies should require that all mobile storage devices be secured
  2. Encrypt all mobile devices including laptops
  3. Educate employees on how to protect privacy
  4. Sanction employees who violate policies
  5. Implement technologies that find transfers of medical data (especially in an unencrypted form). This should include both transfers across the network and via physical devices such as USB thumb drives, iPods, etc.

Read more...

Be the first to comment - What do you think?  Posted by Waynerino - January 28, 2010 at 9:45 am

Categories: Healthcare   Tags: , , , ,

1,700 at Pitt County possibly compromised

USB flashdrive used to move patient data between different computer systems is missing.

Read more...

Be the first to comment - What do you think?  Posted by Waynerino - October 20, 2009 at 7:48 am

Categories: Healthcare, Uncategorized   Tags: , ,