Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
23
24
25
26
27
28
1
2
4
5
6
7
8
9
11
12
13
14
15
16
17
18
19
20
21
23
26
27
28
29
30
31
1
2
3
4
5
Health IT Summit in San Francisco
2015-03-03 - 2015-03-04    
All Day
iHT2 [eye-h-tee-squared]: 1. an awe-inspiring summit featuring some of the world.s best and brightest. 2. great food for thought that will leave you begging for more. 3. [...]
How to Get Paid for the New Chronic Care Management Code
2015-03-10    
1:00 am - 10:00 am
Under a new chronic care management program authorized by CMS and taking effect in 2015, you can bill for care that you are probably already [...]
The 12th Annual World Health Care  Congress & Exhibition
2015-03-22 - 2015-03-25    
All Day
The 12th Annual World Health Care Congress convenes decision makers from all sectors of health care to catalyze change. In 2015, faculty focus on critical challenges and [...]
ICD-10 Success: How to Get There From Here
2015-03-24    
1:00 pm
Tuesday, March 24, 2015 1:00 PM Eastern / 10:00 AM Pacific Make sure your practice is ready for ICD-10 coding with this complimentary overview of [...]
Customer Analytics & Engagement in Health Insurance
2015-03-25 - 2015-03-26    
All Day
Takeaway business ROI: Drive business value with customer analytics: learn what every business person needs to know about analytics to improve your customer base Debate key customer [...]
How to survive a HIPPA Audit
2015-03-25    
2:00 pm - 3:30 pm
Wednesday, March 25th from 2:00 – 3:30 EST If you were audited for HIPAA compliance tomorrow, would you be prepared? The question is not so hypothetical, [...]
Events on 2015-03-03
Health IT Summit in San Francisco
3 Mar 15
San Francisco
Events on 2015-03-10
Events on 2015-03-22
Events on 2015-03-24
Events on 2015-03-25
Articles

May 02: 3 Ways You Can Avoid and Minimize EHR Data Breaches

efficient medical care

As we’ve discussed on this blog, EHR (Electronic Health Records) offers several advantages over its paper-based forebears. But paper-based patient records have one huge advantage over EHR: they’re harder to steal or expose.

Granted, paper files could be accidentally destroyed in a flood or fire, and I suppose people have stolen records for various reasons, but if you’re an enterprising criminal, wouldn’t you prefer to grab an unencrypted laptop from a storeroom or hack into a healthcare provider’s database, rather than page through a box of 30 paper files in the hopes of finding a few social security numbers or credit card slips?

In contrast, data breaches involving EHR are so commonplace that the U.S. Department of Health & Human Services has a Breach Notification Rule webpage documenting all “breaches of unsecured protected health information affecting 500 or more individuals.”

You can search it by Breach Type, which includes:

  • Hacking/IT Incident
  • Improper Disposal
  • Loss
  • Theft
  • Unauthorized Access/Disclosure

Locations, which include:

  •  Desktop Computer
  • Email
  • Electronic Medical Record (EHR)
  • Laptop
  • Network Server
  • Other Portable Electronic Devices

The state in which the breach took place, and the date.

You could spend days looking at these statistics, but to give you a taste of how varied (and at times nutty) these breaches can be, David Vogel of Layered Tech wrote a post compiling the Top 10 HIPAA Data Breaches of 2013.

Writes Vogel:

While penalties haven’t been handed down and lawsuits settled, each of the below likely represent millions of dollars in fines and settlements. For example, during 2013 HHS handed out penalties ranging from $150,000 to $1.7 million. Potential class action lawsuits and the cost of providing fraud protection for those affected can quickly propel those costs into the tens of millions or even billions.

 

The breaches listed in Vogel’s Top 10 sprung from a variety of mishaps from unencrypted laptops to a programming error. The number 1 breach, which affected over 4 million patient records happened when four laptops containing patient data, including social security numbers, were stolen. The organization responsible for allowing this breach, Advocate Medical Group, failed to notify affected patients “until more than a month after the theft [italics mine], and stated the laptops were password protected,” although not encrypted, says Vogel.

At the end of his post, Vogel offers two recommendations to keep yourself off this list in 2014. They are:

1. Encrypt any devices that touch patient data. This takes a concerted effort and investment, but as you can see from half of the top ten breaches, electronic devices get stolen, and password protection is never enough.

2. Choose business associates who value data security and HIPAA compliance as much as you do. Ideally, choose one who will guarantee it.

Of course, no data protection solution or framework is 100% effective, and the common refrain is to prepare for when (not if) a data breach occurs. If you experience a data breach despite all your precautions, I have one more suggestion:

3. Be transparent. If your patient records have been compromised, don’t wait a month to inform your patients! Let them know as soon as the incident has taken place, and provide them with actions they can take to minimize the fallout, whether it involves cancelling a credit card or checking in with the three Credit Bureaus for any peculiar activity.

You might even consider offering affected patients a free subscription to a protection service like AllClear ID, to show your good intentions in handling this breach. Doing so won’t inoculate you from penalties or class action suits, but such actions may help signal to patients that they can still trust you over the long haul.

Source