Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
30
5
6
7
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
1
2
Federles Master Tutorial On Abdominal Imaging
2020-06-29 - 2020-07-01    
All Day
The course is designed to provide the tools for participants to enhance abdominal imaging interpretation skills utilizing the latest imaging technologies. Time: 1:00 pm - [...]
IASTEM - 864th International Conference On Medical, Biological And Pharmaceutical Sciences ICMBPS
2020-07-01 - 2020-07-02    
All Day
IASTEM - 864th International Conference on Medical, Biological and Pharmaceutical Sciences ICMBPS will be held on 3rd - 4th July, 2020 at Hamburg, Germany . [...]
International Conference On Medical & Health Science
2020-07-02 - 2020-07-03    
All Day
ICMHS is being organized by Researchfora. The aim of the conference is to provide the platform for Students, Doctors, Researchers and Academicians to share the [...]
Mental Health, Addiction, And Legal Aspects Of End-Of-Life Care CME Cruise
2020-07-03 - 2020-07-10    
All Day
Mental Health, Addiction Medicine, and Legal Aspects of End-of-Life Care CME Cruise Conference. 7-Night Cruise to Alaska from Seattle, Washington on Celebrity Cruises Celebrity Solstice. [...]
ISER- 843rd International Conference On Science, Health And Medicine ICSHM
2020-07-03 - 2020-07-04    
All Day
ISER- 843rd International Conference on Science, Health and Medicine (ICSHM) is a prestigious event organized with a motivation to provide an excellent international platform for the academicians, [...]
04 Jul
2020-07-04    
12:00 am
ICRAMMHS is to bring together innovative academics and industrial experts in the field of Medical, Medicine and Health Sciences to a common forum. All the [...]
6th Annual Formulation And Drug Delivery Congress
2020-07-08 - 2020-07-09    
All Day
Meet and learn from experts in the pharmaceutical sciences community to address critical strategic developments and technical innovation in formulation, drug delivery and manufacturing of [...]
7th Global Conference On Pharma Industry And Medical Devices
2020-07-08 - 2020-07-09    
All Day
The Global Conference on Pharma Industry and Medical Devices GCPIMD is to bring together innovative academics and industrial experts in the field of Pharmacy and [...]
IASTEM - 868th International Conference On Medical, Biological And Pharmaceutical Sciences ICMBPS
2020-07-09 - 2020-07-10    
All Day
IASTEM - 868th International Conference on Medical, Biological and Pharmaceutical Sciences ICMBPS will be held on 9th - 10th July, 2020 at Amsterdam, Netherlands . [...]
2nd Annual Congress On Antibiotics, Bacterial Infections & Antimicrobial Resistance
2020-07-09 - 2020-07-10    
All Day
EURO ANTIBIOTICS 2020 invites all the participants from all over the world to attend 2nd Annual Congress Antibiotics, Bacterial infections & Antimicrobial Resistance to be [...]
Events on 2020-06-29
Events on 2020-07-02
Articles

May 02: 3 Ways You Can Avoid and Minimize EHR Data Breaches

efficient medical care

As we’ve discussed on this blog, EHR (Electronic Health Records) offers several advantages over its paper-based forebears. But paper-based patient records have one huge advantage over EHR: they’re harder to steal or expose.

Granted, paper files could be accidentally destroyed in a flood or fire, and I suppose people have stolen records for various reasons, but if you’re an enterprising criminal, wouldn’t you prefer to grab an unencrypted laptop from a storeroom or hack into a healthcare provider’s database, rather than page through a box of 30 paper files in the hopes of finding a few social security numbers or credit card slips?

In contrast, data breaches involving EHR are so commonplace that the U.S. Department of Health & Human Services has a Breach Notification Rule webpage documenting all “breaches of unsecured protected health information affecting 500 or more individuals.”

You can search it by Breach Type, which includes:

  • Hacking/IT Incident
  • Improper Disposal
  • Loss
  • Theft
  • Unauthorized Access/Disclosure

Locations, which include:

  •  Desktop Computer
  • Email
  • Electronic Medical Record (EHR)
  • Laptop
  • Network Server
  • Other Portable Electronic Devices

The state in which the breach took place, and the date.

You could spend days looking at these statistics, but to give you a taste of how varied (and at times nutty) these breaches can be, David Vogel of Layered Tech wrote a post compiling the Top 10 HIPAA Data Breaches of 2013.

Writes Vogel:

While penalties haven’t been handed down and lawsuits settled, each of the below likely represent millions of dollars in fines and settlements. For example, during 2013 HHS handed out penalties ranging from $150,000 to $1.7 million. Potential class action lawsuits and the cost of providing fraud protection for those affected can quickly propel those costs into the tens of millions or even billions.

 

The breaches listed in Vogel’s Top 10 sprung from a variety of mishaps from unencrypted laptops to a programming error. The number 1 breach, which affected over 4 million patient records happened when four laptops containing patient data, including social security numbers, were stolen. The organization responsible for allowing this breach, Advocate Medical Group, failed to notify affected patients “until more than a month after the theft [italics mine], and stated the laptops were password protected,” although not encrypted, says Vogel.

At the end of his post, Vogel offers two recommendations to keep yourself off this list in 2014. They are:

1. Encrypt any devices that touch patient data. This takes a concerted effort and investment, but as you can see from half of the top ten breaches, electronic devices get stolen, and password protection is never enough.

2. Choose business associates who value data security and HIPAA compliance as much as you do. Ideally, choose one who will guarantee it.

Of course, no data protection solution or framework is 100% effective, and the common refrain is to prepare for when (not if) a data breach occurs. If you experience a data breach despite all your precautions, I have one more suggestion:

3. Be transparent. If your patient records have been compromised, don’t wait a month to inform your patients! Let them know as soon as the incident has taken place, and provide them with actions they can take to minimize the fallout, whether it involves cancelling a credit card or checking in with the three Credit Bureaus for any peculiar activity.

You might even consider offering affected patients a free subscription to a protection service like AllClear ID, to show your good intentions in handling this breach. Doing so won’t inoculate you from penalties or class action suits, but such actions may help signal to patients that they can still trust you over the long haul.

Source