Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
29
1
2
3
4
6
7
8
9
10
11
13
14
15
16
17
7:30 AM - HLTH 2025
18
19
20
22
23
24
25
26
27
28
29
30
31
1
2
12:00 AM - NextGen UGM 2025
TigerConnect + eVideon Unite Healthcare Communications
2025-09-30    
10:00 am
TigerConnect’s acquisition of eVideon represents a significant step forward in our mission to unify healthcare communications. By combining smart room technology with advanced clinical collaboration [...]
Pathology Visions 2025
2025-10-05 - 2025-10-07    
8:00 am - 5:00 pm
Elevate Patient Care: Discover the Power of DP & AI Pathology Visions unites 800+ digital pathology experts and peers tackling today's challenges and shaping tomorrow's [...]
AHIMA25  Conference
2025-10-12 - 2025-10-14    
9:00 am - 10:00 pm
Register for AHIMA25  Conference Today! HI professionals—Minneapolis is calling! Join us October 12-14 for AHIMA25 Conference, the must-attend HI event of the year. In a city known for its booming [...]
HLTH 2025
2025-10-17 - 2025-10-22    
7:30 am - 12:00 pm
One of the top healthcare innovation events that brings together healthcare startups, investors, and other healthcare innovators. This is comparable to say an investor and [...]
Federal EHR Annual Summit
2025-10-21 - 2025-10-23    
9:00 am - 10:00 pm
The Federal Electronic Health Record Modernization (FEHRM) office brings together clinical staff from the Department of Defense, Department of Veterans Affairs, Department of Homeland Security’s [...]
NextGen UGM 2025
2025-11-02 - 2025-11-05    
12:00 am
NextGen UGM 2025 is set to take place in Nashville, TN, from November 2 to 5 at the Gaylord Opryland Resort & Convention Center. This [...]
Events on 2025-10-05
Events on 2025-10-12
AHIMA25  Conference
12 Oct 25
Minnesota
Events on 2025-10-17
HLTH 2025
17 Oct 25
Nevada
Events on 2025-10-21
Events on 2025-11-02
NextGen UGM 2025
2 Nov 25
TN

Events

Articles

Medicinal services protection criminals merit no kindness

I read with dismay yet another instance of a security breach of a provider’s electronic health record system at the hands of healthcare staff who intentionally accessed patient data for personal gain.

This time, it was a doctor and an office manager of Sight and Sun Eyeworks Gulf Breeze in Gulf Breeze, Fla., who allegedly copied all or parts of the optometry practice’s EHR system, quit their jobs with no notice, moved to a competitor, and used the patient information to market their new employer’s services, in some cases going into Sight and Sun’s EHR system to change appointments to the new employer.  Sight and Sun has notified 9,000 patients about the unauthorized access, according to the Pensacola News Journal.

This is the dark side of EHRs; such tools are at their most vulnerable when people patients entrust with their confidential information–who presumably are trained about HIPAA–take advantage of these systems, wreaking havoc in their wake.

Had these been paper records, the damage would have been less extensive. Sure, patient information still could have been stolen, but the former employees would not have been able to electronically override the scheduling information and change appointments. They also likely would not have been able to access so many records.

Sight and Sun has filed a lawsuit against the two employees–Suzanne M. Day, M.D., and Lynette Bramlett–seeking return of the data and to stop them from using it. Day and Bramlett deny wrongdoing.

This situation is bad all round, no matter how you slice it.

Sight and Sun already has suffered from the security breach, incurring the cost and negative publicity of notifying the 9,000 patients. By improperly accessing and changing appointment information, Day and Bramlett may have compromised the patient records. Other data may have been compromised, as well.  Even if the practice had been complying with HIPAA (and there appears to be some evidence to that effect), Sight and Sun still may be subject to lawsuits by patients and government investigation.

The new employer also could be in legal trouble, if it knew or supported the cybercrime. And even if it didn’t, wouldn’t it behoove the practice, receiving this influx of new patients, to at least question the new employees’ methods? Who’s supervising these people? This office also can be sued by patients for privacy violations, and investigated by the government.

If the accusations are true, Day and Bramlett may very well end up in major legal trouble for their efforts, and there’s precedent for that. Last year, Eric McNeal, a former employee of a physician’s office who pulled a similar stunt on behalf of his new employer, was sentenced to 13 months in prison, plus community service. Is the potential financial benefit in misusing records really worth that kind of cost?

The real victims, of course, are the patients, whose confidential information–including their Social Society numbers–now reside in the possession of people the patients don’t even know, exposing them to potential identity theft and the less-than-savory world of healthcare backstabbing. The patients have been reduced to nothing but dollars. They’re just a commodity.

No wonder patients mistrust EHRs.

I hope that the government pursues a thorough investigation here. And if the government finds wrongdoing, it should show no mercy.

(Source)