Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
26
27
28
29
30
31
2
3
4
5
6
7
8
9
10
8:30 AM - HIMSS Europe
11
12
13
14
15
16
17
18
19
20
21
22
26
27
28
29
1
2
3
4
5
6
e-Health 2025 Conference and Tradeshow
2025-06-01 - 2025-06-03    
10:00 am - 5:00 pm
The 2025 e-Health Conference provides an exciting opportunity to hear from your peers and engage with MEDITECH.
HIMSS Europe
2025-06-10 - 2025-06-12    
8:30 am - 5:00 pm
Transforming Healthcare in Paris From June 10-12, 2025, the HIMSS European Health Conference & Exhibition will convene in Paris to bring together Europe’s foremost health [...]
38th World Congress on  Pharmacology
2025-06-23 - 2025-06-24    
11:00 am - 4:00 pm
About the Conference Conference Series cordially invites participants from around the world to attend the 38th World Congress on Pharmacology, scheduled for June 23-24, 2025 [...]
2025 Clinical Informatics Symposium
2025-06-24 - 2025-06-25    
11:00 am - 4:00 pm
Virtual Event June 24th - 25th Explore the agenda for MEDITECH's 2025 Clinical Informatics Symposium. Embrace the future of healthcare at MEDITECH’s 2025 Clinical Informatics [...]
International Healthcare Medical Device Exhibition
2025-06-25 - 2025-06-27    
8:30 am - 5:00 pm
Japan Health will gather over 400 innovative healthcare companies from Japan and overseas, offering a unique opportunity to experience cutting-edge solutions and connect directly with [...]
Electronic Medical Records Boot Camp
2025-06-30 - 2025-07-01    
10:30 am - 5:30 pm
The Electronic Medical Records Boot Camp is a two-day intensive boot camp of seminars and hands-on analytical sessions to provide an overview of electronic health [...]
Events on 2025-06-01
Events on 2025-06-10
HIMSS Europe
10 Jun 25
France
Events on 2025-06-23
38th World Congress on  Pharmacology
23 Jun 25
Paris, France
Events on 2025-06-24
Events on 2025-06-25
International Healthcare Medical Device Exhibition
25 Jun 25
Suminoe-Ku, Osaka 559-0034
Events on 2025-06-30
Articles

Medicinal services protection criminals merit no kindness

I read with dismay yet another instance of a security breach of a provider’s electronic health record system at the hands of healthcare staff who intentionally accessed patient data for personal gain.

This time, it was a doctor and an office manager of Sight and Sun Eyeworks Gulf Breeze in Gulf Breeze, Fla., who allegedly copied all or parts of the optometry practice’s EHR system, quit their jobs with no notice, moved to a competitor, and used the patient information to market their new employer’s services, in some cases going into Sight and Sun’s EHR system to change appointments to the new employer.  Sight and Sun has notified 9,000 patients about the unauthorized access, according to the Pensacola News Journal.

This is the dark side of EHRs; such tools are at their most vulnerable when people patients entrust with their confidential information–who presumably are trained about HIPAA–take advantage of these systems, wreaking havoc in their wake.

Had these been paper records, the damage would have been less extensive. Sure, patient information still could have been stolen, but the former employees would not have been able to electronically override the scheduling information and change appointments. They also likely would not have been able to access so many records.

Sight and Sun has filed a lawsuit against the two employees–Suzanne M. Day, M.D., and Lynette Bramlett–seeking return of the data and to stop them from using it. Day and Bramlett deny wrongdoing.

This situation is bad all round, no matter how you slice it.

Sight and Sun already has suffered from the security breach, incurring the cost and negative publicity of notifying the 9,000 patients. By improperly accessing and changing appointment information, Day and Bramlett may have compromised the patient records. Other data may have been compromised, as well.  Even if the practice had been complying with HIPAA (and there appears to be some evidence to that effect), Sight and Sun still may be subject to lawsuits by patients and government investigation.

The new employer also could be in legal trouble, if it knew or supported the cybercrime. And even if it didn’t, wouldn’t it behoove the practice, receiving this influx of new patients, to at least question the new employees’ methods? Who’s supervising these people? This office also can be sued by patients for privacy violations, and investigated by the government.

If the accusations are true, Day and Bramlett may very well end up in major legal trouble for their efforts, and there’s precedent for that. Last year, Eric McNeal, a former employee of a physician’s office who pulled a similar stunt on behalf of his new employer, was sentenced to 13 months in prison, plus community service. Is the potential financial benefit in misusing records really worth that kind of cost?

The real victims, of course, are the patients, whose confidential information–including their Social Society numbers–now reside in the possession of people the patients don’t even know, exposing them to potential identity theft and the less-than-savory world of healthcare backstabbing. The patients have been reduced to nothing but dollars. They’re just a commodity.

No wonder patients mistrust EHRs.

I hope that the government pursues a thorough investigation here. And if the government finds wrongdoing, it should show no mercy.

(Source)