Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
30
2
3
4
5
6
7
9
12
13
14
15
17
19
22
25
27
12:00 AM - HLTH 2019
28
29
30
31
1
2
3
01 Oct
2019-10-01 - 2019-10-02    
All Day
The UK’s leading health technology and smart health event, bringing together a specialist audience of over 4,000 health and care professionals covering IT and clinical [...]
08 Oct
2019-10-08 - 2019-10-09    
12:00 am
Looking to maximize the efficiency of your current Revenue Cycle solution? Join us as we present strategies for analyzing your MEDITECH Revenue Cycle, and learn from other [...]
2019 Southwest Dental Conference
2019-10-10 - 2019-10-11    
All Day
ABOUT 2019 SOUTHWEST DENTAL CONFERENCE For 91 years, the Southwest Dental Conference has been the meeting of choice for quality professional development and innovative educational [...]
Annual Conference & Exhibition Lyotalk USA 2019
2019-10-10 - 2019-10-11    
All Day
ABOUT ANNUAL CONFERENCE & EXHIBITION LYOTALK USA 2019 Lyotalk is USA’s largest annual conference on Lyophilization/Freeze Drying. Lyotalk attracts gathering from of 150+ experts from [...]
Lab Indonesia 2019
2019-10-10 - 2019-10-12    
All Day
ABOUT LAB INDONESIA 2019 LabAsia is Southeast Asia’s leading laboratory exhibition, serving as the region’s trade platform for laboratory equipment & services suppliers to engage [...]
30th International Conference on Clinical and Experimental Ophthalmology
2019-10-11 - 2019-10-12    
All Day
ABOUT 30TH INTERNATIONAL CONFERENCE ON CLINICAL AND EXPERIMENTAL OPHTHALMOLOGY The 30th International Conference on Clinical and Experimental Ophthalmology is going to be held during October [...]
7th International Conference on Cosmetology & Beauty 2019
Cosmetology and Beauty 2019 passionately welcomes each one of you to attend a global conference in the field of cosmetology which is held on October [...]
16 Oct
2019-10-16 - 2019-10-17    
All Day
ABOUT 17TH INTERNATIONAL CONFERENCE ON CANCER RESEARCH AND THERAPY Cancer Research Conference 2019 coordinates addressing the principal themes and in addition inevitable methodologies of oncology. [...]
Global Cardio Diabetes Conclave 2019
2019-10-18 - 2019-10-20    
All Day
ABOUT GLOBAL CARDIO DIABETES CONCLAVE 2019 A strong correlation between cardiovascular diseases and diabetes is now well established. The American Heart Association considers that individuals [...]
2019 Rehabilitation Medicine Society of Australia and New Zealand
2019-10-20 - 2019-10-23    
All Day
ABOUT 2019 REHABILITATION MEDICINE SOCIETY OF AUSTRALIA AND NEW ZEALAND On behalf of Rehabilitation Medicine Society of Australia and New Zealand (RMSANZ) and the organising [...]
21 Oct
2019-10-21 - 2019-10-23    
All Day
ABOUT GLOBAL CONFERENCE ON SURGERY AND ANESTHESIA (GCSA 2019) Global Conference on Surgery and Anesthesia (GCSA 2019) scheduled on October 21-23 2019 in Dubai, UAE [...]
21 Oct
2019-10-21 - 2019-10-22    
All Day
ABOUT 10TH INTERNATIONAL CONFERENCE ON MASS SPECTROMETRY AND CHROMATOGRAPHY ME Conferences is excited to announce the “10th International Conference on Mass Spectrometry and Chromatography” that [...]
MEDICAL JAPAN 2019 TOKYO
2019-10-23 - 2019-10-25    
All Day
ABOUT MEDICAL JAPAN 2019 TOKYO B to B Trade Show Covering All the Products/Services/Technologies in the Healthcare Industry! MEDICAL JAPAN TOKYO, a sister show of [...]
15th ACAM Laser and Cosmetic Medicine Conference 2019
2019-10-23 - 2019-10-25    
All Day
ABOUT 15TH ACAM LASER AND COSMETIC MEDICINE CONFERENCE 2019 As the new president of ACAM, I am delighted to welcome you all to the 15th [...]
23rd European Nephrology Conference
2019-10-24 - 2019-10-25    
All Day
ABOUT 23RD EUROPEAN NEPHROLOGY CONFERENCE Theme: The Imminent of Nephrology: Current & Advance Approaches to treat Kidney Diseases 23rd European Nephrology Conference is the world’s [...]
FNCE 2019 Food & Nutrition Conference & Expo
2019-10-26 - 2019-10-29    
All Day
ABOUT FNCE 2019 – FOOD & NUTRITION CONFERENCE & EXPO Experience dynamic educational opportunities not available elsewhere. Gain access to new trends, perspectives from expert [...]
HLTH 2019
2019-10-27 - 2019-10-30    
All Day
ABOUT HLTH 2019 HLTH is the largest and most important conference for health innovation. It’s an unprecedented, large-scale forum for collaboration across senior leaders from [...]
Events on 2019-10-01
01 Oct
Events on 2019-10-08
08 Oct
8 Oct 19
Massachusetts
Events on 2019-10-10
Events on 2019-10-18
Global Cardio Diabetes Conclave 2019
18 Oct 19
Bidhannagar
Events on 2019-10-23
Events on 2019-10-24
Events on 2019-10-26
Events on 2019-10-27
HLTH 2019
27 Oct 19
Las Vegas
Articles

New Hospital Breach Offers Important New Lessons

Yesterday, the Children’s National Medical Center announced yet another major security breach, this one involving Ascend, a former business associate that provided medical transcription services between May 2014 and June 23, 2014. Children’s National learned on February 25, 2016 that a misconfigured file site that contained patient information “allowed access from the Internet to transcription documents for as many as 4107 patients via a File Transfer Protocol (FTP) server from February 19, 2016 to February 25.” There are several alarming facets of this incident that underscore the complexity of today’s hospital information security environment — and they provide important lessons. A few simple observations:

Lesson 1: This is CNMC’s second data breach; the first occurred between July and December 2014 when hospital employees succumbed to phishing exploits, exposing the PHI of 18,000 patients. The hospital has been sued, which remains an ongoing disruption and huge expense. What happened to the old adage “once bitten, twice shy?” In other words, why didn’t the hospital prevent this from happening again?

The lesson: You have felt the pain, and you should figure out how to prevent a reoccurence. Your IT department and security office must make this a priority, starting with a comprehensive security assessment.

Lesson 2: This most recent breach apparently was caused by a mistake of a vendor business associate (BA). Important: the hospital’s systems were not breached by a malicious hacker or compromised by unwitting employees. Instead, this incident highlights the dangers inherent in business associate relationships and the need to manage those relationships. In many hospitals across the country, a business associate agreement is a piece of paper — not a plan that needs managing. As we reported recently from a Ponemon survey, “87% of BAs have experienced electronic data security incidents in the last two years, in contrast to 65% of healthcare providers and payors. Nearly 60% of all [BA]  participants said their incident response process had inadequate funding and resources, and the majority had not performed risk assessments.”

The lesson: Manage your business associates as diligently as Accounts Receivable manages the checks that come in the door. If you don’t, the money (and your reputation) will go right back out the door.

Lesson 3: CNMC’s latest breach occurred more than a year and a half after the business association ended. For shame.  According to CNMC, “Ascend was contractually obligated to delete all Children’s patient information.” Absolutely true, assuming the BA agreement included this requirement, and to be fair (since these agreements have a lot of boilerplate language) it probably did. But, when the agreement was signed by executives, did anyone filter this down to the rank and file to ensure deletion of PHI? Since making revenues has a higher priority than cleaning up systems post-contract, this important step probably was never taken.

The lesson: The 2013 Omnibus HIPAA regs make business associates just as financially liable for breaches as covered entities. Most BA’s don’t know this. They must be attentive to the obligations they have taken on when they are working in healthcare. Read our 7-page summary of Omnibus HIPAA and get hopping.

Another day, another security breach. I will be visiting a physician this week who undoubtedly outsources his transcription. He’s a good doctor. But will my PHI be accessible through some hole in transmission or through a vendor system? As a patient, I have to be concerned. As a healthcare IT systems consultant, I know such security compromises can be prevented. If I were a provider, I would probably have to weigh priorities such as overall patient care, budgets, board worries, staff limitations and more.

In the end everyone wants better patient care, and we have seen much improvement as a result of incorporating ingenious new IT systems. But,despite the foresight of federal HIPAA leaders, we are still putting the cart before the horse — bringing in software and hardware capabilities without adequate or well-managed data protection, and jeopardizing our own security.

To all healthcare providers, HIT vendors, payors … let’s cross the Rubicon now, before it becomes an unnavigable flood plain.

Source Medsphere