Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
28
29
30
31
1
2
3
4
5
6
9
10
12
16
17
19
22
23
27
29
30
1
10th Asian Conference on Emergency Medicine (ACEM 2019)
ABOUT 10TH ASIAN CONFERENCE ON EMERGENCY MEDICINE (ACEM 2019) It is a great pleasure and an honor to extend to you a warm invitation to [...]
APAPU SPUNZA Conference 2019
2019-11-08 - 2019-11-10    
All Day
ABOUT APAPU/ SPUNZA CONFERENCE 2019 We look forward to welcoming you to the combined APAPU/ SPUNZA meeting in Perth – the first time the event [...]
2nd World Cosmetic and Dermatology Congress
2019-11-11 - 2019-11-12    
All Day
ABOUT 2ND WORLD COSMETIC AND DERMATOLOGY CONGRESS 2nd World Cosmetic and Dermatology Congress is going to be held at Helsinki, Finland during November 11-12, 2019. International Congress on Cosmetic [...]
Global Experts Meet on Advanced Technologies in Diabetes Research and Therapy
2019-11-11 - 2019-11-12    
All Day
ABOUT GLOBAL EXPERTS MEET ON ADVANCED TECHNOLOGIES IN DIABETES RESEARCH AND THERAPY It is an incredible delight and a respect to stretch out our warm [...]
Global Congress on Cancer Immunology and Epigenetics
2019-11-13 - 2019-11-14    
All Day
ABOUT GLOBAL CONGRESS ON CANCER IMMUNOLOGY AND EPIGENETICS Epigenetics Conference, The world’s largest Epigenetics Conference and Gathering for the Research Community. Join the Global Congress [...]
Advantage Healthcare-India 2019
ABOUT ADVANTAGE HEALTHCARE-INDIA 2019 ADVANTAGES OF HEALTHCARE AND WELLNESS INDUSTRY IN INDIA: State of the art Hospitals with Excellent Infrastructure Largest pool of Highly qualified [...]
4th International Conference on Obstetrics and Gynecology
2019-11-14 - 2019-11-15    
All Day
ABOUT 4TH INTERNATIONAL CONFERENCE ON OBSTETRICS AND GYNECOLOGY Theme: Current Breakthroughs and Innovative Approaches towards Improving Women’s Reproductive HealthIt’s our pleasure to invite all the [...]
Encompass Health at AAPM&R 2019 in San Antonio
2019-11-15 - 2019-11-17    
All Day
Encompass Health at AAPM&R 2019 in San Antonio San Antonio, Texas Nov 14, 2019 11:00 a.m. CST Headed to AAPM&R’s 2019 Annual Assembly? Swing by [...]
7th Annual Congress on Dental Medicine and Orthodontics
ABOUT 7TH ANNUAL CONGRESS ON DENTAL MEDICINE AND ORTHODONTICS Dentistry Medicine 2019 is a perfect opportunity intended for International well-being Dental and Oral experts too. [...]
ABOUT MEDICA 2019
2019-11-18 - 2019-11-21    
All Day
ABOUT MEDICA 2019   MEDICA is the world’s largest event for the medical sector. For more than 40 years it has been firmly established on [...]
7th Annual Congress on Dental Medicine and Orthodontics
2019-11-18 - 2019-11-19    
All Day
ABOUT 7TH ANNUAL CONGRESS ON DENTAL MEDICINE AND ORTHODONTICS Dentistry Medicine 2019 is a perfect opportunity intended for International well-being Dental and Oral experts too. [...]
20 Nov
2019-11-20 - 2019-11-21    
All Day
  Connected Insurance: The USA’s Premier Gathering Defining the Future of Insurance Since the year 2000, 50 percent of the Fortune 500 companies have disappeared [...]
International Conference on Pathology and Infectious Diseases
2019-11-21 - 2019-11-22    
All Day
ABOUT INTERNATIONAL CONFERENCE ON PATHOLOGY AND INFECTIOUS DISEASES Infectious disease 2019 gathers the world’s leading scientists, researchers and scholars to exchange and share their professional [...]
15th Asian-Pacific Congress of Hypertension 2019
2019-11-24 - 2019-11-27    
All Day
ABOUT 15TH ASIAN-PACIFIC CONGRESS OF HYPERTENSION 2019 The Asian-Pacific Society of Hypertension will hold the 15th Asian Pacific Congress of Hypertension (APCH2019) in Brisbane, Australia, [...]
18th Annual Conference on Urology and Nephrological Disorders
2019-11-25 - 2019-11-26    
All Day
ABOUT 18TH ANNUAL CONFERENCE ON UROLOGY AND NEPHROLOGICAL DISORDERS Urology 2019 is an integration of the science, theory and clinical knowledge for the purpose of [...]
2nd World Heart Rhythm Conference
2019-11-25 - 2019-11-26    
All Day
ABOUT 2ND WORLD HEART RHYTHM CONFERENCE 2nd World Heart Rhythm Conference is among the World’s driving Scientific Conference to unite worldwide recognized scholastics in the [...]
Digital Health Forum 2019
ABOUT DIGITAL HEALTH FORUM 2019 Join us on 26-27 November in Berlin to discuss the power of AI and ML for healthcare, healthcare transformation by [...]
2nd Global Nursing Conference & Expo
ABOUT 2ND GLOBAL NURSING CONFERENCE & EXPO Events Ocean extends an enthusiastic and sincere welcome to the 2nd GLOBAL NURSING CONFERENCE & EXPO ’19. The [...]
International Conference on Obesity and Diet Imbalance 2019
2019-11-28 - 2019-11-29    
All Day
ABOUT INTERNATIONAL CONFERENCE ON OBESITY AND DIET IMBALANCE 2019 Obesity Diet 2019 is a worldwide stage to examine and find out concerning Weight Management, Childhood [...]
Events on 2019-11-07
Events on 2019-11-08
Events on 2019-11-13
Events on 2019-11-14
Events on 2019-11-15
Events on 2019-11-20
20 Nov
20 Nov 19
Chicago
Events on 2019-11-21
Events on 2019-11-24
15th Asian-Pacific Congress of Hypertension 2019
24 Nov 19
Merivale St & Glenelg Street
Events on 2019-11-26
Digital Health Forum 2019
26 Nov 19
Marinelli Rd Rockville
Events on 2019-11-28
Articles

New Hospital Breach Offers Important New Lessons

Yesterday, the Children’s National Medical Center announced yet another major security breach, this one involving Ascend, a former business associate that provided medical transcription services between May 2014 and June 23, 2014. Children’s National learned on February 25, 2016 that a misconfigured file site that contained patient information “allowed access from the Internet to transcription documents for as many as 4107 patients via a File Transfer Protocol (FTP) server from February 19, 2016 to February 25.” There are several alarming facets of this incident that underscore the complexity of today’s hospital information security environment — and they provide important lessons. A few simple observations:

Lesson 1: This is CNMC’s second data breach; the first occurred between July and December 2014 when hospital employees succumbed to phishing exploits, exposing the PHI of 18,000 patients. The hospital has been sued, which remains an ongoing disruption and huge expense. What happened to the old adage “once bitten, twice shy?” In other words, why didn’t the hospital prevent this from happening again?

The lesson: You have felt the pain, and you should figure out how to prevent a reoccurence. Your IT department and security office must make this a priority, starting with a comprehensive security assessment.

Lesson 2: This most recent breach apparently was caused by a mistake of a vendor business associate (BA). Important: the hospital’s systems were not breached by a malicious hacker or compromised by unwitting employees. Instead, this incident highlights the dangers inherent in business associate relationships and the need to manage those relationships. In many hospitals across the country, a business associate agreement is a piece of paper — not a plan that needs managing. As we reported recently from a Ponemon survey, “87% of BAs have experienced electronic data security incidents in the last two years, in contrast to 65% of healthcare providers and payors. Nearly 60% of all [BA]  participants said their incident response process had inadequate funding and resources, and the majority had not performed risk assessments.”

The lesson: Manage your business associates as diligently as Accounts Receivable manages the checks that come in the door. If you don’t, the money (and your reputation) will go right back out the door.

Lesson 3: CNMC’s latest breach occurred more than a year and a half after the business association ended. For shame.  According to CNMC, “Ascend was contractually obligated to delete all Children’s patient information.” Absolutely true, assuming the BA agreement included this requirement, and to be fair (since these agreements have a lot of boilerplate language) it probably did. But, when the agreement was signed by executives, did anyone filter this down to the rank and file to ensure deletion of PHI? Since making revenues has a higher priority than cleaning up systems post-contract, this important step probably was never taken.

The lesson: The 2013 Omnibus HIPAA regs make business associates just as financially liable for breaches as covered entities. Most BA’s don’t know this. They must be attentive to the obligations they have taken on when they are working in healthcare. Read our 7-page summary of Omnibus HIPAA and get hopping.

Another day, another security breach. I will be visiting a physician this week who undoubtedly outsources his transcription. He’s a good doctor. But will my PHI be accessible through some hole in transmission or through a vendor system? As a patient, I have to be concerned. As a healthcare IT systems consultant, I know such security compromises can be prevented. If I were a provider, I would probably have to weigh priorities such as overall patient care, budgets, board worries, staff limitations and more.

In the end everyone wants better patient care, and we have seen much improvement as a result of incorporating ingenious new IT systems. But,despite the foresight of federal HIPAA leaders, we are still putting the cart before the horse — bringing in software and hardware capabilities without adequate or well-managed data protection, and jeopardizing our own security.

To all healthcare providers, HIT vendors, payors … let’s cross the Rubicon now, before it becomes an unnavigable flood plain.

Source Medsphere