Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
25
27
28
29
1
3
5
6
7
8
11
13
15
17
18
19
20
21
22
24
25
27
28
29
31
1
2
3
4
5
3rd International conference on  Diabetes, Hypertension and Metabolic Syndrome
2020-02-24 - 2020-02-25    
All Day
About Diabetes Meet 2020 Conference Series takes the immense Pleasure to invite participants from all over the world to attend the 3rdInternational conference on Diabetes, Hypertension and [...]
3rd International Conference on Cardiology and Heart Diseases
2020-02-24 - 2020-02-25    
All Day
ABOUT 3RD INTERNATIONAL CONFERENCE ON CARDIOLOGY AND HEART DISEASES The standard goal of Cardiology 2020 is to move the cardiology results and improvements and to [...]
Medical Device Development Expo OSAKA
2020-02-26 - 2020-02-28    
All Day
ABOUT MEDICAL DEVICE DEVELOPMENT EXPO OSAKA What is Medical Device Development Expo OSAKA (MEDIX OSAKA)? Gathers All Kinds of Technologies for Medical Device Development! This [...]
Beauty Care Asia Pacific Summit 2020 (BCAP)
2020-03-02 - 2020-03-04    
All Day
Groundbreaking Event to Address Asia-Pacific’s Growing Beauty Sector—Your Window to the World’s Fastest Growing Beauty Market The international cosmetics industry has experienced a rapid rise [...]
IASTEM - 789th International Conference On Medical, Biological And Pharmaceutical Sciences ICMBPS
2020-03-04 - 2020-03-05    
All Day
IASTEM - 789th International Conference on Medical, Biological and Pharmaceutical Sciences ICMBPS will be held on 4th - 5th March, 2020 at Hamburg, Germany . [...]
Global Drug Delivery And Formulation Summit 2020
2020-03-09 - 2020-03-11    
All Day
Innovative solutions to the greatest challenges in pharmaceutical development. Price: Full price delegate ticket: GBP 1495.0. Time: 9:00 am to 6:00 pm About Conference KC [...]
Inborn Errors Of Metabolism Drug Development Summit 2020
2020-03-10 - 2020-03-12    
All Day
Confidently Translate, Develop and Commercialize Gene, mRNA, Replacement Therapies, Small Molecule and Substrate Reduction Therapies to More Efficaciously Treat Inherited Metabolic Diseases. Time: 8:00 am [...]
Texting And E-Mail With Patients: Patient Requests And Complying With HIPAA
2020-03-12    
All Day
Overview:  This session will focus on the rights of individuals to communicate in the manner they desire, and how a medical office can decide what [...]
14 Mar
2020-03-14 - 2020-03-21    
All Day
Topics in Family Medicine, Hematology, and Oncology CME Cruise. Prices: USD 495.0 to USD 895.0. Speakers: David Parrish, MS, MD, FAAFP, Alexander E. Denes, MD, [...]
International Conference On Healthcare And Clinical Gerontology ICHCG
2020-03-14 - 2020-03-15    
All Day
An elegant and rich premier global platform for the International Conference on Healthcare and Clinical Gerontology ICHCG that uniquely describes the Academic research and development [...]
World Congress And Expo On Cell And Stem Cell Research
2020-03-16 - 2020-03-17    
All Day
"The world best platform for all the researchers to showcase their research work through OralPoster presentations in front of the international audience, provided with additional [...]
25th International Conference on  Diabetes, Endocrinology and Healthcare
2020-03-23 - 2020-03-24    
All Day
About Conference: Conference Series LLC Ltd is overwhelmed to announce the commencement of “25th International Conference on Diabetes, Endocrinology and Healthcare” to be held during [...]
ISN World Congress of Nephrology 2020
2020-03-26 - 2020-03-29    
All Day
ABOUT ISN WORLD CONGRESS OF NEPHROLOGY 2020 ISN World Congress of Nephrology (WCN) takes place annually to enable this premier educational event more available to [...]
30 Mar
2020-03-30 - 2020-03-31    
All Day
This Cardio Diabetes 2020 includes Speaker talks, Keynote & Poster presentations, Exhibition, Symposia, and Workshops. This International Conference will help in interacting and meeting with diabetes and [...]
Trending Topics In Internal Medicine 2020
2020-04-02 - 2020-04-04    
All Day
Trending Topics in Internal Medicine is a CME course that will tackle the latest information trending in healthcare today.   This course will help you discuss options [...]
2020 Summit On National & Global Cancer Health Disparities
2020-04-03 - 2020-04-04    
All Day
The 2020 Summit on National & Global Cancer Health Disparities is planned with the goal of creating a momentum to minimize the disparities in cancer [...]
Events on 2020-02-26
Events on 2020-03-02
Events on 2020-03-09
Events on 2020-03-10
Events on 2020-03-16
Events on 2020-03-26
Events on 2020-03-30
Events on 2020-04-02
Events on 2020-04-03
Articles

New Hospital Breach Offers Important New Lessons

Yesterday, the Children’s National Medical Center announced yet another major security breach, this one involving Ascend, a former business associate that provided medical transcription services between May 2014 and June 23, 2014. Children’s National learned on February 25, 2016 that a misconfigured file site that contained patient information “allowed access from the Internet to transcription documents for as many as 4107 patients via a File Transfer Protocol (FTP) server from February 19, 2016 to February 25.” There are several alarming facets of this incident that underscore the complexity of today’s hospital information security environment — and they provide important lessons. A few simple observations:

Lesson 1: This is CNMC’s second data breach; the first occurred between July and December 2014 when hospital employees succumbed to phishing exploits, exposing the PHI of 18,000 patients. The hospital has been sued, which remains an ongoing disruption and huge expense. What happened to the old adage “once bitten, twice shy?” In other words, why didn’t the hospital prevent this from happening again?

The lesson: You have felt the pain, and you should figure out how to prevent a reoccurence. Your IT department and security office must make this a priority, starting with a comprehensive security assessment.

Lesson 2: This most recent breach apparently was caused by a mistake of a vendor business associate (BA). Important: the hospital’s systems were not breached by a malicious hacker or compromised by unwitting employees. Instead, this incident highlights the dangers inherent in business associate relationships and the need to manage those relationships. In many hospitals across the country, a business associate agreement is a piece of paper — not a plan that needs managing. As we reported recently from a Ponemon survey, “87% of BAs have experienced electronic data security incidents in the last two years, in contrast to 65% of healthcare providers and payors. Nearly 60% of all [BA]  participants said their incident response process had inadequate funding and resources, and the majority had not performed risk assessments.”

The lesson: Manage your business associates as diligently as Accounts Receivable manages the checks that come in the door. If you don’t, the money (and your reputation) will go right back out the door.

Lesson 3: CNMC’s latest breach occurred more than a year and a half after the business association ended. For shame.  According to CNMC, “Ascend was contractually obligated to delete all Children’s patient information.” Absolutely true, assuming the BA agreement included this requirement, and to be fair (since these agreements have a lot of boilerplate language) it probably did. But, when the agreement was signed by executives, did anyone filter this down to the rank and file to ensure deletion of PHI? Since making revenues has a higher priority than cleaning up systems post-contract, this important step probably was never taken.

The lesson: The 2013 Omnibus HIPAA regs make business associates just as financially liable for breaches as covered entities. Most BA’s don’t know this. They must be attentive to the obligations they have taken on when they are working in healthcare. Read our 7-page summary of Omnibus HIPAA and get hopping.

Another day, another security breach. I will be visiting a physician this week who undoubtedly outsources his transcription. He’s a good doctor. But will my PHI be accessible through some hole in transmission or through a vendor system? As a patient, I have to be concerned. As a healthcare IT systems consultant, I know such security compromises can be prevented. If I were a provider, I would probably have to weigh priorities such as overall patient care, budgets, board worries, staff limitations and more.

In the end everyone wants better patient care, and we have seen much improvement as a result of incorporating ingenious new IT systems. But,despite the foresight of federal HIPAA leaders, we are still putting the cart before the horse — bringing in software and hardware capabilities without adequate or well-managed data protection, and jeopardizing our own security.

To all healthcare providers, HIT vendors, payors … let’s cross the Rubicon now, before it becomes an unnavigable flood plain.

Source Medsphere