Have Your Mitigated Your Mobile Device Security Risks?
Mobile devices have potential to improve efficiency in the healthcare industry, which in turn leads to increased productivity of the workforce and a reduction in operational costs. However, tablets, Smartphones, laptops and other portable networked devices also introduce new security risks, and can potentially give hackers an easy entry point into a healthcare network. Unfortunately, banning the use of mobile devices in the workplace is no longer a feasible option. The only choice for healthcare providers and other HIPAA covered entities is to leverage the benefits of the devices, while mitigating the risks they pose, as far as is practical and possible. Mobile Devices Carry a High Risk of PHI Exposure Mobile devices carry a high risk of accidental PHI exposure. The devices can be used to connect to healthcare networks and view PHI in many cases, and data can also be stored on the devices; however since they are portable, they are also easily lost or stolen. They can also be used to connect to healthcare networks via insecure public Wi-Fi, and apps are often downloaded to...
New OCR HIPAA Penalty: Cancer Care Group to Pay $750,000
A new OCR HIPAA penalty has been issued for a breach of HIPAA regulations. Cancer Care Group, an Indiana-based radiation oncology private physician practice, has agreed to settle with the Department of Health and Human Services’ Office for Civil Rights for $750,000, for potential HIPAA violations relating to a 2012 data breach. Back in August 2012, Cancer Care Group discovered a laptop computer and unencrypted backup drive had been stolen from the vehicle of an employee. The data breach exposed the Protected Health Information of 55,000 patients. The stolen device contained highly sensitive data, which included the Social Security numbers of patients: Exactly the data needed by identity thieves to rack up tens of thousands of debts in the names of the breach victims. The data on the drives was not encrypted. HIPAA Does Not Demand Data Encryption Under the HIPAA Security Rule, data encryption is only an addressable issue. This means that a HIPAA-covered entity must consider data encryption for all PHI stored, transmitted, or backed up. A HIPAA-covered entity can make an informed...
The UCLA Health Data Breaches Continue: Further 1,242 Records Exposed
The UCLA Health data breaches are continuing: Another security incident has just been announced following the discovery that a faculty member’s laptop was stolen on July 3, 2015. UCLA Health is now in the process of notifying 1,242 patients that a limited amount of Protected Health Information was stored on the unencrypted – but password protected – laptop computer. The data potentially exposed to criminals includes patient names, medical record numbers and health information relating to treatment plans. UCLA confirmed in a press release that no Social Security numbers were stored on the laptop; neither health plan IDS, financial or insurance data; the information thieves seek in order to commit identity fraud and other financial crimes. Since the laptop was password protected the thieves may have been prevented from viewing the data stored on the device. However, passwords can be cracked, and do not offer the same level of security as data encryption so there is a risk that the data could still be viewed and used by the thieves. The healthcare provider was notified of the...
Employees’ Social Media App use makes VA Vulnerable to Data Exposure, says OIG
The VA Office of the Inspector General (OIG) has recently published the findings of its administrative investigation into improper web-based collaboration technology by the Department of Veteran Affairs (VA). It determined the agency is particularly vulnerable to data exposure from employees’ social media app use. Employee’s use of the social media application from Yammer.com could potentially result in the expose of sensitive veteran data. The OIG discovered employees have been using the social media app, even though the app had not been sanctioned by the VA. VA policy requires all social media applications to be approved before use, and have usage monitored. The OIG determined that the application “had vulnerable security features, recurring website malfunctions, and users engaged in a misuse of time and resources.” Yammer Notifier, a desktop application, was approved by one Technical Reference Model (TRM) with constraints; however use of the Yammer social network was not. The application has a lack of security controls and it was too easy for Protected Health Information...
4 out of 5 Healthcare Providers Have Been Hacked, Say KPMG
The healthcare industry is under attack. Hackers are targeting healthcare providers, insurers, and other HIPAA-covered entities for the precious data they hold, yet health firms are still unprepared to deal with the threat. The seriousness of the situation has been illustrated in a recent cybersecurity report from KPMG. The company commissioned a survey (conducted by Forbes Insights) which shows that 81% of health firms have suffered a cyberattack in the past two years, but only 53% of providers and 66% of payers consider themselves ready to defend against a cyberattack. The survey was conducted on CIOs, CTOs, and Chief Compliance Officers in healthcare organizations with revenues in excess of $500 million per annum. Healthcare providers’ and insurers’ cybersecurity measures were assessed via the questionnaire. The report shows that in spite of the increased threat to data security, healthcare organizations are ill-prepared for an attack. A quarter of respondents said their organizations were not able to detect cyberattacks in real-time, as they lacked the necessary software...



