Data Breach Report Demonstrates Why Healthcare Data Encryption is Essential
The California State Attorney General has released a damming report on the state of data security in the healthcare industry, and in doing so has highlighted an essential need for the healthcare industry to encrypt patient data across all mobile devices such as laptops and Smartphones. 70% of data breaches which have affected the healthcare industry in California involved the loss or theft of portable hardware on which protected health information was stored. In other industries, breaches of this nature only accounted for 19 percent of reported breaches. The healthcare industry is particularly vulnerable due to the nature of the data stored and its value to thieves. The wide range of portable devices used in the healthcare industry also makes it an easy target for cyber criminals. According to the report, between 2012 and 2013 there were 25 data breaches affecting the healthcare industry which accounted for 15% of the total number of data breaches reported for the year and involved 1.5 million potentially compromised records. The retail industry was hit particularly hard with 43...
FTC to Address Gaps in HIPAA Regulations to Better Protect Consumers
Privacy and security are two areas of grave concern in healthcare today due to the high volume of highly personal and sensitive patient data being stored and transferred. With Apps now collecting personal information directly from consumers, The Federal Trade Commission (FTC) is likely to become more involved in security and protection of data; a role usually given to the Department of Health and Human Services. The Health Insurance Portability and Accountability Act (HIPAA) covers health tech companies and health care providers that have business relationships with each other. Many companies, software developers and tech companies are not part of the health care system and are therefore not covered under the regulations. Wearables, health apps and a host of other tech collects personal information on patients and the volume of data being collected and stored has raised serious concerns about privacy and security issues. FTC commissioner Julie Brill has recently voiced her concern on the issue. She believes that appropriate security controls and privacy protection must be enforced...
High-Tech Healthcare on the Way
And You Thought We Already Lived in a High-Tech Age? Enter any modern medical facility and you will be immediately surrounded by an assortment of high-tech gadgetry designed to make our lives easier, healthier and more secure. Much of the technological wizardry would not have been conceived a decade ago and yet now we rely on it every day to care for your young, or elderly and our sick. For many people, even when they leave a medical facility, high-tech healthcare still follows them around. It has been estimated that – by 2015 – 500 million people around the world will be using Smartphone apps to monitor weight, blood pressure, cholesterol levels, heart rate and sleep quality; and some claim apps that they are even able to detect cancer. However, not everybody is so keen to adapt to healthcare by phone and, in the same way as the Government had to “incentivize” the healthcare industry to start using EHRs, patients are now being bribed to engage in remote monitoring programs which could not only save their lives – but win them a cash prize too! Not Had a Heart...
Potential HIPAA Violations Settled by Washington County Government
HIPAA compliance is critical in healthcare; however it is not just hospitals and clinics that need to take note of HIPAA regulations. Local and county governments must also comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security and Breach Notification Rules or they face the consequences. Skagit County, Washington is paying the price for failing to implement the appropriate controls and safeguards to protect the data it held. Skagit County agreed to pay the OCR $215,000 following the exposure of data of seven individuals. Data was accessed by unknown third parties after ePHI data was unwittingly transferred to a server accessible to the public. The data breach was small but involved receipts and ePHI being made public. The investigation following the data exposure revealed numerous other HIPAA violations which potentially exposed the data of 1,581 individuals; data which included ePHI and other highly sensitive information covering the treatment, testing and management of infectious diseases. Other issues were uncovered in the...
Organizations Urged to Take Notice of HIPAA Omnibus Rule
The addition of the HIPAA Omnibus rule means organizations need to reassess their privacy and security practices to avoid a wider range of penalties for data security violations. The HHS Office for Civil Rights will start conducting random compliance audits next year and any organization found to be in breach of any HIPAA regulations will face stiff penalties. Recent audits have revealed numerous HIPAA violations which is a cause of serious concern. Many organizations have failed to implement strategies to protect data and become HIPAA compliant. If subjected to an audit, organizations must be able to produce documentation to demonstrate that appropriate efforts have been made to with regard to cybersecurity and that a compliance program has been put in place. Ignorance of current data security regulations is no defense and stiff penalties are being issued for HIPAA failures, including many the new additional penalties under the new Omnibus Rule. Fines for violations have also been increased. Under the new rule there are four areas under which a company can be fined for neglect...



