Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Not Enough Police To Deal With Cybercrime | Main | Sloppy Disposal Aids Cybercriminals »

Medical Identity Theft Is On The Rise

For day 2 of Global Security Week I want to highlight the growing problem of medical identity theft...

Over the past few years, the numbers of people in the U.S. who are having a hard time getting health care has grown astronomically. The answer for many who are desperate, and many who see this as an opportunity, has been to take and use the identities, and health coverage, of others. This, as a very simplistic description, is medical identity theft.

Medical identity theft is on the rise:

  • The medical identities of 250,000 to 500,000 people are stolen each year.
  • Thieves can sell identities for $5 to $50 per name.

Not only can medical identity theft impact the victims' credit reports, potentially take money from their bank accounts and have other financial impacts, it can also cause dangerous changes in the victims' medical records.

It has always been a concern of mine, and many others, that lack of security controls within computer systems, over physical files and docuuments, and lack of privacy protections can have real, physical impact upon people. For example...

  • Consider how some small modifications to the hospital databases for the amounts of medicine to administer to the patients could have insidious widespread and lethal impacts.
  • Having medical files modified and/or falsified by unauthorized persons, can then result in the real persons receiving the wrong, potentially fatal, medical treatment based upon the modifications in the records.
  • Changes to insurance billing codes can impact care that is approved or not approved to be covered by your insurance.
  • Someone else using your insurance can result in your insurance caps being maxed out, leaving you with no insurance coverage when you need it.
  • Changes to your medical files can even give you problems with getting employment, insurance and even problems with law enforcement if someone else's drug problems or abuses are put into your medical files.
  • And many more possibilities...

Medical identity theft happens more often than you may remember seeing it talked about in the news. For example, in April 2008 at the New York Presbyterian Hospital a patient admission representative accessed 49,841 patient records through the patient registration system to which he had authorized access, and then sold the records to people he reportedly knew were going to commit crimes using the information, including medical identity theft, financial identity theft and fraud.

Just a few days ago there was a very interesting interview posted on the WorldHealthcareBlog about medical identity theft; "Is that patient who he claims to be?"

Here are a few places where you can find more information about medical identity theft:

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/805

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold, CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for the past two decades. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the world's best privacy experts and on their list of the best privacy consulting firms in both 2007 and 2008. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 13th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.