Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Another Hospital Suspends Staff For Violating HIPAA Requirements | Main | Sanctions For Ohio Breach: Lost Vacation Time, Terminations, and a "Resignation" »

HIPAA, The Insider Threat & Prison Time

It seems there are more and more stories related to patient privacy and HIPAA popping up lately. Today another story caught my eye related to them.

Joseph Nathaniel Harris, the former branch manager of the San Jose Medical Group's McKee clinic was sentenced last Friday (10/5) to "21 months in prison and three years of supervised release. Judge Jeremy Fogel also ordered him to pay $145,154 in restitution."

Harris pleaded guilty to stealing computer equipment and a DVD containing "patients' names, Social Security numbers, medical diagnoses and other information."

He reportedly also stole money and medications from the clinic, and is suspected of burglerizing the area clinics after he left his job as manager.

What is interesting is that, before he was hired as manager of the clinic, he had been

"fired from a 2003 job at the Silicon Valley Children's Fund for conducting personal business, including selling computers on Craigslist, on company time. After he was fired from that job, there was a burglary at the Children's Fund offices and two computers were stolen."

HIPAA was not mentioned in as a consideration in the charges or sentencing, but prison time is one of the possible sanctions under HIPAA.


* Organizations must be aware of the insider threat and address it with procedures, training and awareness. Background checks for positions with authorized access to sensitive information should be done if possible. Personnel should be told how to spot red flags of coworkers who may be doing bad things, and they should know how to report them.

* It will be interesting to see if the Department of Health and Human Services pursues doing an audit within the clinic to identify HIPAA violations. Considering the extent of Harris' criminal actions it looks as though the privacy and security safeguards required by HIPAA were far from being followed.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/543

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.