Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« FTC Continues Course With More Compliance Activities and Fines: CAN-SPAM and the Adult Labeling Rule | Main | July VA Laptop Theft Was an Inside Job: Another Example of the Insider Threat »

Patient Data Theft & HIPAA Implications

Today Naples News in Florida reported:

"We often hear of Medicare fraud. We shake our head at the millions and even billions of dollars lost to bureaucratic ineptitude and theft. Then a case hits home.  A former employee of Cleveland Clinic Hospital in North Naples and a relative who worked for a Naples-based health-insurance claims company have been arrested and charged with stealing records of more than 1,100 patients.  The Cleveland Clinic receptionist had been on the job for over a year, and the theft took place in June, authorities say. Her suspicious activity was noticed by a co-worker, who alerted superiors. The arrests were made almost immediately.  Authorities so far decline to spell out exactly what the suspects and maybe others planned to do with the data, but suffice it to say that someone other than those who provided care were to get money.  The hopeful rays of light in this story are that the arrests were made so quickly and that a co-worker was empowered to come forward. A harsh light, though, is cast on the inability by law of victimized patients to sue for problems that could result from financial and other personal data falling into the wrong hands. Medical institutions can be entrusted with confidentiality, then be unaccountable for safe-keeping?  It is important for all the details on this case to come to light. The local health-care industry and its consumers stand to learn a great deal."

Some notes about the situation:

  • A coworker was alert and told management about the suspicious conduct.  Thank goodness!  This is something more companies need to encourage their personnel to do.  The amount of crime and fraud committed by trusted insiders is significant, and making all personnel aware of what to do if they see someone doing something that puts the business or health of others at risk is important to not only help catch bad things happening, but also to dissuade those considering crime from doing it if they know it is likely their coworkers will report them.
  • It seems criminal charges could and should be filed in accordance with HIPAA against the former employee and the accomplices.  Hopefully they will be.
  • I don't agree with the statement that the victims cannot sue.  I'm not a lawyer, but it seems there are certainly many ways in which civil actions could be brought against the criminals by the victims.
  • It is likely they could also bring some kind of action against the hospital.  However, any convictions would seem unlikely given the reality of the insider threat to do bad things.  From the hospital's point of view, it is important that they have a comprehensive information security and privacy program in place and are enforcing their policies.  If they have documentation to validate they did everything possible to safeguard information and a trusted employee with authorized access to PHI still committed the theft, then it would be very hard to find the hospital guilty of wrongdoing.  The insider threat is real, and the best way to protect against it in addition to a sound information security program is to raise the awareness of personnel so that you have many eyes and ears noticing and reporting if bad things are going on...not just the folks in the info sec area.

Technorati Tags







TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/185

Comments

Patients are trusting their healthcare providers with not only their health, but also the most sensitive of information. Doctors and hospitals owe it to their clients to take EVERY possible measure in order to secure personal data.
This includes taking care to install firewalls, protecting every laptop that houses patient data to make sure it is secured in case of theft, encrypting outbound email messages and employing an email anti-theft solution, such as Taceo, to protect messages and file attachments after they've been recieved.
Some safety measures might seem "extreme", but with confidential patient info, there is too much at stake to risk having a data leak.

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.