Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Thursday, October 21, 2010

Med students don't understand confidentiality

George Hulme of InformationWeek blogged about medical students tweeting about patients He referenced a Time article that shed more even more light on the subject.


The brunt of both articles is that medical students think what they put on their personal accounts is private. For some reason they think that walking out of the hospital and sitting at their own computer puts them outside the constraints of HIPAA. I'm here to tell them, "You are always under the constraints of HIPAA." This is even worse than the Oxford students a couple of years ago who thought they're privacy was violated when the school provost saw pictures of them acting like fools on Facebook. If you put it online, it's not private. If it's somebody else's private (especially medical) information, you're risking fines, convictions, and job or career loss.


Be careful what you put online. It will bite you in the butt.

Friday, October 8, 2010

Even the privacy breaches are bigger in Texas

Neil Versel of fiercehealthit.com reports that there have been several severe privacy violations in Texas recently. It's not bad enough that Texas apparently is a hotbed for privacy violations, but one of the major perpetrators is the Texas Department of State Health Services. Not an agency to go about (alleged) wrongdoing in a small way, the TDSHS is selling and giving away information on 27,000,000+ hospital stays since 1999. Free information is anonmized, but according to Versel those willing to pay get all kinds of interesting information.:

DSHS makes public through its website files on more than 200 kinds of information, including individuals' insurance coverage, whether the stay involved placement of a heart stent, sterilization, abortion performed due to rape and any tests or medications delivered while in the hospital.

I suddenly have a morbid curiosity to see what information is available that the doctors didn't tell us from hospital stays over the past decade.

The second big violation was CVS Caremark pharmacies. CVS Caremark has allegedly been over-reaching their authority as required by the FTC when it approved the CVS / Caremark merger and capturing patient data for marketing and other purposes in violation of HIPAA laws. They are also accused of using their position and information to squeeze smaller pharmacies out.

Our last home grown privacy violation is from former state Representative Bill Zedler (R-Arlington). Mr. Zedler used his position to get the medical board records on five doctors. At least two of those doctors contributed to his campaign - the story doesn't say if it was before or after he accessed their records.

People wonder why privacy is important, and why it's important that our personal information be kept under our control. These are the reasons why. People, government agencies, and private corporations are profiting by gathering and selling our data. It's not unrealistic to say that in some cases they know more about us than we know about ourselves. That companies can gather, categorize and analyze personal information without our knowledge or consent and sell it to others not just for a profit - but without compensation to us, is wrong. And that's why privacy and privacy protections are important.

Thursday, September 23, 2010

Study shows security of medical data improving, still bad

Earlier this year Kroll Fraud Solutions (Kroll) and Healthcare Information and Management Systems Society (HIMSS) released the results of their second biannual study of patient data safety at healthcare providers.

The study noted that there may be no other place in private industry that is as rich a target for identity theft and data fraud as healthcare providers. They can possess just about every type of identifying info on their patients: Social Security numbers, drivers license numbers, insurance policies, religious affiliation, addresses and phone numbers, etc.

According to the study there have been over 110 breaches of personal data from healthcare organizations since January 2008. The breaches have affected over 5 million people. Almost half of the of them involved employees - negligence or loss was the cause slightly more often than malicious employees. The next biggest cause of data breaches was theft, with system hacks, viruses coming in a very distant 3rd.(1)

According to the study most health organizations are taking steps to insure the security of patient data, but hospitals focus on responding to a breach to the detriment of preventing them.(2) But most hospitals are open to change and to getting help to improve their data security. Not only is the cost of a data breach high and getting higher, they don't want their customer/patients harassed or given any other reason to sue them.

Despite ever increasing regulatory requirements, or maybe because of them, the number of data breaches at hospitals in the past 24 months has increased. Part of the problem is the attitude surrounding patient data. It's not that hospitals don't want to protect their patient data, it's that their efforts since HIPAA was first passed have been geared to react to a breach, not prevent it. Until that changes we will continue to have frequent data breaches. Happily, hospitals seem willing to learn how to better protect their patients data. The only question is, how long will it take?

(1) 2010 HIMSS Analytics Report: Security of Patient Data commissioned by Kroll’s Fraud Solutions p3

(2) ibid p5