Showing posts with label medical record privacy. Show all posts
Showing posts with label medical record privacy. Show all posts

Banking as the Standard Healthcare Should Look Up To On Medical Information Security?

At past posts "Don't Worry, Your Electronic Medical Records Are Getting Safer With Every Passing Day", "Another Episode of "But Don't Worry, Your Records are Safe..." and "Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure", "Don't Worry, Your Records are Safe - Part IV" and others, I wrote on the issue of medical record security.

Banking has been held as the standard as to which medicine has been compared, with medicine being called archaic and behind the times for its reliance on paper.  Banking security is cited as a reason why electronic medical records can also be secured.

There's this:

Fraud Ring In Hacking Attack On 60 Banks 

June 27, 2012

Some 60m euro is stolen from bank accounts in a massive cyber raid, after fraudsters raid dozens of banks around the world.

By Pete Norman, Sky News Online


Sixty million euro has been stolen from bank accounts in a massive cyber bank raid after fraudsters raided dozens of financial institutions around the world.

According to a joint report by software security firm McAfee and Guardian Analytics, more than 60 firms have suffered from what it has called an "insider level of understanding".

"The fraudsters' objective in these attacks is to siphon large amounts from high balance accounts, hence the name chosen for this research - Operation High Roller," the report said.

"If all of the attempted fraud campaigns were as successful as the Netherlands example we describe in this report, the total attempted fraud could be as high as 2bn euro (£1.6bn)."

The automated malicious software programme was discovered to use servers to process thousands of attempted thefts from both commercial firms and private individuals.

The stolen money was then sent to so-called mule accounts in caches of a few hundreds and 100,000 euro (£80,000) at a time.

Credit unions, large multinational banks and regional banks have all been attacked.

Sky News defence and security editor Sam Kiley said: "It does include British financial institutions and has jumped over to North America and South America.

"What they have done differently from routine attacks is that they have got into the bank servers and constructed software that is automated.

"It can get around some of the mechanisms that alert the banking system to abnormal activity."

The details of the global fraud come just a day after the MI5 boss warned of the new cyber security threat to UK business.

McAfee researchers have been able to track the global fraud, which still continues, across countries and continents.

"They have identified 60 different servers, many of them in Russia, and they have identified one alone that has been used to steal 60m euro," Kiley said.

"There are dozens of servers still grinding away at this fraud – in effect stealing money."

That's all very reassuring.   Let's put all of our personal medical secrets online ASAP.  Don't worry, your information's safe and secure.

-- SS


More Electronic Medical Record Breaches: You Could Not Do This With Paper

I have written repeatedly on the dangers posed by poorly managed health IT regarding information breaches.  See "2011 Closes on a Note of Electronic Medical Record Privacy Breach Shame" and other posts at this query link:   http://hcrenewal.blogspot.com/search/label/medical%20record%20confidentiality

Now this, from Kaiser Health News and The Washington Post:

As Patients' Records Go Digital, Theft And Hacking Problems Grow 
Jun 03, 2012

As more doctors and hospitals go digital with medical records, the size and frequency of data breaches are alarming privacy advocates and public health officials.

Keeping records secure is a challenge that doctors, public health officials and federal regulators are just beginning to grasp. And, as two recent incidents at Howard University Hospital show, inadequate data security can affect huge numbers of people.  

With paper, you'd need a stream of trucks to accomplish this magnitude of theft:

On May 14, federal prosecutors charged one of the hospital's medical technicians with violating the Health Insurance Portability and Accountability Act, or HIPAA. Prosecutors say that over a 17-month period Laurie Napper used her position at the hospital to gain access to patients' names, addresses and Medicare numbers in order to sell their information. A plea hearing has been set for June 12; Napper's attorney declined comment.

Just a few weeks earlier, the hospital notified more than 34,000 patients that their medical data had been compromised. A contractor working with the hospital had downloaded the patients' files onto a personal laptop, which was stolen from the contractor's car. The data on the laptop was password-protected but unencrypted, which means anyone who guessed the password could have accessed the patient files without a randomly generated key. According to a hospital press release, those files included names, addresses, and Social Security numbers -- and, in a few cases, "diagnosis-related information."

I add that they could also probably have booted the laptop from alternate media, and/or removed the hard drive and inserted into another computer, to access the contents.

Ronald J. Harris, Howard University's top spokesman, said in an e-mail that the two incidents are unrelated, but declined to answer further questions. In its press release about the stolen laptop, the hospital said it will set new requirements for all laptops used by contractors and those issued to hospital personnel to help protect data.

Still it could have been worse. Much worse.

Just days after Howard University contacted its patients about the stolen laptop, the Utah Department of Health announced that hackers based in Eastern Europe had broken into one of its servers and stolen personal medical information for almost 800,000 people -- more than one of every four residents of the state.

How many trucks (and Stargate SG-1 style invisibility cloaks) would it take to inconspicuously steal 800,000 paper charts, I ask?

And last November, TRICARE, which handles health insurance for the military, announced that a trove of its backup computer tapes had been stolen from one of its contractors in Virginia. The tapes contained names, Social Security numbers, home addresses and, in some cases, clinical notes and lab test results for nearly 5 million patients, making it the largest medical data breach since the Department of Health and Human Services began tracking incidents two and a half years ago.

Five million charts in a country of 300 million people...

As recently as five years ago, it's possible no one outside Howard University would have known about the incidents there. But, new reporting rules adopted as part of the 2009 stimulus act insure the public knows far more about medical data breaches than in the past. When a breach occurs that affects 500 or more patients, health care providers now must notify not only HHS, but also the media.

Meaning there were breaches the public does not know about.

Deven McGraw, director of the health privacy project at the Center for Democracy & Technology, a Washington-based Internet advocacy group, said the number of incidents is growing with the increased use of digital health records. The health care industry, she added, has been slow to respond.

A problem is not enough "motivation."

"Many financial companies have used encryption for years and they probably wonder what the heck is going on with the health care industry," McGraw said. "It's much cheaper to deploy safeguards than to suffer a breach."

I offer a one word answer:  complacency.

Now for the "spin control":

This growing problem puts HHS in a tough spot. It is pushing hospitals and doctors to adopt electronic health records, but it's also responsible for punishing health care providers who fail to properly secure their patients' records.

"Mistakes happen, incidents happen, corners get cut from time to time," said Susan McAndrew, deputy director for health information policy at HHS's Office of Civil Rights. "That's where we come in."

"From time to time" is a rather modest description of the millions of breaches mentioned in just this posting.

 But as I've written before, don't worry, your records are safe.

Just don't tell the doctor about that "incident" at that seedy club the other night, and find some other excuse to get the antibiotics you need, and that information will be safe, too.

-- SS

Don't Worry, Your Electronic Medical Records Are Getting Safer With Every Passing Day

At my Oct. 2011 post "Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure" and others in this query link on medical record privacy, http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy I wrote:

"Don't worry, your medical data's safe."

In Jan 2012 I then posted about Joseph Conn of ModernHealthcare.com's article "2011 Closes on a Note of Electronic Medical Record Privacy Breach Shame."

Don't worry, though; the IT industry's leader, finance, to which medicine is always compared, has gotten closer to getting the situation under control:

From MSNBC:

MasterCard, Visa confirm credit card data theft described as 'massive'
March 30, 2012
By Bob Sullivan

Law enforcement officials are investigating what appears to be a massive theft of U.S. consumers' credit card data, MasterCard and Visa confirmed Friday. The computer security expert who first reported the theft said it might involve as many as 10 million MasterCard and Visa accounts, making it one of the largest known credit card heists.

"MasterCard is currently investigating a potential account data compromise event of a U.S.-based entity and, as a result, we have alerted payment card issuers regarding certain MasterCard accounts that are potentially at risk," that association said in a statement. "Law enforcement has been notified of this matter and the incident is currently the subject of an ongoing forensic review by an independent data security organization."

The theft was first reported by well-known computer security journalist Brian Krebs on his blog, KrebsonSecurity.com. Krebs said the crime involves compromise of a credit card payment processor — a "middle man" that handles transactions between retailers and banks [like these middlemen in medicine? - ed.]

The name of that institution is unknown, but processors have long been a target of identity thieves because of the enormous amounts of data they control. In 2008, Princeton, N.J.,-based Heartland Systems was hacked, exposing tens of millions of credit card account numbers to theft.

Krebs reported that hackers had access to the unknown processors data from Jan 21 through Feb 25, and were able to siphon off enough data to easily create counterfeit cards. His sources called the leak "massive."

...
Gartner security expert Avivah Litan said she's been told that the stolen data is already being used on the street by identity thieves.

"I’ve spoken with folks in the card business who are seeing signs of this breach mushroom. Looks like the hackers have started using the stolen card data more recently," she said.


Read the whole article at the link.

Don't let this trouble you, however. The problem is getting closer to a solution with each mega-break in.

They'll have it fixed any day now, so have no fear telling your EHR-equipped doctor all your private and most sensitive medical business.

-- SS

Proposed new Consumer Privacy Bill of Rights: Is It Too Late For Healthcare?

From the White House:
http://www.whitehouse.gov/the-press-office/2012/02/23/fact-sheet-plan-protect-privacy-internet-age-adopting-consumer-privacy-b

The White House
Office of the Press Secretary
For Immediate Release
February 23, 2012

Plan to Protect Privacy in the Internet Age by Adopting a Consumer Privacy Bill of Rights

CONSUMER PRIVACY BILL OF RIGHTS

The Consumer Privacy Bill of Rights applies to personal data, which means any data, including aggregations of data, that is linkable to a specific individual. Personal data may include data that is linked to a specific computer or other device. The Administration supports Federal legislation that adopts the principles of the Consumer Privacy Bill of Rights. Even without legislation, the Administration will convene multi-stakeholder processes that use these rights as a template for codes of conduct that are enforceable by the Federal Trade Commission. These elements—the Consumer Privacy Bill of Rights, codes of conduct, and strong enforcement—will increase interoperability between the U.S. consumer data privacy framework and those of our international partners.

  1. INDIVIDUAL CONTROL: Consumers have a right to exercise control over what personal data companies collect from them and how they use it. Companies should provide consumers appropriate control over the personal data that consumers share with others and over how companies collect, use, or disclose personal data. Companies should enable these choices by providing consumers with easily used and accessible mechanisms that reflect the scale, scope, and sensitivity of the personal data that they collect, use, or disclose, as well as the sensitivity of the uses they make of personal data. Companies should offer consumers clear and simple choices, presented at times and in ways that enable consumers to make meaningful decisions about personal data collection, use, and disclosure. Companies should offer consumers means to withdraw or limit consent that are as accessible and easily used as the methods for granting consent in the first place.
  2. TRANSPARENCY: Consumers have a right to easily understandable and accessible information about privacy and security practices. At times and in places that are most useful to enabling consumers to gain a meaningful understanding of privacy risks and the ability to exercise Individual Control, companies should provide clear descriptions of what personal data they collect, why they need the data, how they will use it, when they will delete the data or de-identify it from consumers, and whether and for what purposes they may share personal data with third parties.
  3. RESPECT FOR CONTEXT: Consumers have a right to expect that companies will collect, use, and disclose personal data in ways that are consistent with the context in which consumers provide the data. Companies should limit their use and disclosure of personal data to those purposes that are consistent with both the relationship that they have with consumers and the context in which consumers originally disclosed the data, unless required by law to do otherwise. If companies will use or disclose personal data for other purposes, they should provide heightened Transparency and Individual Control by disclosing these other purposes in a manner that is prominent and easily actionable by consumers at the time of data collection. If, subsequent to collection, companies decide to use or disclose personal data for purposes that are inconsistent with the context in which the data was disclosed, they must provide heightened measures of Transparency and Individual Choice. Finally, the age and familiarity with technology of consumers who engage with a company are important elements of context. Companies should fulfill the obligations under this principle in ways that are appropriate for the age and sophistication of consumers. In particular, the principles in the Consumer Privacy Bill of Rights may require greater protections for personal data obtained from children and teenagers than for adults.
  4. SECURITY: Consumers have a right to secure and responsible handling of personal data. Companies should assess the privacy and security risks associated with their personal data practices and maintain reasonable safeguards to control risks such as loss; unauthorized access, use, destruction, or modification; and improper disclosure.
  5. ACCESS AND ACCURACY: Consumers have a right to access and correct personal data in usable formats, in a manner that is appropriate to the sensitivity of the data and the risk of adverse consequences to consumers if the data is inaccurate. Companies should use reasonable measures to ensure they maintain accurate personal data. Companies also should provide consumers with reasonable access to personal data that they collect or maintain about them, as well as the appropriate means and opportunity to correct inaccurate data or request its deletion or use limitation. Companies that handle personal data should construe this principle in a manner consistent with freedom of expression and freedom of the press. In determining what measures they may use to maintain accuracy and to provide access, correction, deletion, or suppression capabilities to consumers, companies may also consider the scale, scope, and sensitivity of the personal data that they collect or maintain and the likelihood that its use may expose consumers to financial, physical, or other material harm.
  6. FOCUSED COLLECTION: Consumers have a right to reasonable limits on the personal data that companies collect and retain. Companies should collect only as much personal data as they need to accomplish purposes specified under the Respect for Context principle. Companies should securely dispose of or de-identify personal data once they no longer need it, unless they are under a legal obligation to do otherwise.
  7. ACCOUNTABILITY: Consumers have a right to have personal data handled by companies with appropriate measures in place to assure they adhere to the Consumer Privacy Bill of Rights. Companies should be accountable to enforcement authorities and consumers for adhering to these principles. Companies also should hold employees responsible for adhering to these principles. To achieve this end, companies should train their employees as appropriate to handle personal data consistently with these principles and regularly evaluate their performance in this regard. Where appropriate, companies should conduct full audits. Companies that disclose personal data to third parties should at a minimum ensure that the recipients are under enforceable contractual obligations to adhere to these principles, unless they are required by law to do otherwise.

For an example of some of the major problems with healthcare data, see my Oct. 2009 post "Health IT Vendors Trafficking in Patient Data?"

I like the proposals.

The question is, regarding electronic health data: are these Federal proposals too little, too late?

Complex systems such as massive computer networks (with myriad stakeholders seeking to 'game' the system, skirt the boundaries of the law, and make handsome profits) can become uncontrollable.

-- SS

Perhaps Hospitals Don't Care Much That EHRs Can Be Dangerous, Because EHRs Lets them Attract 'Good Paying Customers' And Exclude the Old and Poor

This comes as no surprise to me. I believe it may help explain hospital's cavalier attitudes towards the risks of today's commercial health IT.

It's all about money.

We already knew that (for example, see my Feb. 2011 post "Does EHR-Incited Upcoding (Also Known as 'Fraud') Need Investigation by CMS, And Could it Explain HIT Irrational Exuberance?"), but the following news adds to the pecuniary motivations:

Kaiser Health News

Critics say hospitals cherry pick best-paying patients
By Phil Galewitz
KHN Staff Writer

Feb 05, 2012

When the oversized postcard arrived last August from Provena St. Joseph Medical Center promoting a lung cancer screening for current or former smokers over 55, Steven Boyd wondered how the hospital had found him.

Boyd, 59, of Joliet, Ill., had smoked for decades, as had his wife, Karol.

Provena didn't send the mailing to everyone who lived near the hospital, just those who had a stronger likelihood of having smoked based on their age, income, insurance status and other demographic criteria.

The nonprofit center is one of a growing number of hospitals using their patients' health and financial records to help pitch their most lucrative services, such as cancer, heart and orthopedic care. As part of these direct mail campaigns, they are also buying detailed information about local residents compiled by consumer marketing firms — everything from age, income and marital status to shopping habits and whether they have children or pets at home.

Hospitals say they are promoting needed services, such as cancer screenings and cholesterol tests, but they often use the data to target patients with private health insurance, which typically pay higher rates than government coverage. At an industry conference last year, Provena Health marketing executive Lisa Lagger said such efforts had helped attract higher-paying patients, including those covered by "profitable Blue Cross and less Medicare."

Not to mention helping exclude those covered by Medicaid, or the uninsured.

Strategy Draws Fire

While the strategies are increasing revenues, they are drawing fire from patient advocates and privacy groups, who criticize the hospitals for using private medical records to pursue profits.


I don't recall anywhere on the releases at area hospitals saying they would be using their own clinical data for marketing purposes (which likely involve third party contractors). It might be in the fine print, however. I also don't recall any place to sign and give informed consent to the use of experimental medical devices such as the EHR's used to collect the marketing data, either, but that's addressed elsewhere on this blog such as here.


Doug Heller, executive director of Consumer Watchdog, a California-based consumer advocacy group, says he is bothered by efforts to "cherry pick" the best-paying patients.

"When marketing is picking and choosing based on people's financial status, it is inherently discriminating against patients who have every right and need for medical information," Heller says. "This is another example of how our health system has gone off the rails."


I would go beyond "off the rails." How about, straight to perverse? EHR data is used to attract paying customers and then expose them to risk of being maimed due to the disruptive nature of the HIT itself.

Deven McGraw, director of the health privacy project at the Center for Democracy and Technology in Washington, says federal law allows hospitals to use confidential medical records to inform patients about things that may help them.

"If it's technically legal, we can do it, and who gives a damn about the ethics?" is what is being expressed here.

"You want health providers to communicate to patients about health options that may be beneficial to their health," McGraw says. "But sometimes this is about generating business for a new piece of equipment that the hospital just bought."

Using such information for marketing "creeps closer to the line," between what is legal and what is not, she says.


And helping recoup the costs of that hundred-million dollar EHR setup, too.


... Tess Niehaus, vice president of marketing at St. Anthony’s Medical Center in St. Louis, says the approach has been quite successful and makes no apologies for going after the most lucrative business.

"We are here to serve everybody but we market for good paying patients because it preserves our ability to serve everyone," she says. [And the ability to proffer generous executive salaries and raises - ed.]


"Good paying patients?" Does that imply there are bad paying patients? (Might those "bad paying patients" be predominantly the elderly and/or minorities?)

While the practice is legal, most people would be shocked to know their records may be shared with nonmedical personnel and outside firms to help hospitals attract business, says Pam Dixon, executive director of the World Privacy Forum, an advocacy group based in California. "I am really bothered by the overabundance of information that is flowing that is unnecessary and risky," she says.

As I've written before, don't worry, your most sensitive data's safe in the hands of the extremely skilled health IT professionals at most hospitals.

While hospitals may profit from offering cholesterol tests and mammograms, the big payoff is in what those screenings may lead to – additional tests and procedures, including surgery.

"It's all about downstream revenue," says Patrick Kane, senior vice president of marketing at Cape Cod Healthcare in Massachusetts who used such approaches at Wellmont Health System in Kingsport, Tenn. "The old adage in business is that it’s easier to sell an existing customer new services, rather than find a new customer."


So much for medical professionalism and conservatism. At least Mr. Kane admits it's all about money.

... Provena's Lagger says the approach boosted the system's bottom line so it could serve people regardless of insurance status. "This is a means to an end," she says.

The ends don't always justify the means, but that may be a hard concept for some in today's amoral culture to understand.

... Much of the expertise for such campaigns is provided by three consulting firms -- CPM Marketing of Madison, Wis., Medseek of Birmingham Ala. and New York-based Thomson Reuters. They typically charge hospitals $100,000 a year or more.

CPM, which merged in November with Denver, Colo.-based HealthGrades, a health ratings firm, added 100 new hospitals last year to give it a total of 400. Medseek works with more than 250 hospitals and Thomson Reuters, with 150.


Remember Darrin Stevens on Bewitched? "Larry, I've got a great idea for a new campaign! Let's troll for patients using their private data! Never mind that I have donkey ears today... that darn mother in law of mine, Endora!"

The targeting worked in the case of Boyd, who called the number on the back and scheduled the CT scan a few days later. The $169 test showed his lungs were clear, but found potential blockages in coronary arteries that his Provena-affiliated doctor is monitoring.

"In hindsight, I’m glad I had the test," he says.


No mention of patients who had unnecessary testing and interventions that led to bad outcomes ... or patients injured by the very EHR systems that make such marketing possible.

-- SS

2011 Closes on a Note of Electronic Medical Record Privacy Breach Shame

At my Oct. 2011 post "Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure" and others in this query link on medical record privacy, http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy I wrote:

"Don't worry, your medical data's safe."

Joseph Conn of ModernHealthcare.com apparently disagrees (with my sarcasm, that is) and states the obvious outright. I post his story with few comments and several emphases which are mine:

Year closes on a note of breach shame
Modern Healthcare
Dec. 2012

Three-eighty. Three-eighty. Do I hear four hundred?

With 2011 winding down, there are now 380 major data breaches involving 500 or more patients' records listed on the "wall of shame" website kept by HHS' Office for Civil Rights.

So far, from the first wall postings in September 2009 through the latest on Dec. 8 this year, there have been 18,059,831 "individuals affected," and even that massive number is an undercount of the breach problem.

First, the civil rights office hasn't yet released the records of tens of thousands of breaches it has received under a federal reporting mandate on breaches affecting fewer than 500 patients per incident. I've been asking for electronic copies of those records since June. I hope to hear soon on an appeal of a decision last fall by HHS, claiming that the civil rights office can hide those reports while it "investigates" an estimated 30,000 or more breaches they describe.

Second, even the OCR's posted numbers are low.

A Nov. 4 public notice on a breach reported by the UCLA Health System states that "some personal information on 16,288 patients" was stolen, but the wall of shame lists the "individuals affected" in the UCLA incident as 2,761.

UCLA spokeswoman Dale Tate said in an e-mail that the nearly six-times-larger number in its notice "represents the number of individuals who had some information on the hard drive," while the 2,761 figure sent to the OCR "represents the number of people that met the specific criteria" under the federal breach notification rule.

Under the federal rule, Tate says, "the information for these individuals could possibly cause more than a minimal amount of financial, reputational or other harm." Information on the rest of the individuals, Tate said, did not meet the criteria.

Not to get too harpy, but this breach stuff is long past being ridiculous.

The lawyers are already all over it, and maybe that's what it will take for the industry to finally start addressing the problem. Brian Kabateck, a California lawyer, thinks so.

In the past three months, his Los Angeles law firm has filed a pair class-action breach suits against two of the most highly regarded healthcare systems in the state, University of California, Los Angeles and Stanford, as well as one of the latter's business associates, Multi-Specialty Collection Services.

"I think this is a short blip on the radar," Kabateck said. As the settlement costs pile up, he said, "I think big institutions are going to learnfive years from now, these lawsuits are going to be obsolete."

Class-action lawsuits are needed as much for health IT risk and safety issues causing near-misses, injuries and death as for security breaches, I note.

I think five years is highly overoptimistic as well on the breach issue, considering the degree of "institutional learning" that's occurred on how to do health IT "right" over the past ~ three decades, and considering that the breaches that are increasing, not decreasing, in intensity and severity across all industry sectors. That includes industry sectors far better equipped to manage IT security than hospitals.

Right now, though, Kabateck says, "This is not to the level of being an epidemic, but it's close."

I think it is epidemic.

Rather than being a miracle that will revolutionize medicine, health IT is like any other information and communication technology (ICT): it has unintended consequences (UC's) that can dilute or even negate its advantages. The issue of damaged medical record privacy, confidentiality and security is but one UC of health IT.

-- SS

Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure

Case 1. Tumult
October 5, 2011
New York Times
Patient Data Landed Online After a Series of Missteps

By KEVIN SACK

Private medical data for nearly 20,000 emergency room patients at California’s prestigious Stanford Hospital were exposed to public view for nearly a year because a billing contractor’s marketing agent sent the electronic spreadsheet to a job prospect as part of a skills test, the hospital and contractors confirmed this week. The applicant then sought help by unwittingly posting the confidential data on a tutoring Web site. [Got all that? - ed.]

In an e-mail sent to a victim of the breach, the billing contractor, Joe Anthony Reyna, president of Multi-Specialty Collection Services in Los Angeles, explained that his marketing vendor, Frank Corcino, had received the data directly from Stanford Hospital, converted it to a new spreadsheet and then forwarded it to a woman he was considering for a short-term job.

The position was with Mr. Corcino’s one-man shop, Corcino & Associates, Mr. Reyna wrote in the e-mail, which was authenticated by his lawyer, Ellyn L. Sternfield. The job applicant apparently was challenged to convert the spreadsheet — which included names, admission dates, diagnosis codes and billing charges — into a bar graph and charts, Stanford Hospital officials said.

Not knowing that she had been given real patient data, the applicant posted it as an attachment to a request for help on studentoffortune.com [I wrote about that earlier here - ed.], which allows students to solicit paid assistance with their work. First posted on Sept. 9, 2010, the spreadsheet remained on the site until a patient discovered it on Aug. 22 and notified Stanford.

My, how electronic data can travel when mishandled. Try that trick with 20,000 paper charts ...

The hospital, located on the campus of Stanford University in Palo Alto, demanded that the spreadsheet be removed, and the Web site quickly complied. Pressed for time, the job prospect wound up completing the assignment herself and, in the end, did not get hired, Ms. Sternfield said.

Ironically, this was all for naught.

Mr. Corcino, in his first public statement, attributed the breach to “a chain of mistakes which are far too easy to make when handling electronic data.”

Far too easy to make - especially by the dyscompetent.

... Breaches of private medical data have become distressingly commonplace, with two substantial ones disclosed in the last week alone. [We don't know the details of those yet; that's for next week - ed.]

Case 2: Pandemonium
(from same NYT article)

In Orlando, officials with Florida Hospital reported that three employees had improperly combed through emergency department records of 2,252 patients, apparently to forward information about accident victims to lawyers. The employees were fired, and law enforcement officials are investigating.

Trolling for Torts - is this a new EMR TV game contestant show? Perhaps it could be followed by "Trolling for Tarts?"


Case 3: Bedlam (from the same NYT article)

Meanwhile, Science Applications International Corporation disclosed that computer backup tapes containing medical data for 4.9 million military patients [that number also amounts to almost 2% of the total U.S. population - ed.] had been stolen from an employee’s car in San Antonio. The data included Social Security numbers, clinical notes, laboratory test results and prescriptions. The company said the risk of harm was low because retrieving data from the tapes would require specialized knowledge, software and hardware. [Who's to say the theft was not by someone with that specialization, or someone paid by same to steal the tapes? - ed.]

The Texas breach is by far the largest since September 2009, when a new federal law began requiring disclosures of medical privacy violations involving at least 500 people. Some 330 such episodes have been tallied, including four others that affected more than one million people each.

We'd all be buried in stray clinical paper by now if it weren't for computers. Thank god for them!

Officials at the Department of Health and Human Services said the new reporting requirements had exposed deep vulnerabilities and encouraged renewed vigilance.

Exposed to whom? The blind, deaf and dumb?

“We’re moving in the right direction in terms of a culture of compliance,” said Leon Rodriguez, director of the department’s Office for Civil Rights, which investigates medical privacy cases. “Are there still a lot of problems out there? Yeah, my sense is there are still a lot of problems.”

The Titanic was moving in the right direction - towards New York Harbor, in fact, when it met a little unexpected obstacle. Perhaps a culture of brains would be better than a culture of compliance...

The Stanford breach was notable for the duration of public exposure, and for spotlighting the vulnerability created by a medical provider’s business relationships with outside parties.

Last week, lawyers filed suit in state court in Los Angeles, seeking certification as a class action and $20 million in damages from Stanford Hospital & Clinics and Multi-Specialty Collection Services, which is known as MSCS.

$20 million might hurt a bit, and might help motivate the organization to hire better and/or more appropriate clinical information management expertise - in house where it belongs (see below).

The threat of liability set off a predictable round of finger-pointing.

In written responses to questions, Lisa Lapin, Stanford University’s assistant vice president for university communications, said, “MSCS bears the complete and sole responsibility for the breach.”

It's their fault, not ours.

Ms. Lapin said the hospital had sent the data in encrypted form to Mr. Corcino, who requested it on behalf of MSCS to analyze a strategy for improving billing collections. She said Mr. Corcino had regularly represented himself as MSCS’s executive vice president and had been Stanford’s “primary contact” during a seven-year relationship. MSCS, a five-person firm that audits hospital accounts to maximize reimbursement, possessed the passwords to unencrypt the data, she said.

It was all about money and outsourcing.

“This mishandling of private patient information was in complete contravention of the law and of the requirements of MSCS’s contract and is shockingly irresponsible,” the hospital said in a statement.

It is foolish to believe that someone else can run critical aspects of your business, and it is even more foolish to believe that it is OK for someone else to run critical aspects of your business.

Ms. Sternfield, Mr. Reyna’s lawyer, said Mr. Corcino had never been an MSCS employee, but rather was paid a monthly fee to drum up business, typically in face-to-face meetings with health care executives. Mr. Reyna, she said, had no knowledge that the Stanford data had been sent to Mr. Corcino, or that he had passed it on.

Mr. Corcino was not authorized to use an MSCS title, Ms. Sternfield said, but she declined to say whether Mr. Reyna was aware of the practice. She acknowledged that Mr. Corcino sometimes used an MSCS e-mail account.

In his e-mail to the breach victim, who shared it with The Times, Mr. Reyna wrote that Stanford had sent the file to Mr. Corcino “for a potential MSCS project that would audit paid accounts to verify that the reimbursement was correct.”

For his part, Mr. Corcino said in a statement that he was an independent contractor but was “the marketing face of the company,” and that MSCS “allowed me to use the title of executive vice president.” He wrote: “Stanford sent the file to me at MSCS, and I imported the data into a spreadsheet that was forwarded to the job applicant as part of a skills test. I did not intend to provide any personal health information in the file. This was a marketing project.”

Without explaining how or why he sent the data to the applicant, Mr. Corcino said MSCS had not trained him properly and faulted Stanford for sending him private information that he did not need. That, he said, was the “first link in a chain of mistakes.”

“I regret that Stanford released a file containing unnecessary information,” Mr. Corcino said, “that MSCS did not have an appropriate training and audit system for the handling of electronic data and that I was not more careful with the file. While Stanford and MSCS left the information in the file I received, it was my mistake to not catch its inclusion and remove the data.” ... The hospital has terminated its relationship with MSCS, and Mr. Reyna has done the same with Mr. Corcino.

Even I can't follow all that. This will be one convoluted court case...

Stanford Hospital has reassured affected patients that the posted spreadsheet did not contain Social Security numbers, birthdates or credit card numbers, and has offered free identity theft protection services. The hospital said it had not uncovered any misuse of the exposed data.

Yet, that is. (Is it no wonder that sedatives are among the most highly-prescribed medications?)

Moving from the NYT article:

Case 4: Tumult (I'm running out of descriptors)

A large class action lawsuit again Health Net and IBM:

California Legal
Westlaw Journal Insurance Coverage

Health Net’s, IBM’s negligence compromised medical data, suit says

June 7 (Westlaw Journals) - Health Net Inc. and IBM face a class-action lawsuit seeking $5 million in damages over the loss of computer storage devices that held the medical histories, financial data and Social Security numbers of 2 million people.

Health Net Policyholder Alana Bournas’ class-action complaint in the U.S. District Court for the Eastern District of California alleges that the insurer and IBM breached their duty of confidentiality and negligently allowed the release of highly personal and confidential information of millions of Health Net employees and policyholders.

The complaint alleges violation of California’s Confidentiality of Medical Information Act, Cal. Civ. Code § 56; Cal. Civ. Code § 1798.2, which concerns the unauthorized disclosure of customer records; Cal. Bus. & Prof. Code § 17200, the state’s unfair-competition law; and public disclosure of private facts.

Companies will either pay the going price for competent employees, or pay for the mistakes of incompetent ones. It would probably be better for society, however, to do the former habitually.

The suit says IBM agreed to manage Health Net’s information technology database for five years beginning in 2008.

IBM informed Health Net Jan. 21 that it had lost nine disk drives containing the confidential information of 2 million people, including Health Net policyholders and employees.

Health Net failed to alert the victims of the breach until March 14, the complaint says.

IBM allegedly also failed to encrypt the data, thereby enabling anyone who possesses the hard drives to easily access the confidential information. This puts the victims at an increased risk of identity theft and “other unauthorized uses of plaintiff and class members’ personal information” the suit says.

Encryption, a feature now built into mainstream OS's by Microsoft and Apple? (Oh wait...IBM...)

Health Net’s attempt to compensate the victims by providing two years of free credit monitoring services through TransUnion is an inadequate remedy for the defendant’s conduct, Bournas says. This “remedy” fails to address unauthorized disclosures of medical information, and the monitoring services only protect against new account fraud but do not address fraudulent activity with existing accounts, the suit says.

These executives apparently can't even get the fix straight.

Moreover, the complaint says, Health Net has previously been accused of a similar breach of confidential information. In 2009 it lost the same types of records of nearly 1.5 million people and waited six months before notifying the victims. In settling the state of Connecticut’s lawsuit stemming from that security breach, the company promised “to enhance security procedures and training,” the suit says.

What can I say?

The current breach could have been avoided had Health Net and IBM taken proper precautions and implemented security policies to maintain consumers’ confidential data, according to Bournas. Therefore, the protections granted under California law require that Health Net be penalized for its negligence, she says.

The plaintiff notes that millions of people entrusted Health Net with their private data.

“At best, defendants’ actions allowed this private information to go astray. At worst, the private information is being viewed, sold, resold, and used for illegitimate and illegal purposes,” the complaint says.

The suit is seeking injunctive relief, compensatory damages, declaratory relief, and attorney fees and costs.

Bournas v. Health Net Inc., No. 2_11-CV-01262, complaint filed (E.D. Cal. May 11, 2011).

I would revise that to say "The current breach could have been avoided had Health Net and IBM hired personnel in adequate numbers with the qualifications and true gravitas (and not laid them off, of course) to maintain consumers’ confidential data."

Case 5: Maelstrom (I am reaching to the bottom of the barrel for such descriptors).

Wellpoint recently settled class-action suit in CA.

AMA news
By Pamela Lewis Dolan, amednews staff.
Posted Aug. 1, 2011.

WellPoint reaches tentative accord in data breach suit

It is the second settlement to come from lawsuits claiming that the company failed to protect the privacy of individual insurance applicants online.

WellPoint has reached a preliminary settlement that will, if approved, bring an end to a class-action lawsuit filed more than a year ago.

The lawsuit, filed in the Superior Court of the State of California, involves the potential exposure of data belonging to more than 600,000 individual health insurance applicants on a company-run website that allowed insurance applicants to track their applications.

The situation came to light when an applicant to WellPoint-owned Anthem Blue Cross of California sued the company in March 2010. The applicant was able to manipulate the web address within the site to gain access to other applicants' information, including names, addresses, dates of birth, Social Security numbers and health and financial information.

In other words, probably changing a simple number in the URL brought up someone else's records. Good going there, Wellpoint. What were the programmers thinking? (Were they thinking?)

When the suit was filed, the company said an upgrade to the system caused the information to become exposed. The company said a third-party vendor validated that all security measures were in place when, in fact, they were not. Changes were made to the system soon after the situation was discovered.

Blame someone else, yet again.

In addition to the class-action suit, the company was sued by Indiana Attorney General Greg Zoeller in July 2010. The suit, filed in Marion County Civil Superior Court, alleged that the company violated the Indiana Disclosure of Security Breach Act by failing to notify Zoeller, and the 32,051 Indiana residents affected by the incident, in a timely manner. That suit was settled in early July, when WellPoint agreed to pay a $100,000 fine. As part of the settlement, WellPoint admitted it had a security breach and failed to properly notify the attorney general's office as required by law.

Gevalt.

Under the preliminary settlement in the California class-action matter, WellPoint agreed to offer credit monitoring for two years to all affected individuals. Class members are eligible to receive reimbursement for identity theft losses of up to $50,000 per incident, as well as additional time to file identity theft claims until May 31, 2016. Those making identity theft claims are eligible for an additional five years of credit monitoring. The company also will donate a total of $250,000 to two nonprofit organizations whose efforts are directed at protecting consumers' privacy on the Internet.

It might have been cheaper and better for goodwill not to outsource a vital function...those third-party vendors can really hurt you. (I'd really like to know - was this "third party vendor" domestic, or overseas?)

WellPoint did not admit wrongdoing in the case, nor was it found guilty. A fairness hearing is scheduled for November, and the courts then will decide whether to approve the settlement.

Large corporations are immune from such formalities as admitting wrongdoing or being found guilty.

-----------------------

But don't worry. Your medical data's safe.

Sort of. See also:


-- SS

HHS rule would give government everybody’s health records?

I really don't like the sound of this in the Washington Examiner. It contains many warnings of the kind I've written about here at HC Renewal regarding EHR systems, data privacy, confidentiality and security, coding madness, and (especially in the proposed rule) computational alchemy - a belief that one can turn unreliable data into "gold":

HHS rule would give government everybody’s health records
By: Rep. Tim Huelskamp
09/23/11 3:29 PM
OpEd Contributor

It’s been said a thousand times: Congress had to pass President Obama’s health care law in order to find out what’s in it. But, despite the repetitiveness, the level of shock from each new discovery never seems to recede.

This time, America is learning about the federal government’s plan to collect and aggregate confidential patient records for every one of us.

In a proposed rule from Secretary Kathleen Sebelius and the Department of Health and Human Services (HHS), the federal government is demanding insurance companies submit detailed health care information about their patients.

(See Proposed Rule: Patient Protection and Affordable Care Act; Standards Related to Reinsurance, Risk Corridors and Risk Adjustment, Volume 76, page 41930. Proposed rule docket ID is HHS-OS-2011-0022 http://www.gpo.gov/fdsys/pkg/FR-2011-07-15/pdf/2011-17609.pdf)

The HHS has proposed the federal government pursue one of three paths to obtain this sensitive information: A “centralized approach” wherein insurers’ data go directly to Washington; an “intermediate state-level approach” in which insurers give the information to the 50 states; or a “distributed approach” in which health insurance companies crunch the numbers according to federal bureaucrat edict.

It’s par for the course with the federal government, but abstract terms are used to distract from the real objectives of this idea: no matter which “option” is chosen, government bureaucrats would have access to the health records of every American - including you.

There are major problems with any one of these three “options.” First is the obvious breach of patient confidentiality. The federal government does not exactly have a stellar track record when it comes to managing private information about its citizens.

Why should we trust that the federal government would somehow keep all patient records confidential? In one case, a government employee’s laptop containing information about 26.5 million veterans and their spouses was stolen from the employee’s home.

There's also the HHS contractor who lost a laptop containing medical information about nearly 50,000 Medicare beneficiaries. And, we cannot forget when the USDA's computer system was compromised and information and photos of 26,000 employees, contractors, and retirees potentially accessed. [I've written about this issue frequently on this blog - ed.]

The second concern is the government compulsion to seize details about private business practices. Certainly many health insurance companies defended and advocated for the president’s health care law, but they likely did not know this was part of the bargain.

They are being asked to provide proprietary information to governments for purposes that will undermine their competitiveness. Obama and Sebelius made such a big deal about Americans being able to keep the coverage they have under ObamaCare; with these provisions, such private insurance may cease to exist if insurers are required to divulge their business models.

Certainly businesses have lost confidential data like the federal government has, but the power of the market can punish the private sector. A victim can fire a health insurance company; he cannot fire a bureaucrat.

What happens to the federal government if it loses a laptop full of patient data or business information? What recourse do individual citizens have against an inept bureaucrat who leaves the computer unlocked? Imagine a Wikileaks-sized disclosure of every Americans’ health histories. The results could be devastating - embarrassing - even Orwellian.

With its extensive rule-making decrees, ObamaCare has been an exercise in creating authority out of thin air at the expense of individuals’ rights, freedoms, and liberties.

The ability of the federal government to spy on, review, and approve individuals’ private patient-doctor interactions is an excessive power-grab.

Like other discoveries that have occurred since the law’s passage, this one leaves us scratching our heads as to the necessity not just of this provision, but the entire law.

The HHS attempts to justify its proposal on the grounds that it has to be able to compare performance. No matter what the explanation is, however, this type of data collection is an egregious violation of patient-doctor confidentiality and business privacy. It is like J. Edgar Hoover in a lab coat.

And, no matter what assurances Obama, Sebelius and their unelected and unaccountable HHS bureaucrats make about protections and safeguards of data, too many people already know what can result when their confidential information gets into the wrong hands, either intentionally or unintentionally.

Republican Tim Huelskamp represents the first congressional district of Kansas.

While the word "de-identified" is in the proposed rule, I don't have great confidence in such assurances (for instance, see my Oct. 2009 post "Health IT Vendors Trafficking in Patient Data?").

I don't believe additional commentary is needed.

Hat tip - Drudge Report.

-- SS

Another Episode of "But Don't Worry, Your Records are Safe..."

Oops!

NHS trust sends data CD to landfill

By Wesley Johnson

Friday, 16 September 2011

The personal information of 1.6 million people has been put at risk after a CD was sent to a landfill site by an NHS trust by mistake, a watchdog said.

The Eastern and Coastal Kent Primary Care Trust put the CD, which contained the name, address, date of birth, NHS number and GP of about 1.6 million people, in a filing cabinet during an office move.

But no one told staff who sent the cabinet to the landfill site and it has not been recovered, the Information Commissioner's Office said.

... An undertaking signed by the trust's chief executive Ann Sutton read: "The Information Commissioner was provided with a report by the data controller informing that a filing cabinet containing personal data had been sent to landfill during a move of office premises.

"The filing cabinet contained a CD holding the address, date of birth, NHS number and GP practice code of approximately 1.6 million individuals.


Read the whole article. They promise to be more careful - next time.

The trust said it would now take action to bring in clear policies and procedures for when moving office, improve staff training and boost security against unauthorised and unlawful processing, accidental loss, destruction and damage of personal records.

That is reassuring - I guess.

-- SS

New way to get kids interested in medicine: post confidential medical records on a homework site?

Was this a new way to get kids interested in medical careers?

Or was it an accident due to the highest levels of negligence associated with lowest/cheapest standards in hiring for mission critical roles?

Patient Data Posted Online in Major Breach of Privacy
New York Times
Sept. 8, 2011
Kevin Sack

A medical privacy breach at Stanford University’s hospital in Palo Alto, Calif., led to the public posting of medical records for 20,000 emergency room patients, including names and diagnosis codes, on a commercial Web site for nearly a year, the hospital has confirmed.

Since discovering the breach last month, the hospital has been investigating how a detailed spreadsheet made its way from one of its vendors, a billing contractor identified as Multi-Specialty Collection Services, to a Web site called “Student of Fortune,” which allows students to solicit paid assistance with their school work. Gary Migdol, a spokesman for Stanford Hospital and Clinics, said the spreadsheet first appeared on the site on Sept. 9, 2010, as an attachment to a question about how to convert the data into a bar graph.


To teach the kids to be medical bean counters at an early age, perhaps?


Even as government regulators strengthen oversight by requiring public reporting of breaches and imposing heavy fines, experts on medical security said the Stanford incident spotlights the persistent vulnerability posed by legions of outside contractors who gain access to private data.


In the Oct. 2009 post "Private medical records offered for sale" I wrote about how such data was for sale by onion-like layers contractors - cheap.


The spreadsheet contained names, diagnosis codes, account numbers, admission and discharge dates, and billing charges for patients seen at Stanford Hospital’s emergency room during a six-month period in 2009, Mr. Migdol said. It did not include Social Security numbers, birthdates, credit-card accounts or other information used to perpetrate identity theft, he said, but the hospital is offering free identity protection services to affected patients.


(Partial) luck prevailed - this time.


The breach was discovered by a patient and reported to the hospital on Aug. 22, according to a letter written four days later to affected patients by Diane Meyer, Stanford Hospital’s chief privacy officer. The hospital took “aggressive steps,” [i.e., its CIO made a quick, panicky phone call - ed.] and the Web site removed the post the next day, Ms. Meyer wrote. It also notified state and federal agencies, Mr. Migdol said.


Perhaps "aggressive steps" should have been taken before private medical data was published on a kid's homework site?


It is clearly disturbing when this information gets public,” he said. “It is our intent 100 percent of the time to keep this information confidential and private, and we work hard every day to ensure that.”

Would "Master of the Obvious" (a favorite line of my early medical mentor, cardiothoracic surgeon/polymath Dr. Victor P. Satinsky, be too kind a response to this statement?


Diane Dobson, of Santa Clara, Calif., said her “jaw dropped” on Saturday when she intercepted the letter from Ms. Meyer addressed to her 21-year-old son, who she said received emergency psychiatric treatment at Stanford in 2009. Ms. Dobson said it could have been disastrous if her son, who lives at home, had learned that his name was linked online to a diagnosis for psychosis.

“My son, I can tell you, is fragile and confused enough that this would have sent him over the edge,” Ms. Dobson said. “Everyone with an electronic medical record is at risk, and that means everyone.”


My sympathies go out to this mother and her son. Her concerns show that cavalier attitudes towards EMR's can lead to catastrophe beyond identity theft or career damage.


The incident at Stanford, while egregious in its details, is far from rare. Records compiled by the Department of Health and Human Services reveal that personal medical data for more than 11 million people has been improperly exposed during the last two years alone ... The major breaches — a disconcerting log of stolen laptops, hacked networks, unencrypted records, misdirected mailings, missing files and wayward e-mails — took place in 44 states.


I'm certain there is an increasing amount of critical medical data being withheld by patients as publicity about these breaches become more well-known.


The breaches at Stanford reinforce that even the most prestigious medical centers are not immune to risk.

Massachusetts General Hospital in Boston, which trains Harvard medical students, agreed this year to pay a $1 million federal fine after an employee left paper medical records on a subway train while commuting to work. The pages contained the names of 192 patients, and diagnoses for about a third of them, including for H.I.V./AIDS. They were never recovered.


I note these are both pioneers in electronic health records. Imagine what might be happening at Podunk Hollow General Hospital...


Mr. Migdol said the hospital had concluded that “there is no employee from Stanford Hospital who has done anything impermissible.” He said he expected the federal Department of Health and Human Services to conduct its own investigation. Susan McAndrew, deputy director of health information privacy for the department’s Office of Civil Rights, said she could not discuss whether an investigation was in progress ... Bryan Cline, a vice president with the Health Information Trust Alliance, a nonprofit company that establishes privacy guidelines for health care providers, said that nearly 20 percent of breaches were perpetrated by outside contractors, accounting for more than half of all the records exposed.


When you start to outsource mission critical data, you should probably be prepared to take responsibility for whomever you outsource it to.


The vendor, identified by Mr. Migdol as Multi-Specialty Collection Services LLC, based in Los Angeles, could not be reached for comment. Mr. Migdol said the company created the spreadsheet as part of a billing-and-payment analysis for the hospital. He said the hospital immediately suspended its relationship with the contractor and received written certification that previous files would be destroyed or returned securely.


Apparently someone there with access to the spreadsheet was less than careful about keeping it away from children. One wonders if they would have been more careful with pornography...


“We’re still kind of caught in the pre-high-tech trust model instead of the insurance model,” Mr. Cline said. “Health care providers say, ‘I’m going to have some contract language and then just trust that you’ll protect my data because if you don’t I’m going to sue you.’ That just doesn’t work, as we can see. You have to do due diligence, something to assure yourself that the people you’re giving your data to can be trusted.”


I'd say we're still in the stone age with respect to our irrational exuberance about health IT. See my series of articles on these issues at these query links: computer security, medical record privacy, medical record confidentiality.

A fundamental set of rules in today's hire-on-the-cheap, keep-staffing-minimal environment is this:

1. If you want information to be kept secure, don't place it on a computer.
2. If you place the information on a computer, don't place the computer on a network.
3. If you place the computer on a network, the information is no longer secure.

In our current culture I do not believe these issues to be easily remediable, but hiring the truly best and brightest (after satisfactory scores in a very hard test in critical thinking skills) into IT roles - including design, implementation, and management - might be a start.

-- SS

Blogscan: UK unencrypted laptop health breach affects more than 8.6 million records

From the blog "Australian Health Information Technology":

Who Needs Hackers When There Are Accidents Like This? The PCEHR [Personally Controlled Electronic Health Record - ed.] Won’t Avoid Hacker Attention I Suspect.

The following popped up a little while ago.

By Dom Nicastro

Think the United States has its problems with securing patient health information?

We’re not alone.

London Health Programmes, a medical research organization based at the NHS North Central London health authority, has reported missing an unencrypted laptop containing information of 8.63 million patients and 18 million hospital visits, operations and procedures, according to today’s issue of The Sun.

The data does not include names, “but patients could be identified from postcodes and details such as gender, age and ethnic origin,” according to the newspaper. Information on the laptop included records of cancer, HIV, mental illness and abortions.

The computer was one of 20 lost, and officials have since recovered eight. The research organization “only just” reported the missing laptops to police although they went missing three weeks ago, according to the newspaper.

The Information Commissioner’s Office, Great Britain’s independent authority that promotes data privacy for individuals, has issued a statement regarding the laptop theft:

“Any allegation that sensitive personal information has been compromised is concerning and we will now make inquiries to establish the full facts of this alleged data breach.”

More here with a gruesome list of UK breaches.

http://blogs.hcpro.com/hipaa/2011/06/unencrypted-laptop-health-breach-affects-more-than-8-million-records/

Clearly this sort of incident is made more significant when material like this is appearing regularly.


We've posted numerous times at Healthcare Renewal on the impossible dream of electronic medical record privacy, security and confidentiality. See blog query links here and here.

-- SS

Another Blow to the Health IT Idealists: Sony CEO Howard Stringer, and HHS OIG, on Information Security

In a series of Healthcare Renewal posts such as those linked below, I pointed out that healthcare IT information security was largely a pipe dream, and that plans to create a national network of health information, while a seductive idea dating to the beginnings of computer networking, is not a good idea now.


Now you can hear it from another source: The CEO of one of the world's largest electronic companies, Sony.

Emphases mine:

Sony CEO Warns of 'Bad New World'
Wall Street Journal
May 8, 2011

TOKYO—After spending weeks to resolve a massive Internet security breach, Sony Corp. Chief Executive Howard Stringer said he can't guarantee the security of the company's videogame network or any other Web system in the "bad new world" of cybercrime.

Mr. Stringer's comments in a phone interview Tuesday, ahead of a New York roundtable discussion with reporters, come on the heels of a trying month for Sony. The company partially restored two of its online game systems and a streaming movie and music service over the weekend after shutting the services for several weeks when a breach compromised the personal information of more than 100 million account holders.

While Sony has restored part of the PlayStation Network—an online game system for its PlayStation 3 videogame console—in the U.S. and Europe and bolstered security measures, Mr. Stringer, 69 years old, said maintaining the service's security is a "never-ending process" and he doesn't know if anyone is "100% secure."

He said the security breach at PSN, Sony Online Entertainment, an online game service for personal-computer users, and its Qriocity streaming video and music network his company could lead the way to bigger problems well beyond Sony, or the gaming industry. He warned hackers may one day target the global financial system, the power grid or air-traffic control systems. [And healthcare, where identity theft, data alteration, and data destruction might occur - ed.]


I really don't think this is the time to be setting up a national health information network.

Beyond that, I offer no additional comments, other than that regarding the impossibility of keeping healthcare information secure on a national or even regional network, you may have heard it first here at Healthcare Renewal.

It would be prudent and consistent with the Hippocratic Oath to tone down our grandiose expectations and grandiose plans for these technologies in healthcare.

If you feel insecure yet, just wait a moment.

Going from very, very bad to very much worse:


An independent audit of ONC's and CMS's security programs by the HHS OIG (Office of the Inspector General) produced concerning if not alarming results to say the least:

Federal Audits Find HIT Security Problems at CMS, ONC
John Commins, for HealthLeaders Media
May 18, 2011

Audits of the federal agencies charged with implementing and monitoring security measures for healthcare information technology identified this week lax oversight and insufficient standards for healthcare providers.


The audits were conducted by the Department of Health and Human Services' Office of Inspector General, and targeted HIT security standards, privacy protection under HIPAA, and other security measures at the Centers for Medicare & Medicaid Services, and the Office of the National Coordinator. "
These two reports are being issued simultaneously because OIG found weaknesses in the two HHS agencies entrusted with keeping sensitive patient records private and secure," OIG said in a media release.

The CMS audit,
Nationwide Rollup Review of the Centers for Medicare & Medicaid Services Health Insurance Portability and Accountability Act of 1996 Oversight, examined seven hospitals across the country and found 151 "vulnerabilities" in systems and controls that are designed to safeguard electronic protected health information.

Those lapses included 124 "high impact vulnerabilities" such as
unencrypted laptops and portable drives containing sensitive personal health information, outdated antivirus software and patches, unsecured networks, and the failure to detect rogue devices intruding on wireless networks, the OIG audit said.

"These vulnerabilities placed the confidentiality, integrity, and availability of ePHI at risk. Outsiders or employees at some hospitals could have accessed, and at one hospital did access, systems and beneficiaries' personal data and performed unauthorized acts without the hospitals' knowledge," the OIG audit said. "As a result, CMS had limited assurance that controls were in place and operating as intended to protect electronic protected health information, thereby leaving ePHI vulnerable to attack and compromise.


OIG's Audit of Information Technology Security Included in Health Information Technology Standards examined ONC's mandate under the HITECH Act to develop HIT security as part of a national HIT interoperability infrastructure. The audit found "no HIT standards that included general information IT security controls … which provide the structure, policies, and procedures that apply to a healthcare provider's overall computer operations, ensure the proper operation of information systems [which obviously also impacts patient safety - ed.], and create a secure environment for application systems and controls.


That's not very reassuring. In fact, it is downright frightening. ONC has to learn such lessons from HHS OIG? Read the whole thing.

I somewhat mordantly note that organizations such as ONC and CMS would probably never hire a person like me, who might actually kick-start true critical thinking on these issues. This is due to my non-bien pensant "bad attitudes", and lack of faith in cybernetic idols.


Click to enlarge. A well-known idol of gold. Computer circuits use gold, no?

-- SS


EHR as Molestation Candidate Selector: What was this Resident looking for in the EHR before "examining" female patients?

As I was the Director of Clinical Informatics/CMIO (Chief Medical Informatics Officer) at Christiana Care Health System in Delaware back in the mid to late 1990's, and was the physician-architect of their EHR systems then, I find this story particularly disturbing:

First-Year Resident Accused Of Fondling 6 Patients
FoxPhilly.com, Feb. 18, 2011

Warrants Issued, Police Searching For Suspect

NEWARK, Del. - Delaware State Police are trying to find a former first-year resident at Christiana Hospital who they have identified as a suspect in alleged sexual contact with six patients.

According to state police, [the former Medical Resident] has been charged with six counts each of third-degree unlawful sexual contact and abuse, mistreatment or neglect of a patient or resident of a facility.

... The incidents were reported between Oct. 1 and Nov. 15 at the hospital in Newark.

The female patients were between the ages of 20 and 32, police said.

Authorities interviewed victims and hospital staff, reviewed patient charts, and audited access to computer records, which led to the identification of [the Resident] as a suspect, according to state police.

... State police said investigators found [the Resident] accessed the computerized hospital records of the six victims prior to the incidents
, performed "physical exams" on the victims and failed to provide clinical documentation of the examinations in the victims' hospital charts. Scheduling records also indicated that [the Resident] was working when the incidents occurred.

... In three of the incidents, it was determined that the victims were identified as "non- teaching" patients for whom [the Resident] had no direct patient care responsibilities and had no authority to conduct physical exams or access their hospital records.

Also noted in another account of the story in the Delaware News Journal (a newspaper) is this:

... State police initially released details about three of the assaults on Nov. 12 and said at the time that they were investigating why hospital officials did not report the incidents to police until after the third assault, some two weeks after the first victim reported the incident to hospital staff.

During the subsequent police investigation, three additional women contacted state police to report similar incidents.

One could ask, then, why the Medical Resident was able to access these medical records, and why the unauthorized accesses apparently took some time to discover by "investigators" (presumably law enforcement officers), only after complaints were made.

It is also reasonable to assume this Resident did not abuse the first woman's records he found in a search. There was likely a larger series of unauthorized chart accesses as he searched the EMR system. In other words, I don't think he was peeking at an individual record, and then going in to a room to do his nasty work, one at a time. He was likely looking at a number of potential "candidates" before each incident; i.e., he was likely "trolling around" for potential victims.

It would be interesting to see the electronic "footprint" he left.

I had horrifying firsthand experience with abuse of electronic medical information in an earlier role in the public sector.

Specifically, I had observed the events in John Doe vs. the Southeastern Pennsylvania Transportation Authority (link). In this situation a gay co-worker, the SEPTA Employee Assistance Program liaison John Eakes (now deceased of AIDS) with whom I had worked extensively in the SEPTA Medical Department, was discriminated against by administration after peeks at his prescription records. His medications included those used in treating HIV-positive patients:

...[After the disclosure to SEPTA Chief Administrative Officer (and Deputy General Manager - ed.) Judith Pierce, Doe - a.k.a. Eakes] testified that he felt as though he were being treated differently. A proposal he had made for an in-house employee assistance program met with scant interest; he felt that this was because of his HIV condition. In addition, an administrator who reported to Pierce did not call on Doe to assist in the same way that he had called on Doe earlier. Doe testified that he felt as though there was less social chitchat, co-workers ate less of the baked goods he brought to the office to share, and that his work space seemed more lonely than before. He also became fearful of Pierce, who never told Doe that she knew of his illness. Doe alleges that he became depressed and requested a prescription for Zoloft, an antidepressant, from his physician. Later, another antidepressant called Elavil was added to the medications Doe was taking.

John Eakes was a good and conscientious employee and deserved none of this, in these relatively early years of HIV+ intolerance.

Therefore, when I was CMIO at Christiana Care Health System just a few years later, and as Chair of the committee on compliance with the then-new Health Insurance Portability and Accountability Act of 1996 (HIPAA), I recommended strongly that chart audits for unauthorized access be performed on a regular basis by a dedicated person or team, and rapid action taken if it occurred. (Then again, my counsel on healthcare IT was not infrequently ignored.)

Multiple accesses by a resident (trainee) to EHR records of non-teaching (private) patients should have sent up a very large and immediate cybernetic red flag.

Ding! Ding! Ding! Warning! Unauthorized accesses detected...

I am also concerned about the characteristics this former trainee was seeking in reviewing the EHR. A history of gynecological or breast disease to serve as a ploy for performing an intrusive exam? Was he looking for a psychiatric history? A history of prior sexual abuse?

While the EHR proved helpful in post hoc forensics, are we now seeing another potential abuse of EHR's for the identification of patients who may be preyed upon by the disturbed?

It would be helpful to know if there was a common medical theme regarding the patients affected in this rather shocking affair.

-- SS

Feb. 19 Addendum:

This affair reminds me of a saying that became news in the election of President Barack Obama:

"The Chickens Have Come Home To Roost" - Rev. Jeremiah Wright

Feb. 21 Addendum:

It appears that the corporate PR folks are monitoring the airwaves in planning their responses to this scandal. From the blog viewing logs:

IP Address 167.112.160.# (Christiana Care Health Services)
ISP Christiana Care Health Services
Time of Visit Feb 21 2011 9:36:32 am
Last Page View Feb 21 2011 9:42:03 am
Visit Length 5 minutes 31 seconds
Page Views 5
Referring URL http://us.cisionpoint.com/NewsItemDetail.aspx?id=1671771040
Visit Entry Page http://hcrenewal.blogspot.com/2011/02/what-was-this-medical-resident-looking.html
Visit Exit Page http://hcrenewal.blogspot.com/2011/02/what-was-this-medical-resident-looking.html

On the "Cisionpoint" company, us.cisionpoint.com, the "referring" URL that led to this post:

CisionPoint brings together - in one integrated customized dashboard - the on-demand tools you need to create, execute and evaluate superior campaigns from start to finish.

Log in to plan your campaign, connect with the media directly, monitor news coverage and analyze campaign results.


It will be interesting to see how this horrifying episode is "managed" by the corporate spin doctors.

-- SS

Feb. 21 addendum #2:

Here is a message posted by the organization:

Message from the chief operating officer

Posted today

Christiana Care is steadfast in our commitment to the safety and well-being of our patients, employees and all visitors to our campuses.

The Delaware State Police have issued a press release identifying a suspect in the case of inappropriate touching first reported late last year. The suspect is a former first year medical resident at Christiana Care.

The prompt and thorough work of our Department of Public Safety when the allegations first surfaced, and information we shared with the State Police from our robust health information technology system, was instrumental to the process. We quickly identified the medical resident as a person of interest, and took swift action to prevent any further patient contact. As a result of our preliminary investigation, he was suspended and upon further investigation dismissed from employment.

Our rapid response when the allegations were first reported revealed no systemic issues contributed to this incident. As an organization guided by learning, we are continuing a thorough review of best practices in hospital security to determine if there are any new security measures we should adopt.

[Hopefully in the intervening years since I was CMIO, they've become even more of a learning organization compared to here, here and here, where under the prior "C" level leadership they learned so much from me and made me feel so at home, I felt compelled to leave to maintain my sanity - ed.]

We remind and encourage all patients and family to always ask health care providers to identify themselves, explain why they are there to see the patient, and explain the care provided to them. All Christiana Care employees are required to prominently display their identification badges.

[One wonders if they now permit PhD holders to use that credential on the badge, not permitted when I was there - ed.]

We deeply regret the alleged incidents and our concern for the affected patients is shared throughout our health system.

Gary Ferguson
Chief Operating Officer

As I knew Mr. Ferguson in a prior role, and as he is a good person, I with some regret point out that this appears to be corporate spin control.

A truly "robust" HIT security system, in my opinion, would have flagged the perpetrator after the first victim. It might even have prevented the molestation if there was a time delay between when he, as a trainee, trolled for a victim by viewing the records of a private patient, and then saw the patient, without some medical emergency that could have justified the records breach.

Merriam-Webster dictionary

ro·bust
adj \rō-ˈbəst, ˈrō-(ˌ)bəst\

a : having or exhibiting strength or vigorous health
b : having or showing vigor, strength, or firmness [a robust debate] [a robust faith]
c : strongly formed or constructed : sturdy [a robust plastic]
d : capable of performing without failure under a wide range of conditions [robust software]

This "robust" system, after all, is a system critical to human life and well-being, not an inventory system of medical data.

Let an unauthorized person access, say, government intelligence files, and see how far that flies...

(Notwithstanding the Wikileaks affair, where the low-level person who accessed the diplomatic files did have authorization to access the servers, through managerial complacency.)

-- SS

Feb. 26 Addendum:

This story was picked up by the Newark Post, the local newspaper in Newark, Delaware, where Christiana Hospital is located.

Questions raised about access to hospital medical records
By Doug Rainey, Newark Post
Published: Thursday, February 24, 2011

-- SS