Most Popular Stories
Featured Jobs
-
Washington Adult Psychiatrist SH1028psNet
StaffPointe, LLC - southeast , WA -
Indiana Infectious Disease
StaffPointe, LLC - near Richmond , IN -
North Carolina NP or PA
StaffPointe, LLC - east , NC -
South Carolina Nurse Mgr./Psych
StaffPointe, LLC - Florence Q, SC -
Michigan Orthopedics
StaffPointe, LLC - north central , MI
Events
- CIO Healthcare Summit
May 10-13 — Scottsdale, AZ - Four Seasons - National Health Policy Conference (NHPC)
Feb 2-3, 2009 — Washington, DC - Healthcare Conference at Harvard Business School on January 17, 2009
Paid Research Reports
- Stakeholder Opinions: Percutaneous Coronary Intervention - Adverse events with drug-eluting stents demand a new safety standard
- Impact of Pharmacogenomics on Public Healthcare Policy
- The Cardiovascular Disorders Market Outlook to 2012
- 2008 Trends to Watch: Pharmaceutical Technology
- Pharmaceutical Pricing and Reimbursement: Strategies for market access across the US, Europe, Japan and other key geographies
- Emerging markets series: Benchmarking key countries Brazil, Russia, India, China and Turkey
Free Newsletter
FierceHealthIT is the leading source of Healthcare IT news with a special focus on CPOE, EMR adoption, HIPAA compliance and other critical areas. Join 25,000+ healthcare industry insiders who get FierceHealthIT via weekly email for their must know IT news. Sign up today!
About | View Sample | Privacy
Latest News
Popular Topics
Whitepapers
- Addressing Regulatory Compliance in Healthcare
- How "Search" is Changing Healthcare
- A Modest Recipe for Retail Clinics 2.0
- The Definitive IP Address Management (IPAM) Intelligence Whitepaper
- Financing Options for Nonprofit Rural and Community Hospitals
- Premerus Issues Study Addressing Medical Misdiagnosis in America 2008
D.C. hospital finds major e-prescribing security hole
It apparently took an intrepid reporter at Wired to alert Georgetown Hospital to its own EHR security problem. Georgetown University Hospital suspended a trial program with an electronic prescription-writing firm recently after a computer consultant stumbled upon an online cache of data belonging to thousands of patients. The leaked information included patients' names, addresses, Social Security numbers and dates of birth, though not medical data or the drugs the patients were prescribed, says a hospital spokeswoman. The hospital had securely transmitted the patient data to e-prescription provider InstantDx. But an Indiana-based consultant accidentally discovered the data on InstantDx's computers while working to install medical software for a client. The consultant responsible for the discovery, Goshen, IN-based Randall Perry, says bad security practices contributed heavily to the incident. Perry says he accessed the data using a password he discovered hard-coded into a popular medical practice application, where any moderately skilled user could retrieve it. "This is just security through obscurity," says Perry. "My home network is probably 10 times more secure than what they have set up over there." Called Medisoft, the application is an all-in-one medical office suite marketed to small practices, and capable of handling everything from patient appointments to sending out bills. According to the product website, Medisoft is used by 70,000 health care practitioners worldwide.
For more on the trouble at Georgetown:
- see the Wired article
Related Stories
- Group promotes using unique patient IDs for shared EMRs
- Group to create health data security protection standard
- Microsoft kicks off PHR initiative
- Case Study: IT links mother, baby OB care
- University of Iowa discovers patient privacy violations
- HHS blasts CMS's HIPAA enforcement program
- Case study: CA hospital uses IT to find high-risk patients
- Trend: Number of tools to remotely collect health data growing
- Seattle system will pay $100K HIPAA fine after repeated breaches
- ALSO NOTED: AHIP promotes health IT for cost-cutting; UCSF creates infosec task force after break-ins; and much more...
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceSarbox | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceBiotech | FierceBioResearcher | FiercePharma | FierceVaccines | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2008 FierceMarkets, Inc. All rights reserved. |
![]() |





