FierceHealthcareFierceHealthITFierceHealthFinanceHospital Impact   FierceCIOFierceMobileITFierceSarbox

GA hospital health data breach due to outsourcing error

Tools
Tags
security breaches
outsourcing
hospitals
Grady Memorial Hospital
data security
Data Breach

In recent years, Atlanta's Grady Memorial Hospital has made the news for its long-standing financial problems and board-room dramas. This time, however, it's a medical data breach that is bringing additional publicity to the hospital, which just took on a new CEO and is working to plug its financial holes.

The hospital recently found out that records on 45 of its patients ended up on an unsecured, publicly available website and remained available for a few weeks. The data included doctors' notes, medical conditions, diagnoses, documentation of medical procedures and possibly names and ages of patients, the hospital said.

When this was discovered, of course, the hospital yanked the records off of the public access area, but questions remained as to how the data got there. As readers won't be surprised to hear, this particular problem was caused by human error, not some form of outside attack.

The breach seems to have been a result of outsourcing. Grady had outsourced the job of transcribing the notes to one firm, which outsourced it to another--and then, the second firm outsourced it to a third in India.

To learn more about the breach:
- read this Atlanta Journal-Constitution article

Related Articles:
NIH security breach includes data on U.S. Rep
U.S. hospitals have security 'blind spot'
More hospital data security breaches
Johns Hopkins loses patient, employee data

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.

More information about formatting options

What is 16 + 25?
To combat spam, please solve the math question above.