<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.fiercehealthit.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>breaches</title>
 <link>http://www.fiercehealthit.com/tags/breaches-0</link>
 <description></description>
 <language>en</language>
<item>
 <title>Study: Better staff training could protect EMR privacy</title>
 <link>http://www.fiercehealthit.com/story/study-better-staff-training-could-protect-emr-privacy/2008-04-21?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FHI0</link>
 <description>&lt;p&gt;
If providers do a better job of training their staff, privacy breaches will be far less common, according to a new report issued by the AHIMA. Experts quoted in the report note that the recent rash of incidents in which records of celebrities like George Clooney and Britney Spears were accessed demonstrates how easy it is to get to such records. While institutions usually can find out who accessed what record, that&#039;s after the incident takes place. In some cases, far too many people may have access to EMRs, and it&#039;s in a provider&#039;s best interests to impose tougher access restrictions, the authors said. Ultimately, however, technical fixes like this can&#039;t do the job by themselves. Providers need to remind employees regularly what privacy rules are, how to address them, and what the consequences will be if they don&#039;t, experts quoted in the report contended.&lt;br /&gt;
&lt;br /&gt;
To learn more about the report:&lt;br /&gt;
- read this &lt;em&gt;Healthcare IT News&lt;/em&gt; &lt;a href=&quot;http://www.healthcareitnews.com/story.cms?id=9065&quot;&gt;piece&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Related Articles:&lt;/strong&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.fiercehealthit.com/story/ucla-staff-accused-viewing-britney-spears-records/2008-03-24&quot;&gt;UCLA staff accused of viewing Britney Spears&#039; records&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.fiercehealthit.com/story/park-nicollet-suspends-employees-emr-snooping/2007-07-23&quot;&gt;Park Nicollet suspends employees for EMR snooping&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.fiercehealthcare.com/story/union-fights-suspensions-workers-viewing-stars-records/2007-10-12&quot;&gt;Union fights suspensions for workers viewing star&#039;s records&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.fiercehealthcare.com/story/over-applying-and-misapplying-hipaa-is-common/2007-07-03&quot;&gt;Overapplying and misapplying HIPAA is common&lt;/a&gt;
&lt;/p&gt;
</description>
 <comments>http://www.fiercehealthit.com/story/study-better-staff-training-could-protect-emr-privacy/2008-04-21#comments</comments>
 <category domain="http://www.fiercehealthit.com/tags/ahima-0">ahima</category>
 <category domain="http://www.fiercehealthit.com/tags/breaches-0">breaches</category>
 <category domain="http://www.fiercehealthit.com/tags/britney-spears">Britney Spears</category>
 <category domain="http://www.fiercehealthit.com/tags/electronic-health-records">Electronic Medical Records (EMRs)</category>
 <category domain="http://www.fiercehealthit.com/tags/george-clooney">George Clooney</category>
 <category domain="http://www.fiercehealthit.com/tags/hipaa">HIPAA</category>
 <category domain="http://www.fiercehealthit.com/tags/privacy-breaches">privacy breaches</category>
 <category domain="http://www.fiercehealthit.com/tags/suspensions">Suspensions</category>
 <pubDate>Mon, 21 Apr 2008 06:59:56 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">7913 at http://www.fiercehealthit.com</guid>
</item>
<item>
 <title>GAO warns of widespread ID security breaches</title>
 <link>http://www.fiercehealthit.com/story/gao-warns-widespread-id-security-breaches/2007-07-16?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FHI0</link>
 <description>
&lt;P&gt;The &lt;A href=&quot;http://www.fiercehealthit.com/story/gao-reports-numerous-security-breaches/2006-09-11&quot;&gt;reports detailing federal data security holes keep rolling in&lt;/a&gt;, but somehow, nobody seems to be getting terribly upset about it. In a recent report from the Government Accountability Office, just to site a few upsetting stats, the agency said data breaches have been common of late, with more than 570 breaches being reported in the news media between January 2005 and December 2006. What&#039;s more, 17 government agencies reported a total of 788 separate data breaches of government system. It&#039;s enough to give a CIO a giant migraine. As if that wasn&#039;t enough, the GAO notes it&#039;s still not clear to what extent these data breaches result in identity theft.&lt;BR /&gt;&lt;BR /&gt;While some of the breaches fall well outside of the health industry, health data invasions are disturbingly common as well. One recent GAO-mandated AHA survey of 46 hospitals concluded 17 breaches had occurred at 13 of the 46 hospitals since 2003. Three led to fraudulent activity on existing accounts and another three in other forms of ID theft. While all identity theft can do damage, the GAO has previously conceded health identity theft can do perhaps the most long-lasting and harmful damage. Still, the GAO has chosen not to focus its data breach investigations primarily on the health sector of late.&lt;BR /&gt;&lt;BR /&gt;To find out more about the GAO&#039;s research:&lt;BR /&gt;- read this &lt;EM&gt;Modern Healthcare&lt;/em&gt; &lt;A href=&quot;http://www.modernhealthcare.com/apps/pbcs.dll/article?AID=/20070706/FREE/70706013/0/FRONTPAGE&quot;&gt;piece&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Related Articles:&lt;/strong&gt;&lt;BR /&gt;GAO: Government HIT efforts lack privacy, security. &lt;A href=&quot;http://www.fiercehealthit.com/story/gao-gov-t-hit-efforts-lack-privacy-security/2007-02-05&quot;&gt;Report&lt;/a&gt;&lt;BR /&gt;CMS security holes expose patient data. &lt;A href=&quot;http://www.fiercehealthit.com/story/cms-security-holes-expose-patient-data/2006-10-09&quot;&gt;Report&lt;/a&gt;&lt;BR /&gt;VA revamping IT infrastructure. &lt;A href=&quot;http://www.fiercehealthit.com/story/va-revamping-it-infrastructure/2006-10-09&quot;&gt;Report&lt;/a&gt;&lt;/p&gt;

</description>
 <comments>http://www.fiercehealthit.com/story/gao-warns-widespread-id-security-breaches/2007-07-16#comments</comments>
 <category domain="http://www.fiercehealthit.com/tags/aha-0">aha</category>
 <category domain="http://www.fiercehealthit.com/tags/breaches-0">breaches</category>
 <category domain="http://www.fiercehealthit.com/tags/cms">CMS</category>
 <category domain="http://www.fiercehealthit.com/tags/government-accountability-office-0">Government Accountability Office (GAO)</category>
 <category domain="http://www.fiercehealthit.com/tags/hospitals">hospitals</category>
 <category domain="http://www.fiercehealthit.com/tags/infrastructure-report-0">infrastructure report</category>
 <category domain="http://www.fiercehealthit.com/tags/patient-data">patient data</category>
 <category domain="http://www.fiercehealthit.com/tags/security-holes-0">security holes</category>
 <pubDate>Mon, 16 Jul 2007 06:59:56 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">7583 at http://www.fiercehealthit.com</guid>
</item>
<item>
 <title>Editor&#039;s Corner</title>
 <link>http://www.fiercehealthit.com/story/editor-s-corner/2007-03-05?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FHI0</link>
 <description>&lt;P&gt;&lt;IMG height=29 src=&quot;http://static.fiercemarkets.com/public/newsletter/assets/editors_corner_small.gif&quot; width=136 border=0&gt;&lt;IMG height=145 alt=&quot;&quot; hspace=5 src=&quot;http://static.fiercemarkets.com/public/newsletter/fiercehealthcare/anne_headshot.gif&quot; width=112 align=right border=0&gt;&lt;/P&gt;
&lt;P&gt;For several months, the VA has been under intense scrutiny as it struggles to close the &lt;A href=&quot;http://www.fiercehealthcare.com/story/va-loses-records-on-1.8-million-vets-doctors/2007-02-14&quot;&gt;massive holes&lt;/A&gt;&amp;nbsp;in its security infrastructure. In recent times the agency has gotten a great deal of heat from stakeholders, including Congressional committees that oversee its work. &lt;/P&gt;
&lt;P&gt;From reading tales of the VA&#039;s problems, one might think it&#039;s got a uniquely difficult problem to address. In reality, though, the vulnerabilities it faces aren&#039;t much different than the ones which have led to breaches elsewhere. These include maintaining large pools of unencrypted medical data, poor control of laptops loaded with such data, and an inability to track which users have data access.&lt;/P&gt;
&lt;P&gt;Given how common health IT breaches are these days, I&#039;d argue that it&#039;s time to implement a set of health IT security standards uniformly across the industry, perhaps even establishing them as part of The Joint Commission&#039;s hospital surveys. These standards, which would call for both technology and internal process changes, could take HIPAA requirements as a jumping off point. &lt;/P&gt;
&lt;P&gt;Please note that I&#039;m not suggesting that hospital and health system IT managers don&#039;t know their stuff when it comes to security. Still, a healthcare-specific security framework would give health IT managers something to focus on when they&#039;re reviewing their existing security plans. And that can&#039;t be a bad thing.&lt;/P&gt;
&lt;P&gt;Just as importantly, such standards would give IT managers something to use as a consensus-building tool. While it can be hard for IT to pitch security investments to non-technical decision makers, having external standards to comply with is easier to sell.&lt;/P&gt;
&lt;P&gt;I know that the industry already has countless rules to adhere to already. But given how important it is to lower the number of intrusions, it&#039;s worth establishing standards everyone can accept. Adopting new standards might lead to more work at first, but in the end, implementing them would make life easier for all concerned. - &lt;A href=&quot;mailto:anne@fiercemarkets.com&quot;&gt;Anne&lt;/A&gt;&lt;/P&gt;

</description>
 <comments>http://www.fiercehealthit.com/story/editor-s-corner/2007-03-05#comments</comments>
 <category domain="http://www.fiercehealthit.com/tags/breaches-0">breaches</category>
 <category domain="http://www.fiercehealthit.com/tags/health-system">health system</category>
 <category domain="http://www.fiercehealthit.com/channel/hipaa-compliance">HIPAA Compliance</category>
 <category domain="http://www.fiercehealthit.com/tags/hipaa-requirements-0">hipaa requirements</category>
 <category domain="http://www.fiercehealthit.com/tags/hospitals">hospitals</category>
 <category domain="http://www.fiercehealthit.com/tags/medical-data">medical data</category>
 <pubDate>Sun, 04 Mar 2007 19:01:39 -0500</pubDate>
 <dc:creator />
 <guid isPermaLink="false">993 at http://www.fiercehealthit.com</guid>
</item>
<item>
 <title>More hospital data security breaches</title>
 <link>http://www.fiercehealthit.com/story/more-hospital-data-security-breaches/2006-11-06?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FHI0</link>
 <description>&lt;P&gt;Two healthcare organizations are taking a public beating over info security breaches that exposed patient data--and one of them may be on the hook for huge legal penalties. The Akron Children&#039;s Hospital publicly admitted last week that an intruder had gained access to patient and charitable donor information. Around Labor Day, the hospital learned that German intruders had accessed information concerning about 200,000 patients. The data included Social Security numbers, bank account information and donor routing numbers. Last week, the hospital went public with the incident. In a statement on its website addressing the issue, the hospital said that it wasn&#039;t aware of any illegal use of the information. Repairing the breach could be costly; If one industry industry is correct, it could cost Children&#039;s $200 per record breached to lock down its systems again. And there&#039;s no guarantee that it couldn&#039;t happen again, with a world full of attackers trying to outsmart honest admins.&lt;/P&gt;
&lt;P&gt;Still, if Children&#039;s is fortunate, it will avoid the fate of the Sisters of Saint Francis Health Services, which is being sued for an eye-popping $1.3 billion (or $5,000 per claimant) over its recent data breach. SSF, which runs hospitals in Illinois and Indiana, lost track of 260,000 records when a contractor copied patient information onto CDs, placed the CDs in a computer bag, then inadvertently returned the bag to a store with the CDs still inside. The suit names SSF, the contractor and the contractor&#039;s employer, Perot Systems subsidiary Advanced Receivables Management. The attorneys involved are hoping to get the suit certified as a class action. In the mean time, they want to force SSF to pay credit monitoring fees for the patients and employees involved, which apparently, they haven&#039;t yet volunteered to do. (If they haven&#039;t, shame on them.)&lt;BR&gt;&lt;BR&gt;For background on the breaches:&lt;BR&gt;- read this &lt;A href=&quot;http://www.wkyc.com/news/news_article.aspx?storyid=58464&quot;&gt;article&lt;/A&gt; from &lt;EM&gt;WKNY.com &lt;/EM&gt;on the Children&#039;s situation&lt;BR&gt;- read the &lt;EM&gt;Indianapolis Star&lt;/EM&gt; &lt;A href=&quot;http://www.indystar.com/apps/pbcs.dll/article?AID=/20061101/BUSINESS/611010410/1003&quot;&gt;piece&lt;/A&gt;&amp;nbsp;on the St. Francis suit&lt;/P&gt;

</description>
 <comments>http://www.fiercehealthit.com/story/more-hospital-data-security-breaches/2006-11-06#comments</comments>
 <category domain="http://www.fiercehealthit.com/tags/breaches-0">breaches</category>
 <category domain="http://www.fiercehealthit.com/tags/credit-monitoring-0">credit monitoring</category>
 <category domain="http://www.fiercehealthit.com/tags/hospitals">hospitals</category>
 <category domain="http://www.fiercehealthit.com/tags/patient-data">patient data</category>
 <category domain="http://www.fiercehealthit.com/tags/perot-systems-0">perot systems</category>
 <pubDate>Sun, 05 Nov 2006 19:01:38 -0500</pubDate>
 <dc:creator />
 <guid isPermaLink="false">813 at http://www.fiercehealthit.com</guid>
</item>
<item>
 <title>HIPAA case highlights patient legal vulnerability</title>
 <link>http://www.fiercehealthit.com/story/hipaa-case-highlights-patient-legal-vulnerability/2006-09-18?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FHI0</link>
 <description>&lt;P&gt;The recent indictment of a former Florida employee for conspiracy to commit health care fraud with the personal information of more than 1,100 Florida patients probably won&#039;t result in big civil fines against the hospital by the federal government--which has yet to sanction a hospital or other health care entity for patient privacy breaches--says a news article in the Florida &lt;I&gt;Naples News&lt;/I&gt;.&lt;/P&gt;
&lt;P&gt;The case is potentially precedent-setting as it is the first in South Florida to be prosecuted for violating the federal law protecting patients&#039; privacy rights and the third such case nationally, according to the U.S. Attorney&#039;s Office in Miami. But patients may be left out in the cold because of the Health Insurance Portability and Accountability Act (HIPAA) as the federal law doesn&#039;t allow individuals to pursue legal action when there&#039;s been a breach of their personal health information, privacy rights and HIPAA attorneys told the &lt;EM&gt;Naples News.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;For more on the case:&lt;BR&gt;-&amp;nbsp;Read the story at the &lt;EM&gt;Naples News&amp;nbsp;&lt;/EM&gt;&lt;A href=&quot;http://www.naplesnews.com/news/2006/sep/15/florida_health_fraud_case_breaks_new_legal_ground/?local_news&quot;&gt;here&lt;/A&gt;&lt;/P&gt;

</description>
 <category domain="http://www.fiercehealthit.com/tags/breaches-0">breaches</category>
 <category domain="http://www.fiercehealthit.com/tags/health-insurance-portability-0">Health Insurance Portability and Accountability Act (HIPAA)</category>
 <category domain="http://www.fiercehealthit.com/tags/hipaa">HIPAA</category>
 <category domain="http://www.fiercehealthit.com/channel/hipaa-compliance">HIPAA Compliance</category>
 <category domain="http://www.fiercehealthit.com/tags/personal-health-0">personal health</category>
 <category domain="http://www.fiercehealthit.com/tags/patient-privacy-0">privacy</category>
 <pubDate>Sun, 17 Sep 2006 20:01:36 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">738 at http://www.fiercehealthit.com</guid>
</item>
<item>
 <title>GAO reports numerous security breaches</title>
 <link>http://www.fiercehealthit.com/story/gao-reports-numerous-security-breaches/2006-09-11?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FHI0</link>
 <description>&lt;P&gt;Oops. More than 40 percent of federal contractors to the Medicare and Tricare programs and state Medicaid agencies responding to a survey by the Government Accountability Office (GAO) said they had experienced privacy breaches involving personal healthcare information of beneficiaries, according to a study of 378 contractors and agencies.&lt;BR&gt;&lt;BR&gt;Was outsourcing a factor? Kinda sounds like it. More than 90 percent of Medicare contractors and state Medicaid agencies and 63 percent of Tricare contractors reported some outsourcing of their work to domestic companies, while only one federal vendor and one state Medicaid agency reported directly contracting with an offshore entity for outsourced work. And 33 Medicaid Advantage contractors, two Medicare fee-for-service contractors and one Medicaid agency responding to the survey admitted that their domestic vendors transferred some of their work to offshore organizations. &quot;Moreover, the reported extent of offshore outsourcing by vendors may be understated because many federal contractors and agencies did not know whether their domestic vendors transferred personal health information to their locations or vendors,&quot; the report said.&lt;/P&gt;
&lt;P&gt;For more on the breaches:&lt;BR&gt;- see the full &lt;A href=&quot;http://e.ccialerts.com/a/hBE-vh6AIyhSgAa0kNPAoEWk$.Aa0kvL5e/mhc34&quot;&gt;report&lt;/A&gt;&amp;nbsp;(.pdf)&lt;/P&gt;

</description>
 <category domain="http://www.fiercehealthit.com/tags/breaches-0">breaches</category>
 <category domain="http://www.fiercehealthit.com/tags/government-accountability-office-0">Government Accountability Office (GAO)</category>
 <category domain="http://www.fiercehealthit.com/tags/healthcare-information-0">healthcare information</category>
 <category domain="http://www.fiercehealthit.com/channels/healthcare-research-studies">Healthcare Research / Studies</category>
 <category domain="http://www.fiercehealthit.com/tags/personal-health-0">personal health</category>
 <pubDate>Sun, 10 Sep 2006 20:01:34 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">726 at http://www.fiercehealthit.com</guid>
</item>
</channel>
</rss>
