Free EMR Newsletter Want to receive the latest news on EMR, Meaningful Use, ARRA and Healthcare IT sent straight to your email? Join thousands of healthcare pros who subscribe to EMR and EHR for FREE!

Healthcare Data Security, Healthcare Breaches, and EMRs

Posted on October 10, 2011 I Written By

Priya Ramachandran is a Maryland based freelance writer. In a former life, she wrote software code and managed Sarbanes Oxley related audits for IT departments. She now enjoys writing about healthcare, science and technology.

We’ve posted about it earlier on this blog as well, and it’s a point worth reiterating – most data breaches are not the result of hordes of internet hackers out to get your computer system, they’re due to human errors or negligence.

Here are some recent cases of patient data that has emerged from EMRs in unexpected places:
Lost in Break-In: By now, we’ve all probably already shaken our collective heads over the Tricare data breach involving data for 4.9 million military patients. Scientific Applications International Corp. (SAIC), one of Pentagon’s principal contractors, was the outfit that was responsible for the data loss, which was stolen from a break-in into a SAIC employee’s car. The data was contained in backup tapes, and contained information such as SSN, addresses and phone numbers of patients, and personal health data.

There are several perplexing things about this story – a) the statement on Tricare’s website claiming nothing important was really lost: “The risk of harm to patients is judged to be low despite the data elements involved since retrieving the data on the tapes would require knowledge of and access to specific hardware and software and knowledge of the system and data structure” per this story.
b) SAIC’s success with HHS contracts – SAIC was awarded a lucrative $15 million contract by HHS, despite the breach.

Posted on a Homework Help forum: According to this NYT story and its follow-up, patient records (names, diagnosis codes, account numbers, admission codes) from emergency visits for a six month period at Stanford Hospital, CA, were posted online. Supposedly, a Stanford vendor sent the data to a prospective contractor as part of a testing exercise. The contractor posted it all online, on a website offering tutoring help no less, without realizing it was actual patient data. The story says Stanford had the data removed from the website, and reported the breach to federal and state authorities, as well as the patients. Stanford is arguing that none of its staff has done anything wrong, and that it severed its relationship with the contractor. To me, this is the proverbial buck being passed.

Lost in the Subway: The first NYT story mentions how the paper records of 192 patients left on a subway by an employee of Massachusetts General Hospital in Boston. The hospital has agreed to pay a $1 million federal fine for HIPAA violations.

So to summarize some lessons learned from these data breaches:
Loss of paper records is worse than the loss of electronic records: This should be obvious to anyone who’s not a schoolgirl with a fancy diary guarded by a lock.

Your data is only as safe as your weakest link: If you’re farming out your data to vendors, then you have to know what policies your vendor has in place. If your vendor subcontracts further, then you have to keep going down the line till you are reasonably assured of data safety. When the hammer falls, it is *you* who will be coughing up the fines.

Prep with Data-handling Policies and Procedures that you and your staff religiously follow: The data was lost in very human ways – data left inside a car, posted by an untrained contractor. This just means you need to have robust, and enforced, policies in place for how patient data is handled by your employees. Maybe in your company this means that your employees can’t take work home, or that they must clear their workspaces of any patient data before they leave. Decide what makes sense in the context of your business, and maybe hire someone to enforce these rules.

Give kickbacks to HHS: If you’re in the business of contracting with the government, seriously figure out how SAIC has managed to stay in HHS’ good books. I wish I were kidding with this one.

Electronic Medical Records Lost Using External Hard Drive

Posted on August 16, 2011 I Written By

Dr. West is an endocrinologist in private practice in Washington, DC. He completed fellowship training in Endocrinology and Metabolism at the Johns Hopkins University School of Medicine. Dr. West opened The Washington Endocrine Clinic, PLLC in 2009. He can be contacted at doctorwestindc@gmail.com.

I hate to call anyone stupid, but reading stories like Hospital Reports a Possible Data Loss really steams my Chinese dumplings.  According to the post, a doctor who works at two facilities, including the famous Harvard’s Brigham and Women’s hospital (of NOVA fame) walked out carrying a hard drive with over 600 patients’ personal, private medical records and then “lost” it on a trip to Mexico.  How could anyone commit or sanction such a risky action as walking out of a medical facility while hand-carrying an unprotected copy of so many people’s medical records in electronic form?!  And you gotta love that the records ended up in freakin’ Mexico of all places.  Whoever the legendary doctor was — who remains nameless — couldn’t have done a better job, short of sending the records to Al-Qaeda.  Can you imagine?!  Ugh…

You know what the answer to this is?  It’s quite simple — don’t store records on removable hardware. With the Cloud in place, I dream of the day when it’s mandated by law that health records cannot be stored on portable hardware.  We have so many brilliant companies using the latest SaaS technology that I really scratch my head wondering why this isn’t the default choice for all EMR and EHR systems.  There is little reason that the above disaster should still be allowed to happen in 2011.

Rather interestingly, and yet again, this is another example of data theft of patient records that was NOT electronic theft.  No usernames and passwords were hacked to get at the information.  It’s was just a plain, simple (at least as far as anyone knows) dumb-luck loss.  Another shining and yet pitiful  example of why I believe that records are far safer on the web and in the Cloud than in someone’s portable hard drive or laptop.  Do we really need to start anti-theft pad-locking and chaining hardware in place at medical facilities?

On another note, I’d love to have been the fly on the wall when the doctor was asked what happened that encouraged him or her to walk out with it.  Just how common is it?

Dr. West is an endocrinologist in private practice in Washington, DC.  He completed fellowship training in Endocrinology and Metabolism at the Johns Hopkins University School of Medicine. Dr. West opened The Washington Endocrine Clinic, PLLC, as a solo practice in 2009.  He can be reached at doctorwestindc@gmail.com.