Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Docs' file sharing risky business for patient data

March 05, 2010 | Molly Merrill, Associate Editor

Suggested Content

  • File sharing risky business for docs
  • Study: Clinical trial privacy safeguards lacking
  • Study 'undeniably proves' telestroke care saves lives and money
  • Canadian docs in training embrace EMRs
  • To own or not to own: A tale of two health systems
  • Docs averse to sharing patient data, even for public health
  • Canadian provider looks to transcription services to lower costs, improve care
  • Canada launches fight against chronic disease
  • Down Under is looking up

OTTAWA – Doctors who use file sharing software could be putting their patients' medical information at risk, says a recent study.

The study, which was published in the Journal of the American Medical Informatics Association, is the first of its kind to empirically estimate the extent to which personal health information is disclosed through file-sharing applications, said Khaled El Emam, Canada research chair in electronic health information, and the study's lead author.

Researchers used popular file sharing software such as Limewire, BitTorrent and Kazaa to gain access to documents they downloaded from a representative sample of IP addresses. They were able to access the personal and identifying health and financial information of individuals in Canada and the United States.

"The flexibility of these file sharing tools is often the same reason that they are not completely intuitive and can thus lead to errors as to which files or folders are setup for sharing. Without additional protection on the health records, like encryption or elevated access controls, it is entirely possible that a mis-configured file sharing tool could gain full access to the records," said Robert Grapes, chief technologist of the Cloakware team in Irdeto.

El Emam said he and his colleagues found evidence of outsiders actively searching for files that contain private health and financial data. "There is no obvious innocent reason why anyone would be looking for this kind of information," he said.

Researchers advised not using file-sharing tools if they want to protect their sensitive information.

Although this is a simple answer, says Grapes, the reality is that most doctors are using their computers for more than just accessing patient records.

"Email, scheduling, bill payment, medical research, conference bookings and much more are normal activities for these computers, so it makes sense that some, not all, doctors will also install and use file sharing systems," he said.

But trying to use the file sharing software's own privacy safeguards requires considerable information technology expertise, said El Emam.

"Doctors must become familiar with their software applications, file-sharing in this case, and be in a confident position to defend any audit challenges as to the protection of medical health record information," agreed Grapes.

"File and folder encryption are reasonably simple approaches to bolster the protection of these records, but these security methods come with their own management and use challenges that also must be well understood," he said.

Only a small proportion of the IP addresses the researchers examined contained personal health information, but since tens of millions of people use peer-to-peer file sharing applications in North America, that percentage translates into tens of thousands of computers, they said.

Here is a sample of the private health information research team was able to find by entering simple search terms in file-sharing software:

  • An authorization for medical care document that listed an individual's Ontario Health Insurance card number, birth date, phone number and details of other insurance plans;
  • A teenage girl's medical authorization that included family name, phone numbers, date of birth, social security number and medical history, including current medications;
  • Several documents created by individuals listing all their bank details, including account and PIN numbers, passwords and credit card numbers.

CHEO Research Institute's ethic board approved the research for this study. CHEO Research Institute coordinates the research activities of the Children's Hospital of Eastern Ontario.

Click here to read the full JAMIA article.

Related Topics:
  • BitTorrent
  • Canada
  • encryption
  • file sharing
  • Khaled El Emam
  • Limewire
  • Ottawa
  • Robert Grapes
  • United States

Reader Comments (1)Login to Post a Comment

CourtneyM says: More than financially frightening...
March 05, 2010 | 1:42PM GMT

Of course everyone's first thought when you read this is how damaging it can be financially, but what about the damage it does to your personal health record? A person with your insurance card, birth date and other medical information can easily receive health care in your name. Meaning the next time you visit your doctor they could be working with an entirely different person's medical record under your name! Different blood type, allergies and medication. This type of medical fraud is life-threatening and is very dangerous. Be sure you are being an aware medical consumer and take charge of your health care by having an added layer of protection from fraud. A mobile medical record device called the LifeGuard30 can be that layer of protection that will help doctors avoid mistakes due to medical fraud.

www.lifeguard30.com

Most Popular

Latest Headlines
Most Popular
  • 10 most outlandish kinds of ICD-10 codes
  • 5 stages of EHR maturity and patient collaboration
  • 5 simple ways to realize ROI from your EHR
  • 'Obamacare' a lightning rod, but what about health IT?
  • Remote health monitoring pegged at 3 million users by 2016
  • H.I.T. Men and Women to pick up awards at HIMSS12
  • University challenge targets NCDs with mHealth and social media
  • Indiana health exchange taps AT&T to scale up
  • eHealth Initiative releases recommendations for accountable care
  • One surgeon's take on need for culture change in medicine

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    The Scarborough Hospital: Establishing a Document Management Strategy for EHRs
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • ON DEMAND WEBINARS
    The Value of Document and Content Management in Healthcare Transformation
  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
More Resources
Syndicate content

HIMSS JOBMINE

  • Director, Sales - HIMSS - Arlington, VA
  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy