Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Expert weighs in on data loss at South Shore Hospital

July 26, 2010 | Molly Merrill, Associate Editor

Related Resources

  • Healthcare Security Project Book - Secure access to patient data
  • June 6th @ 2PM ET--Healthcare Best Practices: 4 Critical IT Strategies to Avoid Data Breaches
  • Don't Get Hijacked – Protect Your Domain with DNSSEC
  • Unique Challenges of Health Care Networks and the Value of Wireless
  • Best Practices: IT Management for Healthcare Services

AUSTIN, TX – A breakdown in data destruction protocols could help explain why back-up files containing information on 800,000 individuals were lost from a Mass. hospital after a data management company was hired to destroy them.

This is according to healthcare IT security expert, Mac McMillan, CEO of Austin, Tex.-based CynergisTek, a provider of healthcare information security solutions, and chair of the HIMSS Privacy and Steering Committee.

Officials at South Shore Hospital, a not-for-profit, regional provider of acute, outpatient, home health and hospice care for southeastern Massachusetts, said the files were sent to a professional data management company for off-site destruction on Feb. 26 – and on June 17 the hospital was finally notified that only a portion of the files had been received.

The computer files contained personally identifiable information for patients who received medical services at South Shore Hospital – as well as employees, physicians, volunteers, donors, vendors and other business partners associated with the hospital – between Jan. 1, 1996, and Jan. 6, 2010.

If the tapes were encrypted, McMillan says, the hospital wouldn't be having this issue. He points to provisions under the HITECH Act, which state that if lost data is encrypted there is no obligation to report it.

Some of the data was less than a year old, which leaves the hospital with no excuse for not having it encrypted, says McMillan – adding that it would have been possible to encrypt the old data as well. But even without encryption, for an outside source to recover that data on the tapes would take specialized equipment and knowledge, he says.

Although it is not impossible for the information on the back-up tapes to be recovered, it is highly unlikely because the thief would have to have access to the application needed to run the tapes and get the data, McMillan says. It is also highly unlikely that there would be access to such an application away from the hospital.

McMillan recommends that organizations destroy their patient data on-site because it allows them to retain control of the complete process. He points out, however, that there are reputable data management companies, and that organizations simply need to do their homework so they understand the company's processes and how files are received and documented. 

McMillan says that if the hospital had tighter chain of custody processes, it may have been alerted sooner about a problem, and authorities would have a better chance at finding out what happened to this data. "The problem is that if [the hospital] doesn't find out that something went missing until months later, the trail to find it is gone."

According to McMillan the hospital and data management company should have had a business associate agreement, which is required under HIPAA. In this case, the business associate agreement would require that the hospital obtain satisfactory assurances from the data management company that it would appropriately safeguard the protected health information it received. As part of the associate agreement, the hospital should also have had a security agreement, says McMillan. Although, this is not required under HIPAA, he says that more hospitals are beginning to use them because they are finding out that associate agreements aren't cutting it.

In the security agreement hospitals can lay out processes including:

  • How material is prepared for shipping
  • How material is loaded, transmitted, and then received at facility
  • How long the material is held before destruction, and when they should receive a certificate of destruction

"Personal health information needs to be treated the same way as the government treats classified information – with really tight processes," said McMillan.

He adds that, based on everything he has read, the hospital is taking full responsibility and doing a good job of notifying all the appropriate parties. "This is a very unfortunate incident, and very embarrassing. But [the hospital] is doing all the right things."

Related Topics:
  • Austin
  • healthcare information security solutions
  • Mac McMillan
  • Massachusetts
  • South Shore Hospital
  • Privacy and Security

Reader Comments (1)Login to Post a Comment

Tabernus says: On Site Data Destruction Service
July 26, 2010 | 7:02PM GMT

At Tabernus, based in Austin, we have long believed that part of the challenge of handling data through its life-cycle is that most organizations charged with the security of data aren't aware of the options including on site data destruction.

Our specialty is with drives and data erasure so that the drives can be reused rather than tape shredding, but we are intimately aware of the challenges faced by a hospital or other medical facility and the need for a certificate of destruction.

While its regrettable that this happened, perhaps there is some good that can come out of this error and save some other organization from making this same oversight.

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • Tablet adoption by docs soars
  • FCC to vote on broadband space for patient monitoring
  • Computing cluster speeds targeted treatments for childhood cancer
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
  • Tablet adoption by docs soars
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • WHITE PAPERS
    The Scarborough Hospital: Establishing a Document Management Strategy for EHRs
  • UPCOMING WEBINARS
    June 5th @ 1PM ET--Get Control of Your Medical Images with a Cloud-Based Vendor-Neutral Archive
More Resources
Syndicate content

HIMSS JOBMINE

  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
  • Biostatistician II - Saudi Aramco - Dhahran, Saudi Arabia
  • Chief Information Officer - West Virginia - InfoPartners, Inc. - West Virginia
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy