Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Meaningful Use | Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Medicaid data breach 'like an onion'

October 26, 2010 | Molly Merrill, Associate Editor

Suggested Content

  • IT used to score top states in emergency preparedness
  • Delaware system goes live with CPOE

Related Resources

  • Where Information and Care Meet: Secure Mobile Healthcare Solutions that Drive Care Coordination
  • Intel Drives National Discussion on IT Infrastructure for ACOs
  • Improving Care Coordination with Online Services
  • Database Archiving and Legacy Application Retirement for ARRA and Healthcare Reform
  • Wi-Fi Provides Rx for Healthcare Challenges

PHILADELPHIA – One of the largest recent security breaches of personal health information (PHI), involving 280,000 individuals, is on the surface a "pretty low-risk scenario," says one privacy expert. But, he acknowledges, "these things are like an onion: the more layers you peel back, the stinkier it gets."

Affiliated insurers Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan reported the data breach, which involves the records of Medicaid recipients. According to their websites on Sept. 20, Keystone Mercy misplaced a portable computer drive (USB flash drive). The drive had personal health information about some of its members and others who attended some of its community events.

According to the Pennsylvania Department of Welfare this is the first such Medicaid data breach in the state since at least 1997.

Keystone is Pennsylvania's largest Medical Assistance (Medicaid) managed care health plan serving more than 300,000 Medical Assistance recipients in Southeastern Pennsylvania including Bucks, Chester, Delaware, Montgomery and Philadelphia counties. AmeriHealth is a Medical Assistance (Medicaid) managed care health plan serving more than 100,000 Medical Assistance recipients in 15 counties. The two companies are jointly owned by Independence Blue Cross and the Mercy Health System and share headquarters in Southwest Philadelphia, where the drive was said to have gone missing.  

Ed Goodman, chief privacy officer at Identity Theft 911, a Scottsdale, Ariz., provider of data breach solutions, says the news has been so "sensational" due to the high number of individuals involved, "but the reality is that full Social Security numbers were not present."

Goodman says that according to reports, approximately 808 of the individuals' information included full or partial Social Security numbers. He says that although these members may want to take proactive measures to prevent fraud, such as checking their credit files, this is not a huge identity theft risk.

"Even though this is a low risk scenario, it cries out for recognition because it happened on one thumb drive," Goodman said.

Which brings him to the main takeaway – encryption. He says he assumes the data was not encrypted – if it was the companies would not be required under HIPAA to report the breach.

Goodman calls encryption the "one out" to avoid having to report breaches. "You can put systems in place, but there are always going to be breakdowns in processes," he said.
 
Encryption is an uncomplicated, fairly cheap way to protect health information even for small organizations, he adds.

For the moment, the insurers seem to be in accordance with HIPAA.

"We have taken immediate action to make sure this doesn't happen again," wrote Jay Feldstein, DO president, PA Managed Care Plans, Keystone Mercy Health Plan on the company's websites. "We have put safety measures in place and have also re-trained our employees on the importance of protecting the privacy and security of confidential information."

Feldstein says that a letter will be mailed out to all the individuals affected by the incident, outlining what happened and what information was on the drive.

The only issue that is questionable at this point is if the companies reported the breach "without reasonable delay and in no case later than 60 days," said Goodman.

He says the Attorney General's office could latch on to this if they were at all tardy in reporting it, although he sees that as doubtful.

Goodman is also a member of the State Bar of Arizona, and served as the 2008-2009 section chair of the State Bar of Arizona Internet, E-Commerce and Technology Law Practice Section. He is a Certified Information Privacy professional and has studied comparative privacy law at the International Court of Justice in Hague. He's also a member of the International Association of Financial Crimes and Investigators.

Related Topics:
  • Arizona
  • Chester
  • data breach solutions
  • Delaware
  • Ed Goodman
  • encryption
  • Meaningful Use
  • Pennsylvania
  • Philadelphia
  • Scottsdale
  • Privacy and Security

Reader Comments (5)Login to Post a Comment

hobie18 says: Medicaid Breach - Are we really surprised
October 29, 2010 | 4:12PM GMT

Given the high degree of billing fraud that goes undected within Medicaid can we really be surprised that data security is not well managed?

Tom Sowa says: mandatory encryption
October 29, 2010 | 1:21PM GMT

Goodman calls encryption the "one out" to avoid having to report breaches. "You can put systems in place, but there are always going to be breakdowns in processes," he said.
-----------
How easy is it to force or require mandatory encryption of all data on external or thumb drives? If that's the case, the issue is fairly straightforward.

CPRTrev says: Encryption?
October 28, 2010 | 11:23AM GMT

I am amazed that they ASSUME that the data was not encrypted. One would think there would be measures in place to assure that all tranferable data is encrypted and locked. This could have been prevented or at least better damage control.

Jeff Brand says: Lock down USB ports
October 27, 2010 | 2:40PM GMT

I cannot believe Health Systems allow USB drives. You can buy USB locks for $12. This is where most breaches occur, at the USB. It makes all of HIT look bad.

Jeff Brandt
www.comsi.com

Dennis S says: Minimal security
October 27, 2010 | 1:54PM GMT

We are told by many security experts how to manage against breechs in security. So, why would such valuable information be kept on a thumb drive? It doesn't make sense.

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • 6 things patients want from social media
  • Tablet adoption by docs soars
  • FCC gives green light to wireless medical devices
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
  • Tablet adoption by docs soars
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Driving Meaningful Use of Enterprise Content Management
  • UPCOMING WEBINARS
    June 5th @ 1PM ET--Get Control of Your Medical Images with a Cloud-Based Vendor-Neutral Archive
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • UPCOMING WEBINARS
    June 6th @ 2PM ET--Healthcare Best Practices: 4 Critical IT Strategies to Avoid Data Breaches
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
More Resources
Syndicate content

HIMSS JOBMINE

  • Regional Senior Quality Analyst - Memorial Medical Center - Modesto, CA
  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
  • Biostatistician II - Saudi Aramco - Dhahran, Saudi Arabia
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy