Here we have another unnecessary major security breach in a large healthcare organization which resulted in a loss of patient data demonstrating poor baseline security. They clearly are not ready for the new HIPAA provision ARRA and HITECH. Review my threats page and evaluate your current business and system risks to make sure this does not happen to you.
Contact DISC for any question or high level risk assessment.
The Practical Guide to HIPAA Privacy and Security Compliance
By Robert Westervelt, News Editor
19 Nov 2009 | SearchSecurity.com
Health Net Inc. announced Wednesday that it is investigating a healthcare data security breach that resulted in the loss of patient data, affecting 1.5 million customers.
The Woodland Hills, Calif.-based managed healthcare provider said the lost files, a mixture of medical data, Social Security numbers and other personally identifiable information, were collected over the past seven years and contained on a portable external hard drive, which was lost six months ago. The company said the healthcare data was not encrypted, but was formatted as images and required a specific software application to be viewed. The hard drive contained data on 446,000 Connecticut patients.
The company reported the breach Wednesday to State Attorneys Generals offices in Arizona, Connecticut, New Jersey and New York. Health Net said it was beginning the data security breach notification process of sending out letters to its customers. The company said it expects to send notification letters the week of Nov. 30.
Connecticut Attorney General Richard Blumenthal said he was investigating the matter and why it took Health Net six months to report the healthcare breach.
“My investigation will seek to establish what happened and why the company kept its customers and the state in the dark for so long,” Blumenthal said in a statement. “The company’s failure to safeguard such sensitive information and inform consumers of its loss — leaving them naked to identity theft — may have violated state and federal laws.”
Blumenthal said the hard drive also contained financial data, including bank account numbers. He is seeking coverage for comprehensive, long-term identity theft protection for those customers affected by the breach.
Health Net provides medical coverage for approximately 6.6 million people and its subsidiaries operate in all 50 states. In a statement, the company said the breach took place in its Connecticut office. So far there have not been any reports of fraud tied to the missing data..
“Health Net will provide credit monitoring for over two years – free of charge – to all impacted members who elect this service, and will provide assistance to any member who has experienced any suspicious activity, identity theft or health care fraud between May 2009 and their date of enrollment with our identity protection service,” the company said.
It is the second time in a month that a healthcare provider lost customer data. Anthem Blue Cross and Blue Shield of Connecticut reported a stolen laptop was to blame for a breach compromising the personal information of 850,000 doctors, therapists and other healthcare professionals.
Security experts have long been advocating that enterprises deploy encryption on laptops and other devices that contain sensitive data. Still, all the technology in the world won’t end employee mistakes and carelessness, said Mike Rothman an analyst with Security Incite.
“You can do full disk encryption and all sorts of things to protect the device, but you are still fairly constrained by user sophistication,” Rothman said. “You have to start asking questions from a process standpoint relative to why this stuff was on an external drive in the first place.”
In reality you could turn off all USB ports on your devices, but that could hinder employee productivity, Rothman said. Security always gets back to making sure you have the right processes and policies in place and the right training and awareness so that employees understand what those policies are and ways to audit those processes, he said.
Experts say encryption should be used as a last resort when all other security policies and processes fail. While many enterprises have focused on encrypting laptops at the endpoint, encryption can be a bit trickier for portable hard drives and other removable media. If the drive is being shared between different systems people need to have some way to access the key, said Ramon Krikken, an analyst at the Burton Group.
“A lot of these portable hard drives are older without built-in encryption and to the extent to which you can easily deploy encryption has been a challenge for enterprises,” Krikken said.
Some USB makers market the devices with built-in encryption software. In 2008, Seate Technology extended full disk encryption technology to all its enterprise-class hard drives. The company also began pushing for standards for hard drive encryption in storage systems.
Nagraj Seshadri, head of product marketing at Utimaco the encryption software division of Sophos Plc, said healthcare organizations need to be just as responsible as financial firms when it comes to protecting data.
Perhaps healthcare management still doesn’t realize that they might be potentially liable for lack of reasonable safeguards to protect organization assets. Do you think it’s time for healthcare management to take information security seriously as a potential business risk?
Related articles by Zemanta
- New HealthCare Data Breach Program Begins September 23rd (ducknetweb.blogspot.com)
- ARRA – HITECH: Health Care Information Breach Notification Regulations Now In Effect (healthcarebloglaw.blogspot.com)
- Son of HIPAA Breach Notification Rules and Business Associate Requirements: Who’s Ready? (healthblawg.typepad.com)
- Laptop Heist Exposes Doctors’ Personal Data (deurainfosec.com)
- HIPAA Enforcement Meets HITECH: HIPAA Administrative Simplification: Enforcement Rule (healthcarebloglaw.blogspot.com)
November 19th, 2009 1:23 pm
Another wakeup call for healtcare organiztions which put a spot light on their current state of information security – it is high time for healthcare organizations to know their current state of security and develop some sort of transition plan based on security standards (iso 27k) to improve their baseline security.
November 24th, 2009 10:46 am
[…] Health Net healthcare data breach affects1.5 million (deurainfosec.com) […]
December 22nd, 2009 1:50 am
This post is great. Thank you Robert for this post.
I like this type of people who share knowledge with others.
health insurance
December 22nd, 2009 3:38 am
This is indeed a nice post!! I like people those who want to share their knowledge to others. Sometimes it can be very helpful to others.
December 23rd, 2009 9:19 am
Its really cool, I came to know this really worth visiting, just bookmarked your site.
December 24th, 2009 1:03 am
[…] Health Net healthcare data breach affects1.5 million (deurainfosec.com) […]
December 25th, 2009 5:04 am
I love this blog! Will come again next time for sure,
December 25th, 2009 11:26 pm
Its really cool, I've come to know really what to see, just bookmark your site.
July 6th, 2010 10:55 pm
Well , the view of the passage is totally correct ,your details is really reasonable and you guy give us new balance . this is a valuable informative post, I totally agree the standpoint of upstairs. I often surfing on this forum when I m free and I find there is so much good information we can learn in this forum!
August 30th, 2010 3:20 pm
Starting a traveling service in these times takes a lot of courage because, even though the recession officially ended a year ago, there are still people who didn't find a place to work or have even given up searching for one
August 20th, 2011 6:58 am
Awesome website…
Howdy dude,This was a wonderful web page for such a complicated subject to talk about….
September 10th, 2011 1:42 am
Awesome website…
Howdy dude, This was a good page for such aintricate issue to focus on….
September 11th, 2011 12:41 pm
Read was interesting, stay in touch…
Wonderful page and simple to understand description. How can I go about getting permission to post section of the article in my future publication?…
September 12th, 2011 9:25 am
Links…
Hi there! Do you know if they make any extensions to help with Seo? I’m hoping to get my blog to rank for some targeted keywords and phrases but I’m not seeing very good success. If you know of any please write about….