Live data from Hacker News

Breaches of Unsecured Protected Health Information

ocrportal.hhs.gov

11–20 of 31 posts

Re: Breaches of Unsecured Protected Health Information

#11
post #10

Hint: Don’t press “Archive” or you wont’t be able to sleep at night. Crazy how many breaches have occurred.

I think it's interesting that while there are a ton of breaches, we only know about them because HHS requires breach reporting when it affects over 500 patients. How often is this happening in other industries where such regulations don't exist?

Re: Breaches of Unsecured Protected Health Information

#12
I wonder how many of these are encrypted systems. I see a lot of "theft" and "loss" on that list. I know if I were to lose a system that had PHI on it I would be required to report the breach even if the system had full disk encryption. I'd bet many or most of these are similar.

Re: Breaches of Unsecured Protected Health Information

#13

Electronic health records have been way oversold. Expecting every little medical office to have industrial-grade data protection makes them far more of a liability than they are worth. At best mostly subjective observations, at worst full of outright errors, they're largely useless from a health care perspective let alone for research purposes.

In my (relatively limited) experience, most small medical offices pay for cloud-based EHRs on a subscription basis for this exact reason. Have you observed differently?

With regards to the usefulness of medical records, I don't know enough on the topic to address that point.

Re: Breaches of Unsecured Protected Health Information

#14
post #12

I wonder how many of these are encrypted systems. I see a lot of "theft" and "loss" on that list. I know if I were to lose a system that had PHI on it I would be required to report the breach even if the system had full disk encryption. I'd bet many or most of these are similar.

> if I were to lose a system that had PHI on it I would be required to report the breach even if the system had full disk encryption

According to the Texas Medical Association[0],

> there are only two reasons a lost device may not have to be reported as a breach under the HIPAA Breach Notification Rule: (1) no PHI was on the device, or (2) the PHI is unusable - encrypted with FIPS 140-2 encryption

[0] https://www.texmed.org/HIPAALostLaptop/

Re: Breaches of Unsecured Protected Health Information

#16
post #10

Hint: Don’t press “Archive” or you wont’t be able to sleep at night. Crazy how many breaches have occurred.

I think it's interesting that while there are a ton of breaches, we only know about them because HHS requires breach reporting when it affects over 500 patients. How often is this happening in other industries where such regulations don't exist?

This is the thing. HIPAA is really a gold standard in data security legislation. As terrible as it is (e.g. the fax machine loophole, which is surely put there for lawyers), at least there's something punitive. And other things can be tied to it: grants, FDA can disbar them from collaborating in drug development, etc.

Imagine breach notifications for a company like Facebook. FCC could disbar you from transmitting data over mobile networks.

Re: Breaches of Unsecured Protected Health Information

#17

Earlier quoted context omitted.

I think it's interesting that while there are a ton of breaches, we only know about them because HHS requires breach reporting when it affects over 500 patients. How often is this happening in other industries where such regulations don't exist?

This is the thing. HIPAA is really a gold standard in data security legislation. As terrible as it is (e.g. the fax machine loophole, which is surely put there for lawyers), at least there's something punitive. And other things can be tied to it: grants, FDA can disbar them from collaborating in drug development, etc. Imagine breach notifications for a company like Facebook. FCC could disbar you from transmitting dat…

In California that’s been the law for over a decade. Arguably, California’s breach disclosure law is the reason we know about the vast majority of large breaches we hear about.

Re: Breaches of Unsecured Protected Health Information

#18
post #13

Electronic health records have been way oversold. Expecting every little medical office to have industrial-grade data protection makes them far more of a liability than they are worth. At best mostly subjective observations, at worst full of outright errors, they're largely useless from a health care perspective let alone for research purposes.

In my (relatively limited) experience, most small medical offices pay for cloud-based EHRs on a subscription basis for this exact reason. Have you observed differently? With regards to the usefulness of medical records, I don't know enough on the topic to address that point.

> In my (relatively limited) experience, most small medical offices pay for cloud-based EHRs on a subscription basis for this exact reason

That mostly increases the size of the bucket without much in terms of guarantees of the maintainers of that bucket getting it right.

Re: Breaches of Unsecured Protected Health Information

#19
I care less about health info privacy than identity. When I was a kid, hospital admissions were published in the daily paper. Nobody thought much of it.

The number of people interested in your health is tiny. The number of people interested in your money, and motivated to try to take it from you, is much higher.

Re: Breaches of Unsecured Protected Health Information

#20
post #19

I care less about health info privacy than identity. When I was a kid, hospital admissions were published in the daily paper. Nobody thought much of it. The number of people interested in your health is tiny. The number of people interested in your money, and motivated to try to take it from you, is much higher.

Enjoy: Your medical record is worth more to hackers than your credit card

https://www.reuters.com/article/us-cybersecurity-hospitals/y...

Post reply on HN