ENCRYPTING HEALTHCARE INFORMATION

  • By Paul Rubell
  • 28 Aug, 2014

In an era where information is at our absolute disposal, it is imperative for health care providers to maintain the privacy, security, and integrity of their patients’ most personal medical records. Despite this, patient information continues to be vulnerable to both inadvertent as well as intentional disclosure.

This image is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License.

Recently, two significant data breaches occurred: one by a national urgent care provider, and the other by a health insurance plan. In each case, inadequate technological measures had been taken to protect patients’ records. As a result, the Federal government imposed very substantial financial penalties upon each provider for their violations of the Health Insurance Portability and Accountability Act (HIPAA).

After investigating these security breaches, the Department of Health and Human Services (“HHS”) ruled that every healthcare business is required to encrypt its laptops and mobile devices to comply with the law, and to avoid imperiling patients’ privacy rights by placing them in harm’s way.

The whopping cash settlements that Concentra Health Services and QCA Health Plan, Inc. were required to pay should be an eye-opener to other healthcare providers, covered entities, and business associates that have not yet awoken to the government mandate to encrypt the data that resides on all of their laptops and mobile devices.

HHS enforces HIPAA’s two cornerstones of healthcare data integrity in America: the Privacy Rule and the Security Rule. The Privacy Rule protects the privacy of an individual’s personal health information (PHI). The Security Rule sets a national standard to secure electronic PHI. Together, these rules are designed to ensure that healthcare providers deploy sophisticated information storage and transmission technologies to prevent security breaches.

Encrypting data on mobile devices is too often overlooked by healthcare providers. It is much easier to secure a hard-wired network than a wireless mobile network. For this reason, the portability of laptops and mobile devices can put patients’ health information in jeopardy.

This gaping security hole became apparent after unencrypted laptops were stolen from both Concentra and QCA.

In Concentra’s case, a thief stole a laptop from a physical therapy center. An investigation by HHS revealed that Concentra was aware that none of its mobile devices used any encryption technology. As a result, Concentra agreed to pay $1,725,200 as a “resolution amount”. It was also required to adopt and deploy a corrective plan to avoid or mitigate future security breaches.

In contrast, QCA’s security breach involved a different but equally important compromise of patient data[2]. An unencrypted laptop was stolen from a QCA employee’s car. The laptop contained personal health information concerning 148 patients. Although QCA had encrypted all of its mobile devices, the government determined that QCA’s efforts did not meet the national minimum requirement set forth in HIPAA’s Security Rule. The federal government compelled QCA to pay $250,000 as a “resolution amount”; to develop and implement a Corrective Action Plan to enhance its security measures; and to retrain its workforce.

In both of these enforcement actions, HHS imposed draconian financial penalties to send a strong signal to the healthcare community to use best practices to secure PHI information, and to treat PHI with the highest punctilio of care.

In light of the panoply of information that is stored on today’s portable electronic devices, providers, and others in the healthcare industry must take meaningful technological steps (including encryption) to prevent sensitive patient information from falling into the wrong hands

By Paul Rubell November 2, 2018
Cyberliability and privacy are very important to the food, beverage and hospitality industries. Today the industry faces many 21st century risks. Paul Rubell addresses these risks.
By Paul Rubell July 16, 2018
by Paul Rubell, Esq. Every company in the world that has a Facebook social media page may be subject to the European Union’s newly-enacted GDRP (General Data Protection Regulation) and the chokehold of EU law enforcement. Many businesses wrongly believe they are not collecting personal data via their Facebook pages but that is likely not […]
By Paul Rubell August 30, 2017
  by Paul Rubell, Esq. A 36-year old Chinese national from Shanghai has been indicted by a federal court in California for transmitting malicious software tools to companies located in the United States. Yu Pingan was arrested on August 27, 2017 when he arrived in the United States to attend a conference.  Pingan used the online pseudonym […]
By Paul Rubell April 29, 2017
Taking videos is a form of expression that is guaranteed by the Bill of Rights. However, even free speech has constitutional limits. For instance, if you shout "fire" in a crowded theater, you can be arrested and the 1st Amendment will not protect you.
By Paul Rubell April 17, 2017
by Paul Rubell, Esq. Can your business survive a massive data breach? If your business stores, backs up or syncs its data to the cyber cloud, take note. Apple’s iCloud is currently the subject of ransomware. As you will read, the moral to this article is that confidential business data, trade secrets, customer lists and […]
By Paul Rubell April 17, 2017
by Paul Rubell, Esq. Information is the currency of 2017. For this reason it is mission-critical to keep data currency safe, secure and private. Just as gold bricks should be stored in a physical safe, data needs to be kept secret electronically. Passwords are the key to enter the digital vault. Strong passwords are designed […]
By Paul Rubell March 16, 2017
Enjoy my newest article. You can read more on my blog at paulrubellblog.wordpress.com.
By Paul Rubell March 13, 2017
by Paul Rubell, Esq. Witness today’s risks of cyber crime.  Hackers, bad actors and foreign governments have long had the ability to assault our Nation. Current events have opened citizens’ eyes to the reality of the cyber threat. It is remarkable how the public has either forgotten or turned a blind eye to well-known security […]
By Paul Rubell March 3, 2017
By Paul Rubell, Esq. Internet users have been suddenly stripped of an important source of privacy protection.  On March 1, 2017, the Federal Trade Commission (FTC) and Federal Communications Commission (FCC) abruptly suspended the net neutrality rules that had been scheduled to go into effect on March 2nd.  Internet users in the United States have […]
By Paul Rubell February 16, 2017
by Paul Rubell, Esq. It is remarkable that many companies do not know the vastness of private information they obtain from their social media and website.  It is essential for every business to understand its legal responsibility to protect their customers’ personal information. OLD NEWS:  Web browsers can follow your voyage through the Internet. Firefox, Internet […]
More Posts