Showing posts with label PHI. Show all posts
Showing posts with label PHI. Show all posts

Tuesday, July 15, 2014

Who Knows Your Business?: Your Digital Health Footprint






Thanks to the California Healthcare Foundation for this informative info-graphic on how third parties may be tracking your online activities.  Perhaps now's the time to reconsider Google's Incognito browsing option.

Infographic for Your Data: It's Out There

Wednesday, September 11, 2013

Mobile Health, Meet Your Biggest Obstacle: HIPAA.

More and more, doctors are using smartphones, iPads, Dropbox and other mobile devices and cloud storage to share electronic patient health information ("ePHI") with colleagues and to diagnose. In fact, health care reform incentivises the increased use of patient data to improve patient outcomes as one avenue to decrease health care spending.

Technology can facilitate more expedient second opinions, generate better patient outcomes with fewer resources and, therefore, save money.  However it can also expose providers and their business associates with huge fines if usage of this technology violates HIPAA.

Recent reports by Manhattan Research found that a 9% increase in physician smartphone use in 2010 resulted in a 32% increase in data breaches.  Each data breach carries a $50,000 fine, that can be increase drastically if the breach is not remedied.

What Is HIPAA and Who Does it Affect? 

HIPAA is short for the Health Insurance Portability and Accountability Act.  Title I of HIPAA protects health insurance coverage for workers and their dependants when they change or lose their jobs. Title II establishes national standards for electronic health care transactions to protect the privacy of individually identifiable health information that is "created, received, used, or maintained" by a covered entity or its business associate.  The regulations associated with Title II of HIPAA govern the recent increased use of smart phones and cloud storage of ePHI.

A covered entity is a health care provider, health plan, or health care clearninghouse that transmits any information in an electronic form.  A business associate is an individual or business with whom the covered entity engages to help it carry out its health care activities and functions.  Entities that do not meet the definition of either covered entity or business associate do not have to comply with HIPAA.

Common Causes of HIPAA Violations:

CauseIn 2010In 2011
Lost or stolen computing device41%49%
Third-party problem34%46%
Unintentional employee action45%41%
Technical glitch31%33%
Criminal attack21%30%
Malicious insider15%14%
Intentional nonmalicious employee action10%9%

What Can Physicians Do?


  1. Safeguard Mobile Devices
    • Encrypt, encrypt, encrypt. Software is readily available that will encrypt smartphones and mobile devices.  Encryption means that information is sent in non-readable form, and must be unlocked by a key on the device of the person wishing to view it.
    • Conduct periodic risk assessments. Document which devices are being used to transmit ePHI, whether proper encryption exists, and what physical protections are in place to secure ePHI.
    • Password Protect All Devices. The lack of authentication on mobile devices presents a risk that any user of the device could access ePHI stored on the device 
  2. Set policies on mobile use in your practice or at your hospital.  Pay special attention to security measures, such as antivirus software and password protection.  Small physician practices who don't have technology professionals thinking through these issues for them, like hospitals do, should sit down and review their technology policies.  Consider quarterly training meetings for physicians and staff to reinforce these policies.
  3. Have a Secure Wi-Fi Connection.  Mobile devices that use public Wi-Fi or unsecure cellular networks to send and receive information risk exposing ePHI. Unless mobile device users connect to a secure website to transmit data or connect using a VPN ("virtual private networking"), which encrypts data to and from the mobile device, there is a risk ePHI could be compromised.

Wednesday, August 21, 2013

Is Your Xerox Machine Violating HIPAA?

The next time you go visit your doctor's office and notice an employee using the office copy machine, consider the type and volume of data that has crossed through that device -- consider how many patients' protected health information (PHI) is stored in the copier hard drives.

This is a consideration that New York-based Affinity Health Plan, Inc. failed to make before returning its leased copiers back to the leasing company.  As luck would have it, CBS Evening News was the subsequent purchaser of those copiers.  Much to their surprise, CBS discovered the PHI of 344,559 individuals on the copier's hard drive.  

Affinity settled the claim of the alleged massive HIPAA breach for $1,215,780 and the promise to institute a corrective action plan.  

"Electronic equipment with any type of memory or storage media has the capacity to retain data passed through it long after the data is believed to be removed or deleted." (Kevin Alonso, Esq., Arant Boult Cummings LLP, Nashville, TN.)  In light of the risks that newer technologies pose to the privacy and security of PHI, covered entities (health care providers, health plans or health care clearinghouses who transmit any information in electronic form), and now business associates (one who contracts to help a covered entity carry out its health care activities and functions), must do more than empty their computers' Recycling Bins in order to remain HIPAA compliant.

Tuesday, July 23, 2013

GINA Claims Rise Against Employers

In 2008, The Genetic Information Nondiscrimination Act (GINA) was enacted to include genetic information in the definition of personal health information.  GINA prohibits health insurers and employers from using an individual's genetic information to raise health insurance premiums or to make decisions on hiring and firing of employees. The Wall Street Journal reported that employee claims against employers for GINA violations have consistently risen since 2008, totaling 762 as of last November.

What Employees Should Know
Employees who believe their employer has violated GINA may file a charge of discrimination with the Equal Employment Opportunity Commission (EEOC).  The charge must be filed within 180 days. After the charge is filed, the EEOC will conduct an investigation.  If the EEOC finds a violation, they will pursue the case themselves through either mediation with the employer or by filing a lawsuit themselves. However if the EEOC finds no violation or cannot reach a settlement, they will issue the employee a "Right to Sue" letter, giving the employee permission to file a claim in court.

What Employers Should Know
Employers must be extremely careful about how they seek employee genetic information.  The ACA offers new incentives for employers to offer wellness programs to employees in order to improve health and drive down health insurance costs.  Sometimes it may be helpful for an employer to gather information on employee health information, including genetic information, in order to decide which wellness programs to implement.  However if an employer or its agent (someone working on behalf of the employer) asks about the health of an employee or a member of their family, that inquiry could violate GINA and subject the employer to fines by the EEOC if the employer uses that information to discriminate against the employee. Employers who wish to utilize company questionnaires to help shape their wellness programs should stress that employee participation is optional and ensure employees understand they are free to not answer questions. Employers can familiarize themselves with the charge handling process on the EEOC website.