Quantcast
Business Resources
by Category








Try our "Virtual Buyers Guide!"
-flip through the pages!
-search by keyword!
-download to your desktop!
-forward to a colleague!
< Home  < Articles  < Article Details

 
 
Security: Protect Your Practice and Sleep Better
Identity theft is quickly becoming the nation’s No. 1 crime. Protect your practice’s sensitive data.
By Barbara A. Gabriel

“Paper is an insecure form for storing patient data, which is at best locked behind doors or within file drawers,” says Stephen Moulton, director of product development for Innovative Card Scanning, a developer of scanning devices and software for hospitals and practices. “Paper can be copied, stolen, taken without you even knowing it, as well as lost or misplaced, which could give you the feeling that it was stolen if it is out of your control or possession.”

Thomas Weida, medical director of the University Physician Group at Fishburn Road in Hershey, Pa., says that in his previous paper-based office, he recalls an instance in which a file clerk easily pulled a specific paper chart she was unauthorized to view — her ex-husband’s. The practice fired the employee when it learned what she’d done, but not before she shared the stolen information with others. Of course, the practice also had to inform the ex-husband about the incident. Certainly, this was nothing to call a press conference about, but it was a privacy violation for which the practice was responsible, nonetheless.

“From my personal experience,” says Weida, “the protection for inadvertent or malicious access to charts is better electronically than it used to be when we had paper charts. With paper charts, anyone could go to the chart rack, open it up, and look at the full chart. If they were really slick people from outside, they could throw a stethoscope around their neck and put on a white coat and flip through records. … I would say that the information is more secure now than it was before even though more people have the potential to access it, and that’s because we can track every access.”

Electronic charts may be better protected than paper, but they’re hardly failsafe. Indeed, Weida reports that his current practice, which uses an EMR, also experienced an incident in which a woman snooped through her ex-husband’s medical records. In this case, recalls Weida, “the initial excuse was that she needed his new address. But our IT department was able to look at that record, realize that she opened it more than once, maybe about five or six times, and also realized that she was not just opening demographic data. She was terminated. We have a very strong policy on that here. You only get one strike, and you’re out.”

One significant difference between the incidents: The EMR-based practice didn’t have to find out through the grapevine about the security breach or launch a he-said/she-said investigation. The computer kept a record of each accessed file. Another difference: The EMR practice was able to implement additional security protocols to prevent further breaches.

The office network now has a built-in mechanism to ensure that only those authorized individuals can view sensitive patient information.

The bottom line: Both paper and electronic charts are vulnerable to theft or loss. But while paper records carry their inherent vulnerabilities, a stolen or improperly accessed laptop can reveal much more patient data than a single paper file. Although the healthcare industry has in general been slower to adopt new technologies, the electronic age has dawned, and there’s no turning back. You can no longer operate an efficient practice without some type of software containing patient data. And like most new technologies, these capabilities bring with them new opportunities for criminal activity.

An ounce of protection

Still, most people give little thought to the consequences of stolen hardware until it happens to them. When Mark Anthony LaPorta, an internist in Miami, purchased a software-based theft protection service for his new laptop a couple of years ago, it was little more than an afterthought. His fancy new computer cost him $2,000, and paying an additional $105 for three years’ theft protection seemed to make sense. “I was going to be carrying a big brand-new laptop around,” says LaPorta, “so I thought, ‘Let’s protect it and see what happens.’ I’m amenable to that sort of thing. … I thought ‘Oh well, after three years, I’ll forget about it; nothing will happen.’”

Turns out he didn’t have to wait long before something did happen.

A few weeks later, while traveling on a speaking circuit, LaPorta received a call from his local police, informing him that his house had been broken into. He was told that nothing appeared to be missing, but when he returned home he discovered that the shiny new computer he had left sitting on his coffee table was gone.

So LaPorta reported the theft to the vendor of the Computrace LoJack software he’d purchased. At that point, the vendor placed Computrace’s monitoring center on alert for the missing computer. When the thief logged onto the Internet on LaPorta’s stolen laptop, the computer “called” the monitoring center every 15 minutes, allowing Computrace to track its whereabouts.

A week later, LaPorta received an e-mail from his vendor telling him that his computer had “called home.” Computrace’s own “recovery team” was activated and worked with LaPorta’s local law enforcement and his Internet Service Provider to obtain the necessary subpoenas and warrants to apprehend the thief and recover the computer. A few days later, LaPorta’s vendor restored the stolen laptop to the police station in his home town. All he had to do was pick it up.

When LaPorta booted up his retrieved laptop, none of his data was missing: “The software I purchased puts itself on the hard drive, buried down deep inside of the computer, so even if the thief tried to wipe the drive to start over after stealing it, he couldn’t.”





Additional Resources
View more articles from the June 2008 issue

View more articles related to Technology

View more articles related to Operations

 
 


 

Home | Contact Us | Subscribe  | Site Map | Disclaimer | Privacy Policy | Change Zip Code
CancerNetwork | ConsultantLive | Diagnostic Imaging | Psychiatric Times
 SearchMedica

 Subscribe to Physicians Practice RSS

Connect with Physicians Practice on

           

Copyright © 2010 UBM Medica LLC,, a United Business Media company.
 
ADDITIONAL ONLINE RESOURCES FROM UBM MEDICA
Featured Resources > Pediatric Asthma > ASCO Conference Report > APA Conference Report > Consumer Healthcare Information > Patient and Caregiver Resource
CancerNetwork > Cancer diagnosis, treatment, and prevention > Podcasts for Oncologists > Cancer Patient Resources > Oncology Areas of Confusion > Oncology News > Cancer Management Handbook > Oncology E-Learning > Oncology Practice Management
Consultant Live > Practical Clinical Advice > Medical Photoclinic > Diagnosing and Treating H1N1 flu (swine flu) > Primary Care Conference Reports > Primary Care CME
Diagnostic Imaging > Medical Imaging News and Features > Medical Imaging and Radiology White Papers > Radiology Conference Reports > Radiology Special Reports > Radiology Careers > Radiology Net Seminars > Imaging Trends and Advances > CT Dose Issues and Articles > Molecular Imaging Articles
Psychiatric Times > Psychiatry Careers > Psychiatric News and Special Reports > Psychiatric Clinical Scales > Psychiatric Times Blog > Psychiatry Career Opportunities > Psychiatry CME > DSM-V
Physicians Practice > Practice Management > Practice Management Webinars > Medical Buyers Guide > Medical Coding > Practice Management Tools > Practice Management Podcasts > Today's Practice - Practice Management Resource
SearchMedica > Professional Medical Search > Medical Search Tips Newsletter > Medical Search News



 
 
-- Advertisement --


In Summary
Identity theft is fast becoming America’s No. 1 crime. Physician offices that maintain large databases populated with patients’ personally identifiable information are responsible for keeping that data secure. How can you best cover your bases?

  • Don’t revert back to paper files. They are just as vulnerable — or more — to theft or loss.

  • Invest in affordable theft-detection services that may be able to retrieve lost or stolen patient data.

  • If you electronically transmit patient data to a third party, such as a claims processing firm, do your best to ensure that transmission is encrypted on both ends.

  • Physically secure all of your office’s hardware when closing your clinic at the end of each day.

  • If applicable, learn about the security measures your landlord provides your office building.

  • Consider purchasing new hardware that goes beyond password protection.

  •  
    Read More About It
    To stay current on trends in identity theft and to learn how to better protect your data, check out these resources:

  • Learn five easy steps you can take to keep your practice’s sensitive files from prying eyes by reading “Do You Know Where Your Data Is?

  • The Identity Theft Resource Center is a nonprofit organization dedicated exclusively to the understanding and prevention of identity theft. It maintains a comprehensive database updated daily of all detected security breaches in the U.S.

  • What are your legal responsibilities if you do experience a data breach? Go to Perkins Coie for information on each state’s legislation on security breach notification.