
How Employees, Patient Data Create Risk for Medical Practices
A recent inside-job data breach incident reminds us why we need to take necessary precautions.
HIPAA and financial data present an ongoing asset-protection issue for physicians and medical practices. This week we take a look at a specific exposure suffered by up to 40,000 (yes, 40,000) patients of one Arizona medical practice and some simple precautions that may help your practice avoid the same exposure.
Recent
What Could Have Helped?
1. Cyber liability insurance. We’ve previously covered a variety of vital forms of commonly overlooked medical-practice insurance policies, and discussed the importance of
• Any actual losses incurred by patients;
• The expense of formal notification of over 40,000 patients;
• Ongoing remediation including credit monitoring and credit repair for those actually exposed;
•Reputational damage and loss of patient trust.
I’d also add that EPLI, or employment practices liability insurance, could prove useful in such a situation. While much of my previous coverage of this vital issue has centered on its value in protecting a doctor’s office from an employee lawsuit, the best policies often include riders that protect the employer from the liability associated with the unsanctioned actions of an employee as well.
2. Background checks and
I can hope some phones are ringing on these issues at billing companies across the country later this week.
Related to this article









