By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
    Health
    Healthcare organizations are operating on slimmer profit margins than ever. One report in August showed that they are even lower than the beginning of the…
    Show More
    Top News
    stress disorder
    5 Ways To Manage Post-Traumatic Stress Disorder
    October 27, 2021
    Medical device classification and development strategies
    Medical device classification and development strategies
    April 5, 2023
    varicose veins
    Varicose Veins Prevention: 3 Lifestyle Changes to Make Right Now
    May 1, 2022
    Latest News
    How Probate Planning Shapes the Future of Your Estate and Family Care
    July 17, 2025
    Beyond Nutrition: Everyday Foods That Support Whole-Body Health
    June 15, 2025
    The Wide-Ranging Benefits of Magnesium Supplements
    June 11, 2025
    The Best Home Remedies for Migraines
    June 5, 2025
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
    Policy and Law
    Get the latest updates about Insurance policies and Laws in the Healthcare industry for different geographical locations.
    Show More
    Top News
    ACA education
    What Americans Don’t Know About the Affordable Care Act
    April 5, 2018
    Image
    Mobile Health Around the Globe: 10 Best Tools to Boost mHealth Initiatives in Africa: Part I
    September 4, 2012
    health insurance premiums
    What Will You Pay for Insurance Under ObamaCare?
    September 13, 2013
    Latest News
    How IT and Marketing Teams Can Collaborate to Protect Patient Trust
    July 17, 2025
    How Health Choices and Legal Actions Intersect After an Injury
    July 17, 2025
    How communities and healthcare providers can address slip and fall injuries with legal awareness
    July 17, 2025
    Let Your Lawyer Handle the Work Before You Pay Medical Costs
    July 6, 2025
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: The Iceberg Waiting for Your Health Care Data
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > Medical Records > The Iceberg Waiting for Your Health Care Data
eHealthMedical Records

The Iceberg Waiting for Your Health Care Data

David Harlow
David Harlow
Share
6 Min Read
SHARE

Iceberg_ccThe Heartbleed web security exploit was first publicized several weeks ago.

Iceberg_ccThe Heartbleed web security exploit was first publicized several weeks ago. In the time since then, numerous web-based services have let their users know (some more clearly than others) whether and how their data security was compromised by this OpenSSL flaw that has been open for about two years. This is one flaw, one exploit, but on a scale of 1 to 10, it has registered as an 11 on our collective consciousness. Fred Trotter notes in the MIT Technology Review that other similarly worrisome exploits do not get our attention in the same way, and that more health data leaks are likely in our future. He also cites others’ observations that many health IT vendors are not currently equipped to respond effectively to such exploits in a timely manner.

Everyone loves to hate HIPAA (including those who can’t spell it correctly). The core of the privacy and security protections in HIPAA (including the HITECH Act updates) is directed at improving the baseline of patient control (over who has the right to see which pieces of personal health information) so that we can all have greater confidence in EHR systems and related electronic systems handling our health care data. Rather than continuing to heap abuse on HIPAA, I think that critics should turn to addressing the underlying problems of our worldwide cloud infrastructure that, for all the benefits it enables, has its warts. Financial and health care data are regularly stolen on line, and health care records fetch a premium on the black market thanks to the richness of their data. The FBI shares Fred’s perspective regarding the likelihood of additional exploits targeting the health care sector (particularly given the January 1, 2015 target date for Meaningful Use compliance), so this is not the last we’ll be hearing about large-scale security exploits.

The deadline to transition to EHR is January 2015, which will create an influx of new EHR coupled with more medical devices being connected to the Internet, generating a rich new environment for cyber criminals to exploit. According to open source reporting from SANS, Ponemon, and EMC²/RSA, the health care industry is not technically prepared to combat against cyber criminals’ basic cyber intrusion tactics, techniques and procedures (TTPs), much less against more advanced persistent threats (APTs). The health care industry is not as resilient to cyber intrusions compared to the financial and retail sectors, therefore the possibility of increased cyber intrusions is likely.

FBI Cyber Division Private Industry Notification 140408-009. (Updated later; update not available.)

More Read

Image
HealthCare Social Media: What Makes Sense?
What Do Patients Want From Social Media? And What Should They Want?
Enhance Brand Awareness Through Meme Marketing
Google Glass – Day 2
#SXSW, #HIMSS13 and Healthcare Innovation

So what is to be done?

First, come to terms with the fact that privacy and security are not absolutes. The sooner you do, the happier you’ll be. As a family member of mine used to say, “It is what it is.”

Second, keep an eye on The Wall of Shame starting in early June. Health care data breaches experienced by covered entities under HIPAA involving 500 or more individuals must be reported to OCR within 60 days of discovery, and are posted there. (Breaches including fewer than 500 individuals are to be reported within 60 days of year-end.) So far, the only Heartbleed breaches we’ve heard about involve Canadian social security numbers and a newspaper. Information about breaches tied to Heartbleed may turn out to paint an interesting picture of health IT vendors serving covered entities. (I don’t think that the fact that the Heartbleed exploit was available for two years is, in and of itself, a breach worthy of notification. If it were, OCR could be deluged with breach notifications.)

Third, don’t just give up. Do your part to ensure that health data are kept as private and secure as possible. Policies and procedures should be in place — and should be followed (yeah, that) — to minimize the likelihood of a damaging breach, and the effect of a breach when it occurs. Take warnings to heart, and act on them in a timely fashion.

In the face of all these questions about inappropriate access to information in health records, concerns about the accuracy of data input into EHRs was recently identified as the leading concern consumers have about EHRs. So there are concerns about data coming into the system as well as concerns about data coming out of the system.

The industry has a lot of work to do to assure stakeholders that data privacy and security, as well as data integrity, are well in hand.

What are you going to do?

TAGGED:data securityEHRHealth DataHIPAApatient data
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5kFollowersLike
4.5kFollowersFollow
2.8kFollowersPin
136kSubscribersSubscribe

Latest News

Grounded Healing: A Natural Ally for Sustainable Healthcare Systems
How IT and Marketing Teams Can Collaborate to Protect Patient Trust
Global Healthcare Policy & Law
July 17, 2025
paramedics in surgical gloves and masks
How Health Choices and Legal Actions Intersect After an Injury
Health care
July 16, 2025
a woman giving a key
How Probate Planning Shapes the Future of Your Estate and Family Care
Health
July 16, 2025
a woman with kinesio tapes on her back arm
How communities and healthcare providers can address slip and fall injuries with legal awareness
Health care
July 16, 2025

You Might also Like

How to Choose the Best Chiropractic Software

December 8, 2020
wellness
eHealthPublic HealthWellness

Sobering Report for Health of 40+

May 14, 2013
Mobile Health

Meet the Bone Ninja, an iPad App That Analyzes Bone Deformities!

November 28, 2012
eHealth

7 Steps For Successful EHR Implementation

October 23, 2018
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?