We use cookies, including third-party cookies from Google to serve personalized ads through AdSense, to operate this site and understand how it is used. By continuing to browse, you accept this use. See our Privacy Policy and Terms of Use for details, including how to opt out of personalized advertising.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Keep ePHI on Secure Networks, Not Mobile Devices, Recommends OCR
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > Keep ePHI on Secure Networks, Not Mobile Devices, Recommends OCR
eHealth

Keep ePHI on Secure Networks, Not Mobile Devices, Recommends OCR

onlinetech
onlinetech
Share
3 Min Read
2012 Healthcare Data Breach Update
SHARE
2012 Healthcare Data Breach Update

2012 Healthcare Data Breach Update

Of the 425 reported breach events to the OCR (Office of Civil Rights), two-thirds of all large breach cases involved loss or theft of information and more than half of these large breaches involved electronic devices.

2012 Healthcare Data Breach Update

2012 Healthcare Data Breach Update

Of the 425 reported breach events to the OCR (Office of Civil Rights), two-thirds of all large breach cases involved loss or theft of information and more than half of these large breaches involved electronic devices.

While a BAA (business associate agreement) can help a healthcare organization maintain control and insight into privacy and security practices involved with handling their ePHI (electronic protected health information), risks of storing and transporting ePHI are also of concern, as exemplified by the reported 5 million individuals affected by a breach caused by backup tapes being stolen from an employee’s car.

About 1 million have been victims of lost backup tapes in office renovation situations, and 400,000 affected by theft of a laptop from an employee’s car. Desktop computer theft from offices has affected 943,000 more, and 63,000 have been affected by theft of a portable media device from an employee’s car.

More Read

B. Braun Acquires Patent for Wireless Communication Between Medical Devices And Hospital Information Systems
Mobile Health Around the Globe: Aman Telehealth Call Center Increases Access to Care in Pakistan
Delivering Collaborative Breast Cancer Care in the Oncology Medical Home
The Growing Role of Mobile in the Patient Path to Treatment
8 Healthcare Provider Pain Points

What’s the solution to this seemingly prevalent problem with ePHI? Revert to paper records in a healthcare vault with multiple doors and lock combinations? Restrict ePHI to existing only on non-mobile electronics? Demand counter-reform in the face of federal reform with the advent of EHR system implementation?

The answer is fairly simple but often ignored ‘best practice’ advice.

Aside from the common sense lesson of ‘don’t leave your electronics in your car,’ David S. Holtzman from the OCR recommends storing data on a secure network, not a mobile device. Instead of losing data when you lose your phone or laptop, the data should be stored in a HIPAA compliant data center with standardized network security in place.

Sensitive infrastructure, such as servers, power and network should be protected by restricted access. Using an Intrusion Detection Service (IDS) and monitoring can help notify administrators of a potential breach, and give you the tools to resolve an issue, including times and user activity on a server and network.

As a second choice and additional layer of protection, Holtzman recommends encryption to protect the data, with the cost ranking up as minimal compared to breach fines. For a detailed data on the minimum and maximum fines for breaches by type, visit What is a HIPAA Violation?



TAGGED:HITsecurity breach
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

The Administrator's Guide to Auditing Regulated Waste Before an OSHA Inspection -- AI-generated illustration
The Administrator’s Guide to Auditing Regulated Waste Before an OSHA Inspection
Policy & Law
August 31, 2026
What Geographic and Specialty Variation Reveals About How Nursing Compensation Actually Works -- AI-generated illustration
What Geographic and Specialty Variation Reveals About How Nursing Compensation Actually Works
Career Nursing
August 27, 2026
Could Poor Ventilation Be Behind Your Afternoon Headaches?  -- AI-generated illustration
Could Poor Ventilation Be Behind Your Afternoon Headaches? 
Health
August 27, 2026
The Myth That Keeps People Stuck -- AI-generated illustration
The Myth That Keeps People Stuck
Addiction Recovery
August 25, 2026

You Might also Like

negative physician reviews
eHealthSocial Media

Physicians and Negative Online Reviews: Think Before You Sue

April 10, 2013

Crawl, Walk, and Then Run Towards Analytics and Big Data in Healthcare

April 14, 2013
eHealthHealth ReformNewsTechnology

What Will Machine Learning Do With Healthcare In 2020?

December 12, 2019
doctor approachability
eHealth

Debunking the “Unapproachable Doctor” Myth

September 5, 2013
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2026 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?