We use cookies, including third-party cookies from Google to serve personalized ads through AdSense, to operate this site and understand how it is used. By continuing to browse, you accept this use. See our Privacy Policy and Terms of Use for details, including how to opt out of personalized advertising.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Keep ePHI on Secure Networks, Not Mobile Devices, Recommends OCR
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > Keep ePHI on Secure Networks, Not Mobile Devices, Recommends OCR
eHealth

Keep ePHI on Secure Networks, Not Mobile Devices, Recommends OCR

onlinetech
onlinetech
Share
3 Min Read
2012 Healthcare Data Breach Update
SHARE
2012 Healthcare Data Breach Update

2012 Healthcare Data Breach Update

Of the 425 reported breach events to the OCR (Office of Civil Rights), two-thirds of all large breach cases involved loss or theft of information and more than half of these large breaches involved electronic devices.

2012 Healthcare Data Breach Update

2012 Healthcare Data Breach Update

Of the 425 reported breach events to the OCR (Office of Civil Rights), two-thirds of all large breach cases involved loss or theft of information and more than half of these large breaches involved electronic devices.

While a BAA (business associate agreement) can help a healthcare organization maintain control and insight into privacy and security practices involved with handling their ePHI (electronic protected health information), risks of storing and transporting ePHI are also of concern, as exemplified by the reported 5 million individuals affected by a breach caused by backup tapes being stolen from an employee’s car.

About 1 million have been victims of lost backup tapes in office renovation situations, and 400,000 affected by theft of a laptop from an employee’s car. Desktop computer theft from offices has affected 943,000 more, and 63,000 have been affected by theft of a portable media device from an employee’s car.

More Read

Image
Exergaming: Breaking Down the Walls of Social Isolation While Improving Health
Portals, Access, and Engagement: Patients Are Demanding It [INFOGRAPHIC]
Despite the Penalties, Physician Visit Innovation Is Progressing
Time for some healthcare New Year’s resolutions
Virginia Telehealth Summit – Takeaways

What’s the solution to this seemingly prevalent problem with ePHI? Revert to paper records in a healthcare vault with multiple doors and lock combinations? Restrict ePHI to existing only on non-mobile electronics? Demand counter-reform in the face of federal reform with the advent of EHR system implementation?

The answer is fairly simple but often ignored ‘best practice’ advice.

Aside from the common sense lesson of ‘don’t leave your electronics in your car,’ David S. Holtzman from the OCR recommends storing data on a secure network, not a mobile device. Instead of losing data when you lose your phone or laptop, the data should be stored in a HIPAA compliant data center with standardized network security in place.

Sensitive infrastructure, such as servers, power and network should be protected by restricted access. Using an Intrusion Detection Service (IDS) and monitoring can help notify administrators of a potential breach, and give you the tools to resolve an issue, including times and user activity on a server and network.

As a second choice and additional layer of protection, Holtzman recommends encryption to protect the data, with the cost ranking up as minimal compared to breach fines. For a detailed data on the minimum and maximum fines for breaches by type, visit What is a HIPAA Violation?



TAGGED:HITsecurity breach
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

The Administrator's Guide to Auditing Regulated Waste Before an OSHA Inspection -- AI-generated illustration
The Administrator’s Guide to Auditing Regulated Waste Before an OSHA Inspection
Policy & Law
August 31, 2026
What Geographic and Specialty Variation Reveals About How Nursing Compensation Actually Works -- AI-generated illustration
What Geographic and Specialty Variation Reveals About How Nursing Compensation Actually Works
Career Nursing
August 27, 2026
Could Poor Ventilation Be Behind Your Afternoon Headaches?  -- AI-generated illustration
Could Poor Ventilation Be Behind Your Afternoon Headaches? 
Health
August 27, 2026
The Myth That Keeps People Stuck -- AI-generated illustration
The Myth That Keeps People Stuck
Addiction Recovery
August 25, 2026

You Might also Like

In Expanded Medical Systems, Video Bridges The Divide
eHealth

In Expanded Medical Systems, Video Bridges The Divide

April 7, 2018

3 Ways to Adopt Health IoT for Better Care

April 1, 2016
Image
eHealthWellness

Is Design Important in Healthcare?

June 23, 2014
paramedic software
eHealthMedical Records

4 Practical Reasons You Need an Efficient EMS ePCR Software

July 8, 2021
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2026 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?