Another Day, Another Security Breach

by | Apr 14, 2008

The Wall Street Journal’s Health Blog has a post this morning highlighting another breach in medical record security, this time some 50,000 records or so at New York Presbyterian Hospital/Weill Cornell Medical Center.

What is surprising here (and then again maybe not) is that it appears that medical records themselves (patient history & treatment(s)) were not the objective of the ID theft, but those tried and true bits of information such as name, SS number, addresses, etc. that there is already a market. Maybe all the concerns about the theft of medical information is not as big an issue as there may be little interest in such information among thieves – at least I haven’t heard of any examples to date where this information has ben used in a nefarious manner. Unless of course you happen to be Brittany Spears, Farrah Fawcett, George Clooney or some other celebrity, for which we all know the National Enquirer will pay a princely sum for such info.

Concern about privacy and security of medical records is an issue, no doubt, but what this example shows is that breaching such is relatively easy to do and maybe the public should be more concern with the privacy and security practices within medical practices than what Google, Microsoft or other companies looking to provide consumers tools to manage their own medical records are doing. We may indeed find that the latter are indeed more secure than the former.

4.15.08
Note: Going through some older emails, found this story as well from Georgia on ZDNet where some 71,000 records were exposed for several weeks due to some absolutely stupid and clumsy work.  Until people are slapped with some very serious fines for making such blunders, these occurrences will become increasingly commonplace.

0 Comments

Trackbacks/Pingbacks

  1. ICMCC Newspage » Blog Archive » Another Day, Another Security Breach - [...] some 50,000 records or so at New York Presbyterian Hospital/Weill Cornell Medical Center.” Article John Moore, Chilmark Research, 14…
  2. Lots of Press Today on PHRs - Some Good, Some Bad « Chilmark Research - [...] also have to have at least one reference to some privacy breach at a hospital - there are certainly…
Submit a Comment

Your email address will not be published. Required fields are marked *

Related Content

HIMSS24: Back to Form but Haunted by Change Healthcare

HIMSS24: Back to Form but Haunted by Change Healthcare

Good luck trying to get noticed for anything other than AI or cybersecurity HIMSS24 was the first HIMSS national conference that I will have missed since I first attended in 2012. It felt weird not to be there with all my friends and colleagues, and I certainly missed...

read more
ViVE 2024: Bridging the Health 2.0 – HIMSS Gap

ViVE 2024: Bridging the Health 2.0 – HIMSS Gap

Workforce / capacity issues and AI – and where the two meet – are still the two biggest topics on clinical executives’ minds right now at both ViVE 2024 and HAS24. Probably the first time I’ve seen the same primary focus two years in a row – historically we’ve always seen a new buzzword / hype topic every year…

read more
Powered By MemberPress WooCommerce Plus Integration