Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Wednesday, April 10, 2013

3 healthcare laptops stolen, patient data likely compromised

It seems like every month (or week) there is another story about a lost or stolen healthcare laptop containing patient data. The latest one that caught my attention was this one from Burlington NC where: Staff at Hospice Palliative Care of Alamance Caswell and LifePath Home Health notified around 5,370 current and past patients, or their next of kin, about a possible information breach stemming from a Feb. 24 break-in.

What's interesting is that the story reports that "most" of the data on the laptops were encrypted, but emails containing certain elements of patient health data (personal health information) were not encrypted, so some level of patient data was potentially compromised.

So, what's the answer to these health data breach challenges stemming from laptop theft or loss? Encrypt everything? Don't store any PHI on a mobile computer? Lock down every device? Virtualization? All of the above?

Wednesday, January 2, 2013

Another unencrypted hospital laptop gets stolen (and compromises information on 29,000 patients)

Isn't it hard to believe that hospitals are still using unencrypted laptops that contain personal health information (PHI). Most enterprise-level laptops come with fairly robust encryption solutions these days. But, if you're still using an older laptop running Windows XP, your data may not be encrypted.

According to this story on Healthcare IT News, Gibson General Hospital in southwest Indiana reported a data breach that affected 29,000 patients when a hospital laptop was stolen from an employee's home.

Monday, June 15, 2009

Will Cloud Computing Improve EHR Data Security?


As the government pushes for electronic health records (EHRs), many people remain concerned about data security. There have been many reports over the last year about stolen laptops and compromised patient data. Should such critical data reside on a portable machine like a laptop, tablet, or ultra-mobile PC?

Will cloud computing improve EHR data security? If sensitive data is never stored on a laptop, then if the laptop gets stolen, that patient information should be safe as long the person who stole the laptop isn't able to connect with to the health record database. I suppose that if a theif (or hacker) really wanted to get access ot the health record database, he (or she) would not necessarily need a stolen laptop (unless the laptop contains some critical security information, access codes, etc.).

So what's the solution? How can we ensure that electronic healthcare data is secure? Will all hospitals eventually rely on cloud computing? Is cloud computing the answer? Or, do many of the same risks and limitations apply? Maybe the answer is to focus on better data encryption.