Better Health: Smart Health Commentary Better Health (TM): smart health commentary

Article Comments

Security Of Patient Records: The Weakest Link

The Queen of Soul famously wailed about being a link in a “chain of fools.” The lead story in the August 13th Boston Globe tells us about another sort of link in the chain — the weakest link in the chain of custody of patient records.

In brief, a pathology billing service bought out by another service apparently dumped all records more than a year old in a town dump. A Globe photographer taking out his own trash noticed that the paper records (which he was looking at because he thought they ought to be recycled rather than dumped) had identifiable patient data and represented at least four hospitals from across Eastern Massachusetts. Clearly, these records ought to have been shredded or otherwise destroyed before disposal.

Assuming they had some airtight contracts in place, the hospitals involved may well be looking to the seller of the billing service in this case to reimburse them for costs of:

- Identifying the patients involved in this data breach

- Notifying affected patients of the breach

- Providing credit monitoring services to affected patients

- Any damages incurred by patients

- Any fines incurred by the hospitals

Under the HITECH Act’s “Son of HIPAA” rules, the hospitals could be on the hook to the federales for up to $1.5 million in fines each as a result of this incident, and the state AG could get in on the action as well, filing suit on behalf of the affected Massachusetts residents and seeking to ensue that proper procedures are in place.  There may also be a violation of the state data security law here as well.  Massachusetts has a particularly stringent data security law on the books that took effect within the past year, and not all affected businesses have come into compliance.  The AG may be on the prowl for a few high-profile cases, like this one, in which to levy substantial fines and convince the laggards that compliance would be more than worth their while.

The natural question to ask, given the facts of this case, is: What would a meaningful user do?

With the ink barely dry on the meaningful use final rule, and the usual suspects lined up for and against the proliferation of EHRs, it seems clear that the use of electronic health records would have eliminated the problem of plain text paper records flapping in the wind at the Georgetown town dump.  However, their use would not have eliminated the problem of covered entity and contractor bad judgment, if that is in fact the issue in this case.

Digitizing records does not eliminate covered entities’ responsibilities with respect to the operation of their business associates and subcontractors.  As we all know, the latest and greatest laws and regs make covered entities fully responsible for the deeds and misdeeds of their business associates and subcontractors.  (True even if the breach notification final rule is on ice for a while.)  Thus, it becomes imperative for covered entities to have a much better handle on their associates’ understanding of applicable law, on their policies and procedures, and on the actual implementation of their policies and procedures.

Auditing business associate and subcontractor compliance with HIPAA and other privacy laws is probably worth the expense. The costs saved include being called out on page one, above the fold.

*This blog post was originally published at HealthBlawg :: David Harlow's Health Care Law Blog*


You may also like these posts

Read comments »


Return to article »

Leave a Reply

* Including links (URLs) in your comment may result in it being held for moderation

*

Latest Interviews

The Surprising Economic Burden Of ADHD (Attention-Deficit Hyperactivity Disorder)

If you can read this you need to download a more recent browser It is estimated that as many as million U.S. adults have ADHD Attention-Deficit Hyperactivity Disorder A recent research study publication-pending suggests that the economic burden of ADHD on America could be as high as billion annually. I…

Read more »

Is The Adderall Shortage A Harbinger Of Future Drug Supply Problems?

If you can read this you need to download a more recent browser Today most- if not all- Doctor’s offices are strained by the shortage of some prescription medication or vaccine. A month ago President Obama signed his executive order directing the FDA to take steps to reduce drug shortages…

Read more »

See all interviews »

Latest Cartoon

See all cartoons »

Latest Book Reviews

Book Review: The First Step To Improve Health Care Is A Close Examination Of How It’s Delivered

My friend and former Chair of the CFAH Board of Trustees Doug Kamerow has written a book that I think you will like. Besides being a mensch and witty as heck Doug is a family doctor and a preventive medicine specialist. In his new book Dissecting American Health Care Commentaries…

Read more »

“Your Medical Mind” Explores Factors That Influence A Patient’s Medical Decisions

Recently I had a conversation with Shannon Brownlee the widely respected science journalist and acting director of the Health Policy Program at the New America Foundation about whether men should continue to have access to the PSA test for prostate cancer screening despite the overwhelming evidence that it extends few…

Read more »

Book Review: Food Truths, Food Lies

Food Truths Food Lies written by family physician Eric Marcotte M.D. may be the most refreshingly evidence-based diet book of the decade. You will not find a single mention of super-foods magical berries or supplement must-haves in the entire book. What you will find is the cold hard truth about…

Read more »

See all book reviews »