MAR 1, 2011 1:55am ET

Related Links

Social Intelligence: The New Frontier for Business Intelligence
May 20, 2013
Yahoo Acquires Tumblr
May 20, 2013
How to Effectively Outsource BI
May 17, 2013

Web Seminars

Data Protection in the Cloud: What You Need to Know About Security and Compliance—Right Now
Available On Demand

Data Breaches Often Have Simple Source, Fix

Print
Reprints
Email

March 1, 2011 – A health care organization can have hundreds of threats to protected health information each day and not know it, said Sadik Al-Abdulla, senior manager in the security practice at CDW Corp., during a session at HIMSS11.

A recent client, for instance, had 500 breaches a week of employee records because the human resources department was updating the records and transmitting information to the health insurer in an unsecured manner.

“So, they were breaching their own employees’ data on weekly basis,” Al-Abdulla said.

Malicious behavior accounts for only about 12 percent of breaches. The rest are mostly due to accidents, clueless behavior and technological glitches that are easily fixed, he noted. The first step to solving the problem of non-malicious breaches, he advised, is to identify data stakeholders who feel personal ownership of the information and want it protected.

Next, establish a baseline of where data is, how it’s moving and where it is going. Once that’s known, you’ll find that 30 percent of breaches are small issues or glitches that can be fixed fast. The next 30 percent of breaches are tied to a handful of broken processes, also easily fixable, such as teaching users to click the encryption link before sending. Al-Abdulla also suggested implementing technology that automatically notifies users at the moment a mistake is made, such as sending a message that the email just sent contained PHI and was blocked. “When you do that, people will change,” he said.

So, right off the bat, 60 percent of breaches can be cut without affecting employee work practices, Al-Abdulla said. The remaining 40 percent of non-malicious breaches primarily are accidents and many of these can be prevented with streamlined, effective communication to data users.

Instead of requiring employees to read and sign a long, all-encompassing document on privacy and security – which they won’t read but will sign – Al-Abdulla advised writing a half-page primer that explains what PHI is and how to protect it. The primer takes minute to read, “and each of them can tell their peers.”

This story originally appeared on Health Data Management.

Joseph Goedert is news editor at Health Data Management.

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.

Where do young IT professionals (30 and under) obtain information to aid with daily role responsibilities and career development?

Trade publication websites 14%
Social media 23%
Vendor websites 4%
Vendor/community forums 7%
Newsletters 1%
Trade conferences/meetups 2%
RSS feeds 6%
Web search 44%

 

Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.