APR 13, 2010 6:13am ET

Related Links

New Product News – May 17, 2013
May 16, 2013
8 Risks Inherent to All Organizations
May 14, 2013
Second World Risk Day Takes a Project-Minded Path
May 9, 2013

Web Seminars

Data Protection in the Cloud: What You Need to Know About Security and Compliance—Right Now
Available On Demand

Time to Encrypt? You Think?

Print
Reprints
Email

John Muir Health in Walnut Creek, Calif., recently started notifying 5,450 patients after the theft of two laptops containing their health information.

The data wasn't encrypted and John Muir soon will join a growing list of organizations with its data breach displayed on a Department of Health and Human Services' Web site. Most of the breaches listed on the site resulted from thefts and most of those were laptops or other portable media. And they weren't encrypted.

Encryption of protected health information is not required under the HIPAA privacy, security and breach notification rules. But an organization must consider use of encryption when conducting a risk assessment and document the reasons why use of the technology isn't justified.

I've always thought HIPAA's loophole to get out of encrypting was a mistake that coupled with lax federal enforcement of privacy and security rules has not served the public well. Thanks to the HHS breach list, maintained by the Office for Civil Rights which enforces health information privacy laws, it's looking a lot tougher these days to justify not encrypting data--at least on portable devices. That's my view and also the view of the government's top health privacy cop, OCR Deputy Director Susan McAndrew, who has expanded authority and money now to ramp up enforcement efforts.

Beware what McAndrew says in Health Data Management's upcoming May cover story on data breaches: "What all the incidents are showing is that entities must really take a closer look at encryption and reassess whether or not encryption should be a routine part of their security requirements."

Visit HealthDataManagement.com to comment.

Joseph Goedert is news editor at Health Data Management.

Filed under:

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.

Where do young IT professionals (30 and under) obtain information to aid with daily role responsibilities and career development?

Trade publication websites 14%
Social media 23%
Vendor websites 4%
Vendor/community forums 7%
Newsletters 1%
Trade conferences/meetups 2%
RSS feeds 6%
Web search 44%

 

Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.