APR 13, 2010 6:13am ET

Related Links

Kundra: Bring People the Customer Experience They Expect
May 17, 2012
Malicious Cyber Attacks Spike by 81%
May 2, 2012
No Skimping on Security Software
April 26, 2012

Web Seminars

Smarter Service and Security for Citizens
Available On Demand

Time to Encrypt? You Think?

Print
Reprints
Email

John Muir Health in Walnut Creek, Calif., recently started notifying 5,450 patients after the theft of two laptops containing their health information.

The data wasn't encrypted and John Muir soon will join a growing list of organizations with its data breach displayed on a Department of Health and Human Services' Web site. Most of the breaches listed on the site resulted from thefts and most of those were laptops or other portable media. And they weren't encrypted.

Encryption of protected health information is not required under the HIPAA privacy, security and breach notification rules. But an organization must consider use of encryption when conducting a risk assessment and document the reasons why use of the technology isn't justified.

I've always thought HIPAA's loophole to get out of encrypting was a mistake that coupled with lax federal enforcement of privacy and security rules has not served the public well. Thanks to the HHS breach list, maintained by the Office for Civil Rights which enforces health information privacy laws, it's looking a lot tougher these days to justify not encrypting data--at least on portable devices. That's my view and also the view of the government's top health privacy cop, OCR Deputy Director Susan McAndrew, who has expanded authority and money now to ramp up enforcement efforts.

Beware what McAndrew says in Health Data Management's upcoming May cover story on data breaches: "What all the incidents are showing is that entities must really take a closer look at encryption and reassess whether or not encryption should be a routine part of their security requirements."

Visit HealthDataManagement.com to comment.

Joseph Goedert is news editor at Health Data Management.

Filed under:

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.