Thursday, May 07, 2009

Another Electronic Medical Record (EMR/EHR) Data Hack

I have harped on the topics of the potentially disastrous consequences of data loss or theft from medical health database repositories for some time now. I have personally been the victim of such a data loss by the Veteran's Health Administration, which lost all my provider information, financial account and license numbers, social security and business banking numbers, addresses, and all the other personal information to make identity theft a breeze.

Nothing awful happened as a result of this loss. I was given a year's free three bureau credit monitoring subscription by the VHA. It is my personal belief that one of their less experienced employees or interns had simply carried the information for a service provider demographic study offsite on a thumb drive to work on it at home and lost it. Since that time I was again given a free year of credit monitoring when a bank lost a wee bit of data about its customers (around 3 million, as I recall.) I've reported concerns about the National Health Database activity here and elsewhere on other occasions, stating the obvious qualification I would have to make to clients, were I still in active practice and following the privacy and confidentiality rules set forth by the HIPAA act. "I promise that I will keep your health information private and confidential, but there are about 173 other people and agencies out there that may have access to it that I can't vouch for."

A nascent occurrence of that dark vision of the future was announced very recently by many Internet and Traditional Media sources. The web site Office of Inadequate Security (databreaches.net) along with many other sources (I heard just enough of a sentence on CNN to immediately send me into search mode) reported a major health data theft from the Virginia Department of Health Professions. An article in the Richmond Times-Dispatch on 1 May 2009 reported that "Hackers may have gotten to Virginia health professions computers."

It was a little more serious than "may have" if the hacker's ransom demand, reproduced below, is to be believed:

"Thomas Claburn of InformationWeek reports:

An extortion demand posted on WikiLeaks seeks $10 million to return over 8 million patient records and 35 million prescriptions allegedly stolen from Virginia Department of Health Professions.

The note reads: ATTENTION VIRGINIA I have your sh**! In *my* possession, right now, are 8,257,378 patient records and a total of 35,548,087 prescriptions. Also, I made an encrypted backup and deleted the original. Unfortunately for Virginia, their backups seem to have gone missing, too. Uhoh :(

Read more on InformationWeek."

At this point, I will simply leave this example for your contemplation. Consider exactly what identifying information would have been required to be on these records in order for them to be of use to legitimate health care professionals, insurance carriers, Federal and State agencies, pharmacies, data processing centers, and others (including you) who have legitimate access to them. What would be the many possible negative consequences of having these records in the hands of those who do not have our best interests in mind.

Peace, Doc

Copyright © 2009, Thomas A. Blood, Ph.D.

"Like sex in Victorian England, the reality of Big Business today is our big dirty secret." - Ralph Nader

Labels: , , , , , ,

Tuesday, December 16, 2008

EHR, National Health Database, Confidentiality, and More

It has been quite some time since I have made an entry to this blog. My only excuse is that I have been writing and ranting elsewhere and neglecting my self-imposed responsibilities here. I have several concerns with such things as the EHR and its apparent imposition upon us by "bigger" business, the creation of a national health database, the security of anything posted to or transmitted on the web, conflicts between "national security" and net neutrality, and more. I have collected information on these topics, but never quite gotten around to compiling it into coherent posts. In all liklihood these subjects, though interrelated, will be dealt with separately or will intertwine without full explanation as a series of posts.

Until I am able to begin this series, I will leave you with a poem written by a humanistic psychologist. I ran across it in the Psychotherapy.net News newsletter. While you're there, sign up for their free monthly e-newsletter:

EMPIRICALLY VALIDATED PSYCHOTHERAPY
(A POEM)

What works in psychotherapy?
That's far beyond the likes of me.
I've only practiced fifty years,
and still am plagued by doubts and fears.
I muddle on and try my best
to aid my clients in their quest
for ways of being more alive,
somehow in spite of all to thrive.
I wish I knew the right technique
to give them more of what they seek.
The mystery of change persists


unsolved by dogged scientists.
I hope that they will soon impart
quick ways to heal a broken heart.
My efforts stagger, balk, and lurch
unguided by precise research
to tell me how to ease life's pains,
and thus flawed intuition reigns.
Pray science soon will guarantee
sure cures for human misery,
but meanwhile I'll do what I can
without a validated plan.

- Tom Greening

http://www.psychotherapy.net/announcements/Dec08.html


Peace, Doc

Copyright (c) 2008, Thomas A. Blood, Ph.D.


Labels: , , , ,

Friday, August 01, 2008

Electronic Health Records (EHR)

Health Data: Not For Sale

Right now, as Congress considers health IT legislation that would convert our health records from paper to electronic data, patient information is at risk of becoming a commodity that businesses can sell or trade.

While having a nationally connected electronic network for storing and sharing Americans medical information promises to reduce medical error and improve patient care both in emergencies and chronic situations, medical privacy should not become a casualty of the race to set up databases of electronic health records.

We need real patient control of data and damages for misuse or theft. Patients must be able to review files, correct bad data, and block access without consent to personal information. The legislation before the subcommittee does not have these protections.

If Congress fails to require strong privacy and security standards now, during the early stages of development of these online patient records systems, Americans’ medical secrets will be extremely vulnerable to snooping - or being lost or stolen.

Tell Congress: Patients deserve control of their personal health records!

The brief article above is directly from the ACLU’s website. While individuals’ opinions of the organization itself differ widely, it is quite aptly named. It does indeed work toward the preservation and adherence to laws as written, and if there is an inequity in the law, they work toward the fair application of that law to all persons subject to it.

I couldn’t begin to do justice to this topic in a short blog post, but I can tell you that it should scare the bejesus out of you. Think for a moment in terms of the transponders or chips that have been used first to set off alarms if one tried to leave a store without paying for the merchandise, next came barcodes and chips that held information about that product that enabled tracking, dates and places of sale, could correlate that with the credit card that purchased it and know that it was you who bought it. Does your pet have an implanted chip to identify it in case it is stolen or lost? Well, don’t worry, you may have one soon also, only it will have a programmable memory and you will carry your Personal Health Record, implanted under your skin, with you at all times. That could be useful if you ended up in the ER after a car crash and the staff needed information rapidly. Then your treatment, medications, procedures, diagnoses, and any other information would be added to your own little database. This request for information, especially the proposed subject population and agency requesting to carrying it out, should be of concern to all who read between the lines. Physicians’ groups are having qualms about the security of electronic records. This single article is only representative of general concerns.

The issues about the security of the EHR have not come about since last Thursday. It has been a topic of concern for a number of years within the health provider community. It has become a topic of more urgent concern recently since two information giants, Google and Microsoft, have entered the arena, proposing to become the nation’s health information repositories. Have a look at a few other searches here, and here, and especially here.

I will be the first to admit being very suspicious of the EHR. Possibly I border on being paranoid about it, but I don’t think so. Whenever I become confused or uncertain about what is happening in an undertaking of this size and importance, I have to remember to, “Follow the money.” Who stands to profit? Not really the patient or even the doctor who are just as well off with paper records. Who, then? Hospitals, HMO’s, insurance companies (health or disability,) the information transmitters (telecoms which have given the government information illegally and were granted retroactive immunity for their crimes,) the companies of whatever size that are paid to store or backup this health information? Did you notice that little or no profit goes to the individuals involved most directly, and the most to corporations who care little about what happens to a single patient or doc? Who might want this information illegally? Prospective employers not wanting to hire someone with a family history of a particular disease? Life insurance companies that might want a little edge over their actuarial tables? Government or police agencies that might just need a couple hundred thousand DNA codes?

It’s obvious where my feelings lie at this juncture. Given the burgeoning of identity theft over the last few years, is it so unreasonable to believe that the same might well happen with health records? Given the government’s nearly unfettered access to citizen’s private information without their knowledge or consent, can we say that won’t happen in our future? I’m afraid not.

Peace, Doc

Copyright © 2008, Thomas A. Blood, Ph.D.

“He who allows oppression shares the crime.” - Desiderius Erasmus quotes (Dutch Priest, Humanist and Editor of the New Testament, 1469-1536)

Labels: , , , , ,