DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

House Democrat seeks hearing on CHS data breach, but why stop there?

Posted on September 17, 2014 by Dissent

Beth Walsh writes:

A House Democrat seeks a hearing to investigate the recent data breach at Community Health Ssytems which impacted 4.5 million patients.

Rep. Elijah Cummings (D-Md.), who is the top Democrat on the House Oversight and Government Reform Committee, wrote to the House Oversight and Government Reform Committee chair Darrell Issa (R-Calif.) asking for the hearing to identify ways to better protect patient data.

Read more on Clinical Innovation + Technology.

Frankly, I’m a bit shocked that we haven’t heard/read more outrage as a result of this breach. CHS has over 200 hospitals in its system and they put millions of patients’ information at risk. Should such large systems be allowed? And if so, what heightened security should be in place or audited for?

CHS shouldn’t be House Oversight’s only concern, of course. The other day, I broke the story of a breach involving Aventura Hospital in Florida.  Aventura is owned by the for-profit HCA, who describe themselves as:

a company comprised of locally managed facilities that includes about 165 hospitals and 115 freestanding surgery centers in 20 states and England and employing approximately 204,000 people. Approximately four to five percent of all inpatient care delivered in the country today is provided by HCA facilities.

So if the hospitals are locally managed, does HCA have any responsibility for their data security? In the Aventura Hospital breach, there was insider data theft. But what about external hacks? Does it matter that Aventura Hospital is on HCA’s IP address and that other HCA facilities are also on the same IP address?

Are big systems playing with fire or gambling on data security? And if they fail, what price will the patients pay? I hope House Oversight – and HHS – will take a closer look at this issue.


Related:

  • Pro-Russian hackers target Belgian telecom websites in DDoS attack
  • Veradigm's Breach Claims Under Scrutiny After Dark Web Leak
  • UK: Woman charged after NHS patients' records accessed in data breach
  • Landmark civil penalty of AU$5.8 million issued under Australia’s Privacy Act
  • Safaricom-Backed M-TIBA Victim of a Possible Data Breach Affecting Millions of Kenyans
  • Another plastic surgery practice fell prey to a cyberattack that acquired patient photos and info
Category: Health Data

Post navigation

← NEAT Management Group joins stolen laptop club
Senior IT worker at top tech law firm arrested for insider trading →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.