Thanks to Adam Shostack, I realized that although HHS provides two formats for their breach report database, the two databases do not necessarily contain the same number of breach reports on any given day. While he was analyzing data based on the .xml version containing 181 breach reports, I had been using the .csv version,…
Category: Health Data
HIPAA Follies, Monday Edition: Tweeting that your sloppy security resulted in data theft
I’ve reported a number of instances where employees have been disciplined or terminated for imprudent postings on Facebook or MySpace, but a series of tweets I saw on Twitter yesterday demonstrate how to simultaneously diminish the public’s confidence in HIPAA while risking your own future, 140 characters at a time. It started with a twitterer…
Pointer: Lessons from HHS Breach Data
Over on The New School of Information Security, Adam Shostack responded to my recent blog entry about what can we learn from the HHS breach reports. Looking at “insider” incidents, Adam writes, in part: There were 10 incidents, (6% of all incidents involving 500 or more people). They impacted 50,491 people (1% of all…
FTC: No Major PHR Breaches So Far
Howard Anderson reports: … A personal health record is an “electronic record of identifiable health information on an individual that can be drawn from multiple sources and that is managed, shared and controlled by or primarily for the individual,” according to the FTC. Last year, the FTC issued a PHR breach notification rule, as called for under…
NC: Researcher Yankaskas appeals pay cut, demotion
More details are emerging about why the breach involving the UNC-Chapel Hill Carolina Mammography Registry led to consequences for the researcher. C. Ryan Barber reports: […] School of Medicine Office of Information Systems officials first alerted the University to the breach in July 2009 after uncovering a virus and potential security breach on the Carolina…
Ca: Veteran says privacy breaches left him suicidal
After the Tyler Clementi suicide, there’s been a lot of talk about how privacy invasions or privacy breaches might lead to desperate measures such as suicide. The veteran at the heart of a terrible privacy breach involving the Department of Veterans Affairs in Canada says that the violation of his privacy made him suicidal: A…