Are Your Business Associates Accountable for HIPAA Compliance?
HHC said the breach involves a reported theft of electronic record files that contained PHI, personal information, and personally identifiable employee medical information (PIEMI).
The loss of this data, HHC said, occurred through the negligence of a "contracted firm that specializes in the secure transport and storage of sensitive data." In other words, the breach is attributed to a BA of HHC.
An HHC spokesman said in an e-mail to HealthLeaders Media that the van is owned by an information-management company the corporation hired to handle patient records -- GRM Information Management Services, a contracted firm that specializes in the secure transport and storage of sensitive data.
As a result of this theft, HHC said it took additional actions to further secure the transport of backup data off-site, including:
- Suspending the transport of unencrypted backup files from any HHC facility to off-site storage locations
- Expediting its plan to upgrade critical data to the 256-bit Advanced Encryption Standard , considered by the federal government as the highest level of protection against tampering. At the time of the theft, HHC had already upgraded and encrypted nearly 80 percent of the 1,568 systems applications used throughout the corporation. The upgrade is expected to be completed by the fall of 2011. Replacing GRM with a new vendor to handle offsite backup data that will be stored in highly protected facilities that have climate-controlled dedicated tape vaults, secured keycard access, video surveillance and trained personnel
- Surgical Checklists Unused in 10% of Hospitals, CMS Data Shows
- Roundtable: To Arrest HAIs, Culture Trumps Campaigns
- Doctors Feel Pressure to Accept Risk-based Reimbursement
- Wanted: Nurse PhDs
- Slideshow: Healthcare Leaders Name IT Spending Priorities
- 4 Tectonic Shifts Shaking Up Healthcare
- A Fresh Look at End-of-Life Care
- New Orleans East Hospital opens quietly, still seeking accreditation
- 3 Insider Tips on Cutting Costs without Strangling Growth
- CVS Ramps Up Retail Clinics with Provider Affiliations