An inadvertent data leak that stemmed from a physician's attempt to reconfigure a server cost New York Presbyterian Hospital and Columbia University Medical Center $4.8 million to settle with the U.S. Department of Health and Human Services (HHS). The hospitals and HHS announced the voluntary settlement, which ends an inquiry into the incident, on Wednesday.
From the article:
The breach occurred in 2010 after a physician at Columbia University Medical Center attempted to "deactivate" a personally owned computer from an New York Presbyterian network segment that contained sensitive patient health information, according to the HHS.
In a joint statement, the two hospitals blamed the leakage on an "errantly configured" computer server. The error left patient status, vital signs, laboratory results, medication information, and other sensitive data on about 6,800 individuals accessible to all via the Web.
New York Presbyterian will pay $3.3 million, while Columbia will pay $1.5 million to settle the complaint. The hospitals also agreed to take "substantive" corrective action, including development of a new risk management plan and new policies and procedures for handling patient data. HHS will also be provided with periodic progress updates under the agreement.
(Score: 2) by egcagrac0 on Friday May 09 2014, @04:34PM
I am guessing that there was some "convenient" tool like PCAnywhere or LogMeIn running on the personally-owned-system that may have allowed the data to escape.
Of course, I don't know for certain, but it seems logical enough that a somewhat techie doctor might try to do "cool" stuff like that.
(Score: 5, Informative) by egcagrac0 on Friday May 09 2014, @04:36PM
Well, look at that... more information. [healthcareitnews.com]
The doctor in question was an application developer, too.
(Score: 2) by The Archon V2.0 on Friday May 09 2014, @08:08PM
Oh, good lord, one of those. Takes a decade to get where he is, then spends a weekend reading a "For Dummies" book and decides he can do the job someone else took a decade to get to.
(That is a snap judgement, I admit. To be fair, he could be a coder who went back to school and became an MD. I mean, it's possible. I suppose that happened. Once. Maybe.)
(Score: 1) by SecurityGuy on Friday May 09 2014, @08:19PM
It still highlights why there is and should be a separation of duties. If you're both guy charged with "getting things done" and securing the data, sooner or later you're going to cut corners.
"Dammit, I don't know why this isn't working but I need it to work RIGHT NOW! Lemme just turn the firewall off and see if that fixes it...it does! Great, I'll fix it for real later." Then you never turn the firewall back on because you're busy fighting the next fire(s).
(Score: 1) by MostCynical on Friday May 09 2014, @11:26PM
he developed for his own facility.. which means he said he could do it cheaper and better than any 'off the shelf product.. and he was right, provided he and the IT department did the bug fuxes and support on top of their usual duties..
Often, doctors get grants or donations of equipment, which are purchased, provisioned and set up completely independantly from hospital IT. The systems may, over time, get data from other systems in the hospital, eventually being the most complete set of records for patients in the doctor's department.
Once the grant money runs out, or when the doctor leaves, no one seems to be able to fidnout who 'owns' the data.
The doctor will claim it (collected using his grant money, after all), but does that include the rest of the patient's records, collected elsewhere in the hospital?
then the data gets one the web...
"I guess once you start doubting, there's no end to it." -Batou, Ghost in the Shell: Stand Alone Complex