Strategic technology news and ideas for multi-employer Employee Benefit Funds - Hosted and moderated by LaSalle Consulting Partners, Inc.
Tuesday, March 3, 2015
This Blog Has Moved!
The Technology and Multi-Employer Employee Benefit Plans blog has moved. The blog can now be located at http://techbenefitfunds.lpartnersinc.com/. Thank you for your interest.
Monday, January 12, 2015
Securing ePHI Outside of the Office – Northwestern Memorial HIPAA Breach
It is highly advisable to take precautions applicable to notebooks
or other devices which leave the office if they are likely to store ePHI.
Measures must be taken in order to protect confidential information and avoid
costly penalties. At LaSalle Consulting Partners, we recommend that all data be
encrypted using the highest encryption standard available before it leaves your
location, and that it remains encrypted at all times.
Should the laptop or device become misplaced or stolen, the data contained on its encrypted drive is completely inaccessible without the associated encryption key. This extra level of protection prevents unauthorized users from accessing sensitive information. It also means that organizations are not required to notify those whose ePHI is contained on the device should it be misplaced.
In October 2014, a Northwestern Memorial HealthCare laptop computer that was not protected with disk encryption was stolen from an employee’s vehicle. In accordance with the HIPAA Breach Notification Rule, Northwestern Memorial was required to notify the 2,800 patients whose ePHI was contained on the computer (Read more here). Breaches such as this can be easily avoided through the encryption of device hard drives.
Please contact LaSalle Consulting Partners to find out how we can help you develop and implement policies that help safeguard ePHI, even away from the office.
Should the laptop or device become misplaced or stolen, the data contained on its encrypted drive is completely inaccessible without the associated encryption key. This extra level of protection prevents unauthorized users from accessing sensitive information. It also means that organizations are not required to notify those whose ePHI is contained on the device should it be misplaced.
In October 2014, a Northwestern Memorial HealthCare laptop computer that was not protected with disk encryption was stolen from an employee’s vehicle. In accordance with the HIPAA Breach Notification Rule, Northwestern Memorial was required to notify the 2,800 patients whose ePHI was contained on the computer (Read more here). Breaches such as this can be easily avoided through the encryption of device hard drives.
Please contact LaSalle Consulting Partners to find out how we can help you develop and implement policies that help safeguard ePHI, even away from the office.
Subscribe to:
Posts (Atom)