The integration of software and hardware Delivery

Health Care Provider Data Breach Follows Warnings on Digital Copier Security

Affinity May Be Looking at HITECH Act Penalties

Affinity May Be Looking at HITECH Act Penalties
A hard drive lurks within your networked digital copier or printer

ADDITIONAL LINKS:

  • Cypher ultra-portable erasure kit meets NIST and DOD standards.
  • HITECH Act now in effect for medical organizations
  • NIST special publication 800-88 media sanitization guidelines
In November of 2009, Data Destruction Topics reported on the data-breach-waiting-to-happen related to digital copy machine hard drives (OMG: There’s a hard drive in my copy machine!). In that posting, we reported that networked printers are a potential source of data breaches, all but ignored by both owners and security professionals.

Now comes the news that Affinity Health Plan, a New York managed care service, has notified well over 400,000 current and former employees that sensitive medical records have been potentially compromised due to the loss of a digital copier hard drive. The copier had previously been leased by Affinity and was later returned to the leasing company without erasing the drive. The hard drive containing the records was found in a warehouse in New Jersey.

Failure to properly dispose of medical records is a violation of new federal HITECH regulations, as well as New York state privacy regulations. In addition to notification requirements, the violations may also result in fines and other sanctions.

The fact that the hard drive had been returned to the vendor in no way absolves Affinity for failing to comply with private data security records. HITECH explicitly defines the necessity of protecting private data and provides best practices guidelines based on NIST standards; organizations that fail to comply voluntarily with the Privacy Rule may be subject to civil penalties. In addition, certain violations may be subject to criminal prosecution.

The process of erasing sensitive data from hard drives is inexpensive and fast with today’s recent innovations in data erasure technology. Equally important, these products provide the means of generating an audit trail that certifies compliance, precluding the expense of notification, damage to business relationships and criminal charges.

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>