Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISN] 140 Kaiser patients' private data put online |
|---|---|
| Date: | Mon, 14 Mar 2005 03:42:16 -0600 (CST) |
http://www.siliconvalley.com/mld/siliconvalley/11110907.htm By Barbara Feder Ostrov Mercury News March 11, 2005 In a troubling episode involving medical privacy in the digital age, Kaiser Permanente is notifying 140 patients that a disgruntled former employee posted confidential information about them on her Weblog. The woman, who calls herself the ``Diva of Disgruntled,'' claims it was Kaiser Permanente that included private patient information on systems diagrams posted on the Web, and that she pointed it out. The health care giant learned of the breach from the federal Office of Civil Rights in January, said Kaiser spokesman Matthew Schiffgens. Kaiser has been investigating ever since, Schiffgens said, but it wasn't until Wednesday that it asked the Internet service provider hosting the blog to remove the information. Kaiser has not been able to verify the woman's claims that it was responsible for posting private patient information, said Schiffgens. ``If we had a role in making that available, we have a right to be criticized for that,'' Schiffgens said. ``Regardless of how it happened, her initial postings are clearly a breach of her obligation to protect member confidentiality.'' The woman, who identified herself only as "Elisa," told the Mercury News Kaiser posted patient information on an unsecured technical Web site and that she called attention to it before Kaiser took the site down. She also said that she reposted the information on another site to make the point that anyone could have gained access to this information, since it had been widely available on the Web for a year. She said she also filed a complaint with the federal Office of Civil Rights about the security breach. The information includes medical record numbers, patient names and in some cases information about, but not results of, routine lab tests. The former employee apparently reposted the information Thursday, but it was again removed, Schiffgens said. Kaiser contacted or left messages with 90 of the 140 members Thursday to alert them to the security breach, and hopes to reach the remaining members today. The patients were dispersed throughout Northern California, Schiffgens said. ``We apologize regarding this unlawful disclosure,'' he said. ``We take our members' confidential and personal information very seriously.'' Schiffgens said the woman was a low-level Web designer who worked for the Kaiser Permanente Medical Group in Oakland. She was terminated in June 2003, but Schiffgens would not say why or release her name. Kaiser will take legal action against the woman if warranted, Schiffgens said. Under federal health privacy rules known as HIPAA, the woman could face up to $250,000 in fines and 10 years in prison for unauthorized disclosure of patient information. _________________________________________ Bellua Cyber Security Asia 2005 - http://www.bellua.com/bcs2005
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISN] 2001: Bush Warned of Tech Dangers, InfoSec News |
|---|---|
| Next by Date: | [ISN] AOL's Terms of Service Update for AIM Raises Eyebrows, InfoSec News |
| Previous by Thread: | [ISN] 2001: Bush Warned of Tech Dangers, InfoSec News |
| Next by Thread: | [ISN] AOL's Terms of Service Update for AIM Raises Eyebrows, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |