BreachExchange mailing list archives

fringe: Medical Records: Stored in the Cloud, Sold on the Open Market


From: security curmudgeon <jericho () attrition org>
Date: Tue, 20 Oct 2009 07:26:38 +0000 (UTC)



---------- Forwarded message ----------
From: InfoSec News <alerts () infosecnews org>

http://www.wired.com/threatlevel/2009/10/medicalrecords/

By Kim Zetter
Threat Level
Wired.com
October 19, 2009

When patients visit a physician or hospital, they know that anyone 
involved in providing their health care can lawfully see their medical 
records.

But unknown to patients, an increasing number of outside vendors that 
manage electronic health records also have access to that data, and are 
reselling the information as a commodity.

The revelation comes in a recent New York Times article about how 
so-called "scrubbed" patient data isn't as anonymous as people think. The 
piece focuses primarily on how anonymized data can be cross-bred with 
other publicly available databases, such as voting records, which subverts 
the anonymity. Buried near the end of the article is the news that medical 
data is collected, anonymized and sold, not by insurance agencies and 
health care providers, but by third-party vendors who provide 
medical-record storage in the cloud.

Electronic health record (EHR) services have been a growing industry in 
the last few years, according to Sue Reber, marketing director of the 
Certification Commission for Health Information Technology. Reber says 
most vendors used to simply sell software packages; once the product was 
sold, the vendor had no connection to the data stored in it. But an 
increasing number of companies have begun to offer web-based 
software-management applications that include database storage controlled 
and managed by the vendor.

[...]
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)
Archived at http://seclists.org/dataloss/

Get business, compliance, IT and security staff on the same page with
CREDANT Technologies: The Shortcut Guide to Understanding Data Protection
from Four Critical Perspectives. The eBook begins with considerations
important to executives and business leaders.
http://www.credant.com/campaigns/ebook-chpt-one-web.php


Current thread: