Flash Drive and Data Exposure

May 4th, 2015

According to the reports, a lost flash drive containing “limited patient information” rendered a hospital to send out notification letters. As per the statement, Roper St. Francis Hospital mentioned that the flash drive did not contain Social Security numbers, dates of birth or financial information. Affected information includes patients’ names, ages, diagnoses, and dates of procedures.

After conducting a thorough investigation, hospital spokesperson stated that Roper St. Francis does not believe that the information was inappropriately accessed or used in a malicious way.

The story was covered by South Carolina news station, WCSC. It did not state how the flash drive went missing, or if Roper St. Francis was making efforts to adjust its physical, technical, or administrative safeguards.

As per the mail to the security news website-

“A USB flash drive for a computer that contained some patient information was inadvertently misplaced.” The lost flash drive contained information for about 375 patients including name, age, diagnosis, date of service, length of stay, procedure, outcome and provider name, according to the spokesperson. However, it was reiterated that the flash drive did not contain Social Security numbers, financial information, dates of birth, addresses, or insurance information. 

“There is no evidence or reason to believe that the information has been improperly accessed, acquired, or misused in any way,” the spokesman wrote in the email. “We are notifying individuals affected to let them know what we are doing to protect their patient information.”

PHI breach due to break in

March 9th, 2015

Mosaic Medical may have suffered data breach when PHI got exposed due to break-in. The incident took place at a temporary office location for the facility’s Bend, Oregon location. Mosaic is not sure whether the medical record got accessed or not because at prima facie nothing appears to be stolen.

“The personal information that was possibly accessed was on paper documents within the office and included health information, medical insurance information, phone number, and e-mail addresses,” Mosaic said in a statement, according to local news station KTVZ. “A report was filed with the Bend Police Department and they have investigated the break-in.”

Mosiac Medical discovered that a break-in happened at night. According to the reports, the facility has taken steps like moving its HIT office to secure more information. Also, affected patients have been notified via letters.

“We understand the importance of safeguarding our patients’ personal information and take that responsibility very seriously,” Mosaic Medical Chief Operating Officer Allison McCormick said in the statement. “We will do all we can to work with our patients whose personal information may have been compromised.  We regret that this incident occurred, and we are committed to preventing future occurrences.”

Mosaic Medical is a local nonprofit community health center system with primary care clinics in Prineville, Bend, Madras and Redmond.

Alertsec strengthens security

Alertsec has created a web based encryption service that radically simplifies deployment and management of PC encryption by using industry leading Check Point Full Disk Encryption (former Pointsec) software.

Organizations, especially corporate giants, have to have an information security policy in place that proves they have taken necessary steps and measures to safeguard the information they gathered. If these policies are not adhered to, the regulators may prosecute.

Alertsec Xpress is used by organizations that have recognized the need to protect their information. Customers range from single-user sole traders and consultants to multinational companies with a large number of offices around the globe. Over 4 million users worldwide use Alertsec Xpress’s Check Point Full Disk Encryption.