Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 29 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow HIPAA/Regs
EH-Net
May 22, 2013, 05:43:21 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: HIPAA/Regs  (Read 2648 times)
0 Members and 1 Guest are viewing this topic.
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« on: July 08, 2009, 09:14:02 AM »

Ok, so I've got 0 experience dealing with anything HIPAA and I'm a bit concerned with what my wife just told me. Before I call up the pediatrician's office (in a rage) where we take my daughter, I wanted to run this by the community to make sure my concerns are legit.

So, my wife gets this email today titled "PhoneSlip Login Details" with my daughters name welcoming her to "PhoneSlips" [1] and providing a username and password (her birthdate!) - FYI, my daughter is 3 y/o and obviously didn't sign-up for anything.

I instructed my wife to grab the headers and forward them to me along with a copy of the email. I was able to identify a small IT services outfit (looks like their market is doctor offices) as the originator of the email.

So, I'm sure you can see where my concern is going at this point. Who is this IT company, why do they have patient information (my daughter) from the doctors office, and why is my doctors office giving this type of information to third-parties??

Yes, it's just a name and a birthdate (that I'm aware of), but it's the principle here. I don't know how this plays in with patient confidentiality and/or HIPAA or any other laws/regs.

Is this something to complain about or am I just over-reacting?

Thanks!

BillV

[1]
Quote
PHONEslips is an easy to use messaging and office information management system for professional offices. It handles phone messages, memos, e-mails, contact database, schedules and to-do lists for everyone in the office.
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #1 on: July 08, 2009, 09:47:26 AM »

Looks like I might have a pretty good response from my dad:

Quote
HIPAA prevents disclosure of ANY personal infornation that can be tied to a name.  The vendor (Phoneslips) can sign a 'Business Associate' agreement to permit transfer of this information with its client (pediatrician) wherein they promise not to disclose the info except for doing business required by their role.  I am pretty sure they would have signed this so HIPAA is not likely violated.  All new patients sign this same (or similar) agreement when they first visit a new provider; you would have had to do the same.  Your gripe might be sending HIPAA protected info over the ethernet without encryption, we use encryption for this, and could be construed to be a violation.

That sound about accurate?
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1632



View Profile
« Reply #2 on: July 08, 2009, 10:37:24 AM »

Sounds about right, assuming that's all the information they transmitted.  The data should not be transmitted in clear text across the public internet, and so that could be considered a possible breach of the HIPAA policies. 

Their reasoning for having / transmitting the data might be perfectly legitimate, but they should definitely be more careful in how they use / transmit said data.

Tim (Hayabusa0194)
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.074 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.