Follow Slashdot blog updates by subscribing to our blog RSS feed


Forgot your password?
Privacy Medicine Your Rights Online

Loss of a Single Laptop Leads to $50k Fine Against Idaho Hospice 188

netbuzz writes "Losing a single laptop containing sensitive personal information about 441 patients will cost a non-profit Idaho hospice center $50,000, marking the first such HIPAA-related penalty involving fewer than 500 data-breach victims. Yes, the data was not encrypted. 'This action sends a strong message to the health care industry that, regardless of size, covered entities must take action and will be held accountable for safeguarding their patients' health information,' says the Department of Health and Human Services."
This discussion has been archived. No new comments can be posted.

Loss of a Single Laptop Leads to $50k Fine Against Idaho Hospice

Comments Filter:
  • by kriston ( 7886 ) on Monday January 07, 2013 @09:16PM (#42513105) Homepage Journal

    This is why God invented encryption.

  • by gweihir ( 88907 ) on Monday January 07, 2013 @09:21PM (#42513151)

    Yes, it is tragic, but effective encryption is free (TrueCrypt, e.g.) and a non-profit still does not have any business being incompetent.

  • Re:It works! (Score:4, Insightful)

    by DoofusOfDeath ( 636671 ) on Monday January 07, 2013 @09:24PM (#42513185)

    It's hard to tell if you're being sarcastic or not.

  • by Anonymous Coward on Monday January 07, 2013 @09:25PM (#42513195)

    ...what govt penalizers do best: pick on those least capable of defending themselves... in other words go after the low hanging fruit and don't bother with the really hard stuff like rich, for-profit hospitals and clinics that routinely violate HIPAA... because those have armies of high-dollar lawyers who'll make life hard on the govt if they attempt to go after them.

  • Re:It works! (Score:4, Insightful)

    by Alwin Henseler ( 640539 ) on Monday January 07, 2013 @09:30PM (#42513259)

    No it doesn't. For starters: such a fine is a good thing, but it should be payable to the victims of the data breach (as in: the people whose sensitive data was dumped on the street). One way or another, they suffer damage from a data breach, they should be compensated.

    Secondly, it won't prevent further breaches like they happen so often these days. Maybe if fines are stiff enough, and handed out often enough, over time it will produce an effect. I wouldn't hold my breath though. When it comes to keeping data private, a new idiot is born every day. Sometimes an idiot in charge, but that's not always necessary.

  • by sunking2 ( 521698 ) on Monday January 07, 2013 @09:47PM (#42513457)
    Hopsice prices can't just arbitrarily go up for 99.9% of people who use insurance or medicaid. They work on prenegotiated rates. They can charge all they want, insurance is only going to pay them what they agreed to.
  • Re:It works! (Score:5, Insightful)

    by Enry ( 630 ) <> on Monday January 07, 2013 @10:02PM (#42513615) Journal

    Yes, and the next time some Hospice official thinks about not encrypting their data, they're going to remember this event and think better of it.

    HIPAA violations are serious. People have likely lost their jobs over this. Even though I'm not in a position to routinely work with patient data, my employer requires that my laptop is encrypted - in the case of my Linux laptop I was able to convince them that using encrypted LVM was sufficient.

  • by bradorsomething ( 527297 ) on Monday January 07, 2013 @10:16PM (#42513765)
    When you lose one laptop worth of patient data, don't tell anybody.
  • by ColdWetDog ( 752185 ) on Monday January 07, 2013 @11:16PM (#42514207) Homepage

    Nice rant. Too bad you're mostly wrong. HIPAA actually does manage to get data protection pushed far and wide in an industry that fights tooth and nail against any change. It's hardly perfect but it's not terribly onerous and most of the edge cases and implementation problems have been sorted out.

    I'm not sure why they chose to beat up on some rural Hospice provider - they've had plenty of chances to hit some big boys and girls, but this will send out a signal that you shouldn't fuck around and avoid doing simple things. It isn't much of an expense to encrypt laptops. It's not hard to put locks on doors, HIPAA has made it easier to transfer data back and forth between providers because everyone is working off the same set of rules.

    Maybe you should bash your head with your copy of Atlas Shrugged a few more times until things are clearer.

  • Re:It works! (Score:4, Insightful)

    by mlts ( 1038732 ) * on Monday January 07, 2013 @11:18PM (#42514229)

    I'm happy HIPAA is being enforced. We have already had way too many breaches, either tapes left in unsecured locations, or laptops "going missing".

    We already have had a decade of businesses giving security the hind teat, since it is viewed as a cost center, and the belief that "calling Geek Squad" after the fact can fix things. Having it made public that if laws/regs are broken, that fines will be levied might get places to zip their flies.

    Encryption of laptops is not hard, especially Windows laptops that are the mainstay in business that have TPM chips. With any Windows version newer than Vista, Bitlocker is very easy to enable on an enterprise level. For most things, just forcing BitLocker via GPO on laptops, even if the user is a full admin is more than good enough for security.

    For laptops without a TPM, Windows 8 and Windows Server 2012 allow for a password to be set before boot.

    Almost all new major operating systems have some form of DAR/WDE encryption ready to go. Linux has LUKS, BSD has gbde, AIX has EFS, Solaris has encrypt(1), OS X has FileVault II. Enabling this may not be trivial, but it is doable.

    Of course, almost all new backup programs have encryption, usually create/import a key, set a button to encrypt, and let fly. Netbackup has the Media Server Encryption Option, but even better, if one uses LTO-4 or newer media, NBU can just use the tape drive native AES encryption directly.

    There is no excuse for encrypting laptops and media these days. None.

  • Re:A 'Big' fine? (Score:4, Insightful)

    by afidel ( 530433 ) on Tuesday January 08, 2013 @01:17AM (#42515059)

    Dude, it's a small nonprofit hospice, it's doubtful they HAVE an IT guy, more likely a consultant they bring in to fix something every few years. I know because I worked consulting in a practice focused largely on smb medical and only our largest and/or most profitable customers ever engaged us for anything more than break/fix. I got out just as HIPPA enforcement was coming online and almost none of our clients was prepared despite the fact that we had sent along information for several years pointing them to organizations that could help them write their policies (we got nothing directly out of this, though given the state of many of their IT systems they would have needed services to become compliant with legal minimum practices).

Perfection is acheived only on the point of collapse. - C. N. Parkinson