NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Social Responsibility's Strategic Benefits

December 15, 11:30 AM - 12:30 PM US/Eastern (GMT-5)

Join Ed Granger-Happ, CIO of Save the Children, for a discussion of how creating an organization that is socially responsible improves staffing, retention, leadership development and overall corporate health.

Working With and Communicating to Your Board of Directors

January 13, 2009, 4:00 PM - 5:00 PM US/Eastern (GMT-5)

CIO panelists who will share tips and experiences working with their boards: Twila Day of SYSCO; Jeff O'Hare, West Corp.; Marc West, formerly with H&R Block.

IT's Role in Growing Mid-Market Companies

January 14, 4:00 PM - 5:00 PM ET (GMT-5)

Mid-market Council members will share their companies' stories and challenges in driving or coping with growth. Panelists represent Veterinary Pet Insurance, Medicis Pharmaceutical, and Intrax Cultural Exchange.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 
 

Medical Data Breaches Put Patients at Risk

Despite HIPAA, hospitals leave patient data unprotected; one CIO offers tips for getting IT security funding

 

April 29, 2008CIO — Doctors can't cure the common cold and health care IT managers apparently can't stop the common data breach.

Twenty-one of the 101 of the breaches tracked so far this year by information security group Attrition.org occurred at health care organizations.

For example, insurer WellPoint said in early April that lax security on two servers run for it by a vendor likely exposed on the Internet some personal and medical data for 128,000 patients.

Also in April, New York Presbyterian Hospital notified 40,000 patients that their personal information, including names, phone numbers and some Social Security numbers, were stolen, possibly by a hospital employee. A federal investigation and internal audit are underway.

Whether on paper, as so many medical records remain, or electronic, health care data must be protected according to state and federal regulations. But just because health care staff say they know the rules doesn't mean that information is safe, concludes a new survey from the Healthcare Information and Management Systems Society (HIMSS), a nonprofit professional group for IT managers. The group, with security consulting firm Kroll, polled 263 chief security officers and managers of IT and of health care information.

For example, 75 percent of respondents gave themselves the highest rank possible when it comes to familiarity with HIPAA: 7, on a scale of 1 to 7. The Health Information Portability and Accountability Act, or HIPAA, governs whether and how patient data may be seen and by whom.

HIPAA compliance proves difficult in itself for the organizations that must follow those rules. Early this year, the National Institutes of Health had a laptop stolen, containing patient's private information, from an employee's car. In January, Fallon Community Health Plan announced a laptop being used by one of its vendors was stolen and it, too, contained patient data. In reporting those incidents to the public, each said how they "regret" the thefts. While these organizations offered credit monitoring to affected patients, many companies leave identify theft victims to fend for themselves.

What It Takes to Follow Through on Security Rules

Getting employees and contract vendors to follow corporate security policies requires cajoling and sometimes a bit of drama, says John Hummel, chief technology officer at Perot Systems' health care services group. Hummel has also been CIO at Sutter Health> and at the organization that oversees health care in California's state prison system.

Loading...
 
 
IT Jobs
 
 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Webcast: Mitigate Operational Risk- Real Answers for Tough Times

White Paper: Scaling Down HPC for Smaller Organizations

17 Ways to Reduce Cost in IT

Learning from BPM Leaders

Paving the Way for Trusted Collaboration

State of the Market: Application Performance Management

Proactively Identify and Resolve Performance Issues

Union Bank of California Improves its Online Banking Services

The Link Between APM and Customer Satisfaction

Providing Around-the-Clock Customer Satisfaction

Deliver Social Computing Business Value

Make Hidden Trends, Inter-Relationships and Influences Visible.

"Enterprise-Proven" is the Prerequisite for Enterprise SaaS Portal Solutions

File Integrity Monitoring: Prove compliance and secure your IT environments

Affordable technology-no compromise. HP server solutions

SOA Educational Library at the TIBCO SOA Resource Center

CIO Viewpoints: Migrating to Exchange 2007

Thrive during global disruption. Cisco video featuring Juan Enriquez

A new level of interoperability. Make IT Work As One@novell.com

Protect data-HP All-in-One and Disk-Based systems

Businesses Transform with VMware Virtualization

Download the free CIO Starter Kit to access useful resources created by top CIOs

The Business of Managing Content: Xythos Document Management & Microsoft SharePoint

Server Virtualization Benchmark Results

White Paper: Never Enough Compute Power?

Leveraging Social Computing Technologies for ERP Applications

Best Practices: Safe and Secure Hardware Asset Recovery

Operational Excellence Is Key to Maximizing IT Investments

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

First-hand look at this never before seen research

Effectively Managing High-Performing, Business-Critical Web Applications

Managing Service Level Agreements to Achieve Business Goals

APM Solutions: A Window into Complex Web Applications

APM Solutions Offer Insight into Complex Web Applications

Five Best Practices for Enterprise Collaboration Success

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Customer Insight Yields Sales, Marketing Gains

Corral, configure and control all your mischievous machinery with a Lantronix device server

Spend less. Get hosted UC. Get cash back. It's easy under a Cypress

Predict the future with HP Insight Power Manager

Log onto Hitachi True Stories, films inspired by the next great achievement

Earn PROFESSIONAL DOCTORATE Part-Time, Online at Syracuse University's iSchool

Make IT Work As One@novell.com

Predict the future with HP Insight Power Manager

HP LaserJet P4014n printer starting at $799 after $100 IS. www.hp.com

CIO Starter Kit includes useful resources created by top CIOs. Free Download>>

How to Start a PMO & Realize the Benefits Fast

Virtualization Benchmark and TCO Analysis-Read Now

Learn to Leverage Maximum Computing Power

Windows Vista: Essential Benefits and Deployment Strategies