Are Your Business Associates Accountable for HIPAA Compliance?

Dom Nicastro, for HealthLeaders Media , February 23, 2011

HHC said the breach involves a reported theft of electronic record files that contained PHI, personal information, and personally identifiable employee medical information (PIEMI).

The loss of this data, HHC said, occurred through the negligence of a "contracted firm that specializes in the secure transport and storage of sensitive data." In other words, the breach is attributed to a BA of HHC.

An HHC spokesman said in an e-mail to HealthLeaders Media that the van is owned by an information-management company the corporation hired to handle patient records -- GRM Information Management Services, a contracted firm that specializes in the secure transport and storage of sensitive data.

As a result of this theft, HHC said it took additional actions to further secure the transport of backup data off-site, including:

  • Suspending the transport of unencrypted backup files from any HHC facility to off-site storage locations
  • Expediting its plan to upgrade critical data to the 256-bit Advanced Encryption Standard , considered by the federal government as the highest level of protection against tampering. At the time of the theft, HHC had already upgraded and encrypted nearly 80 percent of the 1,568 systems applications used throughout the corporation. The upgrade is expected to be completed by the fall of 2011. Replacing GRM with a new vendor to handle offsite backup data that will be stored in highly protected facilities that have climate-controlled dedicated tape vaults, secured keycard access, video surveillance and trained personnel
1 | 2 | 3

Comments are moderated. Please be patient.




FREE e-Newsletters Join the Council Subscribe to HL magazine


100 Winners Circle Suite 300
Brentwood, TN 37027


About | Advertise | Terms of Use | Privacy Policy | Reprints/Permissions | Contact
© HealthLeaders Media 2015 a division of BLR All rights reserved.