There are several tactics that Codman Square Health Centre can
adopt to ensure that their HIE network is not breached again. A
multi-pronged approach is recommended and would include such
elements as coupling comprehensive privacy breach protocols with
stated expectations of how personnel should abide by them. Further,
all of the workforce that handles private patient health information
should undergo training and sign confidentiality along with end-user
agreements. (Unauthorized access, 2019) Some other tips to avoid
future breaches involve such security measures as password and
controls, limiting access, appropriate data breach management
planning, and making sure that and PHI access systems is continually
monitored, logged, and periodical technical evaluations and audits.
Naturally, there are numerous ways that a privacy breach can
irreparably damage an organization. For example, a loss of trust from
patients and the community can tarnish an organization's reputation.
Additionally, remediating a breach can extract a heavy toll in the
form of lost resources and time. Finally, privacy breaches can even
result in prosecutions and/or legal actions and lawsuits levied against
the organization. This could potentially lead to an enormous loss of
money. Further, the old "you have to spend money to make money"
adage does come into play here. Implementing the necessary tools
and resources that will ensure top-notch security for a healthcare
organization is not cheap. However, it will save costs in the long run
through reducing breach risks. Thanks to Janlyn on this board for
pointing out that the initial expenditures to implement enhanced
security may be considered a hindrance.
Legally and ethically speaking, the breach at Codman Square Health
constitutes a very large problem as the impact reached far beyond
just the clinic. The article mentions that the number of patients
affected extends to many of the organizations using the same New
England Healthcare Exchange Network. Despite protestations to the
contrary, Codman allowed information like social security numbers to
have unauthorized access, therefore, they really do not know the
extent of the damage. Codman declaring that "there is no evidence
the information was misused" (Massachusetts clinic breach, 2016) is
disingenuous at best. Legally, Codman violated the HIPAA Privacy
and Security Rules and can be considered wilfully negligent in
protecting patient information. Additionally, the article mentions that
Codman learned of the breach in July, but apparently, it was not
posted to their website until September meaning they extended their
allotted 60-day time window under the statutes of the Breach
Notification Rule to the very last second. Also, since this case
involves more than 500 patients, they had to notify Health and
Human Services as per the Breach Notification Rule. (Oachs et al.,
2020) While not technically a violation, this does skirt around the
ethics issue. This is personal opinion, but patients should have been
notified immediately upon the July 13th breach discovery. In
addition, most states have their own laws regarding data breaches
meaning this particular clinic would be subject to the specific laws
and data security standards of Massachusetts.
References
Oachs, P. K., Watters, A., & American Health Information
Management Association. (2020). Health information management:
concepts, principles, and practice. (6th ed.). Ahima, American Health
Information Management Association.
Massachusetts clinic breach stems from unauthorized HIE access. (2016,
September 23).
Www.beckershospitalreview.com. https://www.beckershospitalrevie
w.com/healthcare-information-technology/massachusetts-clinic-
breach-stems-from-unauthorized-hie-access.html?
oly_enc_id=9529B8688890A6T
Unauthorized access. (2019). IPC. https://www.ipc.on.ca/health-
organizations/unauthorized-access/