With a data breach like this I think the first step needs to be security audit to
better determine how the intruder was able to breach the system and obtain
patients information. We would also need to conduct a risk assessment.
Employee training and re-training should be top priority to ensure that all
employees understand the importance of HIPAA and ensuing that all
employees understand that it is necessary to ensure that no patient
information is left and that they are not allowing their friends or family
access the healthcare records remotely. When employees are working
remotely, it is imperative that the company utilizes a two-factory
authentication to ensure that the employee is the only one who has access to
the records.
"Ensuring patient confidentiality is imperative to the success of a healthcare
facility. If a patient does not feel like their information is going to be kept
confidential, it is likely that they will seek healthcare elsewhere. It is worth it,
for healthcare companies especially, to spend the extra money that is required
to ensure that the patients records are safe and secure. When there is a
breach, like the one presented in our scenario, patients lose confidence in that
healthcare agency and tend to want to switch their care elsewhere. The only
hinderance I could think of would be the initial expenditure that it would cost
to implement a secure system to ensure that there are no intruders or breach
in information.
When working in a healthcare setting, you are ethically and legally bound to
ensure that the patient’s personal information is not shared. In most, if not all,
healthcare organizations, there is a HIPAA training at the orientation that
goes over all of this and you usually sign something saying that you are not
going to share information about patients, not even amongst your co-workers
as it could be overheard. Patients are also expected to acknowledge and sign
a HIPAA agreement upon presentation to a hospital or clinic, to ensure that
they are notified of their rights and responsibilities, as a patient under the
HIPAA laws.