The Moore American

Local News

January 22, 2013

HIPAA compliance: Does your doctor really care?

MOORE — Recent trips to the doctor’s office have once again led me to question the security of my private medical and financial information. While most people turn a blind eye to how patient records are handled by their favorite doctor or hospital, the security of such records has never been more important.

It’s my observation that, while most doctors, nurses and secretaries have at least heard of the Health Insurance Portability and Accountability Act (HIPAA), many of them aren’t really aware of what is required by the law and a shocking number of health professionals couldn’t seem to care less.

HIPAA basically states that doctors, nurses, office staff, insurance agencies, attorneys, secretaries, vendors, and anyone else who handles patient data must ensure that names, addresses, telephone numbers, social security, credit card, insurance, bank account and other identifying numbers that make their way onto computers must be protected from loss, corruption and unauthorized access.

Computers should not be left unattended in unlocked rooms. Anti-theft measures should be in place. Computers and file systems should be password protected, and particularly sensitive files should be encrypted. Antivirus and antihacker measures should be in place. Patient data stolen by thieves or hackers, destroyed by accidents such as a storm, or damaged by a computer virus has lost its privacy, integrity, and has become unavailable. All three situations can be considered violations, incurring non-compliance citations.

Case in point is Providence Health & Services, a Seattle, Washington-based health care organization, which was once punished to the tune of $100,000 for lax security policies. An investigation by the U.S. Department of Health and Human Services revealed that Providence had experienced the loss or theft of numerous laptop computers, CDs and backup tapes that contained the private medical records of over 386,000 Providence patients. Sadly, none of the lost or stolen information was encrypted or password-protected. Providence is also being forced to implement a rigorous security program designed to stop such unconscionable losses.

In my own experience, it’s always dismaying to have the secretary in the doctor’s office ask me, in front of everyone else in the waiting room, “What’s your social?” I never speak my Social Security Number out loud in such situations. Instead, I insist that I write the number on the form myself. In another office, there I was, observing the names, addresses, phone numbers, Social Security Numbers and medical insurance numbers of numerous other patients. It was almost unavoidable, as patient forms were strewn all over the reception counter for any and all to see.

In another office, after filling out the patient application form and having my insurance cards photocopied, the receptionist held up a digital camera that was connected to a computer (and probably, the Internet) and said that she needed to take my picture. “Why take my picture?” I asked. “It’s so that we’ll know who you are in the future,” she replied. “But, you didn’t even ask to see my drivers license, or any other photo ID,” I said. “What if I stole those insurance cards that you copied? How would you know that the picture you took is of the same guy whose name is on the insurance card?” A blank look came over her face, and after staring at me for a few seconds, she said, “Oh. Gee. I don’t know; it’s just what we do.” Grrrrrr!

Unless we, the patients, demand that all health-care professionals great and small start to take computer and Internet security seriously, and follow the security requirements of HIPAA, more and more patients will continue to be needlessly ripped off.

Here are some questions to ask your doctor: If my private patient data is on a computer, CD, or an external device such as a flash drive, is the data encrypted? Do you back up your computer’s hard drives, and, if so, are the backups encrypted? If you sent my private data across a computer network or the Internet, do you use a secure encrypted connection?

If you give my information to a third party, do you require that they protect its security? Have you ever had a qualified independent company perform a HIPAA security audit? If your doctor says “No” or “I don’t know” to any of these questions, run, don’t walk, to a doctor that will actually give a hoot about your privacy.

Dave Moore has been repairing computers in Norman since 1984, when he borrowed $1,200 to buy a Commodore 64 system. He can be reached at 919-9901 or at www.davemoorecomputers.com.

Text Only
Local News
  • Moore voters approve proposition continuing OG&E distribution

    In a landslide vote Tuesday, Moore voters approved to continue the franchise of OG&E to distribute electricity in the city and maintain poles, wires, conduits and other facilities and equipment in the public rights of way....

    May 14, 2013

  • One step closer to judge post

    Legislative leaders in both houses pledged Tuesday that securing passage of a bill adding a district judge for Cleveland County is a done deal.
     

    May 15, 2013

  • Library to offer email basics class

    Beginning computer users are invited to Email Basics at 11 a.m. Tuesday at the Southwest Oklahoma City Public Library, 2201 SW 134th St. The class takes place in the library’s Computer Training Center.

    May 14, 2013

  • Ashley Miller takes over as library branch manager

    The Moore Public Library has a familiar face as its new branch manager. Ashley Miller, a fixture for several years in the library’s Children’s Department, began her duties leading the library April 16.

    May 14, 2013

  • Technology speeds disaster alerts, response

    Caitria O’Neill remembers her reaction to hearing tornado warnings on June 1, 2011. She went to the grocery store, she said, “becau

    May 14, 2013

  • Baxendale awarded $5,000 scholarship

    Candice Baxendale, of Moore, won a $5,000 scholarship as part of the “Together We Care” Nurse Practitioner Scholarship Program spon

    May 14, 2013

  • Election results online

    Due to early press times, the results of Tuesday’s special election will be posted online at www.mooreamerican.com. The vote is fo

    May 14, 2013

  • Come to my garden

    Your life is more than chaotic and that’s putting it mildly. You are pulled from every angle and no matter how hard you try, you ju

    May 14, 2013

  • Rural water district still struggling

    The Cleveland County Rural Water Board is still wading through bureaucratic red tape, hoping to meet target deadlines required to k

    May 14, 2013

  • Polls to open for special election

    Polls will be open from 7 a.m. to 7 p.m. Tuesday for the City of Moore Special Election. The Cleveland County Election Board Office will begin early voting Friday for the special election.

    May 8, 2013

Community Calendar
Loading…
Events by eviesays.com
Hyperlocal Search
Premier Guide
Find a business

Walking Fingers
Maps, Menus, Store hours, Coupons, and more...
Premier Guide