[ Tuesday, January 08, 2013 ]


One of the More Common HIPAA Insider Breach Scenarios: Hospital employees sell patient data to a third party to target potential customers.  Often it's ER employees selling information on accident victims to attorneys or chiropractors, as it was in this case.  A call to an accident victim's mother, who happened to work at the hospital and knew that information should not have been available, triggered the investigation that nabbed the suspects, but the hospital probably should've been doing more auditing of access; they could've caught the husband, who accessed hundreds of thousands of files.

Jeff [5:42 PM]

