Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Medical Data on 365,000 Patients Stolen

Posted by CowboyNeal on Thu Jan 26, 2006 10:26 PM
from the bandwidth-and-station-wagons dept.
Anonymous writes "Backup tapes and disks with data on 365,000 patients were stolen out of the car of a worker at a healthcare company in Portland. According to this Computerworld story, the tapes were in his car because he took them home as part of a disaster recovery plan, to protect the information from fire and other on-site disasters. D'oh!"
This discussion has been archived. No new comments can be posted.
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • What's the problem (Score:5, Funny)

    by WormholeFiend (674934) on Thursday January 26 2006, @10:29PM (#14575679)
    They still have the originals, so they can make a new set of backups!
  • Well, the question is ... (Score:5, Insightful)

    by ScrewMaster (602015) on Thursday January 26 2006, @10:29PM (#14575680)
    do they have a recovery plan for this disaster?
  • Hehe (Score:5, Funny)

    by Trip Ericson (864747) on Thursday January 26 2006, @10:29PM (#14575681)
    (http://www.rabbitears.info/)
    "But we know the data's safe! We just have no idea where the hell it is."
    • Walking to the bank. by suso (Score:2) Thursday January 26 2006, @11:23PM
    • Re:Hehe by shawn(at)fsu (Score:2) Friday January 27 2006, @12:19AM
      • Reply to sig. by Descalzo (Score:2) Friday January 27 2006, @01:23AM
    • Re:Hehe by hobbesx (Score:1) Friday January 27 2006, @12:27AM
    • 1 reply beneath your current threshold.
  • The further story (Score:5, Informative)

    by daeley (126313) on Thursday January 26 2006, @10:30PM (#14575689)
    (http://www.celsius1414.com/)
    From TFA:

    The data on the tapes was encrypted, Walker said. The data on the disks was in a proprietary file format that was not encrypted, but "is stored in a way that would make it difficult, if not impossible, for someone to access it, then make any sense out of it," he said.

    So not as bad as the summary seemed to indicate, but still not the greatest thing to have happen.

    Especially if that proprietary file format "difficulty" is just the fact that the files are in some old version of Word. ;)
    • Re:The further story by Anonymous Coward (Score:2) Thursday January 26 2006, @10:51PM
    • Re:The further story by GodBlessTexas (Score:3) Thursday January 26 2006, @11:02PM
    • Much worse! Data really on disks! (Score:5, Insightful)

      by SuperKendall (25149) * on Thursday January 26 2006, @11:09PM (#14575911)
      It took me a minute to decypher that cyrptic comment, but look at these two parts from the article together:

      In an announcement yesterday, Providence Home Services, a division of Seattle-based Providence Health Systems, said the records and other data were on several disks and tapes stolen from the car of a Providence employee at his home. The incident was reported by the employee on Dec. 31, according to the health care system.
      The data on the tapes was encrypted, Walker said. The data on the disks was in a proprietary file format that was not encrypted, but "is stored in a way that would make it difficult, if not impossible, for someone to access it, then make any sense out of it," he said.


      So think about it - Tapes AND Disks were stolen (at first I had thought it was just tapes). The hard to read media (tapes) were encrypted. But it doesn't matter, chuck 'em in the river because the DISKS (fasr easier to read by any fool with a computer) have data that is in a format that is just "hard to read"!!

      Give me five minutes with Emacs and/or a Hex editor and/or Strings and I'll bet I could start churning SSN's out of the files right quick! I don't care if they are ISAM or DB2 or Pig-Latin! Security by file format obscurity is zero security, that data has to be treated as widely known at this point.
      [ Parent ]
    • Re:The further story by evil-osm (Score:2) Thursday January 26 2006, @11:24PM
    • Re:encrypted by neonsignal (Score:2) Thursday January 26 2006, @11:46PM
    • Re:The further story by hokeyru (Score:1) Friday January 27 2006, @12:12AM
    • Re:The further story by hunterx11 (Score:1) Friday January 27 2006, @02:55AM
    • 1 reply beneath your current threshold.
  • And that's why... (Score:5, Informative)

    ...you get an archive company that picks up the tapes and signs for them. You want a paper trail.

    Oh, and make sure the vault they keep them in is a)real and b) really able to withstand ANY disaster.

  • Next week... (Score:3, Funny)

    by FalconZero (607567) * <[FalconZero] [at] [Gmail.com]> on Thursday January 26 2006, @10:32PM (#14575701)
    ...on eBay.....
  • hmmm (Score:4, Interesting)

    by rwven (663186) on Thursday January 26 2006, @10:32PM (#14575702)
    (http://www.rwven.com/ | Last Journal: Monday January 23 2006, @02:52PM)
    You've got to wonder why these people didn't have this stuff encrypted... An encrypted filesystem at least or straight up file encryption even... When are these companies going to get a clue?

    And storing the tapes in your car? What happens if it's 100 degrees outside?

    Where i work, they make the backup copies and have someone drive them to one of the other branches at the company. They make a backup every day and keep seven days worth of backup in rotation so if something went wrong 6 days ago and they backed up the problem every day, they ahve the 7th backup left to work with...

    Unfortunatley i don't know what their view on encrypting the data is. With as anal retentive as the IT VP is about security though, i can't imagine they wouldn't be encrypted...
    • Re:hmmm by rwven (Score:2) Thursday January 26 2006, @10:41PM
    • Re:hmmm by OgreChow (Score:2) Thursday January 26 2006, @10:45PM
      • Re:hmmm by jbrader (Score:2) Thursday January 26 2006, @10:50PM
    • Re:hmmm by topham (Score:2) Thursday January 26 2006, @11:53PM
    • Re:hmmm by CyberVenom (Score:2) Friday January 27 2006, @01:49AM
      • Re:hmmm by rwven (Score:2) Friday January 27 2006, @09:35AM
    • 2 replies beneath your current threshold.
  • Why is anyone allowed to take the records? by hsmith (Score:2) Thursday January 26 2006, @10:34PM
  • No problem by baryon351 (Score:1) Thursday January 26 2006, @10:36PM
    • Re:No problem by Anonymous Coward (Score:1) Friday January 27 2006, @12:02AM
      • Re:No problem by OnlineAlias (Score:1) Friday January 27 2006, @08:51AM
      • 1 reply beneath your current threshold.
  • Hard to believe this mistake (Score:3, Informative)

    by Chowser (888973) on Thursday January 26 2006, @10:37PM (#14575725)
    At my clinic where there is an EHR (Electronic Health Record) there is built in redundancy with multiple servers in different locations. It is hard to believe that a hospital system as big as Providence (which owns hospitals in multiple NW states) could have something as stupid as someone taking home a backup in their car.
  • Is it really theft? (Score:5, Interesting)

    by rolfwind (528248) on Thursday January 26 2006, @10:40PM (#14575743)
    The incident is the second data theft from a motor vehicle announced this week. Yesterday, Minneapolis-based financial services company Ameriprise Financial Inc. said it is notifying some 158,000 customers and 68,000 financial advisers that a laptop containing personal information about them -- including names, account numbers or Social Security numbers -- was stolen from a parked car late last month (see "Ameriprise notifying 226,000 customers, advisers of data theft").


    I can see hard disks being stolen..... but not tapes in the one case. Thieves like to take items with obvious value. Am I missing something here? Isn't it possible the workers simply sold the data?
  • What century is this? by aphaenogaster (Score:2) Thursday January 26 2006, @10:40PM
  • just say no to SSN#s by tv_dinners (Score:1) Thursday January 26 2006, @10:40PM
  • OK (Score:3, Insightful)

    by 42Penguins (861511) on Thursday January 26 2006, @10:41PM (#14575757)
    Cue the "bandwidth of a station wagon of backup tapes" cliches? If it's stuff they really don't want stolen, why not buy a safe for his car? Better yet, give him a company truck/van with secure storage. If they have 365,000 patients (customers) then they can surely afford to protect their information.
    • Re:OK by dal20402 (Score:1) Thursday January 26 2006, @11:40PM
      • Re:OK by Keith McClary (Score:2) Friday January 27 2006, @12:41AM
      • Re:OK by dal20402 (Score:2) Friday January 27 2006, @01:09AM
      • 1 reply beneath your current threshold.
    • Re: 365,000 by Lucas Membrane (Score:2) Friday January 27 2006, @01:41AM
  • Thanks, buddy! (Score:3, Funny)

    by Anonymous Coward on Thursday January 26 2006, @10:41PM (#14575758)
    Now I don't have cancer anymore!
  • I think I speak for everyone when I say... by mnemonic_ (Score:2) Thursday January 26 2006, @10:42PM
  • Partially encrypted (Score:5, Interesting)

    by krray (605395) * on Thursday January 26 2006, @10:42PM (#14575764)
    At least the tapes were encrypted (not the disks in this incident). Even though this case doesn't affect me this was the first question that (always) pops in my head.

    For much the same reasons cited here our company backups are taken offsite (daily) -- only difference is that instead of tapes and disks we found that for speed, volume, and cost it was better to go with external hard drives (I figured this out almost ten years ago myself :).

    Even though we are a small organization (under a few hundred employees) the data is encrypted. That was step one and one of the most important IMHO. The average Joe who finds / steals any of our external drives (which has never happened thankfully) would be hard pressed to even figure out the filesystem (Ext3). Not that that would really slow down anybody who knows what they're doing -- nor was it done for security (I just like / trust Linux :).

    Of course I can think of other problem areas where data is flying around unencrypted and sensitive. The Department of Employment Security (which many states all report to for and through payroll to track dead beat dads) takes their data with your social security number in a plain ASCII text file sent through the US mail on a floppy. What happens when you lose a floppy, or what do they do with the processed disks?

    Fortunately and unfortunately we need and there will be laws requiring any such sensitive information to be encrypted for "National Security" (Big Brother [tm]) reasons. It's only a matter of time. It is unfortunate that it will take a law and more bureaucratic BS to make this happen, it is fortunate for all our privacy and the fact someone has to program this (more work for me :).
  • Don't Use Your Car by slashbob22 (Score:2) Thursday January 26 2006, @10:51PM
  • Next MasterCard commercial by bob0the0mighty (Score:1) Thursday January 26 2006, @10:52PM
  • Absurd by seanadams.com (Score:2) Thursday January 26 2006, @10:59PM
    • Re:Absurd by Orangejesus (Score:1) Thursday January 26 2006, @11:29PM
    • Re:Absurd by Average_Joe_Sixpack (Score:1) Thursday January 26 2006, @11:33PM
      • Re:Absurd by Rakishi (Score:2) Thursday January 26 2006, @11:39PM
      • Re:Absurd by Anonymous Coward (Score:2) Friday January 27 2006, @02:03AM
    • Re:Absurd by engagebot (Score:1) Friday January 27 2006, @12:51PM
    • Re:Absurd by seanadams.com (Score:2) Friday January 27 2006, @01:12AM
    • 1 reply beneath your current threshold.
  • I Live In Fear of This (Score:5, Interesting)

    by good soldier svejk (571730) on Thursday January 26 2006, @11:01PM (#14575872)
    I also work at a healthcare provider adn deal with this exposure every day. Normal backups provides us no disaster recovery value because our recover point objective is measured in minutes. Tape simply can't meet it. Likewise if we were to attempt to restore the entire operation from tape it would take months. Just acquiring hardware would take weeks. But our recovery time objective is forty-eight hours. Basically, if we go longer than that we are out of business. So long term, our DR strategy is based on storage and app level replication between data centers. But as it stands, we only have one site. Consequently we send our backups offsite, essentially as a placebo. But it gets better. We don't have the drive resources to duplicate tape, so we send the originals offsite. That means that if we need to do a restore we must wait an hour for someone to retrieve the tape and reinject it into our library.

    Let's review here: we have a fake DR strategy which adds an hour to every file restore and exposes us to data theft. Sounds good huh? I have repeatedly told our brass it would be better to do nothing, but their position is "We don't want to tell the newspapers we had no DR strategy when the disaster strikes."

    How do we remediate this? Well, we could encrypt the tape but that is a big pain in the ass and has its own disadvantages. Really, the answer is to get off our ass and build a DR data center so the potentially deadly placebo goes away.
  • In other news... (Score:5, Funny)

    by Statecraftsman (718862) on Thursday January 26 2006, @11:05PM (#14575889)
    (http://www.davidsterry.com/)
    Google's page count mysteriously jumps by 365,000 records. Coincidence? You decide.
  • Ah, more digital leakage that no... by 3seas (Score:2) Thursday January 26 2006, @11:14PM
  • I see ... / I don't see by Lifix (Score:2) Thursday January 26 2006, @11:23PM
  • Reminds me of the last place I was fired from... by malraid (Score:2) Thursday January 26 2006, @11:26PM
  • Cough Cough by NetNinja (Score:1) Thursday January 26 2006, @11:32PM
  • Hmmm... how big is this company? by ursabear (Score:1) Thursday January 26 2006, @11:45PM
  • Sounds a bit sketchy... by TheNoxx (Score:2) Thursday January 26 2006, @11:50PM
  • Wha? huh? by rnturn (Score:2) Friday January 27 2006, @12:18AM
    • 1 reply beneath your current threshold.
  • I guess no one has heard of encrypting backups. by buss_error (Score:2) Friday January 27 2006, @12:19AM
  • Ironic by Mendokusei (Score:1) Friday January 27 2006, @12:46AM
    • 1 reply beneath your current threshold.
  • My take... (Score:5, Informative)

    by hahn (101816) on Friday January 27 2006, @01:14AM (#14576548)
    (http://flux73.blogspot.com/)
    Well, finally a Slashdot post I can write about with some experience. FWIW, I'm a physician in Portland and medical informatics is an interest of mine.

    First of all, while it may shock many IT people that hospitals would use such rudimentary forms of backup and with little encryption, you have to understand that the state of IT in the medical world is backwards. Very backwards. There are a variety of reasons for this. One is that information systems are designed by IT people with little to no understanding of how the healthcare system works (which is understandable - many people in healthcare have little understanding of how it works). At the same time, you have healthcare professionals who really don't understand the full potential of how IT can be applied to healthcare or what its limitations are, but at the same time will complain about solutions that the IT world comes up with. There's this chasm between the two worlds and what you end up getting is a solution that no one likes and you end up having to go back to the drawing board over and over and over. It is absolutely amazing how much money gets sunk into medical IT and how very little progress it has made.

    Another reasons includes the vast amounts of red tape in the medical world that are MEANT to prevent lawsuits and provide the best quality healthcare. But there's so much that it what it really ends up doing is bringing any kind of progress or new idea to a grinding halt. There is no industry I can think of which is so ill adapted to making changes even when they're necessary or make sense. The legal world has the medical world frozen in fear of the next litigation. The result is a paradoxical decrease in healthcare quality and increased costs.

    Medical information privacy is one of those issues that seems to always be #1 on the list of concerns of electronic medical records. This has always been rather strange to me. How many people are really all that concerned with someone knowing about their cold, or their broken leg? Most people don't have much they would really care about hiding in their medical records. Of course, there are the people with mental illness, HIV, or sexually transmitted diseases. But even then, what exactly is this thief going to do with that information? IMHO medical information privacy is more of a theoretical concern than a real-life concern.

    And then of course, there's the REAL reason people are considered with medical information being digitized identity theft for money reasons. I really blame the credit card industry for this more than anyone else. It's surprising to me that they could simply issue a credit card if someone just writes down a name, social security number and address. In this day and age with inexpensive biometric security systems, one would think they could require a submission of a fingerprint (or two). Hell, nowadays with branch offices literally EVERYWHERE, they could simply request you come in with your driver's license. It seems to me that it would be in a bank's best financial interests to do something like this.

    Just my $0.02.
  • Well HIPAA is gonna get some cash from this... by Treslayr (Score:1) Friday January 27 2006, @01:18AM
  • Hospitals, Schmospitals... by Aelcyx (Score:1) Friday January 27 2006, @02:24AM
  • The disks weren't encrypted. by Devistater (Score:2) Friday January 27 2006, @02:40AM
  • reminds me of the John Cleese sketch... by rgravina (Score:1) Friday January 27 2006, @03:31AM
  • Patent Lawyer by Stan Vassilev (Score:1) Friday January 27 2006, @03:52AM
  • Childish excuses? by VincenzoRomano (Score:2) Friday January 27 2006, @05:00AM
  • Off Site by Anonymous Coward (Score:1) Friday January 27 2006, @08:03AM
  • Data left out in the open by digitaldc (Score:2) Friday January 27 2006, @08:06AM
  • Responsibility in action? by Maljin Jolt (Score:2) Friday January 27 2006, @08:48AM
  • Ok, what's the worry? by FhnuZoag (Score:1) Friday January 27 2006, @08:51AM
  • Competition for the onsite data storage companies by JustMyOptionSB (Score:1) Friday January 27 2006, @09:55AM
  • $20 million? by VisceralLogic (Score:1) Friday January 27 2006, @10:03AM
  • Why were the backups in an empty car? by Lodragandraoidh (Score:2) Friday January 27 2006, @10:18AM
  • Encryption?.... by Physics Dude (Score:2) Friday January 27 2006, @10:25AM
  • social security numbers still used as medical ids by peter303 (Score:2) Friday January 27 2006, @10:32AM
  • Outrageous - more and greater fines needed by rbrewer123 (Score:1) Friday January 27 2006, @11:11AM
  • Insecure Medical Data in Fort Wayne, Indiana by DeonFaustus (Score:1) Friday January 27 2006, @12:15PM
  • Chain of Custody by WillAffleckUW (Score:2) Friday January 27 2006, @01:20PM
  • Nothing new under the sun by 6*7 (Score:1) Saturday January 28 2006, @07:40AM
  • This is the new world order.It was not an accident by ClintJCL (Score:1) Monday January 30 2006, @11:39AM
  • Re:Who Robbed Him? by aliscool (Score:1) Thursday January 26 2006, @10:54PM
    • 1 reply beneath your current threshold.
  • Re:Who Robbed Him? by EZLeeAmused (Score:1) Thursday January 26 2006, @11:32PM
  • Re:SPY? by Rebelgecko (Score:1) Thursday January 26 2006, @11:59PM
  • rfc? by bobamu (Score:1) Friday January 27 2006, @04:50AM
  • 15 replies beneath your current threshold.