Sunday, March 23, 2014
Who needs theives when you have businesses dumping your records.
A Topeka (KS) business discovered numerous boxes with medical records in a dumpster at his business complex. The unidentified businessman was putting stuff in the dumpster at his new office location when he discovered the boxes of sensitive information.
The hoard of information contained confidential medical records, complete with names, phone numbers, and social security numbers from several midwest states. Federal laws strictly restrict the handling of medical and patient information.
The information was in the dumpsters for at least a couple of days - lots of time for someone to make use of it. And it would not even take a sophisticated ID theft ring to do this. Anyone could have reached in and grabbed 2,3,4 or 5 sets of file and been able to make $1,000 in a matter of days. The intrusion of doctors into your personal lives grows each day. Doctors now request not only your medical history but your employment information, your living arrangements and other information that has no direct issue with your medical treatments. The more information they have about you, the more information that is subject to being released to unauthorized parties.
It would be great if this was an isolated incident, however, these breaches of customer information is happening with more and more regularity. The problem is that no one is every being held accountable. While the news reports of people finding such bulk dumping of information in public dumpsters is regular, there is never any follow up to the events. I see no way that police and other officials can not trace the information back to the sources, but there appears to be a lack of desire to investigate. The only reason that the sources of these data breaches are not discovered is a lack of simple and basic research.
The acceptable methods for properly disposing of the information, while not exactly cheap, are also not overly expensive. For a person to dump the records in a dumpster underscores that someone made a decision to save time and money and avoid the proper steps. The old business saying is that the boss sets the tone for the business. The boss is the doctor in charge. The decision to short change the customers may have been made by the office manager, but that would only be if the doctor(s) involved blessed the action. If the office manager is not making the case for spending the money or the doctor(s) are rejecting the request then it is the doctor(s) that are showing a disregard for federal law and their own patients.
It is time that doctors start being held accountable for breaches of information. In this case, since the records involved people from numerous states, it is likely a specific doctor's office is not responsible for the information. However, holding doctors accountable for the conduct of companies they contract with and their handling of patient information would force doctors to select contractors based on more then just who is cheapest.
A growing area of Identity Theft is theft of Medical Services. Once someone has your identity, they can then use your information to get expense medical services and treatments. And access to your medical records could allow them to obtain prescriptions or other restricted items in your name. You could be held accountable for receiving $1,000 of narcotics and charged with federal drug crimes because your doctor used the cheapest company to out source billing or other services.
The next time you are in the doctor's office - ask them, who has access to your information and do they use any out side contractors? If they do - you may want to consider getting a new doctor.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment