HIPAA and data security breaches on mobile devices
According to American Medical News in the February 22 edition of their newspaper, one-third of health professionals store patient data on laptops, smartphones and USB memory sticks and only 39% of health care organizations encrypt data on mobile devices.
Provisions in the federal stimulus package have tightened HIPAA notification and enforcement regulations and have made HIPAA violations more costly. For example, the maximum civil penalty from the Dept. of Health and Human Services for a data breach occurring after Feb. 18, 2009, rose from $25,000 to $1.5 million.
Security experts recommend that the data is secured and encrypted making it next to impossible for anyone who happens to find it. More importantly, users of corporate mobile devices need to be educated on the responsibility and security of the devices provided by the organization and the organization's policy on using the devices. Security awareness of the risks inherent in using mobile devices is essential and should be part of a consistent security awareness program.

Comments
Post new comment