<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: ehs]]></title>
    <link>http://securityratty.com/tag/ehs</link>
    <description></description>
    <pubDate>Wed, 16 Apr 2008 07:00:28 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Elliot Health System reports a breach involving health information]]></title>
      <link>http://securityratty.com/article/abae4f25b1b562e0d35d7dc7888853e0</link>
      <guid>http://securityratty.com/article/abae4f25b1b562e0d35d7dc7888853e0</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/3/08

Organization
The Elliot Health System (EHS

Contractor/Consultant/Branch
Advanced Medical Partners, Inc

Victims
Patients

Number Affected...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/elliot.jpg" align="right" height="67" width="109"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/3/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.elliothospital.org/">The Elliot Health System (EHS)</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>Advanced Medical Partners, Inc.<br><br><span style="font-weight: bold;">Victims:</span><br>Patients<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"electronic protected health information" "name, procedural dates of service at EHS, name of your insurance company and your date of birth"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"A business associate of The Elliot Health System (EHS), Advanced Medical Partners, Inc. (AMPI), has recently informed us that on the evening of February 22, 2008, a thief/thieves broke into corporate headquarters, and stole ten computers.&nbsp; The computers contained electronic protected health information and could potentially include your name, procedural dates of service at EHS, name of your insurance company and your date of birth"<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/elliott.pdf">The New Hampshire State Attorney General breach notification</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>A business associate of The Elliot Health System (EHS), Advanced Medical Partners, Inc. (AMPI), has recently informed us that on the evening of February 22, 2008, a thief/thieves broke into corporate headquarters, and stole ten computers.<br><span style="font-style: italic;">[Evan] Is this the same Advance Medical Partners that was </span><a style="font-style: italic;" href="http://news.moneycentral.msn.com/ticker/article.aspx?Feed=BW&amp;Date=20080320&amp;ID=8367618&amp;Symbol=HTRNby">recently acquired</a><span style="font-style: italic;"> HealthTronics?</span><br><br>The computers contained electronic protected health information and could potentially include your name, procedural dates of service at EHS, name of your insurance company and your date of birth<br><br>AMPI has told us that these computers have safeguards in place, including password protection, to guard against access to this information.<br><span style="font-style: italic;">[Evan] Really?&nbsp; I have two primary problems with this statement.&nbsp; First, is the "AMPI has told us" remark.&nbsp; EHS should know how their vendors/contractors secure confidential information.&nbsp; Contractor information security must be dictated by policy and/or contract language, then audited on a regular basis.&nbsp; Secondly, does EHS and/or AMPI want people to believe that password protection is adequate?</span><br><br>As with any such occurrence, we have reviewed this situation as an opportunity to evaluate current practices, policies and procedures.<br><span style="font-style: italic;">[Evan] You don't need a breach to open an opportunity for improvement.&nbsp; Constant improvement should be built into the information security program from the beginning.</span><br><br>If EHS is informed of any new information related to this security incident by AMPI, EHS will contact you and update you.<br><br>Please accept my apologies for any inconvenience this may have caused you.<br><br>If you require any additional information or assistance, please feel free to contact me.<br>Katherine St. Jean RN, CPC, CMAS<br>Director of Compliance/Corporate Compliance Officer<br>Elliot Health System<br>Compliance Dcparttnent<br>4 Elliot Way<br>Suite 303<br>Manchester, NH 03103<br>603.663.2932-phone<br><br><span style="font-weight: bold;">Commentary:</span><br>This is just a short and quick breach notification without much detail.&nbsp; Feel free to comment. <br><br><b>Past Breaches:</b><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/16/elliot.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 16 Apr 2008 07:00:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/elliot health system">elliot health system</category>
      <category domain="http://securityratty.com/tag/elliot">elliot</category>
      <category domain="http://securityratty.com/tag/health information">health information</category>
      <category domain="http://securityratty.com/tag/contractor information security">contractor information security</category>
      <category domain="http://securityratty.com/tag/ehs andor ampi">ehs andor ampi</category>
      <category domain="http://securityratty.com/tag/ehs">ehs</category>
      <category domain="http://securityratty.com/tag/information security program">information security program</category>
      <source url="http://breachblog.com/2008/04/16/elliot.aspx">Elliot Health System reports a breach involving health information</source>
    </item>
  </channel>
</rss>
