<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: hospital]]></title>
    <link>http://securityratty.com/tag/hospital</link>
    <description></description>
    <pubDate>Thu, 10 Jul 2008 06:09:41 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Docs store unsecured patient data on memory sticks]]></title>
      <link>http://securityratty.com/article/89cd1c374f4ea62fa06e62ebeda02cb3</link>
      <guid>http://securityratty.com/article/89cd1c374f4ea62fa06e62ebeda02cb3</guid>
      <description><![CDATA[In one London hospital, 92 of 105 doctors surveyed carried memory sticks and 79 of the memory sticks held confidential patient information, but only five doctors had followed NHS rules and encrypted...]]></description>
      <content:encoded><![CDATA[In one London hospital, 92 of 105 doctors surveyed carried memory sticks and 79 of the memory sticks held confidential patient information, but only five doctors had followed NHS rules and encrypted their data.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:f585ddbb7e4d2289bcdb13f70724f429:xthKi7wonmPa0jWYC176GbSO6gQY%2FffOtGDjKH1ykQvBBhxlFWhX1NeA134QgQz%2FT9AzIdjDpgSNdCwiCnFKkGc73CkoDANQFZ8Qye5q6rs%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:2953a58368fd74b68f826ab89235afc9:OpKpNVrUK14poXga0ocNLjtNI71uCq2eBY266LucZlCIGHJIjmvJbik68Rz6ziS%2BbMVxBugoxiZ0Vq5%2FA3K0qC44SWfVqtTT1HgbK3bKWQo%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:dd1137038aba8398b5a05763dc18e506:FO56GSHaqhu3khVAx0ithopn9xBz5w1cfo5mVM8qx3ljuoZ5eX2GigsQSYVmxcnmZkcYGc9PTStPyfIPEbSXW%2FUeah9EqIqQSNQcVaSl%2FZM%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:bf89d9a2a3de48c472d2bf0946f3531a:She0m7nknv1IApnZlaZKGPO%2BwYZBtj3DYIj8weDDlPm%2BEwVm92GVSwxDK9BQ2ixSC%2FC5fsZlUeUUpjb5ZdfMwRmoxzwrH6PayysZavA1WOw%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=e5701c6bb846c552a08290d598fd8f96" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=e5701c6bb846c552a08290d598fd8f96" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/memory sticks">memory sticks</category>
      <category domain="http://securityratty.com/tag/doctors">doctors</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/nhs rules">nhs rules</category>
      <category domain="http://securityratty.com/tag/london hospital">london hospital</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=e5701c6bb846c552a08290d598fd8f96">Docs store unsecured patient data on memory sticks</source>
    </item>
    <item>
      <title><![CDATA[Apptis and USNS Mercy Monitoring on the High Seas]]></title>
      <link>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</link>
      <guid>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</guid>
      <description><![CDATA[Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="mike2 (Small)" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/mike2-small.jpg" width="204" align="left" border="0"> Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several customers. We thought Mike would have an interesting perspective to share on EM7, having recently come from the “customer side” and already with a few deployments under his belt.
<p><b>ScienceLogic: Mike, what’s your background working with network and management system tools?</b>
<p><b>Mike Lawson: </b>Before joining Apptis, I worked for the Air Force, mainly in satellite communications for almost nine years. I’m probably most familiar with HP OpenView and BMC Remedy. I managed a team that used them but wasn’t involved in tool selection; like many other federal IT workers, we didn’t have a choice of tools because there were existing enterprise licenses and maintenance contracts.
<p>I also saw a large systems integrator do a full Remedy/Crystal Systems/OpenView installation. It took 6 weeks to stand up and customize to meet just the basic monitoring requirements, and it cost something like half a million dollars. At the time, I thought that wasn’t bad and was a pretty typical experience.
<p><b>ScienceLogic: Coming from where you did, what’s your take on EM7?</b>
<p><strong>Mike Lawson:</strong> Honestly, I didn’t believe that EM7 could really do all that it claimed. In many ways, it was the complete opposite of what I had seen first-hand with other monitoring solutions. Could it really cover that much functionality? At relatively much lower cost to the customer and without the licensing nightmare?
<p>That quickly changed when I needed to understand the system enough to run it at a customer’s site. I went back over the training docs I received during my initial training class and jumped in; now, 6 months later, I’m the EM7 expert and can tell you that it delivers on all those promises. (But I still need to show people to get them to believe it too)
<p>I preach the “EM7 gospel” and when anyone wants to talk monitoring, I ask about the universal pain points: cost, maintenance contracts and licensing, and then I explain EM7. The cost difference is real; the solution is based on capacity, so there’s no licensing and it’s easy to use. They are shocked to learn that they can buy multiple EM7 appliances and years of maintenance for what they paid for most other tools.
<p><b>ScienceLogic: Apptis won the contract for monitoring aboard the USNS Mercy. We love that you’re using EM7 for one of the Navy’s hospital ships. Can you tell us more?</b>
<p><strong>Mike Lawson:</strong> The USNS Mercy is a Military Sealift Command hospital ship. <a href="http://www.navy.mil/navydata/fact_display.asp?cid=4400&amp;tid=400&amp;ct=4" target="_blank">Some stats</a>:
<ul>
<li>849 feet long (nearly the size of a football field)
<li>12 fully-equipped operating rooms, a 1,000 bed hospital facility, digital radiological services, a diagnostic and clinical laboratory, a pharmacy, an optometry lab, a CAT scan and two oxygen producing plants
<li>Crew: 61 civilian mariners, 956 Naval medical staff, and 259 Naval support staff</li>
</ul>
<p>The USNS recently departed on a five-month humanitarian mission in the Western Pacific and Southeast Asia in support of Pacific Partnership 2008. The partnership provides international medical, dental and engineering teams this summer to provide humanitarian support and conduct joint, combined, and cooperative Civil-Military Operations in order to improve regional stability and build partner capacity to respond to natural disasters and pandemic.
<p>For the most part, the ship’s network is self-contained, but can also use a landline when docked. The network covers 400 devices, including Windows/Exchange servers and VMware for server virtualization. Prior to using EM7, none of the monitoring was integrated; each system was independently monitored through individual vendor-specific consoles.
<p>Out of the box, EM7 provided integrated systems, application and network management for all network gear, applications and virtual machines in one solution. We didn’t have to do a lot of customization – EM7 includes best-practice based thresholds, event and monitoring templates and this covered what USNS Mercy needed to monitor.
<p><b>ScienceLogic: You’re a systems integrator with a very useful “customer point of view” when it comes to looking at tools. From that perspective, can you share what you think are the biggest benefits that EM7 provides?</b>
<p><strong>Mike Lawson:</strong> First of all, EM7 stands up right away. We’re talking days, not weeks. In contrast to the lengthy installation of OpenView and Remedy I witnessed during my military career, I was able to configure, customize, and implement the EM7 solution for the USNS Mercy in three days.
<p>Second, it’s easy to train people on and the support is outstanding. This judgment is from first-hand experience. Right before the USNS Mercy departed on its latest voyage, the system administrator I had trained on EM7 left, so I had all of a day to train some new EM7 admins. I prepared a seven-page “cheat sheet” and over a 3-hour conference call, we walked through the entire EM7 solution; I haven’t gotten a support call since.
<p>And when a problem did crop up with a device being discovered incorrectly, ScienceLogic was very responsive. We contacted ScienceLogic support on a Saturday and they created and emailed us a video to help troubleshoot the same day. Within 30 seconds of watching the video, the problem was resolved.
<p>Finally, EM7 helps us be good stewards of the government’s money. This is very important to me personally and to Apptis as a company. Because EM7 is cheaper and deploys so quickly and easily, you might think that it’s just the opposite of what a system integrator would want to use. But that’s short-term thinking. We believe in deliver the most value for customers every time. It’s what creates trust and long-term relationships with our customers. Instead of that half million spent on standing up the solution and basic setup, I’d much rather (and I know the customer would rather) spend that on fine-tuning or extending the solution to do much, much more.
<p>As a former government employee, I know what it’s like to use a tool that doesn’t fit my needs. EM7 proves that the best solution can totally break the old model of costly, lengthy installations. EM7 has the right model: the right solution and the right price delivered as an appliance that is easy to deploy, train on and use. </p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Apptis+and+USNS+Mercy+%26ndash%3B+Monitoring+on+the+High+Seas&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fapptis-and-usns-mercy-monitoring-on-the-high-seas%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:59:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/entire em7 solution">entire em7 solution</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/em7 gospel">em7 gospel</category>
      <category domain="http://securityratty.com/tag/em7 proves">em7 proves</category>
      <category domain="http://securityratty.com/tag/em7 admins">em7 admins</category>
      <category domain="http://securityratty.com/tag/multiple em7 appliances">multiple em7 appliances</category>
      <category domain="http://securityratty.com/tag/em7 solution">em7 solution</category>
      <category domain="http://securityratty.com/tag/explain em7">explain em7</category>
      <source url="http://blog.sciencelogic.com/apptis-and-usns-mercy-monitoring-on-the-high-seas/08/2008">Apptis and USNS Mercy Monitoring on the High Seas</source>
    </item>
    <item>
      <title><![CDATA[Hundreds Of UCLA Medical Employees Abused Privilege And Looked Into Celebrities Medical Records]]></title>
      <link>http://securityratty.com/article/fea55b84111bf15eac312f51d1f08d63</link>
      <guid>http://securityratty.com/article/fea55b84111bf15eac312f51d1f08d63</guid>
      <description><![CDATA[More than 120 workers at a Los Angeles hospital looked at celebrities medical records and other personal information without permission between January 2004 and June 2006, nearly double the number...]]></description>
      <content:encoded><![CDATA[More than 120 workers at a Los Angeles hospital looked at celebrities&#8217; medical records and other personal information without permission between January 2004 and June 2006, nearly double the number initially reported earlier this year, according to a state report.
Even after UCLA Medical Center warned employees about severe measures against unauthorized access to medical records, [...]]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 19:26:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/medical records">medical records</category>
      <category domain="http://securityratty.com/tag/celebrities medical records">celebrities medical records</category>
      <category domain="http://securityratty.com/tag/los angeles hospital">los angeles hospital</category>
      <category domain="http://securityratty.com/tag/ucla medical center">ucla medical center</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/severe measures">severe measures</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/workers">workers</category>
      <source url="http://cyberinsecure.com/hundreds-of-ucla-medical-employees-abused-privilege-and-looked-into-celebrities-medical-records/">Hundreds Of UCLA Medical Employees Abused Privilege And Looked Into Celebrities Medical Records</source>
    </item>
    <item>
      <title><![CDATA[Ah, the joys of blogging!]]></title>
      <link>http://securityratty.com/article/2e21442e3f94142ee989877a5ea060c4</link>
      <guid>http://securityratty.com/article/2e21442e3f94142ee989877a5ea060c4</guid>
      <description><![CDATA[People ask why do you blog? In the final analysis I blog because I like to. Every once in a while though you get a comment from a reader that reminds you why it is all worth while. Here is one I...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>People ask why do you blog?&nbsp; In the final analysis I blog because I like to. Every once in a while though you get a comment from a reader that reminds you why it is all worth while.&nbsp; Here is one I received today from a person alleging to be a Julie Peterson:</p><blockquote><p><em>Julie Peterson commented on </em><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/04/safe-access-win.html"><em>Safe Access wins SC Magazine Award Reader Trust Award, again!</em></a><em>: </em></p>

<p><em>Dressed in a tuxedo and chewing those rubber chicken breasts at the award ceremony is your idea of fun? Aren't you the same mentally retarded idiot who said in 2007 that you hated SC awards and that anyone can buy the SC awards with a sponsorship? Why do you think people give over $10k as sponsorship for the SC awards? Who is watching the awards except other vendors? By the way you suck big time with your rubbish blogs. Didn't networld magazine give you the boot within 3 months? Think before you write Mr. mental. Well done on winning, but please, dont give the impression that you cant buy an award from SC! And don't forget to eat your medication pills tonight, otherwise from your hair it is obvious you ran away from a mental hospital.</em> </p></blockquote><p>First of all Julie, let me thank you for your kind words! You made the statement and let me answer your questions for you.</p>

<p>1. Is dressing in a tuxedo and chewing rubber chicken breasts my idea of fun?&nbsp; Actually, I do enjoy dressing up in a tuxedo once in a while.&nbsp; The food at the awards ceremony was actually pretty good, if not diet friendly, as were the cocktails.&nbsp; The entertainment at the awards show was pretty good as well. Catching up with friends you had not seen for a while and networking with industry peers was pretty worthwhile too.&nbsp; Maybe your idea of a good time is putting on a bowling shirt and swilling a couple of beers and pretzels before going home and undressing into your dirty ripped underwear. Hey I say to each his own.</p>

<p>2. I am not the idiot who in 2007 said that I hated the SC awards and that anyone can buy the SC awards with a sponsorship.&nbsp; I am the idiot who <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2007/08/ssaaty-blog-win.html">said that about the InfoSec Products Guide</a> award by the folks at Silicon Valley Communications.&nbsp; In contrast I have always said nice things about the SC awards. I actually have a lot of respect for them.&nbsp; Also for the record, StillSecure has never been a sponsor of the SC Magazine awards. I have seen sponsors who did not win awards as well.&nbsp; So looks like you got that one wrong Julie, but it happens.</p>

<p>3. ???Networld??? magazine didn???t give me the boot within 3 months.&nbsp; They never had the chance, as I never wrote for ???networld, network world or any other magazine. Maybe you have me confused with Mike Rothman or Mitchell Ashley, who do and did write for Network World. But let me assure you that I do try and think before I write.</p>

<p>4. Regarding what medication pills I take and does my hair make it obvious I ran away from a mental hospital. I don???t take any medication, maybe I should.&nbsp; Better living through chemistry you know ;-)&nbsp; As to my hair, what can I say.&nbsp; At this stage I am happy I have any hair at all.&nbsp; My wife always says when I get my haircut it looks like a Buzz Lightyear style, but no one ever mentioned a mental hospital look to it.&nbsp; In any event sorry it doesn???t appeal to you.</p>

<p>So who is this troll Julie Peterson?&nbsp; Could it be Richard Stiennon in drag?&nbsp; Maybe his wife striking out?&nbsp; Maybe another one of my fans?&nbsp; Who knows, but these sort of comments keep me juiced about blogging and remind me of how much fun I have doing it.&nbsp; Thanks again Julie!</p></div>
]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 14:10:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/troll julie peterson">troll julie peterson</category>
      <category domain="http://securityratty.com/tag/julie peterson">julie peterson</category>
      <category domain="http://securityratty.com/tag/networld magazine">networld magazine</category>
      <category domain="http://securityratty.com/tag/magazine">magazine</category>
      <category domain="http://securityratty.com/tag/awards">awards</category>
      <category domain="http://securityratty.com/tag/win awards">win awards</category>
      <category domain="http://securityratty.com/tag/magazine awards">magazine awards</category>
      <category domain="http://securityratty.com/tag/awards ceremony">awards ceremony</category>
      <category domain="http://securityratty.com/tag/julie">julie</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/ah-the-joys-of.html">Ah, the joys of blogging!</source>
    </item>
    <item>
      <title><![CDATA[Ah, the joys of blogging!]]></title>
      <link>http://securityratty.com/article/822d1a6ac16159dd85108200273bf839</link>
      <guid>http://securityratty.com/article/822d1a6ac16159dd85108200273bf839</guid>
      <description><![CDATA[People ask why do you blog? In the final analysis I blog because I like to. Every once in a while though you get a comment from a reader that reminds you why it is all worth while. Here is one I...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>People ask why do you blog?&nbsp; In the final analysis I blog because I like to. Every once in a while though you get a comment from a reader that reminds you why it is all worth while.&nbsp; Here is one I received today from a person alleging to be a Julie Peterson:</p><blockquote><p><em>Julie Peterson commented on </em><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/04/safe-access-win.html"><em>Safe Access wins SC Magazine Award Reader Trust Award, again!</em></a><em>: </em></p>

<p><em>Dressed in a tuxedo and chewing those rubber chicken breasts at the award ceremony is your idea of fun? Aren't you the same mentally retarded idiot who said in 2007 that you hated SC awards and that anyone can buy the SC awards with a sponsorship? Why do you think people give over $10k as sponsorship for the SC awards? Who is watching the awards except other vendors? By the way you suck big time with your rubbish blogs. Didn't networld magazine give you the boot within 3 months? Think before you write Mr. mental. Well done on winning, but please, dont give the impression that you cant buy an award from SC! And don't forget to eat your medication pills tonight, otherwise from your hair it is obvious you ran away from a mental hospital.</em> </p></blockquote><p>First of all Julie, let me thank you for your kind words! You made the statement and let me answer your questions for you.</p>

<p>1. Is dressing in a tuxedo and chewing rubber chicken breasts my idea of fun?&nbsp; Actually, I do enjoy dressing up in a tuxedo once in a while.&nbsp; The food at the awards ceremony was actually pretty good, if not diet friendly, as were the cocktails.&nbsp; The entertainment at the awards show was pretty good as well. Catching up with friends you had not seen for a while and networking with industry peers was pretty worthwhile too.&nbsp; Maybe your idea of a good time is putting on a bowling shirt and swilling a couple of beers and pretzels before going home and undressing into your dirty ripped underwear. Hey I say to each his own.</p>

<p>2. I am not the idiot who in 2007 said that I hated the SC awards and that anyone can buy the SC awards with a sponsorship.&nbsp; I am the idiot who <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2007/08/ssaaty-blog-win.html">said that about the InfoSec Products Guide</a> award by the folks at Silicon Valley Communications.&nbsp; In contrast I have always said nice things about the SC awards. I actually have a lot of respect for them.&nbsp; Also for the record, StillSecure has never been a sponsor of the SC Magazine awards. I have seen sponsors who did not win awards as well.&nbsp; So looks like you got that one wrong Julie, but it happens.</p>

<p>3. “Networld” magazine didn’t give me the boot within 3 months.&nbsp; They never had the chance, as I never wrote for “networld, network world or any other magazine. Maybe you have me confused with Mike Rothman or Mitchell Ashley, who do and did write for Network World. But let me assure you that I do try and think before I write.</p>

<p>4. Regarding what medication pills I take and does my hair make it obvious I ran away from a mental hospital. I don’t take any medication, maybe I should.&nbsp; Better living through chemistry you know ;-)&nbsp; As to my hair, what can I say.&nbsp; At this stage I am happy I have any hair at all.&nbsp; My wife always says when I get my haircut it looks like a Buzz Lightyear style, but no one ever mentioned a mental hospital look to it.&nbsp; In any event sorry it doesn’t appeal to you.</p>

<p>So who is this troll Julie Peterson?&nbsp; Could it be Richard Stiennon in drag?&nbsp; Maybe his wife striking out?&nbsp; Maybe another one of my fans?&nbsp; Who knows, but these sort of comments keep me juiced about blogging and remind me of how much fun I have doing it.&nbsp; Thanks again Julie!</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=SHtn9x"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=SHtn9x" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=6lQ41J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=6lQ41J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=wHd2XJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=wHd2XJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ubGPNJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ubGPNJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=19TqYJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=19TqYJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=DScy2j"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=DScy2j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=D7Fxhj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=D7Fxhj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/349857433" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 13:12:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/troll julie peterson">troll julie peterson</category>
      <category domain="http://securityratty.com/tag/julie peterson">julie peterson</category>
      <category domain="http://securityratty.com/tag/networld magazine">networld magazine</category>
      <category domain="http://securityratty.com/tag/magazine">magazine</category>
      <category domain="http://securityratty.com/tag/awards">awards</category>
      <category domain="http://securityratty.com/tag/win awards">win awards</category>
      <category domain="http://securityratty.com/tag/awards ceremony">awards ceremony</category>
      <category domain="http://securityratty.com/tag/magazine awards">magazine awards</category>
      <category domain="http://securityratty.com/tag/julie">julie</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/349857433/ah-the-joys-of.html">Ah, the joys of blogging!</source>
    </item>
    <item>
      <title><![CDATA[Yes Virginia there really are HIPAA police]]></title>
      <link>http://securityratty.com/article/d0bc1624fe44937818753412e25aeeaa</link>
      <guid>http://securityratty.com/article/d0bc1624fe44937818753412e25aeeaa</guid>
      <description><![CDATA[One of the things that I have always not understood about HIPAA is what teeth do these regulations have and who is going to enforce them. There are plenty of firms willing to take your money and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>One of the things that I have always not understood about <a class="zem_slink" rel="wikipedia" title="Health Insurance Portability and Accountability Act" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a> is what teeth do these regulations have and who is going to enforce them.&nbsp; There are plenty of firms willing to take your money and rubber stamp you HIPAA compliant, but who is going to say your not HIPAA compliant and why should you care. Finally reading <a href="http://security.blogs.techtarget.com/2008/07/24/hipaa-violations-cost-seattle-health-care-provider/">this article in Security Bytes</a> it looks like the federal government has stepped up to enforce HIPAA and have put some bite behind the bark. Providence Health in Seattle was fined 100k by US Department of Heath and Human Services for losing data containing patients information.&nbsp; </p>&nbsp; <p>I say good for the HHS!&nbsp; A few well publicized fines where people had to pay real money will go further in getting people to take HIPAA seriously than all of the other dog barking and warnings that have taken place to date.&nbsp; The same goes for other regulations and statues on compliance as well.&nbsp; Lets hear about some financial sanctions or penalties around <a class="zem_slink" rel="wikipedia" title="PCI DSS" href="http://en.wikipedia.org/wiki/PCI_DSS">PCI</a> and you will see a drastic rise in compliance there as well.&nbsp; Rules and regulations without enforcement serve no purpose at all and hurt more than they help.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.huffingtonpost.com/deane-waldman/shoot-hipaa-the-hippo_b_109753.html">Deane Waldman: Shoot HIPAA the Hippo</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.cbc.ca/health/story/2008/05/05/fhealth-digitalrecords.html">Online health records: Convenience vs. privacy</a></li>

<li class="zemanta-article-ul-li"><a href="http://valleywag.com/368365/hospital-to-fire-13-employees-who-snooped-on-britneys-records">Hospital to fire 13 employees who snooped on Britney's records [Hipaa Hurray]</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.news.com/8301-10789_3-9879608-57.html?part=rss&amp;subj=news">DHS: U.S. health care records are the target of foreign hackers</a></li></ul></fieldset>

<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/6559114c-ee1e-4ac7-88f1-2c49c262e632/" class="zemanta-pixie-a"><img alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=6559114c-ee1e-4ac7-88f1-2c49c262e632" class="zemanta-pixie-img" style="border: medium none ; float: right;" /></a></div></div>
]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 11:58:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hipaa">hipaa</category>
      <category domain="http://securityratty.com/tag/enforce">enforce</category>
      <category domain="http://securityratty.com/tag/enforce hipaa">enforce hipaa</category>
      <category domain="http://securityratty.com/tag/records hipaa hurray">records hipaa hurray</category>
      <category domain="http://securityratty.com/tag/hipaa compliant">hipaa compliant</category>
      <category domain="http://securityratty.com/tag/health care records">health care records</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/regulations">regulations</category>
      <category domain="http://securityratty.com/tag/online health records">online health records</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/yes-virginia-th.html">Yes Virginia there really are HIPAA police</source>
    </item>
    <item>
      <title><![CDATA[Yes Virginia there really are HIPAA police]]></title>
      <link>http://securityratty.com/article/32e9a69dd0414f72767bec1ca3e39a8c</link>
      <guid>http://securityratty.com/article/32e9a69dd0414f72767bec1ca3e39a8c</guid>
      <description><![CDATA[One of the things that I have always not understood about HIPAA is what teeth do these regulations have and who is going to enforce them. There are plenty of firms willing to take your money and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>One of the things that I have always not understood about <a class="zem_slink" rel="wikipedia" title="Health Insurance Portability and Accountability Act" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a> is what teeth do these regulations have and who is going to enforce them.&nbsp; There are plenty of firms willing to take your money and rubber stamp you HIPAA compliant, but who is going to say your not HIPAA compliant and why should you care. Finally reading <a href="http://security.blogs.techtarget.com/2008/07/24/hipaa-violations-cost-seattle-health-care-provider/">this article in Security Bytes</a> it looks like the federal government has stepped up to enforce HIPAA and have put some bite behind the bark. Providence Health in Seattle was fined 100k by US Department of Heath and Human Services for losing data containing patients information.&nbsp; </p>&nbsp; <p>I say good for the HHS!&nbsp; A few well publicized fines where people had to pay real money will go further in getting people to take HIPAA seriously than all of the other dog barking and warnings that have taken place to date.&nbsp; The same goes for other regulations and statues on compliance as well.&nbsp; Lets hear about some financial sanctions or penalties around <a class="zem_slink" rel="wikipedia" title="PCI DSS" href="http://en.wikipedia.org/wiki/PCI_DSS">PCI</a> and you will see a drastic rise in compliance there as well.&nbsp; Rules and regulations without enforcement serve no purpose at all and hurt more than they help.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.huffingtonpost.com/deane-waldman/shoot-hipaa-the-hippo_b_109753.html">Deane Waldman: Shoot HIPAA the Hippo</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.cbc.ca/health/story/2008/05/05/fhealth-digitalrecords.html">Online health records: Convenience vs. privacy</a></li>

<li class="zemanta-article-ul-li"><a href="http://valleywag.com/368365/hospital-to-fire-13-employees-who-snooped-on-britneys-records">Hospital to fire 13 employees who snooped on Britney's records [Hipaa Hurray]</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.news.com/8301-10789_3-9879608-57.html?part=rss&amp;subj=news">DHS: U.S. health care records are the target of foreign hackers</a></li></ul></fieldset>

<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/6559114c-ee1e-4ac7-88f1-2c49c262e632/" class="zemanta-pixie-a"><img alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=6559114c-ee1e-4ac7-88f1-2c49c262e632" class="zemanta-pixie-img" style="border: medium none ; float: right;" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=XQSA85"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=XQSA85" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=qHfO6J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=qHfO6J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=xF8DFJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=xF8DFJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=LSj7GJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=LSj7GJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=icR7BJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=icR7BJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=l8Ddqj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=l8Ddqj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Ka0I2j"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Ka0I2j" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/345972583" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 11:01:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hipaa">hipaa</category>
      <category domain="http://securityratty.com/tag/enforce">enforce</category>
      <category domain="http://securityratty.com/tag/enforce hipaa">enforce hipaa</category>
      <category domain="http://securityratty.com/tag/records hipaa hurray">records hipaa hurray</category>
      <category domain="http://securityratty.com/tag/hipaa compliant">hipaa compliant</category>
      <category domain="http://securityratty.com/tag/health care records">health care records</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/regulations">regulations</category>
      <category domain="http://securityratty.com/tag/online health records">online health records</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/345972583/yes-virginia-th.html">Yes Virginia there really are HIPAA police</source>
    </item>
    <item>
      <title><![CDATA[Finland privacy judgment]]></title>
      <link>http://securityratty.com/article/ed9a9b4c2d0f7a235d0ab0241c8f80d1</link>
      <guid>http://securityratty.com/article/ed9a9b4c2d0f7a235d0ab0241c8f80d1</guid>
      <description><![CDATA[In a case that will have profound implications, the European Court of Human Rights has issued a judgment against Finland in a medical privacy case
The complainant was a nurse at a Finnish hospital,...]]></description>
      <content:encoded><![CDATA[<p>In a case that will have profound implications, the European Court of Human Rights has issued a <a href="http://www.cl.cam.ac.uk/~rja14/Papers/echr-finland.pdf">judgment</a> against Finland in a medical privacy case.</p>
<p>The complainant was a nurse at a Finnish hospital, and also HIV-positive. Word of her condition spread among colleagues, and her contract was not renewed. The hospital&#8217;s access controls were not sufficient to prevent colleages accessing her record, and its audit trail was not sufficient to determine who had compromised her privacy. The court&#8217;s view was  that health care staff who are not involved in the care of a patient must be unable to access that patient’s electronic medical record: &#8220;What is required in this connection is practical and effective protection to exclude any possibility of unauthorised access occurring in the first place.&#8221; (Press coverage <a href="http://www.helsinkitimes.fi/htimes/index.php?option=com_content&amp;view=article&amp;id=2156%3Aechr-finds-finland-in-breach-of-patient-confidentiality&amp;catid=33%3Ageneral&amp;Itemid=158">here</a>.)</p>
<p>A &#8220;practical and effective&#8221; protection test in European law will bind engineering, law and policy much more tightly together. And it will have wide consequences. Privacy compaigners, for example, can now argue strongly that the NHS Care Records service is illegal. And what will be the further consequences for the Transformational Government initiative - the &#8220;Database State&#8221;?</p>
]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 11:26:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/hospitals access controls">hospitals access controls</category>
      <category domain="http://securityratty.com/tag/effective protection test">effective protection test</category>
      <category domain="http://securityratty.com/tag/effective protection">effective protection</category>
      <category domain="http://securityratty.com/tag/medical privacy">medical privacy</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/health care staff">health care staff</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/law">law</category>
      <source url="http://www.lightbluetouchpaper.org/2008/07/23/finland-privacy-judgment/">Finland privacy judgment</source>
    </item>
    <item>
      <title><![CDATA[Employee fraud hits Baptist Health in Arkansas]]></title>
      <link>http://securityratty.com/article/4227f770b7017f7d953c43516b49d951</link>
      <guid>http://securityratty.com/article/4227f770b7017f7d953c43516b49d951</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/2/08

Organization
Baptist Health

Baptist Health is the largest not-for-profit healthcare organization in Arkansas

Contractor/Consultant/Branch
None...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/baptisthealth.jpg" width="120" align="right" height="274"><font size="2"><b>Date Reported: </b><br>7/2/08<br><br><b>Organization: </b><br><a href="http://www.baptist-health.org/">Baptist Health*</a><br><br><font size="1">*Baptist Health is the largest not-for-profit healthcare organization in Arkansas</font><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Patients<br><br><span style="font-weight: bold;">Number Affected:</span><br>~1,800<br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, address, date of birth, Social Security number, and reason for coming to Baptist Health"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"LITTLE ROCK (AP) - A North Little Rock woman has been arrested for using financial information from patients at Baptist Health to illegally obtain Wal-Mart gift cards for her own use. The hospital has notified about 1,800 patrons of the ID theft."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.wxvt.com/Global/story.asp?S=8609129&amp;nav=menu1344_2">Associated Press via WXVT Channel 15 News</a> <br><a href="http://arkansasmatters.com/content/fulltext/news/?cid=80211">KARK Channel 4 News</a> <br><a href="http://www.nwanews.com/adg/News/230290/">Arkansas Democrat-Gazette</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Toby Manthey, Arkansas Democrat-Gazette<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Baptist Health has sent letters warning about 1,800 patients that the hospital system’s records may have been breached<br><span style="font-style: italic;">[Evan] Uh, "may have been breached"?!</span><br><br>The notification came after the arrest of a Baptist Health employee at a Wal-Mart store on 25 counts of financial identity fraud.<br><span style="font-style: italic;">[Evan] Wouldn't life be grand if we could trust our employees?&nbsp; Maybe, I suppose.</span><br><br>The letters, mailed last week, follow the firing of the woman in early June<br><br>North Little Rock police say Tamara Hill, 30, of that city worked at Baptist Health Medical Center-North Little Rock in the emergency department.<br><br>Hill, an admissions clerk, was arrested May 30 at the Wal-Mart<br><br>Ebony Flowers, 25, also of North Little Rock, was arrested at the store the same day on three counts of identity fraud<br><br>Flowers was listed in a police report as a janitor for the North Little Rock School District<br><span style="font-style: italic;">[Evan] Key word is "was".</span><br><br>Baptist Health recorded more than 950,000 patient visits systemwide in 2007, a number that includes repeat visits.<br><br>Mark Lowman, spokesman for the Little Rock-based Baptist Health system, confirmed that the system fired the employee after notification of the arrest.<br><br>Police reports say the women used a victim’s personal information to obtain temporary Wal-Mart "account authorization numbers" - credit cards, essentially - used to buy Wal-Mart gift cards.<br><br>The victim reported to police that he had not authorized the transactions<br><br>the same victim confirmed he was a Baptist Health patient<br><br>He expressed appreciation of the handling of the case by the system and by the North Little Rock police. <br><br>Among the items found during a search connected with the arrest of Hill was personal information for 24 other people, including "screen shots" - printouts showing the exact appearance of the images on a computer screen - that showed victims’ personal information.<br><span style="font-style: italic;">[Evan] This seems like confirmation that "may have been breached" is not all that accurate.</span><br><br>Also found were four Wal-Mart gift cards and $ 1,490 in cash<br><br>Police found a small bag of marijuana on Flowers, according to the reports. In a search connected with her arrest, they also discovered a. 25-caliber magazine with six bullets, as well as a receipt for four of the gift cards and information on three-identity theft victims.<br><span style="font-style: italic;">[Evan] A thug.</span><br><br>The U. S. Secret Service is helping with the investigation. <br><br>"Due to a breach of our information systems security policies, there is a possibility that some personal information, such as your name, address, date of birth, Social Security number, and reason for coming to Baptist Health, was accessed by an unauthorized person."<br><span style="font-style: italic;">[Evan] This is from the letter to the victims.</span><br><br>No information in the patient’s "medical records" and no information about the patient’s diagnosis or prognosis was accessed<br><br>while no "medical record" information was accessed, the letter mentioned the patient’s "reason for coming" to the system possibly was accessed<br><br>Lowman said a reason stated by a patient using the system isn’t considered medical information because the reason is a layman’s explanation, not one from a medical professional.<br><span style="font-style: italic;">[Evan] This is Mark Lowman, spokesman for the Little Rock-based Baptist Health system</span><br><br>He said the breach wouldn’t violate the Health Insurance Portability and Accountability Act, or HIPAA. <br><br>But Pam Dixon, executive director of the San Diego-based World Privacy Forum, a privacy advocacy group, thinks all the information mentioned in the letter falls under HIPAA.<br><br>"It doesn’t matter that [it’s not ] a prognosis or diagnosis," she said. <br><span style="font-style: italic;">[Evan] Splitting hairs.&nbsp; The bottom line is that confidential personal information was stolen and there are victims.&nbsp; Whether or not it is a HIPAA violation seems somewhat irrelevant.</span><br><br>Dixon found the system’s letter lacking in several respects, such as clarifying the exact meaning of a "reason for coming to Baptist Health." The letter also should have mentioned when and for how long the breach occurred, she said.<br><br>"Almost all breach letters have that," Dixon added.<br><span style="font-style: italic;">[Evan] Almost all breach letters have what?&nbsp; A mention about for how long the breach occurred?&nbsp; I must be reading some of the wrong breach letters because it seems to me that this information is 50/50 at best.&nbsp; Also missing is the "we have no reason to believe that the information will be misused", but this one doesn't fit does it?</span><br><br>Dixon said Baptist Health should have offered in the letter to set up free credit monitoring for victims.<br><span style="font-style: italic;">[Evan] Why?&nbsp; One year (or two) of credit monitoring is almost useless.&nbsp; Credit monitoring alerts a victim after fraud has already occurred and one year (or two) of monitoring is too limited for information that has a much longer lifespan.&nbsp; I guess credit monitoring would be better than nothing, but not by much.</span><br><br>Lowman said the health system continually conducts audits to know which staff members are accessing what information, and whether or not the access is appropriate.<br><span style="font-style: italic;">[Evan] Good!</span><br><br>"We’re always looking to provide better audits and better oversight of private, confidential and protected information," Lowman said.<br><span style="font-style: italic;">[Evan] And Good!</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Preventing and detecting employee fraud has always been a challenge.&nbsp; This doesn't mean we give up though.&nbsp; We have some tools at our disposal such as employee background checks, role-based access control, segregation of duties, and job rotation to name a few.<br><br>I don't think that these two crooks are anything more than common criminals.&nbsp; The fact of the matter is that identity theft and fraud are very easy crimes to commit and require very little skill. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/10/baptisthealth.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 20:00:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/confidential personal information">confidential personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/baptist health system">baptist health system</category>
      <category domain="http://securityratty.com/tag/health system">health system</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/victims personal information">victims personal information</category>
      <category domain="http://securityratty.com/tag/employee fraud">employee fraud</category>
      <category domain="http://securityratty.com/tag/baptist health">baptist health</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <source url="http://breachblog.com/2008/07/10/baptisthealth.aspx">Employee fraud hits Baptist Health in Arkansas</source>
    </item>
    <item>
      <title><![CDATA[CBAC & Medical Identity Theft]]></title>
      <link>http://securityratty.com/article/02105d066a63c57c66a00f92ef63e99d</link>
      <guid>http://securityratty.com/article/02105d066a63c57c66a00f92ef63e99d</guid>
      <description><![CDATA[Good story to keep in mind for those of you working on CBAC. Claims neeed protection and verification. Why steal an identity when you can capture a claim? (hattip: askelizabeth
The Sopranokovs
The...]]></description>
      <content:encoded><![CDATA[<p>Good story to keep in mind for those of you working on CBAC. Claims neeed protection and verification. Why steal an identity when you can capture a claim? (hattip: <a href="http://askelizabeth.typepad.com/weblog/2008/07/medical-identity-theft-the-new-frontier-for-organized-crime.html">askelizabeth</a>)

</p><blockquote><p>
	The Sopranokovs 
	</p></blockquote><blockquote><p>The Russian mob comes to town with a new scam—medical identity theft. 	
	</p></blockquote><blockquote><p>When FBI special agent Ted Price peered through the window of a dingy brick storefront on Southwest Morrison Street in March, it was what he didn’t see that caught his attention. 	</p></blockquote><blockquote><p>The business, called UnimedCorner, claimed to provide ailing seniors with orthotics—braces and other devices to correct foot, joint and back problems. 	
	</p></blockquote><blockquote><p>Price and other federal investigators were skeptical. 	
	</p></blockquote><blockquote><p>On Unimed’s showroom floor, Price saw wheelchairs, motorized scooters, a variety of canes and, on the walls, a selection of amateurish paintings and framed photographs. There was no evidence, however, of the kinds of equipment for which Unimed had billed Medicare nearly $2 million in the previous couple of months. 	
	</p></blockquote><blockquote><p>“I observed wheelchairs and canes through the window but did not see any orthotics in the store,” Price later wrote in a search-warrant affidavit. “It is a sign of fraud that the store is not stocking the items [for which] it is billing.” 	
	</p></blockquote><blockquote><p>By the time Price arrived on the scene, the company’s owner, a shadowy Russian immigrant named Alexandr Shcherbakov, was long gone. 	
	</p></blockquote><blockquote><p>Today, Shcherbakov’s store sits undisturbed. The message light on the phone blinks, dead potted plants droop and a stuffed toy monkey slumps in a glass display case. 	
	</p></blockquote><blockquote><p>And behind the cash register hangs a framed poster of television’s best-known mobsters, the Sopranos. 	
	</p></blockquote><blockquote><p>From interviews and information presented in federal affidavits, it is clear Shcherbakov moved to Oregon to commit a crime elegant and lucrative enough to make Tony Soprano envious: medical identity theft. 	
	</p></blockquote><blockquote><p>... 	
	</p></blockquote><blockquote><p>“Medical identity theft is the new frontier for organized crime,” says Alex Johnson, a former FBI agent who investigates fraud for Regence BlueShield. “Pretty much anybody can set up a mom-and-pop operation and start cranking out claims.”
	
	Someday, most Americans will need a cane, wheelchair, home hospital bed or another of the items healthcare professionals call “durable medical equipment,” or DME. 	
	</p></blockquote><blockquote><p>For those over 64 and without private insurance, there’s a good chance federally funded Medicare will pick up the tab for that equipment. Last year, according to federal statistics, Medicare spent $8.6 billion on DME. 	
	</p></blockquote><blockquote><p>Here’s the way the system is supposed to work: A doctor prescribes a device such as a wheelchair for a patient, who presents his prescription to a DME supplier. The supplier provides the equipment and bills Medicare, which typically pays 80 percent of the cost.
	
	Unlike pharmacists, who fill prescriptions under strict scrutiny of state and federal watchdogs, DME suppliers are lightly regulated.
	
	“DME is very vulnerable to fraud,” says Consuelo Woodhead, the chief healthcare fraud prosecutor for the U.S. Attorney’s Office in Los Angeles. “It doesn’t require any background in medicine, any kind of professional licensure or appreciable capital. </p></blockquote><blockquote><p>There are barriers of entry in other medical fields, but not in DME.”
	
	To operate, DME suppliers simply need a place of business, a business license and liability insurance. Unlike pharmacists, DME suppliers operate under an honor system: The feds count on them to supply the equipment they claim to provide to the beneficiaries who need it. 	
	</p></blockquote><blockquote><p>That honor system is not working. 	
	</p></blockquote><blockquote><p>The epicenter of DME fraud, according to the federal Department of Health and Human Services, is South Florida, where Medicare billing for DME quadrupled from 2002 to 2006 to $1.7 billion.
	
	Investigators found much of that increase was due to fraud. In 2006, federal inspectors revoked the licenses of 634 DME suppliers in South Florida, nearly half the DME dealers in the region. </p></blockquote><blockquote><p>Later the same year, raids in Southern California yielded similar results: The feds shut down 95 DME suppliers.
	
	Many of the DME suppliers shut down around Los Angeles were run by immigrants from the former Soviet Union. It’s probably no coincidence that when the feds raided Los Angeles DME suppliers, some Angelenos fled to cities where there was less scrutiny—such as Portland.</p></blockquote>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 06:09:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dme suppliers simply">dme suppliers simply</category>
      <category domain="http://securityratty.com/tag/dme suppliers">dme suppliers</category>
      <category domain="http://securityratty.com/tag/dme fraud">dme fraud</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/dme">dme</category>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/medical identity theft">medical identity theft</category>
      <category domain="http://securityratty.com/tag/dme dealers">dme dealers</category>
      <category domain="http://securityratty.com/tag/dme supplier">dme supplier</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/cbac-medical-identity-theft.html">CBAC &amp; Medical Identity Theft</source>
    </item>
  </channel>
</rss>
