in

This Blog

Syndication

Tags

News

AlertBoot offers a cloud-based full disk encryption and mobile device security service for companies of any size who want a scalable and easy-to-deploy solution. Centrally managed through a web based console, AlertBoot offers mobile device management, mobile antivirus, remote wipe & lock, device auditing, USB drive and hard disk encryption managed services.

Archives

AlertBoot Endpoint Security

AlertBoot offers a cloud-based full disk encryption and mobile device security service for companies of any size who want a scalable and easy-to-deploy solution. Centrally managed through a web based console, AlertBoot offers mobile device management, mobile antivirus, remote wipe & lock, device auditing, USB drive and hard disk encryption managed services.

HIPAA Disk Encryption: Covered Entities Not Immune from Data Breaches Stemming From "Acts of God"

As I've often noted, you can't eliminate systematic risk, a term I've borrowed from my college economics classes and which refers to a risk inherent within a system.  When it comes to HIPAA data breaches, it means that try as you might, certain risks will always remain, no matter what.  The following case is a reminder of that, and why using medical data encryption is always better than physical and policy-based security practices.

Breach Notification because of Earthquake

According to phiprivacy.net, the Napa County Health and Human Services Agency is sending breach notification letters to Home Supportive Services clients.  The notification mentions that a flash drive was lost "in the rubble after a big earthquake."  The information on the thumb drive was not encrypted.

It is amazing that the agency even figured out the loss of the drive, seeing how "the loss was discovered on August 27, three days after the earthquake, when the agency attempted to deal with the rubble in its office (which remains unusable from the damage)."

Why not Use Encryption?

Why was encryption software not used to protect the contents of the USB drive?  Chances are, because the employees were trustworthy and the agency had a data security policy that prohibited taking any data outside of the agency's grounds.  This is a commonly used data security policy and a good way to lower the risk of a data breach.  The problem is, though, that some organizations use it as a replacement to technical solutions.

The thought process, apparently, goes like this: the employees will follow the policies (especially because they're being reminded and educated on the issue periodically); the employees are 100% dependable; thus, the data will not leave the organization's grounds; the organization's grounds are protected from outsiders; conclusion: there's no way you can have a data breach from a small data storage device.

Assuming all of the above is true, however, you still have to deal with systematic risks such as earthquakes, like Napa County.  Or a flood, for that matter.  It was four years ago that another covered entity had filed a breach notification with the HHS, noting that their computers and paper documents had disappeared when their offices were hit by a flood.

Unlike Napa County, however, they had encrypted their computers, nipping an electronic data breach in the bud.  It goes to show that technical solutions bring a lot to the table, much more than a policy/behavioral based solution.

Related Articles and Sites:
http://www.phiprivacy.net/napa-county-notifies-in-home-supportive-services-clients-of-missing-thumb-drive/

 

 
<Previous Next>

Managed Encryption Service: E & Y Hostage To Used Computer Dealer

HIPAA Encryption: Burglars Break Through Metal Doors To Steal Laptop

Comments

No Comments

About sang_lee

Sang Lee is a Senior Account Manager and Security Analyst with AlertBoot, Inc., the leading provider of managed endpoint security services, based in Las Vegas, NV. Mr. Lee helps with the deployment and ongoing support of the AlertBoot disk encryption managed service. Prior to working at AlertBoot, Mr. Lee served in the South Korean Navy. He holds both a B.S. and an M.S. from Tufts University in Medford, Massachusetts, U.S.A.