Columbia Gorge News

Your local online source

PRIVACY, OR LACK THEREOF

Providence Bares Patients’ All In Records Theft


By Dan Richardson, 1-26-06

In what must rank among the top (bottom?) examples of corporate jack-assery, Providence health group has lost medical records for 365,000 patients.

Or, rather, 365,000 Oregonians and Washingtonians have lost their medical records — and, in many cases, their Social Security numbers and other identity information — to a thief, who stole a set of backup computer disks. Unencrypted disks. From a Portland-area Providence employee's car. Which was left unsecured in a driveway. Overnight.

Now, we're talking medical records. The results of your STD test, your pap smear, your prostate exam. But don't worry, says Providence, this only affects patients who received home services from Providence... which means, only the ones who needed in-home help. The most vulnerable, in other words.

Providence runs several Northwest hospitals, including the one here in Hood River. (One might ask, how? given that their execs and techs flubbed up something as essential as medical record privacy.)

There's no evidence that identity thieves have yet begun to use the information to impersonate or defraud people. Of course, that evidence might be easier to come by if the Clackamas County Sheriff's Office hadn't had to suspend its investigation of the theft due to lack of evidence from the scene. Or if Providence officials had come clean sooner — the theft happened a month ago, and word was released just this week.

The records could be in a landfill somewhere by now. Or in the hands of some meth-head ID thief who knows just what to do with them.

Providence officials say they make backup medical records in case of system failures and emergencies. Fair enough. But why not simply make backup disks, walk them down the hall to a second office, and place them in a fireproof safe? That keeps, no would keep records secure, separated and backed up. Why, why, why have a policy of sending records home with one of the office dunces?!

Unencrypted records?!

"What we didn't do was evaluate the practice of taking it home. That's where we fell short," Rick Cagen, Oregon regional CEO for Providence, told The Oregonian.

Didn't evaluate? How much evaluation does keeping the medical records secure take? That's not lack of evaluation, it's just plain old-fashioned stupid. Thoughtless. Cavalier.

You can bet that if Cagen had a disk with his personal financial information, Social Security number, or bed-wetting habits, mental health treatments, you-name-it — in other words, his medical record — he and other officials wouldn't have to evaluate whether it's a good idea to send the disk home with some employee.

Electronic medical records are all the rage in the medical community. They're supposed to be more efficient and effective than paper records. But here's the thing: No one's going to lose 365 folders of paper records, let alone 365,0000. Electronic records don't just make things easier — listen up, Cagen and company — they create an added ethical burden, because they're easily lost if placed on handy disks.

Providence needs to fire somebody, and make somebody else accountable for basic records security. Buy that safe, gentlemen. Encrypt your records. Keep them someplace more secure than a glove box. You see, "First, do no harm," doesn't just apply to physicians, but to all of you who work to help heal people. Even the guys in suits, and their office dunces. Well, you've done harm, or let it be done, and undoing it will be a tough duty, indeed.



Like this story? Get more! Sign up for our free newsletters.

Back to the NewWest Columbia Gorge page

Comments

Add your comment below

By Anonymous Providence employee, 1-27-06
By Dan, 1-27-06
By Kim, 1-28-06
By Janet, 2-05-06

Comment Policy

NewWest.Net encourages robust and lively, but civil participation from our readers. By posting here, you agree to the NewWest.Net terms of service. You agree to keep your comments on topic, respectful and free of gratuitous profanity. Contributions that engage in personal attacks, racism, sexism, bigotry, hatred or are otherwise patently offensive will be subject to removal.

Other than using a filter that scans for comment spam, we do not moderate contributions before they are posted and we do not review every thread, so we ask that you help us in keeping the discussions civil and appropriate. Please email info@newwest.net to notify us of comments that may violate these guidelines. Thanks for your help and cooperation. Click here for some tips on how to best interact on NewWest.Net.

Your Comment

Name

Email

Remember my name and email address.

Notify me of follow-up comments.