Newsvine
  • Welcome
  • Help
  • Report Bug
  • Conversation Tracker
  • Your Column
  • Replies
  • Friends
Type Comments Since You Last CheckedArticle Source Last Checked Stop Tracking All Clear Tracking All
Advertise | AdChoices
Log In | Register
Close the Login Panel
Existing users log in below. New users please register for a free account.

New Users:

Existing Users:

E-Mail:
Password:
Forgot Password?
Please enter the e-mail address or domain name you registered with:
E-Mail/Domain:
Back to Login
Log Out
  • Top News
  • Local News
  • World
  • U.S.
  • Sports
  • Politics
  • Tech
  • Entertainment
  • Science
  • Business
  • Health
  • Odd News
  • More
    • Arts
    • Education
    • Environment
    • Fashion
    • History
    • Home & Garden
    • Not News
    • Religion
    • Travel
What is Newsvine?

Updated continuously by citizens like you, Newsvine is an instant reflection of what the world is talking about at any given moment.

Get a Free Account
Help
Fun Stuff
  • Your Clippings
  • Leaderboard
  • E-Mail Alerts
  • Top of the Vine
  • Newsvine Live
  • Newsvine Archives
  • The Greenhouse
  • Recommended Articles
  • Wall of Vineness
Put a Seed Newsvine link on your own site

Stanford Hospital privacy breach puts data online

Fri Sep 9, 2011 3:37 AM EDT
us-news, us, medical, new-york-times, data, breach, new-york-times', medical-data, stanford-hospital
Associated Press
Advertise | AdChoices

PALO ALTO — Stanford Hospital in California is blaming a subcontractor used by an outside vendor for a privacy breach that led to the posting online of medical information for thousands of emergency room patients.

The breach was first reported Friday by the New York Times ( http://nyti.ms/p84zWa). The data of 20,000 patients, including names and diagnosis codes, remained on a commercial website for nearly a year until it was discovered last month and taken down, according to the newspaper.

In a statement, Stanford Hospital said the file that contained the patient information and was posted to the site was created by a subcontractor employed by one of its vendors, Multi Specialties Collection Services.

The hospital did not name the subcontractor, but it said Multi Specialties Collection Services is investigating how the company caused patient information to be posted to the website. Stanford said that in the meantime, it has suspended working with Multi Specialties Collection Services.

"This incident was not caused by the hospital, and responsibility has been assumed by a contractor working with the vendor," the hospital said in its statement.

Breaches of medical data are common though most typically involve lost or stolen computers or storage devices.

Roughly one-fifth of the publicly disclosed breaches in the last seven years have involved health care providers, according to a database kept by the Privacy Rights Clearinghouse.

The digitization of medical data is creating new problems, as the information travels more easily among the dozens of contractors that are typically authorized to handle a person's medical records and is more easily lost or accidentally posted online.

Last month, The Associated Press reported on a California firm that posted the medical files of nearly 300,000 workers' compensation patients on a website that the firm mistakenly believed only its employees could see.

In the Stanford case, the data ended up on a homework-help website called Student of Fortune, according to the New York Times.

Someone needing help converting data into a bar graph posted a spreadsheet along with the sensitive information, Gary Migdol, a spokesman for the hospital, told the Times. The spreadsheet first appeared there a year ago Friday, Migdol said.

The privacy breach did not involve any hacking, and data weren't on Stanford's or the collection agency's website, but on Student of Fortune's.

The information also contained medical record numbers, hospital account numbers, emergency room admission and discharge dates and billing charges, according to the hospital. It did not contain credit card or Social Security numbers, information commonly associated with identity theft.

The affected patients were seen by the hospital's emergency department between March 1, 2009, and Aug. 31, 2009.

"The hospital notified affected patients quickly and also arranged for free identity protection services, though the data involved is not associated with identity theft," the hospital said in its statement.

Migdol told the Times that he expected the federal Department of Health and Human Services to conduct its own investigation. Susan McAndrew, a deputy director in the department's Office for Civil Rights, said she could not discuss whether an investigation was in progress.

© 2011 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.
  • Enjoy this article? Help vote it up the 'Vine.

Back To Top | Front Page

Published to:

  • Associated Press's Column, All of Newsvine
  • Groups: none
  • Regions: New York
  • Public Discussion (0)
Leave a Comment:
You're in Easy Mode. If you prefer, you can use XHTML Mode instead.
You're in XHTML Mode. If you prefer, you can use Easy Mode instead.
(XHTML tags allowed - a,b,blockquote,br,code,dd,dl,dt,del,em,h2,h3,h4,i,ins,li,ol,p,pre,q,strong,ul)
Newsvine Privacy Statement
As a new user, you may notice a few temporary content restrictions. Click here for more info.
FUN STUFF:
  • Leaderboard |
  • E-Mail Alerts |
  • Top of the Vine |
  • Newsvine Live |
  • Newsvine Archives |
  • The Greenhouse
COMPANY STUFF:
  • Code of Honor |
  • Company Info |
  • Contact Us |
  • Jobs |
  • User Agreement |
  • Privacy Policy |
  • About our ads
LEGAL STUFF:
  • © 2005-2012 Newsvine, Inc. |
  • Newsvine® is a registered trademark of Newsvine, Inc. |
  • Newsvine is a property of msnbc.com