Risk
10/23/2008
00:27 AM
George V. Hulme
George V. Hulme
Commentary
Connect Directly
RSS
E-Mail
50%
50%

New FTC Rules Governing Health Providers Go Into Effect Nov. 1

Are you ready? In about a week, new so-called "Red Flag Rules" from the FTC go into effect, aimed at curbing medical identity theft.

Are you ready? In about a week, new so-called "Red Flag Rules" from the FTC go into effect, aimed at curbing medical identity theft.It's a good thing, too. It seems new headlines surrounding medical identity theft surface all of the time. Just last week, a Californian pleaded guilty to federal charges for defrauding Medicare. The man allegedly used patients' Medicare identification numbers without their knowledge. His sentencing is scheduled for sometime this January, and he faces 12 years for billing the Medicare system for about $1,640,000.

Sometimes it's not outright fraud, sometimes it's just negligence on the part of hospitals themselves for failing to properly protect patient data. Consider this recent story about patients at Mary Washington Hospital, who learned it was possible for anyone to look at the private medical information of about 803 maternity patients on the hospital's online registration system. A hospital spokesperson called the incident an "anomaly." Ten years of reporting on these types of breaches tells me its a high probability of neglecting to properly secure or patch the system. While there was no medical identity theft in this specific case (that we know of), such carelessness can and will certainly lead to more incidents.

Now, the U.S. Department of Health & Human Services (HHS) is showing more interest the role health care providers can play in combating medical identity theft in the face of new Federal Trade Commission rules that go into place Nov. 1.

According to this press release, many hospitals aren't even aware of the rules:

In October, both the HHS Office for Civil Rights (OCR) and the Office of the National Coordination for Health Information Technology (ONC) signaled that stronger actions to address the issues of identity theft and particularly medical identity theft are coming.

On Oct. 10, OCR said it was examining the FTC's identity theft regulations, as questions have been raised over whether violations of the so-called "Red Flag" rules could also constitute violations of the HIPAA privacy or security rules. There also have been no decisions on whether OCR or CMS would refer cases to the FTC when they receive complaints in their HIPAA enforcement systems.

Many health care organizations are not aware that they will come under FTC authority as a result of identity theft rules that were once thought to only apply to financial institutions and other lenders.

The Red Flag rules require any organization -- including nonprofits and government agencies not traditionally subject to FTC jurisdiction -- that does not require payment at the time it provides service to establish and maintain a program to spot and address possible ID theft.

In recent weeks, the FTC said the rules also applied to health care entities.

This is good news, even if these red flag rules from the FTC do overlap with HIPAA. Why? Because too few hospitals have been fined or sanctioned for failing to properly safeguard patient data -- like Mary Washington Hospital -- by adequately putting into place the precautions necessary to make sure someone's health privacy isn't violated by an avoidable "anomaly."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2006-1318
Published: 2014-09-19
Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka "Microsoft Office Control Vulnerability."

CVE-2012-2588
Published: 2014-09-19
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.

CVE-2012-6659
Published: 2014-09-19
Cross-site scripting (XSS) vulnerability in the admin interface in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-1391
Published: 2014-09-19
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.

CVE-2014-3614
Published: 2014-09-19
Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.

Best of the Web
Dark Reading Radio