Potential Ky. data breach reported

Our Lady of Peace, a 278-bed psychiatric hospital in Louisville, Ky., is notifying 24,600 individuals about a potential patient data breach after a flash drive containing unencrypted patient information went missing April 1.

The flash drive reportedly contained data on patients admitted since 2002 as well as patients assessed, but never admitted, since 2009. Data on admitted patients included name, room number, insurer name, and admission and discharge dates.

Data on assessed patients included name, date of assessment, date of birth and the time they left the hospital.

The HITECH Act’s breach notification rule requires healthcare organizations to disclose within 60 days breaches known to affect 500 or more individuals. Smaller breaches must be reported on an annual basis. The hospital ran a legal advertisement notifying the public in the Louisville Courier-Journal on April 29.

Our Lady of Peace is re-educating employees on ways to protect patient information, implementing encryption technology and disciplining an undisclosed number of employees, according to a media statement.

 

Around the web

The American College of Cardiology has shared its perspective on new CMS payment policies, highlighting revenue concerns while providing key details for cardiologists and other cardiology professionals. 

As debate simmers over how best to regulate AI, experts continue to offer guidance on where to start, how to proceed and what to emphasize. A new resource models its recommendations on what its authors call the “SETO Loop.”

FDA Commissioner Robert Califf, MD, said the clinical community needs to combat health misinformation at a grassroots level. He warned that patients are immersed in a "sea of misinformation without a compass."

Trimed Popup
Trimed Popup