After major breach, L.A. County looking to require encryption for contractors
Following a computer theft at the county health contractor’s office that compromised the personal health information of more than 342,000 patients, Los Angeles County supervisors are taking steps to tighten security rules, according to an article in the Los Angeles Times.
While the county currently requires its workers’ laptops to be encrypted, the supervisors voted to expand the policy to incorporate all county departments’ computer workstation hard drives. They also voted to develop rules requiring all of the country’s contractors that exchange personal identifiable information and protected health information to encrypt data as a condition of working with the county.
In February, eight computers were stolen from the Torrance office of Sutherland Healthcare Solution. Personal information at risk included first and last names, Social Security numbers, billing information, birth dates, addresses, diagnoses and other medical information.
Since then, at least three lawsuits have been filed against the county and Sutherland over the incident, alleging, among other things, that the company failed to encrypt the data stored on the computers, reports Los Angeles Times.