HITRUST discloses breach of 111 records

The Health Information Trust Alliance (HITRUST) informed the public that a compromised web server caused the leak of 111 records, which included some real names, companies, addresses, phone numbers and email addresses, in addition to six encrypted passwords. The files did not contain personal health or other sensitive information, according to the May 28 notice.

The compromised information derived from a test database populated with rosters previously made public from planning meetings during 2008, in addition to some fictitious data created by developers.

In its statement, HITRUST said it had not deemed this web server or test data as requiring higher security, but it has updated its policies to secure test environments and public general information websites at a higher assurance level.

“We sincerely regret any inconvenience this has created and take data security very seriously. It is our mission to protect information and do so in a manner that is appropriate and practical given the risks,” according to the notice.

Around the web

The American College of Cardiology has shared its perspective on new CMS payment policies, highlighting revenue concerns while providing key details for cardiologists and other cardiology professionals. 

As debate simmers over how best to regulate AI, experts continue to offer guidance on where to start, how to proceed and what to emphasize. A new resource models its recommendations on what its authors call the “SETO Loop.”

FDA Commissioner Robert Califf, MD, said the clinical community needs to combat health misinformation at a grassroots level. He warned that patients are immersed in a "sea of misinformation without a compass."