NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Technology
Slice by Program

Snoops, spies and private eyes

By: Richard Bray(12-15-2006)


HO-002 is a spy story. Instead of 007's Casino Royale, the setting is the Ottawa Hospital and the plot involves the aftermath of a failed marriage rather than international espionage. But the lessons it holds for public sector security managers may be much more relevant.

The story, documented in the Ontario Privacy Commissioner's report, "HO-002," began when a female in-patient at the Ottawa Hospital told staff she did not want two hospital employees, her estranged husband and his girlfriend, to know she had been admitted or to see her personal health information. The security office was notified. The privacy office was not.

After she left the hospital, the patient's husband revealed to her that he had knowledge of her hospital stay and details of her treatment. Not surprisingly, the patient complained to the hospital. The hospital's privacy office immediately audited the records to confirm that the estranged husband's girlfriend, a nurse, had indeed looked at the record without permission.

The privacy office then tagged the patient's Electronic Health Record (EHR) so it would be informed every time the record was accessed. Anyone attempting to look at the record from then on saw a warning screen that said the information had been deemed "highly sensitive" and would be "closely monitored for potential violations of patient privacy."

At this point, the spies either did or should have known that they were being watched. As Glen Geiger, the Ottawa Hospital's medical director of clinical information systems, said: "Only a true bumbler would keep doing it, after having seen the VIP flag had now been set, and have read that warning, and still not suspect that somebody was on to them."

Keep on doing it they did, three more times. Finally, the hospital stepped in and did the job of protecting patient privacy that it was supposed to do. The nurse who accessed the records received a four-week suspension without pay, and the estranged husband was suspended without pay for 10 days. And the woman whose privacy was so egregiously violated will probably receive a substantial amount of taxpayers' money in an out-of-court settlement.

In its report, the Ontario Privacy Commission concludes: "The ultimate responsibility, of course, lies in the actions of the two offending parties," and, "The negative consequences flowing from the unauthorized access and use of a patient's health information are extensive and far-ranging. Patients have enough to deal with - any additional stress arising from an unauthorized party peering into their health records is completely unacceptable."

In other words, the failure had an impact on an individual and people caused the failure. The answer is not increased electronic security measures around personal information, but a culture of respect for privacy. That cultural change can only begin at the institutional level. Unfortunately, there is evidence that there is a massive failure of respect for privacy there as well.

Research is at the heart of medical innovation and its lifeblood is data. Medical researchers believe they have a right, if not an obligation, to acquire patient information. After all, the goal of their research is better health. As Geiger said, "Any suggestion to the contrary produces apoplexy and warnings that the health system will crumble, or their careers will crumble, if they can't have this data."

When he asks the researchers if the patients mind having their information used for research, they often answer that the patients don't know anything about it. Shouldn't they know about it? Geiger says the researchers respond with: "Well, if they did know about it, things might not go well."

In other words, patients might withhold permission and that would bring research projects, and their enabling grants, to a standstill.

In a recent meeting, says Geiger, a researcher simply admitted: "I've got a friend in the lab who gets me data."

"It's not like it's unique," adds Geiger. "We knew. It's just funny being in a meeting where somebody actually says this, and doesn't think about the implications of what they have just said. 'I'm stealing data from the lab.'"

Stopping the practice would not only halt research projects, it would seriously compromise the operations of the hospital, Geiger says. "So it is not possible to confront these people at this time. But this has got to stop. I am sure it is the same at most healthcare institutions. This sort of stuff is going on all the time."

Electronic health records are quickly becoming an urgent national priority. The Canadian Institute for Health Information has estimated that as many as 65 people die needlessly in our hospitals every day, and many of these deaths can be attributed to missing information.

According to Canada Health Infoway, a nation-wide EHR system could save $6.1 billion a year, or almost five per cent of total healthcare spending.

The collective benefits may be impressive, but the privacy risk Canadians and their physicians face is individual. If they do not believe that people with access to an EHR system will respect their privacy, they will withhold their support and their information. Without those, there will be no system and no benefits.

Richard Bray is an Ottawa-based freelance journalist specializing in high technology and security. He can be contacted at rbray@itworldcanada.com


Read about the state of Security and Emergency Services in Canada
Learn more on the Pal Initiative

More news on Canadian Government Technology

Complete coverage on Canada Inter-Government News site map


Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Stalled PCI DSS compliance efforts put Canadian organizations in limbo: Hereb�s how to get back on track
You might have long ago abandoned your efforts to achieve full PCI DSS compliance, but herebs a report that offers some helpful ideas to get back on track again. It highlights the five bsticking pointsb that typically hinders PCI DSS compliance progress and suggests how to get unglued from the mess.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada