In a discussion about electronic health records (EHRs) a couple weeks ago, one of the Human Resource team members at a prospective client said, “I don’t believe it’s possible to secure electronic health data. It’s always an accident waiting to happen.”
There is some truth to that. More and more, our Personal Health Information (PHI) is in electronic formats that allow it to be exchanged with professionals and organizations throughout the health care continuum. It is highly unlikely that each contact point has the protections to wrap that data up tightly, away from those who would exploit it.
Of course, PHI is among the richest examples of personal data, often with all the key ingredients prized by identify thieves: social security number, birthday, phone numbers, address, and even credit card information. This should give health care organizations considerable pause.
Then consider that, while paper charts contain the same information, electronic files often aggregate hundreds of thousands or even millions of records, information treasures troves for someone really focused on acquiring, mining and making use of the data.