All the latest UK technology news, reviews and analysis

Healthcare workers putting patient data at risk

by Ian Williams

20 Nov 2008

Be the first to comment

  • Tweet this
Healthcare worker
A third of healthcare workers keep confidential information on portable devices without adequate security

Healthcare professionals are putting sensitive patient information at risk by storing records, medical images, contact information and other data on unprotected mobile devices.

A survey of around 1,000 workers from the healthcare industries in the US and the UK found that over a third keep confidential information on laptops, BlackBerrys and USB sticks without adequately securing the data.

The Mobile Device Usage in the Healthcare Sector report was conducted by mobile security firm CredentTechnologies, together with E-Health Insider in the UK and Outpatient Surgery Magazine in the US.

A fifth of respondents admitted to using their own devices to transport patient information, meaning that they are not controlled by IT departments and often breach existing security policies.

Data being stored in this way includes patient demographics, medical research data, diary and patient records and laboratory and operation procedures.

Just over a third of those surveyed rely solely on passwords to secure their work laptops and other mobile devices, an approach seen as wholly inadequate considering the type of information being carried.

Six per cent of UK respondents admitted to storing sensitive patient details with no security whatsoever, jumping to 18 per cent in the US.

Although regulations exist in both territories to protect this type of data, the survey revealed that security practices in the US are still way below the standards upheld in the UK.

Some 56 per cent of healthcare professionals in the UK use strong security to protect their devices. Around 35 per cent use encryption, 17 per cent rely on two-factor authentication, three per cent use biometrics and one per cent use smart cards.

However in the US, just 23 per cent use strong security to protect their mobile devices.

When asked why they were using these potentially dangerous devices, the majority cited convenience, capacity and speed of removal as the primary reason.

Fortunately the report also highlights the positive steps taken in recent months, particularly following the high profile data losses from various government organisations.

Two rounds of instructions and guidance have been issued to NHS chief executives in the past year about the security of data in transit and on mobile devices.

There has also been a dramatic rise in the number of healthcare organisations placing restrictions on the use of mobile devices in the workplace, such as blocks on USB connections, cameras on phones being disabled or people not being allowed to download information from a hospital's network onto a mobile device.

"Anyone who owns a mobile device such as a smartphone or laptop should stop and think whether someone can easily open it," said Michael Callahan, vice president of global marketing at Credent.

"If so, once they are in, could they access patient records, read my emails and then use this information to access the company network, such as the NHS hospital network? If so what damage could they do if they were to assume my identity?"

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Order Processing Specialist

Order Processing Specialist - 12 Month Fixed Term Contract...

Inside Sales Manager - Berkshire - Global Software Co!

Great opening with one of the worlds leading information...

JAVA J2EE Developer required with RIA, web services, REST, JSON, AJAX

JAVA J2EE Developer required with RIA, web services...

Linux Administrator

Hi, Job Title : Linux Admin Location : Brussels...

To send to more than one email address, simply separate each address with a comma.