Another huge medical data breach is mishandled

Published on

Both president-elect Barack Obama and Sen. John McCain backed electronic medical[Related: Patient Stories][Related: Medical Malpractice Story L…][Related: Patient Stories][Related: Medical Malpractice Story L…] records during their campaign. Computerizing patient data, which could increase efficiency and cut costs, is part of every major federal health reform proposal. But what are the rules for this data? An extortion threat reported today, and involving up to 50 million patients’ prescription drug records, shows the huge risks in letting unregulated for-profit companies take charge of Americans’ medical records.

The company, called Express Scripts, not only had a serious hole in its data security, it also isn’t doing nearly enough to help its clients.

Express Scripts is a pharmacy benefit manager, handling prescription drug plans for clients including insurance companies, employers and union health plans. It covers about 50 million people. Yes, 50 million. It’s a very profitable middleman job in the health industry.

Here’s what happened, according to the NY Times story:

The company said Thursday that it had been investigating the threat since early October, when it received a letter that contained personal information on about 75 of its members including names, dates of birth, Social Security numbers and, in some cases, prescription information.

Wouldn’t you want to know if your information may have been stolen? Don’t look to Express Scripts for much help. The company has called in the FBI, but it hasn’t personally notified any of its patients, except for the 75 people named in the extortion letter. So the company waited a month before going public. Its stated reason, according the Wall Street Journal, is that it wanted to "get the investigation up and running" first.

Pardon my suspicion, but I think Express Scripts was waiting to see if it got reports of identity theft. It says it hasn’t, but how would most of us even know that a credit problem was linked to a huge but nearly anonymous "pharmacy benefits manager?"

Even people who order their drugs online don’t see the company mailing back their Lipitor as a brand like MasterCard or Visa (and credit card companies at least have to follow strict rules about disclosing data breaches). Patients who get their prescriptions at a drugstore wouldn’t have almost no direct contact with Express Scripts.

Here are other ways that Express Scripts is failing its duty:

•    Instead of notifying all patients, it is depending on the news media to get the word out and guide patients (if they even know they’re "clients" of Express Scripts) to a special "support" website about the extortion threat.
•    People who hear about Express Scripts in passing, for instance on radio news, won’t find a word about possible theft of their data on Express Script’s main corporate website. As of today, it has a small-type link for people with "questions about safeguarding your personal privacy." Most of us would take this to be something about the corporate privacy policy.
•    I put "support" in quotes in discussing the client web site because it offers precious little support. It links to credit bureaus like Experian, and some government agencies. It just tells folks to go check their credit reports for themselves.. No advice is offered regarding possible release or misuse of their private medical information, except to be "alert" to any irregularities in their pharmacy benefit statements
•    The support site suggests that individuals "consider placing a security/fraud alert or extended security/fraud alert through the credit bureaus," which, depending on whether you opt for a "security freeze," can cost money and freeze up individual’s ability to get credit unless they pay for a temporary lifting of the alert. In any case, it’s a thrash to contact all three major credit bureaus.
•    In similar data theft instances involving financial companies and the Veterans Administration, possible victims were offered free credit monitoring for a year or more, even if no instances of fraud were detected. In the case of a stolen laptop at the VA, it was recovered two months later with the files unopened.

Express Scripts says it was able to identify the location on their system from which the data was lifted, and says it has plug whatever security loophole might have been found. Unfortunately, there is no regulation of how secure such data must be, no impetus in the for-profit world to put top-notch data security at the top of the corporate list.

Drug companies increasingly seek to use pharmacy databases for commercial purposes, including direct advertising of their own drugs for a patient’s condition. This offers another opportunity for hacking or theft, as well as inappropriate interference in doctor-patient relationships. Read here and here about how Consumer Watchdog fought off an attempt to make this use legal in California.

Google, the search giant, is offering Google Health," where consumers can store their own health data. Google, however, keeps the data. It says it will only use your data in aggregated ways, without personal information. But it does allow third parties to ask you for access, even for advertising and promotional uses. Google reserves the right to change its policies in the future, and theft is always a threat.  

President-elect Obama has signaled that broad health care reform may have to be delayed because of the financial meltdown, but that he is open to faster partial reforms. Here’s one that he can take on at no cost to taxpayers:

•    Oversee and regulate all of these huge patient databases held by for-profit companies.
•    Make sure that intense security comes before, not after, profit. Ban any third-party commercial use of patient information.
•    Put simply, ensure that patient privacy is the first thing that a CEO thinks about in the morning–or else.

Consumer Watchdog
Consumer Watchdoghttps://consumerwatchdog.org
Providing an effective voice for American consumers in an era when special interests dominate public discourse, government and politics. Non-partisan.
Latest Healthcare Videos
Video thumbnail
KERO-BFL (ABC): Medical Board Suspends License Of Dr. Yu
02:11
Video thumbnail
KGTV-SD (ABC): Doctor On Probation Missed Mandatory Testing
03:57
Video thumbnail
KGTV-SD (ABC) - San Diego, CA: Secret Doctor Rehab Program On Hold
00:56
Video thumbnail
KGTV-SD (ABC) - San Diego, CA: Secret Doctor Drug Treatment Program
02:38
Video thumbnail
KBAK (CBS) – Bakersfield, CA: Doctor Accountability
03:18
Video thumbnail
ABC10: California bill aims to help struggling doctors, but critics warn of patient safety risks
02:24
Video thumbnail
TURNTO23: Latina Maternal Health Awareness
02:36
Video thumbnail
KBAK: 4th Annual Latina Maternal Health Fair
02:46
Video thumbnail
ABC 10 - Medical Board Proposes Confidential Drug Rehab Program For Doctors
02:20
Video thumbnail
KBAK-Bakersfield, CA: Desert Cities Face Ongoing Crises Amid Financial Struggles & Hospital Downsize
07:48
Video thumbnail
KBFX (FOX) - Bakersfield, CA: Latina Maternal Health Awareness Month
02:31
Video thumbnail
KBFX (FOX) - Bakersfield, CA: Latina Health Fair For Maternal Health
00:49
Video thumbnail
KERO-BFL (ABC) - Bakersfield, CA: Local Doctor Being Investigated For Negligence
02:30
Video thumbnail
KGTV-SD (ABC) - San Diego, CA: Doctor On Probation After Being High On Duty
06:27
Video thumbnail
KCAL - Los Angeles, CA: Abortion Emergency Debate
02:39
Video thumbnail
NBC 7 - San Diego, CA: Bill Aims To Slow Maternity Ward Closures
01:49
Video thumbnail
KGTV-SD (ABC) - San Diego, CA: Doctor Accused of Putting Hidden Camera In A Hospital Restroom
03:22
Video thumbnail
KFMB-SD (CBS) - San Diego, CA: Dental Visit Leads To Hospital Stay
02:51
Video thumbnail
KGET - Bakersfield, CA: California Medical Board Meets in Bakersfield to Address Maternal Mortality
02:52
Video thumbnail
KBAK (FOX58) - Bakersfield, CA: High Maternal Mortality Rate
02:59
Video thumbnail
KERO-BFL (23ABC) – Bakersfield, CA: Maternal Mortality Addressed By Medical Board
03:12
Video thumbnail
KERO-BFL (23ABC) – Bakersfield, CA: Pregnancy Care Mistreatment
02:22
Video thumbnail
CNBC - Last Call: Home Insurance Crisis
06:45
Video thumbnail
KOVR-SAC (CBS) - Sacramento, CA: Physician Under Fire For Sexual Battery
02:12
Video thumbnail
KERO-BFL (ABC) - Bakersfield, CA: Crystal Guijarro Rodriguez on the Negligence of Doctors
06:09
Video thumbnail
KERO-BFL (ABC) - Bakersfield, CA: "DO NO HARM: Loss and Liability in the Medical Field"
44:03
Video thumbnail
KFMB-SD (CBS) - San Diego, CA: Hundreds Wrongly Told They May Have Cancer
03:20
Video thumbnail
KERO-BFL (ABC) - Bakersfield, CA: Larcenia Taylor on the Loss of Her Husband James Taylor
05:13
Video thumbnail
KERO-BFL (ABC) - Bakersfield, CA: Monica De La Rosa Speaks About the Loss of her Daughter Sabrina
04:35
Video thumbnail
KERO-BFL (ABC) - Bakersfield, CA: Tracy Dominguez Speaks About The Loss of Her Daughter and Grandson
07:22
Video thumbnail
KERO-BFL (ABC) - Bakersfield, CA: Michele Ramos Speaks About Loss and Liability in the Medical Field
07:58
Video thumbnail
KGET - Consumer Watchdog Advocates Note The Importance of Making Change Within The Healthcare System
02:26
Video thumbnail
ABC - Bakersfield, CA; Consumer Watchdog Shows Support in Honor of the Latina Maternal Health Fair
02:53
Video thumbnail
KABC- Los Angeles, CA; Pathways Medical in Toluca Lake Owner Falsely Claims to be A Licensed Doctor
02:22
Video thumbnail
Spectrum News; CW Argues Senate Bill 815's Proposed Changes Aren't Enough To Protect Patients
02:39
Video thumbnail
WABI (CBS) - Bangor, ME; Consumer Watchdog's Jerry Flanagan Speaks Upon Medical Debt Reform
01:27
Video thumbnail
KBAK-TV; Bakersfield Report on EuroPhoria
03:00
Video thumbnail
KGO - San Francisco, CA; The Shortest, Most Expensive Ambulance Ride
05:20
Video thumbnail
23 (ABC); Tracy Dominguez and Selena Alvarez Seek Justice At The Osteopathic Medical Board Meeting
02:44
Video thumbnail
CBS 8: Chula Vista Plastic Surgeon Charged With Manslaughter Still In Practice
03:14
Video thumbnail
KTLA - Los Angeles, CA; Consumer Watchdog Group Members Calling For A Patient Bill of Rights
02:31
Video thumbnail
KNBC - Los Angeles, CA; Medical Board Member TJ Watkins Calls On Californians To Help
04:17
Video thumbnail
KGET NBC TV-17 Bakersfield, CA: Gov Newsom Signs Bill To Increase Med Mal Damages Cap
00:53
Video thumbnail
KGET NBC TV-17 Bakersfield, CA: Local Family Supports Passage of AB 35 To Raise Med Mal Cap in CA
01:13
Video thumbnail
KNSD NBC TV-7 San Diego, CA: CA Bill Seeks to Raise Medical Malpractice Damages Cap
03:35
Video thumbnail
KOVR CBS TV-13 Sacramento, CA: How Will State Raising Medical Malpractice Cap Affect Patients?
03:37
Video thumbnail
KERO ABC TV-23 Bakersfield, CA: Families of Malpractice Victims Push for Doctor Accountability
01:18
Video thumbnail
KABC TV-7 Los Angeles, CA: Victims of Medical Malpractice Demand Changes at California Medical Board
02:10
Video thumbnail
KCBS TV-2 Los Angeles, CA: COVD Testing Lab Defrauding Consumers in California
05:15
Latest Healthcare Report

Support Consumer Watchdog

Subscribe to our newsletter

To be updated with all the latest news, press releases and special reports.