Wednesday, August 15, 2007
How Can I Miss You
Regulars to this site will have noticed that my posting has been light lately. I have been working on a fairly lengthy paper on compliance transparency and it has been taking far too much of my HIPAA energy. It should be done sometime next week, and then I'll be back to my usual irregular posting :)
Blinded by the Light
Here is what people say when they have been terrified by HIPAA training:
Yeah, except nobody ever has.
You know you can go to jail," firefighter Jim Robertson told the Potterville-Benton Township Fire Board. "You know you can go to jail if you have a HIPAA (federal privacy law) violation."
Yeah, except nobody ever has.
Too Much Love
Interesting piece by Phillip Alexander in Security Park titled "The Dangers of Too Much Data Privacy"-- while I don't entirely agree with him, he brings ups some good points.
By the way, just in general Security Park has some cool stuff.
The private sector as a whole has not always been responsible stewards of the non-public personal information that consumer entrust to them. It is axiomatic that when the private sector fails to act responsibly, the public sector will enact regulations to mandate changes in behavior. The slew of highly publicized data breaches and the accompanying public outcry are at least partially responsible for the stampede of data privacy laws passed in recent years.
By the way, just in general Security Park has some cool stuff.
Monday, July 16, 2007
Fear the Reaper
Because, you know, if we continue with HIPAA the terrorists win. From a letter to the editor of the Asbury Park Press:
There are so many things wrong with this I don't have the energy to fully rebut them. Leaving aside the delusional nature of the thing and concentrating on HIPAA, the writer is of course mistaken. PHI in India is still under jurisdiction of US courts via Business Associate Agreements, which make at least the US based sides responsible for the conduct of their foreign counterparts.
Now there are boogymen under every hospital bed. Sheesh.
Finding terrorist cells in the British health care industry is disturbing, because it exposes those doctors as criminals intending to cause mass murder. Al-Qaida is recruiting people from nations such as India and Pakistan who work within the industry. The easy access and knowledge doctors have of dangerous biological agents, chemicals and drugs poses a new threat.
Medical terrorists also have access to private information in our medical records. In cases of our recovering soldiers, they see the wounds inflicted that make them unfit for further duty.
The medical reports of millions of Americans are routinely sent over the Internet to India and Pakistan to be typed or transcribed. Most Americans are unaware the doctor treating them here is sending their private medical history and treatment record to India to be typed. Depending on the turnaround time, your medical report already may be somewhere in India before you return home from treatment.
Once these private medical reports leave the United States via the Internet, they enter a cyber-system, where the medical information can be passed from one company to another within a business chain. Your doctor may not know where the medical dictation finally ends up downloaded to a foreign computer to be typed or transcribed.
All of this is legal under the less-than-adequate medical privacy law called HIPAA. The solution to this crisis is simple: Don't allow our personal medical information to leave the jurisdiction of the U.S. court system. Plenty of qualified medical transcribers live here, where it is easier to maintain privacy and trace the path of this sensitive information.
There are so many things wrong with this I don't have the energy to fully rebut them. Leaving aside the delusional nature of the thing and concentrating on HIPAA, the writer is of course mistaken. PHI in India is still under jurisdiction of US courts via Business Associate Agreements, which make at least the US based sides responsible for the conduct of their foreign counterparts.
Now there are boogymen under every hospital bed. Sheesh.
One Clear Moment
Great article on EHR from Government Health IT:
Among other things, it discusses the Nationwide Health Information Network and health information exchanges (HIEs), also known as regional health information organizations, and their role in disclosure and auditing. My wife is on the Governor's Commission on this in our state, and I have been following it with great interest. As I know more, I'll report.
At the same time, he acknowledged that simply building security features into a system doesn’t ensure that the data will be protected if no one reviews the logs, insists that passwords be changed regularly and so on.
“Everyone in this field of privacy and security acknowledges that the weak link is humans and their training,” Leavitt said. “So you get a false sense of security. You look at the features and you’re quite impressed, but most breaches occur because of human problems.… It’s very important to recognize that the human component — the training component and the policy component — is as important or more important than the software features. You never want to focus only on these technical features.”
In the same vein, most of the people interviewed for this article mentioned the need for HHS to more strongly enforce HIPAA rules. The department enforces the rules only when someone complains. When HHS discovers violations, officials have chosen to work with the offenders to bring them into compliance rather than take them to court.
Without more rigorous enforcement, critics say, the public will have little confidence that health care providers are actually using audit trails and other EMR security features. Runyon noted approvingly that in March the HHS inspector general undertook an audit of an Atlanta hospital’s compliance with HIPAA’s security rules. It was the agency’s first such audit, but the IG is reportedly planning more.
Among other things, it discusses the Nationwide Health Information Network and health information exchanges (HIEs), also known as regional health information organizations, and their role in disclosure and auditing. My wife is on the Governor's Commission on this in our state, and I have been following it with great interest. As I know more, I'll report.
Monday, July 02, 2007
Mr. Postman
From the comments faaaaar below:
As a professionally paranoid security guy I must say that this looks like an attempt to circumvent the safeguards in place. To an outsider this looks like a test run. The mother's best course of action (if truly innocent) was to firmly tell the daughter no, and explain why it was not appropriate to ask, and really not appropriate to try to game the PHI filters. Made up data has an even worse potential for damaging the privacy of the individual than real data. If they were truly innocent of planning skullduggery, then they are both extremely guilty of poor judgemnt and disregard for the rules.
Can't blame this one on HIPAA--- the mother was guilty of circumventing the protections set in place, breaking the security rules of the insurance company, and playing fast and loose with the patient's PHI, fabricated or not. And yes, HR had no reason to review the real PHI, which would have definatly violated the patient's privacy.
Anonymous said...
My friend works for a large health insurance company and her daughter works at one of the insurance company's key accounts. The daughter sent the mother an email one day asking for some information about a key account coworker. The mother replied that the daughter's request, which had the last name and date of birth of coworker, tripped the PHI filter on the email and the mother had to delete the request. The daughter resends the request with the information 'hidden' within a song of silly words and asks if the stupid filters caught the last name and date of birth that time. The mother replies that it didn't. The mother fabricates a response to the daughter so she would stop asking for this information. A day later the mother was fired from her job because human resources said that she had violated HIPAA. How can HIPAA be violated when the mother did not use the name and date of birth and fabricated her response? HR will not look up the key account woman's information because they claim they would be in violation of HIPAA based on the reason that they have no need to know if real/false medical information was given because their perception of what the mother did is more than necessary for them to have fired her. Is this really how HIPAA works or is someone misreading the rule? Thank you in advance for helping.
As a professionally paranoid security guy I must say that this looks like an attempt to circumvent the safeguards in place. To an outsider this looks like a test run. The mother's best course of action (if truly innocent) was to firmly tell the daughter no, and explain why it was not appropriate to ask, and really not appropriate to try to game the PHI filters. Made up data has an even worse potential for damaging the privacy of the individual than real data. If they were truly innocent of planning skullduggery, then they are both extremely guilty of poor judgemnt and disregard for the rules.
Can't blame this one on HIPAA--- the mother was guilty of circumventing the protections set in place, breaking the security rules of the insurance company, and playing fast and loose with the patient's PHI, fabricated or not. And yes, HR had no reason to review the real PHI, which would have definatly violated the patient's privacy.
Friday, June 15, 2007
Save My Grave
Wow! Another great "Golden Hippo" nominee for creative use of HIPAA. This time it is Nebraska Attorney General Jon Bruning, who has declared that numbered markers on graves from the state mental hospital from over a century ago cannot be indentified by name, because of HIPAA. The McCook Daily Gazette disagrees:
We understand Nebraska Health and Human Services' reluctance to release patient information -- most of us wouldn't want such information about ourselves to be made public.
But we have seen HIPAA used as an excuse for all sorts of obstruction, from the condition of accident victims to the location of a house fire.
We have to question the need to conceal the name or date of death for someone who died nearly 120 years ago, especially to people who only want to trace their family trees.
Send in the Clowns
Security is a strategy, not a policy!
Sheesh. Who'da ever thunk that cleaning people might mishandle patient records?
A box left in a trash bin could end up leaving some local doctors a little lighter in the wallet.
The Greenwich Post was given a box filled medical documents from the Dearfield Medical Building that may have been improperly disposed of. The box was discovered at 4 Dearfield Drive inside a trash bin in May and contains information about lab tests and insurance approvals as well as other medical issues. These documents are not medical charts, but do contain patient names and contact information.
According the United States Department of Health and Human Services, under the privacy regulations for the Health Insurance Portability and Accountability Act (HIPAA), documents such as the ones in the trash bin are supposed to be kept confidential and then shredded when disposed of, not just thrown out in a box.
While it was not confirmed from which office at the medical building all the documents originated, the names of Alfred Padilla and Judith Goldberg-Berman, who run an endocrinology practice in the building, appear frequently on the documents.
Dr. Padilla spoke to Greenwich Post on Tuesday and expressed surprise that the documents had not been shredded. He said it was the practice’s policy to make sure all medical documents were properly disposed of.
“We take HIPAA very seriously,” Dr. Padilla said. “In general we will shred everything we throw away.”
Dr. Padilla said there were some documents that were kept in a room at the practice to be shredded, but hadn’t yet been. He speculated that the cleaning crew at the building might have accidentally disposed of them.
“We have a pile of boxes to be shredded,” Dr. Padilla said. “If the cleaning people came and took the box, mistaking it for garbage, that would have been what happened... My suspicion is that one of our shredding boxes ended up in the trash bin. That’s the only theory I can come up with.”
Sheesh. Who'da ever thunk that cleaning people might mishandle patient records?
Fight For All The Wrong Reasons
I TOLD you so!
If your management has been slacking on compliance, it is time to read them this article from Computer World. Enforcement is the new black; the free ride is over. I absolutely agree with Barry Runyon:
Good grief, we in this industry have had plenty of time to get our acts together, and most of the provisions are nothing more than best practices anyway.
Please, please, please do not be the next hospital, clinic, or other covered entity that I write about here. Get compliant!
An audit of Atlanta's Piedmont Hospital that was initiated by the U.S. Department of Health and Human Services in March is raising concerns in the health care industry about the prospect of more enforcement actions related to the data security requirements of the federal HIPAA legislation.
The audit was the first of its kind since the Health Insurance Portability and Accountability Act's security rules went into effect in April 2005, joining data privacy mandates that were already in place. The security rules require organizations that handle electronic health data to implement measures for controlling access to confidential medical information and protecting it against compromise and misuse.
If your management has been slacking on compliance, it is time to read them this article from Computer World. Enforcement is the new black; the free ride is over. I absolutely agree with Barry Runyon:
The mere fact that an audit of HIPAA security compliance was conducted for the first time has many in the health care industry preparing for more enforcement actions, according to Barry Runyon, an analyst at Gartner Inc. "I don't think Piedmont was an anomaly," he said. "My sense is that there is going to be more feet on the street from HHS going on unannounced audits."
Good grief, we in this industry have had plenty of time to get our acts together, and most of the provisions are nothing more than best practices anyway.
Please, please, please do not be the next hospital, clinic, or other covered entity that I write about here. Get compliant!
Wednesday, June 13, 2007
If Everyone Cared
From another forum where I am a moderator comes this question from someone worried about IT security:
The problem is, of course, that enforcement has been criminally lax. But with the recent change in power comes a new emphasis on enforcement, and there are going to be covered entities that are going to become the big, awful example. In the past very little was done when someone was found to be out of compliance, but recent news suggests that the tide is turning.
One of the most compelling reasons to follow the HIPAA security rules is that they are generally best practices anyway. The time to protect yourself is not after you have already been exposed.
All it would take would for there to be a big data loss, with PHI exposed, and those same scofflaws would be scrambling to save their behinds. And the goat would be the IT guy--- no matter the final outcome, the first instinct of those in charge is to blame underlings, and nobody likes IT people anyway.
The process is complaint driven, which means that someone has to rat them out first. The good news is that any affected person can complain, which in practice means just about anybody.
I would suggest the hair-on-fire approach, pointing out to the beancounters that the exposure is real, the dangers are extreme, and the risk to their jobs, the economic strength of the facility, and the possible irreparable PR disaster of a major data loss is not in any way worth not following procedures.
Of course, it is important to make certain that the procedures and policies don't interfere with the business at hand. Healthcare frontliners are notoriously hostile to extra steps that seem to make their primary mission more difficult. Your procedures need to be as transparent to the end user as possible, or they will be disregarded, bypassed or ignored.
The person may be able to convince management of the possible financial risks involved, as money seems to motivate. They may also volunteer to be the champion on this, as sometimes the only reason things don't happen is nobody wants to bell the cat.
Of course, without the buy-in of top management, this is all moot, because every organization is like a fish, in that it rots from the head down. Without a security officer, and absent help from on high, there is not much to be done.
Good luck on this!
I was asked this question, and I'm not quite sure how to answer it. Where does one turn when they see a complete disregard and lack of importance in the compliance for HIPAA security. The privacy rules are basically followed. But on the technology side, they have policies in place that are just not followed, upper management has stated behind closed doors that HIPAA and security really aren't that important. There really is no one who is the HIPAA security officer. HR is the HIPAA privacy officer. And no one in the healthcare facility will take the issues seriously - even when approached by their own IT about its importance.
Where do they turn, and how do they go about it while keeping their job
The problem is, of course, that enforcement has been criminally lax. But with the recent change in power comes a new emphasis on enforcement, and there are going to be covered entities that are going to become the big, awful example. In the past very little was done when someone was found to be out of compliance, but recent news suggests that the tide is turning.
One of the most compelling reasons to follow the HIPAA security rules is that they are generally best practices anyway. The time to protect yourself is not after you have already been exposed.
All it would take would for there to be a big data loss, with PHI exposed, and those same scofflaws would be scrambling to save their behinds. And the goat would be the IT guy--- no matter the final outcome, the first instinct of those in charge is to blame underlings, and nobody likes IT people anyway.
The process is complaint driven, which means that someone has to rat them out first. The good news is that any affected person can complain, which in practice means just about anybody.
I would suggest the hair-on-fire approach, pointing out to the beancounters that the exposure is real, the dangers are extreme, and the risk to their jobs, the economic strength of the facility, and the possible irreparable PR disaster of a major data loss is not in any way worth not following procedures.
Of course, it is important to make certain that the procedures and policies don't interfere with the business at hand. Healthcare frontliners are notoriously hostile to extra steps that seem to make their primary mission more difficult. Your procedures need to be as transparent to the end user as possible, or they will be disregarded, bypassed or ignored.
The person may be able to convince management of the possible financial risks involved, as money seems to motivate. They may also volunteer to be the champion on this, as sometimes the only reason things don't happen is nobody wants to bell the cat.
Of course, without the buy-in of top management, this is all moot, because every organization is like a fish, in that it rots from the head down. Without a security officer, and absent help from on high, there is not much to be done.
Good luck on this!
Tuesday, May 22, 2007
Three Of A Perfect Pair
HIPAA as a PR Shield:
HIPAA as interpreted by the Three Stooges:
And finally, HIPAA as the New Sheriff in Town:
Javier Espinosa, a senior at SMU, recently came within two hours of dying. Doctors at Methodist Hospital in Dallas saved his life with an emergency liver transplant.
While Espinosa initially went to SMU's Memorial Health Center to be treated and diagnosed for his cold-like symptoms, he said the health center is not equipped with proper resources to diagnose and treat severe cases.
"The health center can't recognize and [doesn't] really know how to handle hard-core cases like mine," Espinosa said.
Espinosa said he expected the health center to offer advice and guidance when they were unable to diagnose his symptoms. However, staff at the health center said very little and did not suggest going to a hospital.
"I expected the health center to be more responsible," he said. "It was obvious my test results were off the chart and they weren't like 'Go and see a doctor in this hospital,' and they should have."
The health center had no comment regarding Espinosa's case and referred questions to SMU's Assistant Director of News & Communications, Robert Bobo.
Bobo said that Espinosa's case cannot be talked about unless he signs a contract releasing the school from HIPAA or FERPA. HIPAA is the Health Insurance Portability and Accountability Act and according to the online U.S. Department of Health and Human Services it's the "national standards to protect the privacy or personal health information." FERPA is the Family Educational Rights and Privacy Act.
HIPAA as interpreted by the Three Stooges:
So, we all trooped in to the county’s selected health care provider for TB testing. I really didn’t know exactly what was supposed to be done and presumed that the Occupational Medicine Center we went to did. Wrong. I came to find out that while half of us received the appropriate testing, the other half received misinformation. And our second test was done way too soon, necessitating a third test. Further, I found out that we were treated as “new hires” in a big hospital rather than acute EMS exposures. After several weeks of attempting to deal with the situation as Jane Q. Paramedic, I was still unable to convince the hospital to give me a copy of my own medical records, despite executed HIPAA releases and dozens of phone calls. Seems you have to get your medical records from somewhere six states away. Then, they sent me all of my medical records for the last 10 years, with the exception of the one for the exposure, which was the only one I requested. They also sent me a big bill for the copies.
And finally, HIPAA as the New Sheriff in Town:
Arizona requires mandatory disclosure of medical records in medical malpractice cases and, amazingly, is currently considering a change to mandatory arbitration procedures to require the same thing. As we have often explained, these provisions violate HIPPA, the comprehensive federal scheme that provides essential privacy rights for medical records.
The voice of reason is finally kicking in: the Georgia Supreme Court recently struck down their statute requiring mandatory disclosure of medical records in medical malpractice cases citing HIPPA preemption. The decision basically holds that the Georgia statute's failure to include provisions required by HIPPA, such as "the HIPAA requirement of notice of the right to revoke" or "the failure to require a specific and meaningful identification of the information to be disclosed and the failure to provide for an expiration date or a sufficient expiration event," makes the Georgia invalid in light of the preemptive effect of HIPPA.
Sunday, April 29, 2007
I Made My Excuses and Left
No more excuses:
The same swing can be seen with other laws. Twenty-five percent of large companies are not compliant with California’s security breach notification law but only 14 percent of midsize companies are not compliant. Midsize companies are less compliant when it comes to the Health Insurance Portability and Accountability Act, or HIPAA (27 percent of midsize companies are noncompliant versus 21 percent of large companies).
The reason, as usual, is money. Sarbanes-Oxley and HIPAA compliance is more complicated and expensive than, for example, GLBA compliance. But the mid-market’s excuse that it doesn’t have the money to comply may be becoming obsolete. According to Mark Lobel, a PricewaterhouseCoopers advisory partner specializing in security, the price is dropping for technologies that help companies comply with security and privacy laws. With affordable tools coming onto the market that can sniff out the data you need to protect, excuses from mid-market CIOs that it’s too expensive to comply with Sox and other laws will no longer work, Lobel asserts.
Mo Money, Mo Problems
AAAAAAAAArrrrrrgggggg!
Too much time and money? Yeah, like there hasn't been any data-breeches lately in the health-care sector. Only if you are spending your money stupidly. Only if your time is spent trying to find ways to just barely comply, as a part of a general CYA policy concerning compliance.
Show me a properly designed and fully supported patient data security system. Then bitch about too much time and money. Anybody who thinks this deserves whatever exposure to lawsuit they get.
"It's a strategy, not a policy!"
Attorney David Hanson, a partner in Michael Best & Friedrich and chairman of its healthcare practice group, noted there are people in the health field who think the industry already is spending too much time and money on patient data security - thanks to regulations like the Health Insurance Portability and Accountability Act.
Too much time and money? Yeah, like there hasn't been any data-breeches lately in the health-care sector. Only if you are spending your money stupidly. Only if your time is spent trying to find ways to just barely comply, as a part of a general CYA policy concerning compliance.
Show me a properly designed and fully supported patient data security system. Then bitch about too much time and money. Anybody who thinks this deserves whatever exposure to lawsuit they get.
"It's a strategy, not a policy!"
Days of Our Wives
You know, this HIPAA thing often seems to lead in completely unexpected directions. Who would have ever guessed that a boring collection of medical regulations would somehow connect with the trial for statuatory rape of a notorious cult leader?
You know, it used to be if I wanted to be left alone on a long flight, when the person in the seat next to me asked what I did, I told them I was a HIPAA consultant and offered to tell them all about it. They would immediately feign fatigue, and be fake-snoring in minutes. But if this sort of thing keeps happeneing, I'll be wearing wrap-around shades and travelling with an entourage.
A 5th District judge has ordered a media coalition seeking to unseal a secret petition issued in the prosecution of polygamous sect leader Warren S. Jeffs to submit to the court briefs addressing issues of the leader's privacy rights under HIPAA, the Health Insurance Portability and Accountability Act of 1996.
You know, it used to be if I wanted to be left alone on a long flight, when the person in the seat next to me asked what I did, I told them I was a HIPAA consultant and offered to tell them all about it. They would immediately feign fatigue, and be fake-snoring in minutes. But if this sort of thing keeps happeneing, I'll be wearing wrap-around shades and travelling with an entourage.
Hat too Flat
At a recent speech in Washington DC, Google's Adam Bosworth set forth a bunch of stuff planned for Google Health, described as as likely to be “simple, sloppy solution” as befitting the Google way of doing business. All of it sounded pretty good, except when he unleashed this whopper:
Ummm.... this is already a right under HIPAA--- Mr.Bosworth seems to have been talking through his hat.
Google is trying to lay the groundwork to have HIPAA overturned, and short of that would like to educate providers and patients about how to get at their information even within the constraints of current laws. They’d like to see consumers have the ability to review and challenge their records as is the case with credit bureau information
Ummm.... this is already a right under HIPAA--- Mr.Bosworth seems to have been talking through his hat.
Wednesday, April 04, 2007
Stupid Things
How in the world can this still happen?
Not one day passes that there isn't another report of ID theft or smething similar, so awareness must surely be there. Low cost encription software is cheap, easy to use and ubiquitous. There are thousans of us out there talking ourselves blue in the face about this stuff.
Johns Hopkins had a similar issue lately, but the data was encripted, so no problem.
How can this still happen?
Empire Blue Cross and Blue Shield, a division of WellPoint a medical services company in the US , has begun notifying 75,000 members that a compact disc holding their personal and medical information has been lost, according to published reports.
The personal data was stored on an unencrypted CD
Not one day passes that there isn't another report of ID theft or smething similar, so awareness must surely be there. Low cost encription software is cheap, easy to use and ubiquitous. There are thousans of us out there talking ourselves blue in the face about this stuff.
Johns Hopkins had a similar issue lately, but the data was encripted, so no problem.
How can this still happen?
Highway Rain
Shred, please.
Uh huh.
Hundreds of confidential documents from the Cleveland Clinic littered Interstate 77 on Tuesday after blowing off the back of a garbage truck.
Clinic spokeswoman Eileen Sheil said "almost all" of the 300 to 500 documents were recovered from the area of Fleet Avenue.
The documents are employees' performance reviews and patients' results from the cardiology laboratory, Sheil said.
The federal Health Insurance Portability and Accountability Act requires patient documents to be shredded, which these were not.
"Procedures were not followed," Sheil said. Clinic officials are investigating who was responsible.
Uh huh.
The First Cut Is The Deepest
ID theft is a huge problem, and when it involves medical records, the outcome can sometimes be deadly. But see if you can see the problem with this:
Five times? At what point do you notice something wrong? And who in the world is yanking so many appendices, anyway? What sort of patient population would allow for this? And how many is too many? Do you cut them off at some point? "Sorry, this coupon has a limit of three per customer."
Somehow I think someone is exaggerating for effect, don't you?
HIPAA also addressed security and privacy of health data, encouraging the widespread use of electronic data interaction.
The danger, however; comes when a thief uses a fraudulent identification to seek health treatment. His history - allergies, blood type, and treatment record - then becomes part of the data stored in the system, and can affect the care of the actual person.
“That's when they start giving me the wrong blood,” Jennings said, adding grimly. “I know a surgeon in Warsaw, Ind., that's removed an appendix from the same person five times.”
Five times? At what point do you notice something wrong? And who in the world is yanking so many appendices, anyway? What sort of patient population would allow for this? And how many is too many? Do you cut them off at some point? "Sorry, this coupon has a limit of three per customer."
Somehow I think someone is exaggerating for effect, don't you?
I Write the Songs
Gotta love a guy who heads his posts with song titles! This piece, titled Paper Doll, is a quick rundown on the various technologies available at low cost to help you get a little closer to that goal of a paperless office, dental style.
Most small practices don't have anybody to ramrod changes. New technology usually happens as something breaks. There are some ways that are relatively painless steps to friendlier processes, though, and if they are less expensive and easy to impliment, then they are both more likely to find their way into use, and less likely to be bypassed by the end users as being too much trouble or getting in the way of care.
Most small practices don't have anybody to ramrod changes. New technology usually happens as something breaks. There are some ways that are relatively painless steps to friendlier processes, though, and if they are less expensive and easy to impliment, then they are both more likely to find their way into use, and less likely to be bypassed by the end users as being too much trouble or getting in the way of care.
One (Hu)man, One Vote Remix
From the comments on the post below about the pharmacy worker who was using patient records for her husband's political campaign:
My wife is a candidate for city council of the city in which we reside. I promise not to pirate anyone's information for her fundraising activities :)
pharmdatamining said...
She lives near me.
I'm changing pharmacies now! Doh!
My wife is a candidate for city council of the city in which we reside. I promise not to pirate anyone's information for her fundraising activities :)
Subscribe to:
Posts (Atom)