UNCATEGORIZED

FTC: Medical lab’s lax security led to data leak

Aug 29, 2013, 7:46 PM

WASHINGTON (AP) – The Federal Trade Commission on Thursday accused a small Atlanta-based medical lab that specializes in cancer detection of not doing enough to protect its patients’ online records, resulting in the leak of Social Security numbers and birth dates of more than 9,000 consumers.

The complaint against LabMD describes what many consumers fear: being forced to hand over personal information to a doctor’s office or hospital, not knowing how that data is handled or who has access to it, only to become vulnerable to identity theft. The allegations also raise questions about the federal government’s push for the health care industry to swap paper for electronic records to save money when doing so relies on cybersecurity investments by private companies.

In a statement, LabMD said the company “looks forward to vigorously fighting against the FTC’s overreach by seeking recourse through the available legal processes.”

Jessica Rich, director of the FTC’s bureau of consumer protection, said LabMD’s practices put consumers at serious risk of identity theft.

“The FTC is committed to ensuring that firms who collect that data use reasonable and appropriate security measures to prevent it from falling into the hands of identity thieves and other unauthorized users,” she said in a statement.

More than half of doctors’ offices and 4 out of 5 hospitals have transitioned from paper to electronic medical records, according to the government. Moving to computerized records is the rare consensus issue in health care, enjoying support from across the political spectrum. Taxpayers have already contributed more than $14 billion to help speed the move through an incentive program that was part of the Obama administration’s economic stimulus package.

The hope was that going digital would make caring for patients safer and less costly by helping avoid medical mistakes and cutting down on duplicative tests. But concerns have also surfaced about patient privacy and vulnerability to fraud. And progress has been mixed in getting medical computers from different offices to talk to each other, the key to a seamlessly efficient system.

A pair of reports in 2011 by the Health and Human Services inspector general warned that the drive to connect hospitals and doctors electronically was being layered on top of a system that already has privacy problems. The administration said in response it would pursue stronger safeguards.

The complaint filed Thursday means that the allegations will be tried in a formal hearing before an administrative law judge. The FTC wants the judge to order LabMD to institute a comprehensive information security program with professional audits every two years for the next 20 years. The proposed order also would require LabMD to notify consumers whose information was compromised.

LabMD founder Michael Daugherty has objected to these terms and has been fighting the FTC investigation for several years. He claims on his personal website that LabMD is a victim of theft by a cybersecurity firm that he says was trying to sell his company services. Daugherty says that when he refused, the stolen data was supplied to government regulators, who are using the leak to punish him as a small business owner and justify additional government regulation. Daugherty has written a book on the subject that he says will be published in September.

The trade commission’s “enforcement action against LabMD based, in part, on the alleged actions of Internet trolls, is yet another example of the FTC’s pattern of abusing its authority to engage in an ongoing witch hunt against private businesses,” LabMD said in its statement.

According to the FTC complaint, a LabMD spreadsheet with insurance billing data on more than 9,000 consumers was discovered on a public file-sharing network. The spreadsheet contained Social Security numbers, birth dates, insurance information and medical treatment codes. The FTC says California police later discovered that identity thieves had acquired personal data from at least 500 LabMD consumers.

In its complaint, the FTC said lax security controls at LabMD resulted in the leak of the spreadsheet. Regulators say the company did not maintain a “comprehensive data security program” or use “readily available measures” to identify common vulnerabilities. The company also did not adequately train employees or prevent unauthorized access, according to the FTC.

(Copyright 2013 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.)

Uncategorized

...

Promotions

“Kingdom of the Planet of the Apes” Advanced Screening

Enter below for a chance to win a pair of tickets to see an advanced screening of "The Kingdom of the Planet of the Apes" on May 7th!

8 days ago

...

Promotions

Dr. Jordan B. Peterson: We Who Wrestle with God Tour-NEW SHOW ADDED!

Register to win tickets to Dr Jordan Peterson's We Who Wrestle With God Tour, on May 14th at Arizona Financial Theatre

17 days ago

adunlap

Win Opening Day Tickets

Win D-backs Opening Day tickets for this Thursday!  Follow @Anthony987sport

1 month ago

...

Promotions

Tedeschi Trucks Band

Tedeschi Trucks Band is coming to Arizona Financial Theatre on June 11th! Register now for your chance to win tickets!

2 months ago

Axon Enterprise headquarters in Scottsdale. (Jim Poulin/Phoenix Business Journal)...

Ron Davis/Phoenix Business Journal

Axon’s north Scottsdale development comes under fire at planning commission meeting

Axon Enterprise Inc.'s mixed-use development plans in north Scottsdale were tabled Jan. 24 in the face of criticism from city commissioners and a standing-room only crowd.

3 months ago

(Pexels Photo)...

Associated Press

States have lost millions of dollars to fight and treat STDs

State and local health departments across the U.S found out in June they’d be losing the final two years of a $1 billion investment to strengthen the ranks of people who track and try to prevent sexually transmitted diseases — especially the rapid increase of syphilis cases.

6 months ago

Sponsored Articles

...

DESERT INSTITUTE FOR SPINE CARE

Desert Institute for Spine Care is the place for weekend warriors to fix their back pain

Spring has sprung and nothing is better than March in Arizona. The temperatures are perfect and with the beautiful weather, Arizona has become a hotbed for hikers, runners, golfers, pickleball players and all types of weekend warriors.

...

COLLINS COMFORT MASTERS

Here are 5 things Arizona residents need to know about their HVAC system

It's warming back up in the Valley, which means it's time to think about your air conditioning system's preparedness for summer.

...

Midwestern University

Midwestern University Clinics: transforming health care in the valley

Midwestern University, long a fixture of comprehensive health care education in the West Valley, is also a recognized leader in community health care.

FTC: Medical lab’s lax security led to data leak