<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: DMHC fines Kaiser Permanente $200,000 for exposing patient information on the Internet</title>
	<atom:link href="http://www.kaiserthrive.org/2005/06/21/dmhc-fines-kaiser-permanente-200000-for-exposing-patient-information-on-the-internet/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kaiserthrive.org/2005/06/21/dmhc-fines-kaiser-permanente-200000-for-exposing-patient-information-on-the-internet/</link>
	<description>Kaiser Permanente: Failure to Thrive -- A Managed Care Watch Web Site</description>
	<pubDate>Sun, 06 Jul 2008 04:09:34 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: L</title>
		<link>http://www.kaiserthrive.org/2005/06/21/dmhc-fines-kaiser-permanente-200000-for-exposing-patient-information-on-the-internet/#comment-4751</link>
		<dc:creator>L</dc:creator>
		<pubDate>Sat, 30 Sep 2006 03:02:13 +0000</pubDate>
		<guid isPermaLink="false">http://kaiserthrive.org/wordpress/2005/11/11/dmhc-fines-kaiser-permanente-200000-for-exposing-patient-information-on-the-internet/#comment-4751</guid>
		<description>HIPAA is a joke.  There are so many things that are supposed to be secured that aren't.  For instance, when you check in, that's supposed to be held in private so that no one can hear you.  They aren't supposed to use whiteboards any longer where patients may see other patients symptoms, etc.  Last time I checked, all that crap was still available for anyone to see in a hospital, especially Kaiser's.  

Heaven forbid there is a security breach and someone gets into Kaiser's intranet and web applications.  There are apps out there that log all kinds of Personal Health Information (PHI) in their application logs.

$200,000 is pittance for this security breach, and yeah, I think it should go to Elisa as a reward for pointing it out.</description>
		<content:encoded><![CDATA[<p>HIPAA is a joke.  There are so many things that are supposed to be secured that aren&#8217;t.  For instance, when you check in, that&#8217;s supposed to be held in private so that no one can hear you.  They aren&#8217;t supposed to use whiteboards any longer where patients may see other patients symptoms, etc.  Last time I checked, all that crap was still available for anyone to see in a hospital, especially Kaiser&#8217;s.  </p>
<p>Heaven forbid there is a security breach and someone gets into Kaiser&#8217;s intranet and web applications.  There are apps out there that log all kinds of Personal Health Information (PHI) in their application logs.</p>
<p>$200,000 is pittance for this security breach, and yeah, I think it should go to Elisa as a reward for pointing it out.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
