Slashdot Mirror


Accessing Medical Files Over P2P Networks

Gov IT writes with this excerpt from NextGov: "Just days after President Obama signed a law giving billions of dollars to develop electronic health records, a university technology professor submitted a paper showing that he was able to uncover tens of thousands of medical files containing names, addresses and Social Security numbers for patients seeking treatment for conditions ranging from AIDS to mental health problems. ... The basic technology that runs peer-to-peer networks inadvertently exposed the files probably without the computer user's knowledge, Johnson said. A health care worker might have loaded patient files onto a laptop, for example, and taken it home where a son or daughter could have downloaded a peer-to-peer client onto the laptop to share music."

5 of 137 comments (clear)

  1. P2P?! Oh no! by Manip · · Score: 4, Insightful

    Sorry but what does one have to do with another?

    Currently Doctors are using word documents with every patient's name as the title in some locations. While others are using VB apps with a Acess Database type solution.

    Putting real money into a real electronic system with access controls and a audit trail is a GOOD thing and will stop things like records spreading onto P2P networks.

    It is good for patients, it is good for doctors, and it is good for the general quality of healthcare.

    I grant that it is expensive though. I also grant that governments are bad at large IT projects and always give it to the lowest bidder.

    1. Re:P2P?! Oh no! by RiotingPacifist · · Score: 4, Insightful

      >>>will stop things like records spreading onto P2P networks.

      Right because the government has never, ever accidentally let private information leak out ("Congressional worker has laptop stolen)." They government has never, ever let anyone have access to my social security number ("State website published millions of SS numbers online"). We can trust the government to keep our stuff secure ("Our records show you were unemployed in 2003." "How do you know that?" "We just called the IRS; they reported your income was near-zero.")

      An inperfect but well designed system is miles better than the current system.

      Go watch GATTACA if you believe having our medical records available to any doctor who asks is such a great idea. With public sharing of formerly-private data, companies can discriminate against unhealthy persons whenever they desire. Here's a link: http://isohunt.com/torrent_details/39287978/GATTACA?tab=summary

      Go watch people die when a doctor doesn't have a full medical record when treating a patient.Wow a sci-fi film must obviously have taken a lot more time to do a cost benifit analysis of the situation, and come to a much better conclusion about what would really happen, than an actual analysis of the situation.

      It's bad enough I have a credit score attached to my name, along with how much debt I owe, with which employers can decide to hire or not hire me. Now they'll learn about my heart condition, and in order to reduce medical costs, decide to skip-over me and give the job to someone else.

      This idea is all kinds of bad.

      Erm when did the medical records become public information? Having a system where a doctor (when authorized), can access your medical records (when needed ( with proper punishment when its abused)), is very different from given everybody full access to your medical records.

      --
      IranAir Flight 655 never forget!
  2. Wrong issue by ZouPrime · · Score: 5, Insightful

    The issue here aren't P2P networks. The issue is government employees either loading confidential data on non-approved environments, or unauthorized software being installed on supposedly restricted environments. Both these problems must be addressed with traditional security controls that are completely independent of P2P technologies.

    1. Re:Wrong issue by evilkasper · · Score: 5, Insightful

      Exactly until they people handling the sensitive or classified material learn how to handle it with the care it needs we will keep seeing things like this. I mean how many times a week do we see something about a lost or stolen laptop or device that contained sensitive information. The issue (as per normal) is the USERS

    2. Re:Wrong issue by ValentineMSmith · · Score: 5, Insightful

      Neither the story nor the summary mentioned anything about government employees. The private sector is just as capable of screwing up as the government is.

      --
      Karma: Chameleon - mostly influenced by bad '80s New Wave music