Access To Clinical Data Too Easy Via Phone

Posted on October 26, 2012 I Written By

Anne Zieger is a healthcare journalist who has written about the industry for 30 years. Her work has appeared in all of the leading healthcare industry publications, and she's served as editor in chief of several healthcare B2B sites.

Lately, I’ve had reason to be in touch with my health insurance company, my primary care doctor and multiple specialists.  In speaking with each, what I’ve noticed is that the data they collect to “protect my privacy” isn’t likely to do a good job. And I’ve been wondering whether an EMR can actually help tighten up access.

When I called to discuss clinical matters, both the payer and providers asked for the same information: My date of birth, my street address and my name. As far as I know, folks, you can get all of that information on a single card, a driver’s license.  So, anyone how finds or steals or has access to my wallet has all the info they need to crawl through my PHI.

So, OK, let’s say providers and payers add a requirement that you name the last four digits of your social security card.

There’s a few problems with that approach. First, anyone who has your wallet may well have your Social Security Card.  Second, storing patients’ SSNs in the clear in an EMR is an invitation to be hacked, as the SSN is the gold standard for identity theft. Third, if you want to store them in a form that only allows the last four digits to be read, that’s another function you need to add to your system.

So, what’s the solution? Would it work to have patients identify which doctor they see (something a thief wouldn’t know) or a recent treatment or procedure they’d had?  Probably, although some patients — forgetful elderly, or the chronically ill with multiple providers — might not remember the answers.

Seems to me that when there’s universal use of patient portals by both providers and payers, this problem will largely go away, as patients will be able to be looking at their own records when talking to providers. This will make a more sophisticated security screening possible.

But in the mean time, I’m troubled to know that my payer and several of my doctors use a security method which can be so easily compromised.  Do any of you have suggestions as to what those offices might do in the interim between now and when they have a useful portal to offer?