« Synchronizing Oracle IRM desktop in VMWare | Main | Cisco research reveals common data loss mistakes »

More personal data lost in health care

BlueCross and BlueShield LouisianaIt seems to be happening every week, sensitive information is being lost from health care organizations. This time email is the culprit.
BlueCross & BlueShield of Louisiana have had to publicly announce details of an incident where a document was accidentally attached to an email sent to a group of about 1,700 brokers. The document contained social security numbers, phone numbers and addresses. Fortunately the information was about the same group of people the email was sent to, no customer information was involved. This demonstrates how easily mistakes like this can happen and how BlueCross & BlueShield are required, by law, to make this information public knowledge. Fines for such incidents can be incurred although no details of a fine have been reported in this case.

Louisiana Blue Cross confirms data breach

Oracle IRM can prevent such incidents in many ways. Firstly, if this document had been classified and protected using IRM and the recipients had not been given rights to the classification, then the document would never have been accessible by this group brokers. This is often the most valuable aspect of using an IRM technology. Having a classification which only allows access to confidential information to those within your organization so that if the document or email is accidentally lost, attached and forwarded via email or stolen, it is unusable for anyone outside your organization.

However what if the document had been protected incorrectly to a classification which the brokers did have access? Unlike many other similar technologies, Oracle IRM separates the rights to content from the documents and stores all this information on the centralized Oracle IRM server. In this case once the mistake has been realized/reported, the BlueCross & BlueShield classification manager could simply deny access to this, or many documents even after they have been distributed. When the brokers then attempt to access the document in the email, they are denied. Even those who were able to access the documents before the organization knew of the error, would be denied access once their rights have been centrally changed. They may however still have access to other content, in the same classification. Such is the flexibility of the Oracle IRM classification model.

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Oracle IRM resources

IRM at oracle.com
Online demonstration
Oracle MIX group
Downloads on OTN
Technical white paper
Business white paper
More...

Want to evaluate how Oracle IRM works? Please contact us and we can quickly setup you up with a hosted evaluation.

About This Entry

This page contains a single entry from the blog posted on October 1, 2008 10:13 AM.

The previous post in this blog was Synchronizing Oracle IRM desktop in VMWare.

The next post in this blog is Cisco research reveals common data loss mistakes.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type and Oracle