Breach at insurance company highlights insider threat

06.04.2006

As an entity covered by the Health Insurance Portability and Accountability Act, Maimonides is required by law to have controls for securing protected health information (PHI). The hospital is using Reconnex's appliance to detect PHI leaving its networks in an unauthorized fashion, Moroses said.

"From our point of view, the insider threat comes from people either knowingly or unknowingly damaging our reputation" by leaking sensitive information, Moroses said. "Patients come here for AIDS tests and for pregnancy tests that they don't want to share" with other people, he said. "A patient is not going to come to our hospital if they think we are not doing everything to protect their information. So our reputation is paramount because it affects our bottom-line business."