SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Technology

Hong Kong earmarks funds for patient data security

Hong Kong earmarks funds for patient data security

By:  Computerworld Hong Kong staff  On: 10 Sep 2008 For: Computerworld Hong Kong (hs) Creator

After 10 incidents of data loss, with apparently no disclosures of patient information, the city has decided to spend just over US$4 million to improve information security

HONG KONG - The Hospital Authority here has earmarked HK$35 million (US$4.4 million) to improve patient data security and privacy based on recommendations by the privacy commissioner and authority's own taskforce.

The HA said last week a budget of HK$10 million has been allocated for the remainder of the financial year and HK$25 million next year. The fund will be spent on setting up the new information security and privacy office and upgrading data security infrastructure.

Stephen Lau, chairman of the taskforce said that 26 recommendations were made in a taskforce report and presented to the Hospital Authority Board covering improvements in four major areas -- policy; structure and people; procedures and guidelines; and technology.

The taskforce studied 10 reports of data loss cases involving 16,000 patients in six hospitals and clinics since April. The authority said all patients had been notified and no data had been leaked.

The taskforce suggested the appointment of a chief information security and privacy officer for leading HA-wide information security and privacy programs in a coordinated manner.

It added in the report that data security and privacy should be integrated into organizational performance objectives and for which chief executives have an explicit accountability within their clusters and should be required to make an annual report on information security and privacy.

The taskforce also made recommendations for adoption in the short term to minimize risk of further patient data loss. These include: automatic encryption of downloaded data; whole disk encryption for portable electronic devices; physical restriction of the use of devices; and storage and sharing of data on secure file servers.

In addition, it has come up with several principles for ongoing enhancement of data protection. They include: minimizing access to and use of personally identifiable information; minimizing transport of such information; guarding the systems containing such information against external threats; and providing concrete procedures and handling guidelines.

Andre Greyling, CIO of the Hospital Authority, said it has already implemented some of the recommended measures including automatic encryption of patient data downloaded from its clinical systems.

He added that the organization will study the report in detail, together with recommendations made by the Privacy Commissioner for Personal Data (PCPD) in its inspection report earlier this year.

"We are in the process of drawing up an action plan to implement practicable measures as recommended in both reports to enhance patient data security and privacy," said Greyling. "A dedicated team is also being set up to work solely on improving data security within the authority."

He added that the HA will provide PCPD with quarterly progress reports and a full report, at the end of 12 months, on the implementation of the 39 recommendations in the inspection report, together with the 26 enhancement measures recommended by the taskforce.


Sign up for our Newsletters












Print |  Views: 750   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Computerworld Hong Kong staff Computerworld Hong Kong staff is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Security staff migrating to business
Security staff migrating to businessA recent study indicates that security professionals are set to move beyond IT director control in future, as they take a more proactive approach in order to secure their organizations.
New data security measures implemented by U.K. defence ministry
New data security measures implemented by U.K. defence ministryThe Ministry of Defence (MoD) has detailed how it intends to implement a number of recommendations made by the Information Assurance Advisory Council regarding its data security.
Management practices critical to information privacy, says Stoddart
Management practices critical to information privacy, says StoddartTJX and its retail companies collected too much information, held it too long and used inadequate encryption technology to protect it, the Privacy Commissioner of Canada said in a report published Tuesday.
ShmooCon 4
last weekend was the 4th annual shmoocon. tickets for the event sell out very quickly as they limit attendance. this year, 1200 self-proclaimed hackers came to the event that promised “less moose than ever”. far from the formality of a regular conference, shmoocon runs talks by researchers presenting new findings and new tools. attendees are encouraged t
Obama, the security threat
much hay was made in the now-mercifully-ended u.s. election campaign (next one starts in january!) about whether the democrats were soft on homeland security. regardless of opinion, the president-elect -- congratulations, sen. obama -- has predictably become an it security threat.websense, symantec and sophos labs reported today on pusa-related security issues. websense says its threats
blog comments powered by Disqus