Release time:2023-11-09 20:21:03
In the previous article, we introduced through cases that due to the inherent characteristics of medical information, the unlawful disclosure of such information causes extremely grave harm. Judicial and law enforcement authorities both in China and abroad attach great importance to such security incidents, and the disclosure of medical information by internal personnel of medical institutions by taking advantage of the convenience in the performance of their duties has become a typical hidden risk to the information security of medical institutions. This article continues to analyze, through cases, the security hidden risks that are prone to lead to medical information disclosure, and the approaches for medical institutions to strengthen information security management so as to prevent medical information disclosure.
III. The absence of supervision over outsourcing services leads to the leakage of medical information.
The U.S. GMR Transcription Case
GMR is a company based in California, the United States, engaged in audio-to-text transcription services. Its clients include institutions of higher education, well-known enterprises, government authorities, medical institutions and other entities, and GMR operates its business entirely online. Medical institutions entrust GMR to transcribe audio recordings generated in the process of diagnosis and treatment into text through online channels. Upon receipt of the documents, GMR will assign them to a typing company located in India for processing. Without taking any information security measures, GMR stores these documents on its leased servers for the Indian company to download, and exercises no management over the storage and transmission of such files by the Indian company. The information contained in these audio and text files includes: name, address, date of birth, email address, telephone number, social security account number, driver's license number, tax information, medical history, medical examination results, psychiatric records, etc., among which a large volume of children's diagnosis and treatment information is also included.
The aforesaid acts of GMR were determined to be illegal by the U.S. Federal Trade Commission, which issued a penalty order against GMR stipulating that GMR shall establish an information security mechanism, undergo regular information security assessments and fulfill other relevant requirements.
Case of Infringement of Personal Information Committed by a Maternal Health Educator of a Hospital in Taizhou, Jiangsu Province
Between 2019 and 2020, Defendant Xu took advantage of the opportunity to assist a certain people's hospital in Taizhou and a certain traditional Chinese medicine (TCM) hospital in Taizhou in carrying out prenatal publicity and education for pregnant women, and obtained information containing details including the names, ages, gravidity and parity, expected dates of delivery, residential addresses and contact information of pregnant women. Xu provided the aforesaid information to other co-defendants in the same case by sending information pictures and other content via WeChat, for the purpose of inviting pregnant women to participate in prenatal publicity and education activities held by the hospitals or carrying out brand promotion activities, with the total number of involved information exceeding 7,000 pieces. Upon trial, the court held that Defendant Xu violated relevant state regulations by illegally obtaining and providing citizens' personal information to others, with particularly serious circumstances. He was sentenced to three years of fixed-term imprisonment with a three-year probation period, and a fine of RMB 10,000.
Service outsourcing is widely applied across all walks of life. However, failure to exercise information security supervision and impose restrictions on outsourcing personnel may also lead to severe information security incidents. In a case in the United States, when US medical institutions sent audio-to-text transcription requests to GMR Transcription, they were completely unaware of the potential risks of medical information leakage. They recklessly transmitted diagnosis and treatment audio recordings containing a large amount of medical information to GMR via the Internet without encryption, and did not impose any security requirements or restrictions on GMR's transcription services. Ironically, GMR "did not disappoint" these medical institutions, as it assigned all the documents to an Indian company for transcription. This Indian company was even more negligent: it stored medical audio and text documents via FTP, and transmitted its work results to GMR via the Internet without encryption. Under such "full-process loss of control" operations, an investigation by the US Federal Trade Commission (FTC) found that the FTP server of the Indian company on the Internet could be searched through mainstream search engines, and thousands of medical documents sent to it by GMR could be easily retrieved in the directory, which were completely publicly accessible. In addition to personal information, the documents also contained highly sensitive information including children's diagnosis and treatment information, mental disorder records, alcoholism treatment records, substance abuse treatment records and abortion records, among others. It can be seen that if medical institutions neglect the supervision and restriction of outsourcing service personnel, the harm caused thereby is no less serious than that caused by internal staff of medical institutions. Therefore, this issue also merits close attention.
IV. Inadequate System Security Measures and Lax Account Management
The Case of Patient Information Leakage of Zhengzhou Stomatological Hospital
In June 2018, Defendant Ma Moumou served as Head of the Marketing Department at the Jingsan Road Branch of Zhengzhou Weimei Stomatological Hospital in Jinshui District, responsible for market expansion. The hospital collected and stored basic patient information such as names, phone numbers, genders, consultation records, inquiry records, electronic medical records, treatment records and other materials through the "E Kanya" medical auxiliary software system. In July 2019, Defendant Ma Moumou resigned from Zhengzhou Weimei Stomatological Hospital. In March 2020, Ma Moumou was recruited to work at Zhengzhou Lesasha Stomatological Hospital. Later, either in the office of the said hospital or at his residence, Defendant Ma Moumou used account usernames and passwords belonging to himself or former employees of Weimei Stomatological Hospital to log in to the "E Kanya" system of Weimei Stomatological Hospital without authorization, and called patients by leveraging their personal information stored in the system to persuade them to receive medical consultation, treatment and other services at Zhengzhou Lesasha Stomatological Hospital. According to statistics, Ma Moumou illegally obtained a total of 1,258 pieces of personal information. The court found Ma Moumou guilty of the crime of infringing upon citizens' personal information, and sentenced him to one year of fixed-term imprisonment and a fine of RMB 12,000.
In the present case, the stomatological hospital in Taizhou failed to promptly cancel the accounts of its employees after their resignation, which is a common scenario of information leakage caused by information system security issues. In the aforementioned *U.S. LabMD Medical Information Leakage Case*, the dereliction of duty in system security by this U.S. medical institution is also highly representative. The U.S. Federal Trade Commission (FTC) disclosed after investigation that during the period from 2005 to 2010, LabMD had the following practices: it failed to adopt file monitoring and intrusion detection and prevention measures, and did not monitor information entering and exiting through the firewall; it had no login password management mechanism in place, and the computer login passwords of at least 6 employees had been set to "labmd" for a long time; it never upgraded its software and systems, and took no protective measures against known illegal intrusion vulnerabilities. In terms of authority management for employees' use of systems or computer equipment, LabMD's practices were even more shocking. Its laboratory software LabSoft was originally configured with access authority settings, but LabMD disabled this function for work convenience, so that even short-term part-time enrolled students could easily access patients' medical information and relevant sensitive information. Sales representatives of LabMD could use physicians' accounts to log into the LabSoft software to view relevant sensitive personal information. Until the autumn of 2009, the defendant's administrative staff and sales personnel all had administrator privileges for their computers, and they could modify computer privileges at will. The U.S. Federal Trade Commission (FTC) held that the most direct consequence of LabMD's series of negligent acts in system security was that a P2P sharing software named Limewire had been running on its financial staff's computer for as long as three years (2005-2008), and automatically shared the medical information stored on the computer to the Internet.
V. Suggestions for Medical Institutions on Conducting Information Security Work
1. In light of the actual circumstances, dynamically grasp the "reasonableness" of information security measures
Article 1226 of the Civil Code of the People's Republic of China Medical institutions and their medical personnel shall keep confidential the privacy and personal information of patients. Whoever divulges a patient's privacy and personal information, or discloses the patient's medical records without the consent of the patient, shall bear tort liability. As the law explicitly stipulates the confidentiality obligations of medical institutions and their medical personnel, while information security appears extremely hard to guard against in many cases, how to prevent illegal disclosure of medical information inevitably causes anxiety among practitioners. In fact, there is no perfect once-and-for-all solution for information security, be it in the medical sector or any other sector. The U.S. Federal Trade Commission once stated on information security as follows: The Commission never requires, nor does there exist in fact, any so-called perfect security solution. Reasonable security measures are a process of dynamic adjustment constantly adapted to evolving situations. The core criterion for evaluating information security work is "reasonableness", which means whether an enterprise has put in place protective measures commensurate with the volume, sensitivity and other relevant attributes of the data it holds. When considering the information security work of your entity, company or department, you may approach the work from the following perspectives:
Enterprises shall clearly identify the types of consumer information in their possession, as well as the scope of employees and third parties with access to such information. The information collected and retained by enterprises shall be limited to the scope of legitimate business purposes, and no excessive collection of information shall be conducted, so as to mitigate information security risks. Enterprises shall adopt information security protection measures on the basis of security risk assessment, with priority given to the following key areas: physical security, cybersecurity, employee training, and supervision of outsourced personnel; regularly dispose of obsolete data; and formulate emergency response plans for information security incidents. It shall be noted that the aforesaid requirements shall be implemented periodically on a rolling basis and dynamically adjusted in light of the development status of enterprises, so as to ensure that the current information security measures of enterprises always maintain "reasonableness".
2. Tiered and Categorized Management of Key Sectors and Key Personnel
It is also evident from the aforesaid cases that certain specific businesses are exposed to high risks of information leakage, such as the maternal and obstetric information, dental information and other data mentioned in the foregoing cases. On this basis, we recommend that medical institutions sort out the medical information held by their own institutions and respective departments, classify such information according to the level of leakage risk and the degree of information sensitivity, and adopt corresponding "reasonable" management measures. For example, reproductive health and obstetric information as well as dental diagnosis and treatment information are the most vulnerable to leakage, and shall be given key attention. The number of personnel with access to such information shall be kept to the minimum possible scope. Personnel with low business relevance and no sufficient necessity for access shall not be granted access rights to such information. It is also found in the cases that large-scale information leakage occurs as staff members are entitled to query the full scope of information. It is therefore recommended that different query permissions be allocated in accordance with the identity and duties of different personnel. For instance, the granularity of accessible information may be set based on business necessity: physicians who need to carry out diagnosis and treatment shall have access to the finest and most complete granularity of information, while nurses, pharmacists and dietitians shall be granted access to information at different levels of detail due to their different professional duties. Settings may also be made from the perspective of relevance. For example, a physician may only query the medical information of patients admitted by himself/herself, and shall not access the information of patients treated by other physicians. In addition, the queryable time dimension may be restricted in accordance with the diagnosis and treatment cycle of relevant medical services, among other measures.
3. Establish information security management measures and systems
It is evident from several cases cited in this article that some medical institutions lack a reasonable set of information security systems. After the maternal information leakage case in Nanning, Guangxi, the case-handling procuratorate issued a procuratorial suggestion to the relevant medical institution, requiring it to improve its information security management measures and systems. Following two information leakage cases involving medical institutions in the United States, the Federal Trade Commission (FTC), in its penalty order against the involved enterprises, explicitly required the establishment of an information security system. The requirements for such "security system" also embody the principle of "reasonableness": the information security system must be reasonably designed to protect the security, privacy and integrity of the personal information collected by the defendant. This system shall include protection measures covering administrative management, technology and physical protection, and shall be commensurate with the size and structural complexity of the defendant's entity, the nature and scale of the defendant's business, as well as the sensitivity level of the data to be administered. This article recommends that medical institutions take the capabilities in the following aspects into consideration when establishing an information security system:
The ability to detect internal and external information security risks, including: the provision of information security awareness training for employees and the administration of employees; the formulation of measures covering information processing, storage, transmission and disposal, among others; and measures for the prevention, detection and handling of system intrusion, attack or system failure, etc.
Risk testing capability, including: conducting regular risk assessments, regularly verifying the effectiveness of handling measures, among others.
Formulate reasonable procedures to improve the capacity for screening outsourcing service providers, including verifying that outsourcing parties have the capacity to manage information obtained from medical institutions, and imposing binding constraints on outsourcing service providers through contractual means, etc.
The capability to dynamically adjust the information security system in accordance with the results of risk testing, adjustments to the medical institution's own business operations or changes in the environment.