Started By
Message

re: Dozens fired from hospital for viewing Jussie Smollett's medical records

Posted on 3/8/19 at 8:01 am to
Posted by Centinel
Idaho
Member since Sep 2016
46660 posts
Posted on 3/8/19 at 8:01 am to
And don't think this is just a HIPAA/medical world thing. This is most of corporate america now.

I can see every website a user accesses, for how long, if they downloaded a file, what the file was, if the uploaded a file, what that file was, if they copied a file to any type of removable media and the type/size/name of that file. There is absolutely nothing you can do on our network or on your laptop that I can not see and have logs of. Nothing. And that includes if you're using it at home on your home network.

And if you think you're being slick and using a VPN, a) I know you're using that VPN, and b) SSL decrypt is a thing.





This post was edited on 3/8/19 at 8:03 am
Posted by lsunurse
Member since Dec 2005
129146 posts
Posted on 3/8/19 at 8:03 am to
And that is why I NEVER access TD from my work computer and work laptop


Always only TD post on my phone.
Posted by baldona
Florida
Member since Feb 2016
24439 posts
Posted on 3/8/19 at 8:10 am to
quote:

And don't think this is just a HIPAA/medical world thing. This is most of corporate america now.


What about my cell phone though?

I’ve never understood why someone would look at questionable stuff on their work computer while having a smart phone. I’ve literally told employees to use their smart phone for that crap and I don’t care, but I’d write them up if they used their comp.
Posted by Sasquatch Smash
Member since Nov 2007
25961 posts
Posted on 3/8/19 at 8:12 am to
quote:

She’s appealing


Pics?

If she's so appealing, I'm sure some MD has snatched her up already...
Posted by Legion of Doom
Old Metry
Member since Jan 2018
5773 posts
Posted on 3/8/19 at 8:14 am to
quote:

All have the ability to audit


I know a guy who looked up his own MRI results in Meditech instead of going through medical records. He got written up. He’s still butthurt about it to this day.
Posted by Wtodd
Tampa, FL
Member since Oct 2013
68603 posts
Posted on 3/8/19 at 8:14 am to
Culcha and shite
Posted by Centinel
Idaho
Member since Sep 2016
46660 posts
Posted on 3/8/19 at 8:19 am to
quote:

What about my cell phone though?


Depends on the MDM (Mobile Device Management) solution your company is running if you have work email on your phone.

In our case I can't see what you're surfing on your phone, but I can see all the applications you have on your phone, how much you use them, etc....and can remote wipe it. Other solutions are much more intrusive.
Posted by baldona
Florida
Member since Feb 2016
24439 posts
Posted on 3/8/19 at 8:22 am to
I’m a little ignorant here, but you are talking about it it’s a work provided phone you have access to right? Not a personal phone?
Posted by Centinel
Idaho
Member since Sep 2016
46660 posts
Posted on 3/8/19 at 8:25 am to
quote:

I’m a little ignorant here, but you are talking about it it’s a work provided phone you have access to right? Not a personal phone?




Personal phone. You want work email on your phone? You get the MDM platform and all the Big Brother fun that comes with it. Our larger clients require it. In fact we have to dance around the fact our solution isn't intrusive enough. Some of the biggest clients (Fortune 10s) want us to have absolute full access to every aspect of the employee's phone if it has any type of their (the client) data on the phone, even if it's just email. It all revolves around Data Loss Prevention (DLP). Basically we have to have full access of every single aspect of any device the employee uses that could possibly transmit data in the event they use the device to email or text client data to outside entities.

Personal laptop at home, personal iPad, personal phone....doesn't matter.

This post was edited on 3/8/19 at 8:27 am
Posted by Legion of Doom
Old Metry
Member since Jan 2018
5773 posts
Posted on 3/8/19 at 8:48 am to
Damn. But that’s only if the person is receiving their work email on a personal device, correct? I don’t receive work email on my phone. Do you still have that ability?
Posted by Centinel
Idaho
Member since Sep 2016
46660 posts
Posted on 3/8/19 at 8:53 am to
quote:

Damn. But that’s only if the person is receiving their work email on a personal device, correct?


Correct. There is nothing saying an employee/partner has to have their work email on their phone. Realistically though, just about everyone does.

And yes, the MDM software has to be loaded on the phone for the access.

Now on a firm-provided laptop or other device, you don't get a choice in the matter.
Posted by lsunurse
Member since Dec 2005
129146 posts
Posted on 3/8/19 at 9:14 am to
quote:

I know a guy who looked up his own MRI results in Meditech instead of going through medical records. He got written up. He’s still butthurt about it to this day.


He’s lucky he didn’t lose his job. Some hospitals would quickly fire someone over that cause you’ve already proven you are an idiot when it comes to observing HIPAA regulations and could be a liability to the organization.
Posted by idlewatcher
Planet Arium
Member since Jan 2012
98619 posts
Posted on 3/8/19 at 9:17 am to
quote:

And if you think you're being slick and using a VPN, a) I know you're using that VPN, and b) SSL decrypt is a thing.


Perhaps so, but the whole point of the VPN is to mask your browsing activity....and you wouldn't be privy to that.
Posted by baldona
Florida
Member since Feb 2016
24439 posts
Posted on 3/8/19 at 9:19 am to
quote:

You get the MDM platform and all the Big Brother fun that comes with it. Our larger clients require it


Yeah ok, you meant that you have to download the software first on the phone. I thought you meant you were able to track shite without anything downloaded lol. I was like woah buddy.

If you have software on your phone that your employer monitors that’s the same as a work laptop. You are stupid to be looking at anything inappropriate. Get a burner phone for that, it’s not that expensive to even just get a $25/ month cell plan and an outdated smart phone for personal stuff.
Posted by touchdownjeebus
Member since Sep 2010
26778 posts
Posted on 3/8/19 at 9:19 am to
Somehow, some way, this dude is going to rotate back into being the victim in all of this. What a strange world we live in...
Posted by baldona
Florida
Member since Feb 2016
24439 posts
Posted on 3/8/19 at 9:22 am to
quote:

Somehow, some way, this dude is going to rotate back into being the victim in all of this. What a strange world we live in...


Not somehow, dude just got a mil or two most likely settlement from the hospital to shut up and not take this to the media. The hospital wants this over yesterday and out of the news, they don’t want every half way decent person thinking anytime they are admitted there are 25 nurses checking their data.
Posted by SUB
Silver Tier TD Premium
Member since Jan 2009
26276 posts
Posted on 3/8/19 at 9:23 am to
quote:

HIPAA violations are serious shite.


Well, if they have access to it and didn't provide access to an unauthorized person, it's not a violation. It may be an internal policy that you shouldn't go snooping around random people's medical records.

To me, it sounds more like the hospital has an issue with allowing access to records to too many people, which will lead to stuff like this.
Posted by wasteland
City of peace
Member since Apr 2011
5923 posts
Posted on 3/8/19 at 9:29 am to
quote:

Bull fricking shite. Not everyone is as dumb as you to buy this lame excuse.

You got what you deserved.





I'm not shocked. Nurses are not far behind hair dressers as dumbest people I've met.
Posted by NCDawg52
Atlanta, GA
Member since Dec 2014
3151 posts
Posted on 3/8/19 at 9:31 am to
Per Becker’s Review, Northwestern Memorial has been using Epic since 2018.

As some have said, VIP records are password locked and protected within Epic, and any instances of “breaking the glass” are recorded with ID/time stamp.

There is no situation in which “scrolling past the record” would trigger the same flag.

Smollett is a POS, but HIPPA rules are clearly laid out for all hospital employees, and this seems like a clear violation.
Posted by deeprig9
Unincorporated Ozora
Member since Sep 2012
76075 posts
Posted on 3/8/19 at 9:32 am to
Centinel,

Is it true that the info is usually only accessed if they are looking for a way to fire someone? They don't have a secret command center watching everyone's screens, i dont imagine.

Followup question-

If I have a browser open with ten tabs, do you necessarily know which tabs im viewing and for how long etc?

We have cyberark to record sessions over rdp on servers, but i don't think there's that level of intrusion on the workstations.
This post was edited on 3/8/19 at 9:36 am
first pageprev pagePage 3 of 4Next pagelast page

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on X, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookXInstagram