<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Security Safeguards- OFAD2033 by Heba Sadek</title>
      <link>https://padlet.com/hsadek3/2w2nu046kzykmasb</link>
      <description>1- What went wrong?

2- How could this incident have been prevented?  what are the missing safeguards?
</description>
      <language>en-us</language>
      <pubDate>2024-11-04 05:22:06 UTC</pubDate>
      <lastBuildDate>2024-11-05 16:29:56 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url>https://padlet.net/icons/png/1f4ac.png</url>
      </image>
      <item>
         <title></title>
         <author>hsadek3</author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199873399</link>
         <description><![CDATA[<p>During a fire, physical documents containing personal health information are destroyed because they were stored in a room without adequate security measures and no disaster recovery plan was implemented.</p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-04 05:32:29 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199873399</guid>
      </item>
      <item>
         <title></title>
         <author>hsadek3</author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199879483</link>
         <description><![CDATA[<p>During a fire, physical documents containing personal health information are destroyed because they were stored in a room without adequate security measures and no disaster recovery plan was implemented.</p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-04 05:37:11 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199879483</guid>
      </item>
      <item>
         <title></title>
         <author>hsadek3</author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199885559</link>
         <description><![CDATA[<p>Without established audit policies, a staff member with unauthorized access modifies patient records for personal gain, leading to a significant breach of patient privacy.</p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-04 05:42:03 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199885559</guid>
      </item>
      <item>
         <title></title>
         <author>hsadek3</author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199886070</link>
         <description><![CDATA[<p>A hacker exploits weak password protocols to gain access to the organization’s electronic medical records system, resulting in the download of sensitive patient data.</p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-04 05:42:24 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199886070</guid>
      </item>
      <item>
         <title></title>
         <author>hsadek3</author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199886445</link>
         <description><![CDATA[<p>A former employee gains unauthorized access to the facility and retrieves sensitive records stored in unlocked filing cabinets. This breach exposes patient information to potential misuse.</p><p><br></p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-04 05:42:44 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199886445</guid>
      </item>
      <item>
         <title></title>
         <author>hsadek3</author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199887329</link>
         <description><![CDATA[<p>A staff member inadvertently sends sensitive patient information to an unauthorized recipient via email. The organization had not provided regular training on data privacy policies and procedures.</p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-04 05:43:30 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199887329</guid>
      </item>
      <item>
         <title></title>
         <author>hsadek3</author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199900446</link>
         <description><![CDATA[<p>The hospital system implemented a flexible work policy, allowing healthcare professionals to access patient records remotely on various devices, including laptops and tablets. One day, a physician inadvertently left their laptop in a taxi after a meeting. This laptop contained sensitive patient data, including medical histories and personal information for thousands of patients.</p><p>The lost device was eventually recovered by another passenger, who discovered the laptop was accessible and reviewed the data without encountering any security measures. This unauthorized access led to the exposure of confidential patient information, prompting immediate concern among patients and staff.</p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-04 05:53:19 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3199900446</guid>
      </item>
      <item>
         <title></title>
         <author></author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202798176</link>
         <description><![CDATA[<p><strong>What did I do incorrectly?</strong></p><p>The ex-employee could get into the building without screening processes in place, and important documents were left unsecured in the file cabinets. This security lapse created a situation where anyone could easily access details about patients and misuse this information for purposes. </p><p><strong>What could have been done to prevent this situation from happening in the place?</strong> </p><p>The building need to control access by revoking ex-employees access and storing documents in cabinets for security purposes. </p><p><strong>What safeguards are not, in place? </strong></p><p>The safeguards that are not, in place comprise security measures such as doors and limited access for former employees; secure filing cabinets for confidential documents; and routine checks, on access permissions to guarantee only approved individuals can enter the facility—a system that would deter unauthorized entry and protect against information leaks. </p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-05 16:00:35 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202798176</guid>
      </item>
      <item>
         <title></title>
         <author>hsadek3</author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202801699</link>
         <description><![CDATA[<p>Please do not use Chat GPT or internet sources</p><p><br/></p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-05 16:02:57 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202801699</guid>
      </item>
      <item>
         <title></title>
         <author></author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202802671</link>
         <description><![CDATA[<p>What went wrong?</p><p><br/></p><p>The documents were not stored securely and properly, and there was no disaster recovery plan. This caused their loss in the fire. This situation shows a lack of preparation and failure to follow regulations, which compromised patient privacy.</p><p><br/></p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-05 16:03:36 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202802671</guid>
      </item>
      <item>
         <title></title>
         <author>liratim</author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202804481</link>
         <description><![CDATA[<p>The hypothetical situation occurs when the nurse is entering a patient's data into the system and when caring for another patient, all of the patient's data is exposed. Given this, it would be important to create training for the team and create ways for the computer screen to automatically lock to keep the data locked.</p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-05 16:04:59 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202804481</guid>
      </item>
      <item>
         <title></title>
         <author></author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202807744</link>
         <description><![CDATA[<p>How could this incident have been prevented?</p><p><br/></p><p>To keep important papers safe, you can store them in a fireproof box. Make sure you have smoke detectors or fire alarms to alert you if there’s a fire. It’s also a good idea to have a backup of important information stored somewhere safe, just in case something goes wrong.</p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-05 16:07:10 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202807744</guid>
      </item>
      <item>
         <title></title>
         <author></author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202810862</link>
         <description><![CDATA[<p>1. <strong>What went wrong?</strong>: In this scenario, several things went wrong. First, the physician left their laptop containing sensitive patient data unattended in a taxi, which is a significant security risk. Second, the laptop lacked proper security measures, such as password protection or encryption, allowing the unauthorized passenger to access the confidential information easily.</p><p>2.<strong>How could this incident have been prevented?:</strong> This incident could have been prevented by implementing stricter security protocols for accessing patient data remotely. For example, the hospital could require strong passwords, automatic locking of devices after a short period of inactivity, and encryption of sensitive data stored on devices. Additionally, training healthcare professionals on the importance of securing their devices and being cautious when handling sensitive information is essential.</p><p>3.<strong>Missing safeguards</strong>: The key missing safeguards include:</p><p>- Device encryption: Ensuring that all sensitive data on devices is encrypted so that even if the device is lost, the data remains protected.</p><p>- Access controls: Implementing strong password requirements and two-factor authentication for accessing patient records.</p><p>- Remote wipe capability: Having the ability to remotely wipe data from lost or stolen devices to prevent unauthorized access.</p><p>- Regular training: Providing ongoing training for employees on best practices for data security and the importance of safeguarding patient&nbsp;information.</p><p><br/></p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-05 16:09:14 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202810862</guid>
      </item>
      <item>
         <title></title>
         <author></author>
         <link>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202815535</link>
         <description><![CDATA[<p>What are the missing safeguards?</p><p><br/></p><p>Proper physical safeguards were missing like:</p><p>Fireproof safe</p><p>Smoke detectors/Fire alarms</p><p>Environmental controls</p><p><br/></p>]]></description>
         <enclosure url="" />
         <pubDate>2024-11-05 16:12:10 UTC</pubDate>
         <guid>https://padlet.com/hsadek3/2w2nu046kzykmasb/wish/3202815535</guid>
      </item>
   </channel>
</rss>
