September 13, 2002

Windows and HIPAA

Does Microsoft's new 'we will update you' license comply with U.S. law on health-care privacy?

I REPORTED that Windows' newest patches -- Service Pack 1 for Windows XP and SP3 for Windows 2000 -- contain new license language that gives Microsoft the right to silently revise your operating system (see " Sneaky service packs ").

This upsets many companies whose PCs can't be allowed to morph at will. But those who are worried the most are IT pros in the health care field. They must comply by April 14, 2003, with HIPAA (Health Insurance Portability and Accountability Act). Among other things, the law requires "a compliant technical information infrastructure." All systems must ensure the security and privacy of medical records online. (See http://www.hipaadvisory.com/regs/HIPAAprimer1.html .)

Let's set aside for the moment whether today's Windows can ensure security of any kind. Let's also note that, except for XP's Media Player and digital rights management, Windows doesn't silently do all that much yet.

Here's the question: Since Microsoft may start using its new rights any time, won't it soon be against federal law for health care providers to rely on Windows to handle patient records?

"The EULA [end-user license agreement] change has really got me worried," writes Peter Clark, the owner of PClark.net Consulting. "I think the new SP3 license terms are in direct conflict with HIPAA. Either I don't install the service pack -- and am therefore running an OS with known security holes, which HIPAA frowns upon -- or I do install the service pack and thereby install a new security hole, which allows for automatic changes of the software configuration."

Clark has an idea, though. "Since the automatic update/security holes only apply to Microsoft, the health care industry needs to go to Microsoft with a joint NDA (nondisclosure agreement) and indemnification agreement, requiring Microsoft to hold their HIPAA-compliant customers harmless should patient information be leaked via this mechanism."

The issue has escalated beyond tech workers to alarm medical doctors themselves.

"Our procedures sometimes involve surgery to place over 100 recording electrodes in the patient, sometimes on the surface of the brain," says Dr. Bob Webber, a systems manager at a teaching hospital. "These PC-based systems use Microsoft Windows [because all but one vendor of these systems use Microsoft operating systems] and multimedia programs to capture the patient's data."

Webber asks, "If, after a Microsoft service pack is applied to overcome a security weakness in their operating system, and the service pack also secretly breaks the multimedia software and/or revokes access to our patient's data, thus damaging our patient care, who is responsible?"

It's not just hospitals but every user of Windows who should be wondering. You'd think Microsoft would understand that customers don't want their mission-critical systems changing in the dead of night. This isn't brain surgery.

Close

On Twitter now

Platforms

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Platforms Resource Alerts

Subscribe to the Today's Headlines: First Look Newsletter

Find out what will be news for the day, with our first-thing-in-the-morning briefing.

©1994-2009 Infoworld, Inc.