News: 1708046413

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Quest Diagnostics pays $5M after mixing patient medical data with hazardous waste

(2024/02/16)


Quest Diagnostics has agreed to pay almost $5 million to settle allegations it illegally dumped protected health information – and hazardous waste – at its facilities across California.

This sum won't hurt at all for the corporation, one of the largest clinical medical lab networks in the US. In all, Quest is being charged slightly less than two days of its $994 million [1]annual profit in 2023 – hardly a serious disincentive.

Under [2]the settlement [PDF], Quest will pay $3,999,500 to ten California counties (Alameda, Los Angeles, Monterey, Orange, Sacramento, San Bernardino, San Joaquin, San Mateo, Ventura, and Yolo), plus give $300,000 to environmental projects and an additional $700,000 to foot attorneys' fees and other costs. In exchange, it admits no guilt over the matter.

[3]

It also agreed to hire an independent environmental auditor to review waste-disposal practices at its facilities, and improve processes for handling, storage, and disposal of medical and hazardous waste – as well as personal health information – at four laboratories and more than 600 patient service centers in California.

[4]

[5]

Asked about the California settlement, Quest Diagnostics spokesperson Denny Moynihan told The Register on Thursday:

Quest takes patient privacy and the protection of the environment very seriously and has made significant investments to implement industry best practices to ensure hazardous waste, medical waste, and confidential patient information are disposed of properly. These include investing in technologies for treatment of biological waste, secured destruction of patient information, programs to maximize recycling efforts and minimize waste-to-landfill disposal, waste-to-energy recovery of non-recyclable wastes, and enhanced waste audit and inspection measures to ensure continued compliance with applicable laws.

"Through our meticulous waste audits, it came to light that Quest Diagnostics may have encountered challenges in properly managing confidential patient data, medical waste, and hazardous materials," San Joaquin County district attorney Ron Freitas [6]gushed .

"Our initial inquiry in San Joaquin County prompted us to engage with the attorney general's office and other relevant parties."

In total, the district attorneys' offices said they conducted more than 30 inspections of Quest labs and patient centers across California.

[7]

During those inspections, authorities dug through Quest's compactors and dumpsters, and said they found hundreds of containers of chemicals, as well as bleach, reagents, batteries, electronic waste, unredacted medical information, medical waste such as used specimen containers for blood and urine, and hazardous waste such as used batteries, solvents, and flammable liquids.

[8]Romanian hospital ransomware crisis attributed to third-party breach

[9]Ignore Uncle Sam's 'voluntary' cybersecurity goals for hospitals at your peril

[10]After injecting cancer hospital with ransomware, crims threaten to swat patients

[11]'Scandal-plagued' data broker tracked visits to '600 Planned Parenthood locations'

This waste and data disposal broke hazardous waste law, California's Medical Waste Management Act, unfair competition law, and civil laws prohibiting the unauthorized disclosure of personal health information, prosecutors argued in their [12]court submissions [PDF].

While improperly dumping hazardous waste can have terrible human health and environmental consequences, leaving people's personal records in places where identity thieves can pilfer them – even if they have to wade through bio-waste to get it – isn't particularly ideal, either.

It's bad enough that [13]ransomware crews and other criminals are hitting healthcare facilities to steal protected health records, which can be extremely damaging to [14]patients and [15]organizations .

Monterey County district attorney Jeannine Pacioni commented optimistically: "This settlement will help ensure that patients' personally identifiable and private health information is protected and will protect worker safety and human health by ensuring that hazardous and medical wastes are properly managed and disposed of." ®

Get our [16]Tech Resources



[1] https://ir.questdiagnostics.com/press-releases/press-release-details/2024/Quest-Diagnostics-Reports-Fourth-Quarter-and-Full-Year-2023-Financial-Results-Provides-Guidance-for-Full-Year-2024-Increases-Quarterly-Dividend-5.6-to-0.75-Per-Share/default.aspx

[2] https://regmedia.co.uk/2024/02/15/quest_diagnostic_settlement.pdf

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zc7r@X@9QQDde10zCjz9sAAAAEw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zc7r@X@9QQDde10zCjz9sAAAAEw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zc7r@X@9QQDde10zCjz9sAAAAEw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-nearly-5-million-settlement-quest-diagnostics

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zc7r@X@9QQDde10zCjz9sAAAAEw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2024/02/14/romanian_hospital_ransomware_crisis/

[9] https://www.theregister.com/2024/02/05/us_voluntary_cybersecurity_goals_hospitals/

[10] https://www.theregister.com/2024/01/05/swatting_extorion_tactics/

[11] https://www.theregister.com/2024/02/15/data_broker_location_abortion/

[12] https://regmedia.co.uk/2024/02/15/quest_diagnostic_complaint.pdf

[13] https://www.theregister.com/2024/02/14/romanian_hospital_ransomware_crisis/

[14] https://www.theregister.com/2024/01/05/swatting_extorion_tactics/

[15] https://www.theregister.com/2023/05/02/data_breach_costs_rise/

[16] https://whitepapers.theregister.com/



aerogems

Said it before, will say it again. You want fines to actually be a deterrent, make them proportional. Say 5% of gross revenues for the previous FY. It has the added bonus of being much more equitable since it hurts every company exactly the same amount. Large companies can't just simply write it off as a cost of doing business and smaller companies won't necessarily be put out of business by a large fine, giving them a chance to reform. If CEOs start having to explain to investors why 5% of their gross revenues disappeared, there might be a lot more shakeups in C-Suites. The fear of losing their cushy do-nothing high-paying job will mean that executives will actually make sure that changes are implemented.

I'm also all in favor of making anyone who has a title in the CxO family, personally liable for any criminal actions undertaken by the company. So, if Quest were to be found guilty of HIPAA violations, which call for prison time, it would be served by one or more of the C-Suite residents. That, or the company would be effectively put in prison, meaning it would be unable to do business for the duration of its sentence, or would only be able to earn roughly a few cents per hour like any other prisoner, all the rest of the money going to the state and/or federal government.

COBOL:
An exercise in Artificial Inelegance.