Skip Links

Network World

  • Social Web 
  • Email 
  • Close

GAO report highlights importance of security controls when outsourcing

Experiences of federal and state health insurance outsourcing
By Dan Twing , Network World , 09/13/2006
  • Share/Email
  • Comment
  • Print

The Government Accounting Office (GAO), a non-partisan audit, evaluation and investigative arm of Congress, recently surveyed federal and state health insurance operators to determine the extent of personal information being shared with domestic and offshore outsourcers (PDF of the report here). The results can remind us all of the security risks and controls required when sharing information with outsourcers.

Federal contractors and state Medicaid agencies are responsible for the day-to-day operations of the Medicare, Medicaid and TRICARE heath insurance programs. Because these entities may contract with vendors to perform services involving the use of personal health data, outsourcing and privacy protections are of interest. The GAO surveyed all federal Medicare and TRICARE contractors and all state Medicaid agencies (a combined total of 378 entities). Federal contractors and state Medicaid agencies widely reported domestic outsourcing of services involving the use of personal health information but little direct offshore outsourcing. More than 90% of Medicare contractors and state Medicaid agencies and 63% of TRICARE contractors reported some domestic outsourcing in 2005.

One federal contractor and one state Medicaid agency reported outsourcing services directly offshore. However, some federal contractors and state Medicaid agencies also knew that their domestic vendors had initiated offshore outsourcing. Thirty-three Medicare Advantage contractors, two Medicare fee-for-service (FFS) contractors, and one Medicaid agency indicated that their domestic vendors transfer personal health information offshore, although they did not provide information about the scope of personal information transferred offshore. Moreover, the reported extent of offshore outsourcing by vendors may be understated because many federal contractors and agencies did not know whether their domestic vendors transferred personal health information to other locations or vendors. The bulk of the known offshore outsourcing was to India, with Ghana, Mexico, Canada, Jamaica, Bermuda and the Philippines also receiving such work.

More than 40% of the federal contractors and state Medicaid agencies reported that they experienced a recent privacy breach involving personal health information. The frequency or severity of these breaches was not reported.

  • Share/Email
  • Comment
  • Print
Partner Content

Simplify Your Branch Infrastructure

Learn how to simplify your branch infrastructure while dramatically increasing app performance with Citrix Branch Repeater.

Download the Free Info Kit

Next-Gen Load Balancing

Free Guide: "Next Gen Load Balancing: 8 Things You Need to Handle Today's Network Traffic" shows you the functionality needed in your next load balancer.

Download the Free Guide

Accelerate Your Web Apps by up to 5x

Free Guide: "The Secret to Getting Maximum Speed from your Web Applications." Learn how you can deliver Web apps up to 5x faster.

Download the Free Guide

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.