Screen Shot 2019-08-21 at 3.04.07 PM-1

In a familiar story line for many CIOs, an employee of the NY Fire Department accessed ePHI (electronic protected health information) from a department system, then transferred it to a personal portable drive which was subsequently lost.  The department learned of the missing hard drive on March 4, and started notifying impacted individuals in August.   From the outside, it is too easy to cast stones at the FDNY for what appears to be an obvious procedural issue that should not have happened. The reality is much more nuanced.