Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » Blogs » Mobile/Wireless | Privacy and Security

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Bring Your Own Device

October 04, 2011 | John Halamka, Life as a Healthcare CIO

Related Resources

  • Overcoming Interoperability Challenges in HIE Communities
  • Better Patient Care: Virtually There
  • Focus on Patient Care without Worrying about Underlying Technology
  • Unique Challenges of Health Care Networks and the Value of Wireless
  • Old data learns new tricks: Managing patient security and privacy on a new data sharing playground

At BIDMC, I oversee 10,600 desktops and 2000 laptops. They are all locked down with System Center Configuration Manager 2007 and McAfee ePolicy Orchestrator.

Given that most of our applications are thin client and web-based, we can stretch the lifetimes of our desktops to 5-6 years and our laptops to 3-4 years. Capital funding puts limits on how much hardware we can buy and how long we keep it.

Like many IT departments, we have to balance many priorities - security, cost, software compatibility, performance and the user experience.

This balance means that the locked down, image managed, economical device provided by the IT department will almost always be older, lower powered, and less capable than the device in your home.

The same is true of mobile devices like Blackberries which are a one time purchase and are only replaced when they stop functioning.

Consumer devices are more than just technology, they've become lifestyle accessories. Are you an iPad2 or a Macbook Air 11 person? Does Android tickle your fancy or are you holding out for the Samsung tablet with Windows 8?

The cost of these devices is low enough that consumers can buy them on their own and may upgrade yearly as new models are released.

All of this has led to the BYOD movement - Bring Your Own Device to work.

One of my passions as a CIO has been to create web-based applications that run anywhere on anything. That approach has enabled our applications to run on every version of the iPad, iPhone and iPod touch as well as Android and Blackberry devices like the Playbook.

However, I'm also accountable for the privacy and security of each byte of person identified data and we have over 1.5 petabytes to protect.

The internet is an increasingly hostile place. Clicking on a picture of Heidi Klum results in a 1 in 10 chance that your device will become infected.

Online apps distributed via social networks are filled will malware.

Hacked websites can bring malware onto our device. A CIO at the recent Information Week 500 conference described that hackers inserted malware, which was only one pixel by one pixel, into a public-facing website his lab supported. All internal users who browsed to the website and did not have the latest version of Adobe Flash were infected. Once infected, their workstations scanned for other vulnerabilities on the network.

Breach reporting regulations in HITECH are strict. If a keystroke logger embedded in malware results in username/password compromise and a hacker downloads files or views data for more than 500 people, the prominent media needs to be notified. It is unlikely that the media will see much difference between an infected personal device and something under the CIO's control - the CIO will be held accountable!

BIDMC has over 1000 iPads and over 1600 iPhones accessing its network for email and web applications.   I absolutely see the value of the Bring Your Own Device movement.

However, the compliance and regulatory requirements that grow more complex every day make the BYOD movement very problematic.

It may be that we'll find some compromise, such as encouraging BYOD, noting that little support will be available, and requiring mobile device security solutions such as Good Technologies before a personal device is allowed on the network.

BYOD can be empowering to users. Let's hope we can mitigate the risk and afford the applications needed to comply with federal and state laws.

 

John Halamka, MD, blogs regularly at Life as a Healthcare CIO.

Related Topics:
  • Android
  • Android
  • mobile devices
  • Samsung
  • thin client
  • Mobile/Wireless
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

receive news by email

Most Popular

Latest Headlines
Most Popular
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 14 Ways Social Media May Soon Change Your Doctor's Visit
  • No 'bubble' for healthcare IT, analysts say
  • AMA calls for 2-year extension of ICD-10 deadline
  • Twitter recap: Lee Aase talks social media in healthcare
  • Chinese hospital uses new tech to manage cancer treatment
  • 6 reasons physicians need to be on social media
  • Text messaging initiative targets young smokers
  • Health Union launches mobile app to help manage migraines
  • Oregon to implement new statewide HIE

WEBINARS AND WHITE PAPERS

  • UPCOMING WEBINARS
    June 5th @ 1PM ET--Get Control of Your Medical Images with a Cloud-Based Vendor-Neutral Archive
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • UPCOMING WEBINARS
    June 6th @ 2PM ET--Healthcare Best Practices: 4 Critical IT Strategies to Avoid Data Breaches
  • WHITE PAPERS
    Driving Meaningful Use of Enterprise Content Management
  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
More Resources
Syndicate content

HIMSS JOBMINE

  • VP, CLINICAL INFORMATICS - The Methodist Hospital System - Houston, TX
  • Senior Radiology Information Systems Analyst - Universal Health Services - King of Prussia, PA
  • Director, Professional Services - Sunquest Information Systems - IL
  • Senior Clinical Informatics Analyst - Cottage Health System - Santa Barbara, CA
  • Senior Integration Specialist - Health Information Exchange - Cottage Health System - Santa Barbara, CA
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy