Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » Blogs

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Five best practices for safeguarding EHRs

March 31, 2010 | Matt Marshall, Vice President of Engineering, Redspin Inc.

Suggested Content

  • Health data breaches up 97 percent in 2011
  • Report: More than 6M affected since breach notification rule
  • University challenge targets NCDs with mHealth and social media
  • eRx makes steady gains in California, report shows

People who get paid to try to break into information systems are in a great position to give advice. Here at Redspin, Inc., a company of "ethical hackers" and IT security consultants based in Carpinteria, Calif., we've found that the healthcare companies most successful at safeguarding electronic information tend to follow these five best practices. These recommendations are based on years of Redspin's IT security assessment consulting work with dozens of leading companies.

1. An organization-wide commitment to strong security
A complete Information Security Program (ISP) cuts across the entire enterprise, not just the IT department. It also includes items such as facilities availability and contingency, disaster preparedness, employee safety and human resource confidentiality.
 
2. A view of IT security as a competitive advantage
Savvy companies understand that in ever increasing amounts, the heart of an enterprise is found in the proper collection, storage, communication, availability, integrity and protection of electronic data. Security best practices leaders view protecting that information as a competitive advantage. In contrast, companies that experience IT security breakdowns are subject to damaging consequences that can limit competitiveness, such as:

* Reputation damage, loss of customers, negative media reporting and mandatory breach notifications
* Large monetary penalties from regulators
* Theft and/or misuse of the data itself
* Legal expenses dealing with affected customers/business associates/vendors
* Loss of mission-critical IT systems including web applications, business associate networks and internal networks
 
3. A sharp focus on security policies and processes
Having the latest and greatest array of technical "gear" such as firewalls, wireless infrastructure, virtualization and vulnerability management software appears to lead to a false sense of security in many cases. The best gear can be compromised without well-documented security policies and procedures that are rigorously followed and periodically updated, and the discipline to monitor and measure compliance to industry best practices such as ISO 27002.
 
4. Include business associates and partners in EHR security programs
As the exchange of electronic health information becomes more pervasive, the Department of Health and Human Services has made it clear that all entities in the chain bear responsibility for safeguarding electronic data. A breakdown anywhere in the chain affects all entities, both practically and legally speaking, and even a business associate's breach of electronics health records may require the notification of the customers/patients of all entities with access to the data. Successful organizations collaborate with business associates on the implementation of security programs and revise contracts to include data security/compliance requirements, breach notification costs, independent security assessments and other related issues.
 
5. Regularly conduct independent security assessments
The IT security environment is becoming ever more complex; safeguarding it is a dynamic endeavor that requires constant vigilance. HIPAA law requires covered entities to conduct routine evaluations of the effectiveness of records security programs, policies and procedures. An independent security assessment can evaluate security against potential risks in a format compliant with HIPAA Security Standards, even including business associates and partners with whom health data is exchanged. A high quality security assessment will:

* Maintain independence from the sales and management of IT products, equipment and tools
* Identify security vulnerabilities according to levels of risk (high/medium/low)
* Provide specific recommendations on how to address security concerns
 

Redspin delivers independent Information Security Assessments through technical expertise, business acumen and objectivity. Redspin customers include leading companies in industries of healthcare, financial services and hotels, casinos and resorts, as well as retailers and technology providers.

Related Topics:
  • California
  • Carpinteria
  • ISP
  • Redspin Inc.

Reader Comments (0)Login to Post a Comment

receive news by email

Most Popular

Latest Headlines
Most Popular
  • 10 most outlandish kinds of ICD-10 codes
  • 5 stages of EHR maturity and patient collaboration
  • 5 simple ways to realize ROI from your EHR
  • 'Obamacare' a lightning rod, but what about health IT?
  • Remote health monitoring pegged at 3 million users by 2016
  • H.I.T. Men and Women to pick up awards at HIMSS12
  • University challenge targets NCDs with mHealth and social media
  • Indiana health exchange taps AT&T to scale up
  • eHealth Initiative releases recommendations for accountable care
  • One surgeon's take on need for culture change in medicine

WEBINARS AND WHITE PAPERS

  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
More Resources
Syndicate content

HIMSS JOBMINE

  • Director, Sales - HIMSS - Arlington, VA
  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy