Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • February 2012
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
  • Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » ARRA/Stimulus | Electronic Health Records | Health Information Exchange (HIE) | Policy and Legislation | Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Government watchdog raises red flag on health IT security

May 17, 2011 | Healthcare IT News Staff

Suggested Content

  • $103M in government funding targets chronic disease
  • Beacon Communities snag more money for IT
  • HHS establishes research center for disability services
  • HHS announces $162 million in 16 state HIE grants
  • On Daschle, expectations
  • ICD-10 inches closer to delay, ICD-11 in the wings
  • Inspector General review highlights IT challenges for HHS
  • AMA, AHIMA at odds on ICD-10
  • HHS names 32 Pioneer ACOs
  • Community college training of HIT professionals questioned

Related Resources

  • Focus on Patient Care without Worrying about Underlying Technology
  • Executing Best Practices for EMR Implementation
  • Cutting Through the Hype: Evaluating Tablet PCs for Point-of-Care Productivity
  • Meaningful Use Buyer’s Guide
  • GE Healthcare Case Study: New EDI services platform delivers high availability, scalability cost-effectively

WASHINGTON – A Department of Health and Human Services Office of Inspector General review of health IT security has found that the Office of the National Coordinator (ONC) has yet to address fully the security concerns associated health information technology.

While the ONC has security controls in the interoperability specifications, there are no HIT standards that include general information IT security controls, the OIG noted in its report.

As defined by the OIG, general IT security controls are the structure, policies, and procedures that apply to an entity's overall computer operations, ensure the proper operation of information systems, and create a secure environment for application systems and controls.

“At the time of our initial audit, the interoperability specifications were the ONC HIT standards and included security features necessary for securely passing data between EHR systems (e.g., encrypting transmissions between EHR systems). These controls in the EHR systems were application security controls, not general IT security controls,” the OIG states in its executive summary.

“We found a lack of general IT security controls during prior audits at Medicare contractors, State Medicaid agencies, and hospitals,” OIG officials state. “Those vulnerabilities, combined with our findings in this audit, raise concern about the effectiveness of IT security for HIT if general IT security controls are not addressed.

The OIG recommended that the ONC

  1. broaden its focus from interoperability specifications to also include well-developed general IT security controls for supporting systems, networks, and infrastructures;
  2. use its leadership role to provide guidance to the health industry on established general IT security standards and IT industry security best practices;
  3. emphasize to the medical community the importance of general IT security; and (4) coordinate its work with the Centers for Medicare & Medicaid Services and the Department's Office for Civil Rights to add general IT security controls where applicable. ONC concurred with our recommendations.
Related Topics:
  • ARRA/Stimulus
  • Department of Health
  • Department of Health and Human Services
  • Washington
  • Electronic Health Records
  • Health Information Exchange (HIE)
  • Policy and Legislation
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • ICD-10 inches closer to delay, ICD-11 in the wings
  • 8 trends for a changing healthcare workforce
  • 5 tips for preparing for a potential privacy incident or data breach
  • HIMSS announces transfer of mHealth Summit
  • Interoperability still a barrier to meaningful use, experts find
  • HIMSS12 Twitter recap: The untethered doctor
  • ONC team lays out transition to permanent EHR certification program
  • Mercy Health rises from the ashes, thanks in part to IT
  • Building a new financial infrastructure for healthcare
  • CMS expected to release Stage 2 proposed rule Thursday

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
  • WHITE PAPERS
    The Scarborough Hospital: Establishing a Document Management Strategy for EHRs
  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
More Resources
Syndicate content

HIMSS JOBMINE

  • Manager, Specialty Education - HIMSS - Chicago, IL
  • Implementation Consultants - Peer Consulting - USA/Canada
  • SW engineer - Healarium - Boston, MA
  • Vice President & Chief Information Officer (VP/CIO) - Greater Hudson Valley Health System - Middletown, NY
  • Director of Measurement Services - URAC - Washington, DC
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy