Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

HIMSS Security Survey: A Lot of work needs to be done

November 03, 2009 | Patty Enrado, Special Projects Editor

Suggested Content

  • 'Most Wired' hospitals for 2011 named
  • RSNA: Use of CT exams in ER grows exponentially
  • HIMSS: Quarter of practices don't have security requirements
  • Healthcare data at risk
  • $600M to boost construction, IT at community health centers
  • Connecticut radiology practice goes paperless
  • Coalition clamors for decision support in imaging

CHICAGO – Want to know how you stack up against your peers in terms of information security?

Then be sure to tune in to “The HIMSS Security Survey: Insights into the Status of Healthcare Security Implementations” this afternoon at 2:15pm CT.

HIMSS conducted a survey from August 2009 to October 2009, with respondents being asked to characterize their organization’s readiness for today’s risks and security challenges, said Jennifer Horowitz, senior director of Research for HIMSS Analytics.  This survey was sponsored by Symantec.

The results, from a total of 196 responses, will be presented by Lisa Gallagher, senior director of Privacy & Security for HIMSS, Horowitz and David Finn, health information technology officer for Symantec.

Highlights from the survey, which will be discussed in detail during the webinar, include:

  • Respondents characterized the maturity of their organization’s security program as mid-level, or 4.27 on a scale of one to seven where one is low and seven is high.
  • Nearly one-quarter (21 percent) stated that they spent less than one percent of their budget on information security. Another 40 percent reported that their organization spends between one and three percent of their budget on information security – a metric that has remained relatively unchanged in the past year.
  • Fewer than half of the respondents indicated that their organization has a formally designated Chief Information Security Officer or Chief Security Officer.
  • Only three-quarters conduct a formal risk assessment (and only half of these conduct this assessment on a yearly basis or more frequently), which has remained the same in the past year. Three-quarters of organizations who did conduct risk assessments found patient data at risk due to inadequate security controls, policies and processes. One-third of respondents reported that their organization has had at least one known case of medical identity theft.
  • Healthcare organizations are not always using available technologies to secure data, such as data encryption and data loss prevention

“These results are somewhat concerning as the operating environment is becoming increasingly complex, due to an increase in adoption of health IT and a complex threat environment,” said Gallagher. “This puts the data at a higher risk of exposure in the future, as more data is housed electronically.”

The survey also assessed healthcare organizations’ ability to comply with the new privacy statutes in the American Recovery and Reinvestment Act (ARRA), as well as related upcoming regulation from the Dept. of Health and Human Services. Under ARRA, healthcare organizations are required to provide notification of data breaches to the patient (as well as HHS and the public in some circumstances) and provide accounting of all disclosures of protected health information upon patient request (for the three years prior to the request).

Most of the healthcare organizations of the survey respondents use audit logs. Currently, only a quarter of the respondents reported that all analysis of log data is done entirely electronically. “Without some type of automated assistance to detect breaches and analyze log data, organizations may not be equipped to provide patients with proper breach notification,” said Finn. “In addition, they may have difficulty producing a clear and accurate accounting of disclosures.”

Healthcare organizations today face increasing challenges as they are being urged to adopt electronic health records in the midst of a complex legal, regulatory and risk environment. To effectively secure patient data, it is important that organizations appropriately resource and manage their security initiatives. Trends as reflected in the survey results indicate that organizations are currently required to be extremely efficient in terms of how they are using their security resources and that much work still remains to be done in order to adequately protect health data.

Related Topics:
  • Chicago
  • Connecticut
  • David Finn
  • Jennifer Horowitz
  • Lisa Gallagher
  • Symantec

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • Tablet adoption by docs soars
  • 6 things patients want from social media
  • Healthcare part of White House mobility mandate
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
  • Tablet adoption by docs soars
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • UPCOMING WEBINARS
    June 6th @ 2PM ET--Healthcare Best Practices: 4 Critical IT Strategies to Avoid Data Breaches
  • WHITE PAPERS
    Driving Meaningful Use of Enterprise Content Management
  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
  • UPCOMING WEBINARS
    June 5th @ 1PM ET--Get Control of Your Medical Images with a Cloud-Based Vendor-Neutral Archive
More Resources
Syndicate content

HIMSS JOBMINE

  • Regional Senior Quality Analyst - Memorial Medical Center - Modesto, CA
  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
  • Biostatistician II - Saudi Aramco - Dhahran, Saudi Arabia
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy