Healthcare IT NewsHealthcare IT News
  • Home
  • Sections
    • Industry News
    • Hospitals & IDNs
    • Physician Practices & Ambulatory Care
    • Payers
    • Vendors
    • International
  • Issues
    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
  • Resource Central
    • Research
    • White Papers
    • Web Seminars
    • Videos
    • Podcasts
  • Blog
  • Events
  • Jobs
  • About
  • Subscribe
  • Advertise
  • Newsletters
  • RSS
  • Twitter
  • LinkedIn
  • Solutions Series
Select Your Homepage
Search eConnect
Login | Register
Home » News » Industry News

E-mail to a FriendPrint
Social Bookmarking
  • Delicious Delicious
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Reddit Reddit
  • Newsvine Newsvine
  • Furl Furl
  • Facebook Facebook
  • Google Google
  • Yahoo Yahoo
HIMSS Security Survey: A Lot of work needs to be done

HIMSS Security Survey: A Lot of work needs to be done

November 03, 2009 | Patty Enrado, Special Projects Editor

Suggested Content

  • $600M to boost construction, IT at community health centers
  • Connecticut radiology practice goes paperless
  • Coalition clamors for decision support in imaging
  • Vendor Notebook - Cardinal Health to co-market Patient Safety Technologies' safety sponge system
  • Visage Imaging Introduces Visage 7 for Windows and Mac OS X
  • Vendor Notebook - API Healthcare announces new contracts for human capital management
  • Closing VCE Keynote: Don't underestimate EMR usability
  • Virtual Conference Opening keynote: Lessons learned for HIEs
  • HIMSS VCE: If you build it, be mindful of meaningful use
  • Vendor Notebook - GE Healthcare launches business unit for health information exchange

CHICAGO – Want to know how you stack up against your peers in terms of information security?

Then be sure to tune in to “The HIMSS Security Survey: Insights into the Status of Healthcare Security Implementations” this afternoon at 2:15pm CT.

HIMSS conducted a survey from August 2009 to October 2009, with respondents being asked to characterize their organization’s readiness for today’s risks and security challenges, said Jennifer Horowitz, senior director of Research for HIMSS Analytics.  This survey was sponsored by Symantec.

The results, from a total of 196 responses, will be presented by Lisa Gallagher, senior director of Privacy & Security for HIMSS, Horowitz and David Finn, health information technology officer for Symantec.

Highlights from the survey, which will be discussed in detail during the webinar, include:

  • Respondents characterized the maturity of their organization’s security program as mid-level, or 4.27 on a scale of one to seven where one is low and seven is high.
  • Nearly one-quarter (21 percent) stated that they spent less than one percent of their budget on information security. Another 40 percent reported that their organization spends between one and three percent of their budget on information security – a metric that has remained relatively unchanged in the past year.
  • Fewer than half of the respondents indicated that their organization has a formally designated Chief Information Security Officer or Chief Security Officer.
  • Only three-quarters conduct a formal risk assessment (and only half of these conduct this assessment on a yearly basis or more frequently), which has remained the same in the past year. Three-quarters of organizations who did conduct risk assessments found patient data at risk due to inadequate security controls, policies and processes. One-third of respondents reported that their organization has had at least one known case of medical identity theft.
  • Healthcare organizations are not always using available technologies to secure data, such as data encryption and data loss prevention

“These results are somewhat concerning as the operating environment is becoming increasingly complex, due to an increase in adoption of health IT and a complex threat environment,” said Gallagher. “This puts the data at a higher risk of exposure in the future, as more data is housed electronically.”

The survey also assessed healthcare organizations’ ability to comply with the new privacy statutes in the American Recovery and Reinvestment Act (ARRA), as well as related upcoming regulation from the Dept. of Health and Human Services. Under ARRA, healthcare organizations are required to provide notification of data breaches to the patient (as well as HHS and the public in some circumstances) and provide accounting of all disclosures of protected health information upon patient request (for the three years prior to the request).

Most of the healthcare organizations of the survey respondents use audit logs. Currently, only a quarter of the respondents reported that all analysis of log data is done entirely electronically. “Without some type of automated assistance to detect breaches and analyze log data, organizations may not be equipped to provide patients with proper breach notification,” said Finn. “In addition, they may have difficulty producing a clear and accurate accounting of disclosures.”

Healthcare organizations today face increasing challenges as they are being urged to adopt electronic health records in the midst of a complex legal, regulatory and risk environment. To effectively secure patient data, it is important that organizations appropriately resource and manage their security initiatives. Trends as reflected in the survey results indicate that organizations are currently required to be extremely efficient in terms of how they are using their security resources and that much work still remains to be done in order to adequately protect health data.

Related Topics:
  • Chicago
  • Connecticut
  • David Finn
  • Jennifer Horowitz
  • Lisa Gallagher
  • Symantec

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • Survey shows nurses spend most of their time on paperwork
  • Five features missing from most EHRs
  • WebMD launches social media
  • ONC issues rough draft of 2010 HIT strategic framework
  • Healthcare industry one of the most mobile
  • HHS announces $162 million in 16 state HIE grants
  • Denmark docs fully wired
  • GE Healthcare unveils new Virtual Sleep Lab
  • HIMSS10 registration figures up on all counts
  • European Union outlines 10-year eHealth plan
receive news by email

Resource Central

  • Web Seminars
    On-Demand--Part II-The Crystal Clear Healthcare Provider: How Cleveland Clinic Delivers Transparency to Stakeholders with Business Intelligence
  • White Papers
    Six Things Hospitals Need to Know About Replacing Pagers With Smartphones
  • White Papers
    Manage healthcare assets and optimize asset utilization with IBM Maximo Asset Management
  • Web Seminars
    On-Demand--On Point with a Smart Supply Solution
  • Web Seminars
    On-Demand--The Benefits of Client Virtualization in Healthcare
More Resources
Syndicate content

HEALTHCARE IT JOB SPOT

  • Architect - Clevelan Clinic Abu Dhabi - Abu Dhabi, U.A.E.
  • Epic Business Systems Analyst Ambulatory Practice Management Revenue Cycle - Lee Memorial Health System - Fort Myers, FL
  • Family Medicine Opportunity with EMR - Marshfield Clinic - Rice Lake, Ladysmith & Hayward, WI
  • Meditech Applications Analyst - Saint Joseph Health System - Anaheim, CA
  • Epic Revenue Cycle Manager - Lee Memorial Health System - Fort Myers, FL
more jobs

  • Healthcare Finance News

    Healthcare Finance News is the leading news source for healthcare's financial managers.

  • EHRWatch.com

    EHRWatch.com offers news, commentary and community participation on the developments in electronic health records.

  • Priming the Pump

    Priming the Pump provides practical news on the stimulus package and the incentives that it offers to healthcare providers.

  • Facebook

    Join Healthcare IT News on Facebook to connect with other readers!

  • NHINWatch

    Visit NHINWatch.com for coverage of the Nationwide Health Information Network.

  • Mobile Health Watch

    Stay up to date on the latest mobility news at Mobile Health Watch.

  • MedTech Publishing

    Visit our company Web page to learn more about MedTech Publishing.

  • LinkedIn

    Join our LinkedIn group to connect with other readers. Click here to join the group.

     

  • Healthcare IT Job Spot

    Check out the latest open positions at Healthcare IT Job Spot.

Marketplace

  • Home
  • Issues
  • Resource Central
  • Blog
  • Events
  • Subscribe
  • Advertise
  • About Us
  • Site Map
  • Privacy Policy
Healthcare IT News is a publication of MedTech Publishing Company LLC.
For more information about MedTech Publishing Company and its publications, please visit medtechpublishing.com.
©2009 MedTech Publishing
Powered by Phase2 Technology.