Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Privacy not the barrier to health IT

October 25, 2010 | Deven McGraw
From the November 2010 print issue

Related Resources

  • Disruptive Innovation: The Key to Empowering Patients, Transforming the Healthcare System
  • Enabling Fast and Secure Clinician Workflow with One-Touch Desktop Roaming
  • Cost Cutting Strategies for Improving the Delivery of Explanation of Benefits and Securing Health Information Exchange
  • Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
  • IBM with IDC Health Insights: Exploring the HITECH Act for Privacy and Security of Personal Health Information

Deven McGraw director, Health Privacy Project Center for Democracy & Technology testified before U.S. House of Representatives Committee on Science and Technology  Subcommittee on Technology and Innovation. Below is an excerpt of her remarks.

 

Survey data consistently show the public supports health IT but is very concerned about the risks health IT poses to individual privacy. Contrary to the views expressed by some, privacy is not the obstacle to health IT. In fact, appropriately addressing privacy and security is key to realizing the technologyʼs potential benefits.

Simply stated, the effort to promote widespread adoption and use of health IT to improve individual and population health will fail if the public does not trust it.

To build and maintain this trust, we need the “second generation” of health privacy — specifically, a comprehensive, flexible privacy and security framework that sets clear parameters for access, use and disclosure of personal health information for all entities engaged in e-health.
Such a framework should be based on three pillars:
Implementation of core privacy principles, or fair information practices;
Adoption of trusted network design characteristics; and
Strong oversight and accountability mechanisms.

This requires building on – and in some cases modifying – the privacy and security regulations under the Health Insurance Portability and Accountability Act (HIPAA) so that they address the challenges posed by the new e-health environment. It also requires enacting new rules to cover access, use and disclosure of health data by entities outside of the traditional healthcare system and stimulating and rewarding industry implementation of best practices in privacy and security.

In a digital environment, robust privacy and security policies should be bolstered by innovative technological solutions that can enhance our ability to protect data. This includes requiring that electronic record systems adopt adequate security protections (like encryption; audit trails; access controls); but it also extends to decisions about infrastructure and how health information exchange will occur.

For example, when health information exchange is decentralized (or “federated”), data remains at the source (where there is a trusted relationship with a provider) and then shared with others for appropriate purposes. These distributed models show promise not just for exchange of information to support direct patient care but also for discovering what works at a population level to support health improvement. We will achieve our goals much more effectively and with the trust of the public if we invest in models that build on the systems we have in place today without the need to create new large centralized databases that expose data to greater risk of misuse or inappropriate access.

We are in a much better place today in building that critical foundation of trust than we were two years ago. The privacy provisions enacted in the stimulus legislation – commonly referred to as HITECH or ARRA – are an important first step to addressing the gaps in privacy protection. However, more work is needed to assure effective implementation and address issues not covered by (or inadequately covered by) the changes in ARRA.

In my testimony below, I call for:
•Establishing baseline privacy and security legal protections for personal health records (PHRs);
•Ensuring appropriate limits on downstream uses of health information;
•Strengthening    protections    against    re-identification    of    HIP A A    de-identified    data;
• Encouraging the use of less identifiable data through the HIPAA minimum necessary standard;
• Tightening restrictions on use of personal health information for marketing purposes;
•Strengthening accountability for implementing privacy and security protections; and
•Strengthening accountability for implementing strong security safeguards.

Related Topics:
  • November 2010
  • e-health
  • U.S. House of Representatives
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • 6 things patients want from social media
  • FCC gives green light to wireless medical devices
  • Tablet adoption by docs soars
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
  • Tablet adoption by docs soars
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • UPCOMING WEBINARS
    June 5th @ 1PM ET--Get Control of Your Medical Images with a Cloud-Based Vendor-Neutral Archive
  • ON DEMAND WEBINARS
    Redefining Value and Success in Healthcare: Charting the Path to the Future
  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
  • ON DEMAND WEBINARS
    A Smarter Approach to Healthcare PC Virtualization
More Resources
Syndicate content

HIMSS JOBMINE

  • Clinical Informatics Physician - Epic - Verona, WI
  • Regional Senior Quality Analyst - Memorial Medical Center - Modesto, CA
  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy