Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Health Information Exchange (HIE) | Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Privacy panel calls for data encryption for information exchange

May 25, 2010 | Mary Mosquera, Contributing Editor

Suggested Content

  • Veterans Affairs CIO Roger Baker on VLER progress
  • Data security critical with VA's intro of iPhone
  • Consumer trust 'essential enabler' to EHR adoption
  • Docs tell government panel EHR tales of woe
  • Tiger team proposes authentication policies for data exchange
  • VA launches fourth data exchange pilot on NHIN
  • Health IT policy panel approves HIE consent rules
  • Tiger team calls for providing patients with 'meaningful choice' in consent decisions
  • VA ramps up enforcement of contractor data security
  • One surgeon's take on need for culture change in medicine

WASHINGTON – Healthcare providers should encrypt patient information when they share it with another provider, even in a case of the direct exchange of personal health information or data that is not facilitated by a health information exchange or other third-party organization.
 
The privacy and security workgroup of the Health IT Policy Committee made its recommendation for guarding patient data at a May 19 policy committee meeting.

In recent weeks the workgroup has been wrestling with determining at what point in a health information exchange it becomes necessary for providers to obtain consumer consent to approve an exchange.

The workgroup took the perspective of what a "reasonable patient would expect," said Deven McGraw, the panel's co-chair. McGraw is also director of the Health Privacy Project at the Center for Democracy and Technology.

The panel proposed that policies for encryption, limits on identifiable information in a message header and verification of the identification of the sending and receiving providers should govern one-to-one exchanges.

Encryption, which makes information unreadable until the intended recipient unlocks it, should be required, especially when the potential exists for transmitted data to be exposed, according to the recommendations.

Meaningful use or certification criteria or a modification of the Health Insurance Portability and Accountability (HIPAA) security rule could include that requirement, she said.

"If strong policies, such as the above, are in place and enforced, we don't think this scenario needs any additional individual consent beyond what is already required by current law," said McGraw.

Providers must conduct simple direct exchanges of health information as part of the first-stage requirements for meaningful use of electronic health records in order to qualify for financial incentives in 2011. Some providers might require a third party, such as a directory service, to assist even in a simple one-to-one exchange.

More complex health information exchanges or other models of exchange, such as state health information exchange, may require stronger policies, including patient consent, McGraw said.

Related Topics:
  • Deven McGraw
  • encryption
  • Mary Mosquera
  • Washington
  • Health Information Exchange (HIE)
  • Privacy and Security

Reader Comments (1)Login to Post a Comment

mneece says: Privacy versus Security
May 25, 2010 | 11:41AM GMT

The security of patient records is certainly addressed by data encryption, however, encryption does nothing to address the privacy of patient records.

Privacy and Security are quite different issues.

Security is solved through robust data encryption.

Privacy is solved through real-time patient data redaction based on "purpose of use" by the person/system accessing the patient record.

Michael Neece, FlowLogic.com
E-mail: mneece@flowlogic.com
LinkedIn http://www.linkedin.com/in/michaelrneece

Most Popular

Latest Headlines
Most Popular
  • 10 most outlandish kinds of ICD-10 codes
  • 5 stages of EHR maturity and patient collaboration
  • 5 simple ways to realize ROI from your EHR
  • 'Obamacare' a lightning rod, but what about health IT?
  • Demand exceeds supply for some health IT jobs
  • H.I.T. Men and Women to pick up awards at HIMSS12
  • University challenge targets NCDs with mHealth and social media
  • Indiana health exchange taps AT&T to scale up
  • eHealth Initiative releases recommendations for accountable care
  • One surgeon's take on need for culture change in medicine

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
  • WHITE PAPERS
    Driving Meaningful Use of Enterprise Content Management
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
More Resources
Syndicate content

HIMSS JOBMINE

  • Director, Sales - HIMSS - Arlington, VA
  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy