Healthcare IT NewsHealthcare IT News
  • Home
  • Sections
    • Industry News
    • Hospitals & IDNs
    • Physician Practices & Ambulatory Care
    • Payers
    • Vendors
    • International
  • Issues
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • Sept. 2009
  • Resource Central
    • All Resources
    • Research
    • White Papers
    • Web Seminars
    • Videos
    • Podcasts
  • Blog
  • Events
  • Jobs
  • About
  • Subscribe
  • Advertise
  • Newsletters
  • RSS
  • Twitter
  • LinkedIn
  • Solutions Series
Select Your Homepage
Search eConnect
Login | Register
Home » News » Industry News

E-mail to a FriendPrint
Social Bookmarking
  • Delicious Delicious
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Reddit Reddit
  • Newsvine Newsvine
  • Furl Furl
  • Facebook Facebook
  • Google Google
  • Yahoo Yahoo
Study: Healthcare isn't ready for new security rules

Study: Healthcare isn't ready for new security rules

November 12, 2009 | Bernie Monegain, Editor

Related Links

  • More about the survey
  • Register for the Web seminar

Suggested Content

  • Blog: Updates on meaningful use, certified EHR technology and the stimulus bill
  • Washington sharpens focus on the NHIN
  • Complex, fast, disruptive, aggressive, strategic
  • Blog: Blog: The top 10 barriers to EHR implementation
  • Blog: New physician adoption statistics
  • Physicians see meaningful use as a 'tsunami'
  • Pharmacists rally for tougher e-prescribing rules
  • AAFP says meaningful use rules will be tough for small practices
  • Public comments will shape final meaningful use rule
  • CCHIT updates certifications to go with new standards rule

OAK BROOK, IL – A recent survey of healthcare organizations found that 94 percent aren't ready to comply with the privacy and security provision of the Health Information Technology for Economic and Clinical Health (HITECH) Act, which take effect next February.

The survey of 77 U.S. healthcare organizations was conducted by the Ponemon Institute and sponsored by Crowe Horwath LLP, one of the largest public accounting and consulting firms in the United States.

The HITECH Act extends the Health Insurance Portability & Accountability Act's (HIPAA) rules for security and privacy safeguards, including increased enforcement, penalties and audits.

According to the survey, many current HIPAA compliance programs have deficiencies in the areas of privacy and security, including inadequate program testing and failure to update the programs. Yet only 47 percent of the respondents indicate they have the necessary funding and resources to fully comply with the new regulations.

"We believe that most organizations are not ready for HITECH as a result of compliance issues within their existing HIPAA programs," said Raj Chaudhary, a principal in Crowe Horwath's risk consulting group. "Even though most organizations acknowledge that their HIPAA compliance programs are deficient, our survey found that implementing necessary controls or securing third-party assistance to help ensure compliance may be limited due to budgetary restraints."

The study also found that 79 percent of organizations do not regularly have a required independent assessment or audit of their program to determine adequacy. Fifty-seven percent say they have known deficiencies concerning privacy or security or both. Only 29 percent of respondents report no deficiencies.
 
Other survey findings include:

  • Most organizations experienced one or more data breach incidents involving the loss or theft of protected health information during the past two years. Ninety percent of respondents had a breach involving at least one protected health record.
  • Lack of management support may slow down compliance goals. Fifty-five percent of respondents report there is no management support for HITECH compliance.
  • Many organizations report significant gaps in their privacy and security programs. Sixty percent say their organizations have only partially implemented a risk-based program for protecting the privacy of protected health information. Approximately half of respondents say they don't provide adequate staff training for privacy and security. Forty-five percent believe their organizations have not effectively developed a privacy policy that clearly summarizes appropriate use and sharing of PHI.
  • Third-party assistance may be necessary for achieving certain compliance goals. Nearly half of the respondents said they may need assistance from a third party to conduct a detailed risk assessment.  Forty-five percent need outside support for staff training, while 42 percent will need assistance in implementing procedures for fielding complaints. Thirty-nine percent will rely on help in developing the privacy program.
  • Responsibility for ensuring HITECH compliance varies considerably among organizations. Security leaders and chief compliance officers are the roles identified as most likely to be responsible for achieving HITECH compliance, according to respondents. Organizations with more than 5,000 employees were much more likely to see the security leader as having primary responsibility than smaller companies.

"It is disappointing, though not surprising, to learn that a majority of companies do not believe they are prepared for the latest in healthcare information security regulations," said Larry Ponemon, chairman and founder of the  Ponemon Institute. "Our research consistently finds that a lack of budgetary and moral support from the executive suite is a common barrier to proper data security and management programs, even with the specter of regulatory enforcement looming."

Crowe Horwath and the Ponemon Institute will abe discussing the findings during a one-hour Webinar at noon EST on Tuesday, Nov. 17. 

 

Related Topics:
  • Crowe Horwath LLP
  • information technology
  • OAK BROOK
  • stimulus

Reader Comments (0)Login to Post a Comment

receive news by email

Most Popular

Latest Headlines
Most Popular
  • Five healthcare IT decisions to avoid
  • Blumenthal: EHRs will become 'an absolute requisite' for docs
  • Video program puts docs at bedside 24/7 at MassGeneral
  • Banner Health to control labor costs with benchmarking
  • FCC to promote mobile health apps
  • New Hampshire hospital pulls its data together
  • KLAS questions vendor claims on HIEs
  • Terso expands to Germany
  • SunCrest Healthcare contracts with Philips for telehealth monitors
  • Canada launches fight against chronic disease

Resource Central

  • Research
    Business Trends - Healthcare Technology
  • White Papers
    Solving Desktop Challenges in Healthcare with ScriptLogic's Desktop Authority
  • White Papers
    Validation process and compliance support with IBM Maximo Asset Management in regulated industries
  • White Papers
    Six Things Hospitals Need to Know About Replacing Pagers With Smartphones
  • Web Seminars
    On-Demand--Part II-The Crystal Clear Healthcare Provider: How Cleveland Clinic Delivers Transparency to Stakeholders with Business Intelligence
More Resources
Syndicate content

HEALTHCARE IT JOB SPOT

  • Software Engineer - GE Healthcare - Boston, MA
  • Lead Software Engineer - GE Healthcare - Boston, MA
  • Conversion Analyst - GE Healthcare - WA
  • Show Site Director - GE Healthcare - North Carolina
  • Health Information Manager - Center for Spinal Surgery - Nashville, TN
more jobs

  • Destination HIMSS

    Going to HIMSS this year? Then you can't afford to miss our Destination HIMSS site and newsletter. 

  • EHRWatch.com

    EHRWatch.com offers news, commentary and community participation on the developments in electronic health records.

  • Priming the Pump

    Priming the Pump provides practical news on the stimulus package and the incentives that it offers to healthcare providers.

  • Facebook

    Join Healthcare IT News on Facebook to connect with other readers!

  • NHINWatch

    Visit NHINWatch.com for coverage of the Nationwide Health Information Network.

  • Mobile Health Watch

    Stay up to date on the latest mobility news at Mobile Health Watch.

  • MedTech Publishing

    Visit our company Web page to learn more about MedTech Publishing.

  • LinkedIn

    Join our LinkedIn group to connect with other readers. Click here to join the group.

     

  • Healthcare IT Job Spot

    Check out the latest open positions at Healthcare IT Job Spot.

Marketplace

  • Home
  • Issues
  • Resource Central
  • Blog
  • Events
  • Subscribe
  • Advertise
  • About Us
  • Site Map
  • Privacy Policy
Healthcare IT News is a publication of MedTech Publishing Company LLC.
For more information about MedTech Publishing Company and its publications, please visit medtechpublishing.com.
©2009 MedTech Publishing
Powered by Phase2 Technology.