Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Study points to critical gaps in hospital data security

April 06, 2010 | Mike Miliard, Managing Editor

Suggested Content

  • Healthcare data at risk
  • HHS, Emdeon to deliver EHRs to underserved
  • ACS acquires CredenceHealth
  • Interoperability Showcase finds home in Nashville
  • HIMSS, AUPHA and CAHME to jointly define IT curriculum
  • DoD enlists CSC, Emdeon for Rx data services
  • Emdeon adds power to portfolio
  • Top 10 'urban myths' of EHRs

NASHVILLE – Even as providers work to update their security environments, hospital data continues to be at serious risk, according to the 2010 HIMSS Analytics Report: Security of Patient Data.

Despite new statutory requirements for healthcare privacy and security, the study found critical gaps in data security – and its findings suggested that efforts to keep data safe were often more reactive than proactive, with hospitals dedicating more resources to breach response than to breach prevention.

The report, based on a biannual survey of 250 healthcare professionals nationwide, was commissioned by Kroll Fraud Solutions, a leading provider of data protection and identity theft response services, in partnership with HIMSS Analytics, a wholly-owned, not-for-profit subsidiary of the Healthcare Information and Management Systems Society (HIMSS).

"The results of the latest study are bittersweet to say the least," said Brian Lapidus, Kroll's chief operating officer. "On one hand, healthcare organizations are demonstrating increased awareness of the state of patient data security as a result of heightened regulatory activity and increased compliance. On the other, organizations are so afraid of being labeled ‘noncompliant’ that they overlook the bigger elephant in the room, the still-present risk and escalating costs associated with a data breach. We need to shift the industry focus from a ‘check the box’ mentality around compliance to a more comprehensive, sustained look at data security.”
 
When the last HIMSS Analytics report on the security of patient data was released in April 2008, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) was the primary regulatory requirement for hospitals. At that time, the study suggested that HIPAA’s focus on medical privacy fostered a significant lack of awareness among healthcare providers around the frequency, cause and seriousness of patient identity theft.

Unfortunately, despite the recent flurry of regulatory activity around patient data security, and the severe financial penalties these laws impose, the same is true in 2010, according the new report, key findings of which include:

  • Despite new regulatory activity, including the implementation of Red Flags Rule and HITECH Act, and increased compliance among healthcare providers, the reporting of healthcare breaches is on the rise.
  • The majority of survey participants indicated that they were compliant with existing laws and regulations.
  • Average responses were above a 6.0 (on a scale of 1-7, with 7 being the highest level of compliance) for almost all laws and regulations, including CMS Regulations, HIPAA, State Security Laws and Red Flags Rule. Only HITECH scored lower (5.75), most likely due to the fact that HITECH was still not fully implemented at the time of the survey.
  • The number of healthcare organizations that reported a breach increased by six percent in 2010 to 19 percent of total respondents – up from 13 percent in 2008.
  • When asked to rate their level of "preparedness" for a future security breach, respondents from organizations having experienced a breach cited a preparedness level of 6.06 (on a scale of 1-7, with 7 being most prepared).
  • Healthcare organizations continue to underestimate the high costs of a data breach, despite the fact that penalties for HITECH violations can reach as high as $1.5 million dollars.
  • Patient satisfaction was most frequently cited as the primary impact of a data breach on their organization (38 percent), while only 15 percent cited the financial costs —  down from 18 percent in 2008.
  • Healthcare organizations continue to think of data security in specific silos (IT, employees, etc.) and not as an organization-wide responsibility, which creates unwanted gaps in policies and procedures.
  • Eighty-seven percent of respondents indicated that they have policies in place to monitor access and sharing of electronic health information, yet research shows that 84 percent of healthcare breaches since 2003 were due to "low tech" incidents such as lost or stolen laptops, improper disposal of documents, stolen backup tapes, etc.
  • Sixty percent of respondents said they required third party vendors to provide proof of employee training and only half indicated that they required third party vendors to provide proof of employee background checks. As organizations prepare for the broader sharing of electronic health records across massive networks of providers, payers, state and federal repository systems, third party involvement is only expected to increase in the coming years.

The 2010 HIMSS Analytics Report did note significant differences between security policies and procedures according to hospital type. For instance, critical access facilities lagged behind general medical/surgical facilities and academic medical centers in several key areas, including monitoring electronic patient health information access and sharing (74 percent of respondents from critical access hospitals said their organization has such policies in place, as compared with 100 percent of academic medical center respondents and 95 percent of general medicine/surgical); and auditing processes for sharing patient data with outside entities (61 percent of critical access hospitals reported conducting regular audits, compared with 90 percent of academic medical centers and 80 percent of general medicine/surgical hospitals).
 
"We’d still like to see increasing maturity of data security function — from a checklist compliance approach to an organization-wide risk management approach," said Lisa Gallagher, senior director of privacy and security for HIMSS. "We’d like to see recognition of security risk as a business risk and have the function appropriately supported and resourced by executive management. The healthcare environment is only going to become more complex over time with the emphasis on health information exchange and new technology approaches such as cloud computing."

To read the full 2010 HIMSS Analytics Report: Security of Patient Data, click here.

Related Topics:
  • HIMSS
  • Kroll Fraud Solutions
  • Mike Miliard
  • Nashville

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • Analytics and the future of healthcare
  • CNIO position on the rise
  • Health data breaches up 97 percent in 2011
  • Docs use iPads, but don't see them as game-changers
  • Greenway set for IPO
  • HIT figures prominently in GOP primary battle for Nevada
  • Mostashari expects big year ahead for data exchange
  • AMA, AHIMA at odds on ICD-10
  • Minnesota: A healthy appreciation for HIT
  • 5 issues affecting cloud service quality and performance

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
  • ON DEMAND WEBINARS
    The Value of Document and Content Management in Healthcare Transformation
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
More Resources
Syndicate content

HIMSS JOBMINE

  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
  • Vice President - Tower Strategies - Remote
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy