Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Survey: Senior management lacks resources for patient privacy

October 20, 2009 | Molly Merrill, Associate Editor

Suggested Content

  • Costly healthcare data breaches jump 32 percent
  • 3D medical imaging market pegged at $5.9B by 2017
  • Researchers don't wait for iPhone 4S to make healthcare customizations
  • Versus, Salamander introduce patient tracking for mass casualty disasters
  • SSO can save providers more than $2M annually
  • E-prescription market headed to $204.6M

TRAVERSE CITY, MI – A new survey shows that IT practitioners believe their organizations are lacking when it comes to protecting patient information.

The study – conducted by Ponemon Institute, an independent researcher on privacy, data protection and information security policy, and sponsored by San Jose-Calif-based LogLogic – surveyed 542 IT practitioners from healthcare organizations with an average of more than 1,000 employees.

According to the study, 61 percent of practitioners believe their organizations don't have enough resources to meet privacy and data security requirements – and 70 percent think senior management doesn't consider it a priority.

“The majority of IT practitioners in our study don’t believe that their organizations have adequate resources to protect patients’ sensitive or confidential information,” said Larry Ponemon, chairman and founder of The Ponemon Institute. “The lack of resources and support from senior management is putting electronic health information at risk.”

The majority of survey respondents say their organizations had one or more data breaches that involved the loss of patient health information. Of those respondents, 33 percent say more than 90 percent of their organization’s data breaches involved electronic health information stored on databases.

According to the study, the most frequently cited security measures used to protect electronic health information are policies and procedures (81 percent), anti-virus and anti-malware systems (69 percent), training and awareness programs (67 percent) and perimeter controls such as multilayered firewalls (61 percent).

Researchers say that since one of the most significant threats is a data breach, it's surprising that only 23 percent of healthcare institutions use data loss prevention (DLP) solutions.

“Without resources and support from senior management, preventing the loss of data may be very difficult,” the study consluded. “We recommend that organizations pursue a strategy of assigning accountability for the protection of electronic health information, appropriate technology to prevent the insider threat (such as DLP solutions) and senior management buy-in for the necessary resources to get the job done right.”

LogLogic also surveyed healthcare IT security professionals at seven large hospitals and medical groups to understand how they balance the benefits of electronic medical records with instituting practices and technology solutions to guard patient confidentiality. Survey respondents say the new HIPAA rules, while not a perfect security solution, are a good start in improving the protection of electronic patient records.

The survey cites two challenges for going electronic and meeting HIPAA and security requirements. The first is understanding the new HIPAA 2.0 rules and applying them to patient data in the organization.

“With HIPAA, it’s all around the patient data,” said the chief compliance officer at a Northeastern medical organization. “You need to make sure patient data is not inadvertently or inappropriately accessed, but first you have to think about where that data resides and how it’s used.”

The second concern is providing management support for implementing proper security measures.

“Our top challenge is really political, not technical,” said the security head at a hospital in the Midwest. “Getting senior management buy-in to get things HIPAA requires done is hard. They see a lot of this as a hindrance to workflow and clinicians. We don’t have a problem with funding. It’s implementing simple security practices that is hardest with senior management.”
 

Related Topics:
  • DLP
  • Larry Ponemon
  • SAN Jose
  • The Ponemon Institute
  • Traverse City

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 10 most outlandish kinds of ICD-10 codes
  • 5 stages of EHR maturity and patient collaboration
  • 5 simple ways to realize ROI from your EHR
  • 'Obamacare' a lightning rod, but what about health IT?
  • Remote health monitoring pegged at 3 million users by 2016
  • H.I.T. Men and Women to pick up awards at HIMSS12
  • University challenge targets NCDs with mHealth and social media
  • Indiana health exchange taps AT&T to scale up
  • eHealth Initiative releases recommendations for accountable care
  • One surgeon's take on need for culture change in medicine

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
More Resources
Syndicate content

HIMSS JOBMINE

  • Director, Sales - HIMSS - Arlington, VA
  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy