Healthcare IT NewsHealthcare IT News
  • Home
  • Sections
    • Industry News
    • Hospitals & IDNs
    • Physician Practices & Ambulatory Care
    • Payers
    • Vendors
    • International
  • Issues
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • Sept. 2009
  • Resource Central
    • All Resources
    • Research
    • White Papers
    • Web Seminars
    • Videos
    • Podcasts
  • Blog
  • Events
  • Jobs
  • About
  • Subscribe
  • Advertise
  • Newsletters
  • RSS
  • Twitter
  • LinkedIn
  • Solutions Series
Select Your Homepage
Search eConnect
Login | Register
Home » News » Industry News | Hospitals & IDNs | Physician Practices & Ambulatory Care

E-mail to a FriendPrint
Social Bookmarking
  • Delicious Delicious
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Reddit Reddit
  • Newsvine Newsvine
  • Furl Furl
  • Facebook Facebook
  • Google Google
  • Yahoo Yahoo
Survey: Senior management lacks resources for patient privacy

Survey: Senior management lacks resources for patient privacy

October 20, 2009 | Molly Merrill, Associate Editor

Suggested Content

  • Cisco launches telemedicine pilot
  • IT ramping up sales at BCBSNC
  • MultiCare Health System launches solution for improved interoperability
  • Vendor Notebook - IBM to buy National Interest Security Company
  • Cisco, Molina Healthcare launch telemedicine project in southern California
  • Vendor Notebook: Cerner rolls out solution to improve data security
  • Vendors collaborate to improve data sharing between providers
  • $600M to boost construction, IT at community health centers
  • White paper outlines healthcare interoperability goals
  • Vendor Notebook - eClinicalWorks delivers EMR to physicians network

TRAVERSE CITY, MI – A new survey shows that IT practitioners believe their organizations are lacking when it comes to protecting patient information.

The study – conducted by Ponemon Institute, an independent researcher on privacy, data protection and information security policy, and sponsored by San Jose-Calif-based LogLogic – surveyed 542 IT practitioners from healthcare organizations with an average of more than 1,000 employees.

According to the study, 61 percent of practitioners believe their organizations don't have enough resources to meet privacy and data security requirements – and 70 percent think senior management doesn't consider it a priority.

“The majority of IT practitioners in our study don’t believe that their organizations have adequate resources to protect patients’ sensitive or confidential information,” said Larry Ponemon, chairman and founder of The Ponemon Institute. “The lack of resources and support from senior management is putting electronic health information at risk.”

The majority of survey respondents say their organizations had one or more data breaches that involved the loss of patient health information. Of those respondents, 33 percent say more than 90 percent of their organization’s data breaches involved electronic health information stored on databases.

According to the study, the most frequently cited security measures used to protect electronic health information are policies and procedures (81 percent), anti-virus and anti-malware systems (69 percent), training and awareness programs (67 percent) and perimeter controls such as multilayered firewalls (61 percent).

Researchers say that since one of the most significant threats is a data breach, it's surprising that only 23 percent of healthcare institutions use data loss prevention (DLP) solutions.

“Without resources and support from senior management, preventing the loss of data may be very difficult,” the study consluded. “We recommend that organizations pursue a strategy of assigning accountability for the protection of electronic health information, appropriate technology to prevent the insider threat (such as DLP solutions) and senior management buy-in for the necessary resources to get the job done right.”

LogLogic also surveyed healthcare IT security professionals at seven large hospitals and medical groups to understand how they balance the benefits of electronic medical records with instituting practices and technology solutions to guard patient confidentiality. Survey respondents say the new HIPAA rules, while not a perfect security solution, are a good start in improving the protection of electronic patient records.

The survey cites two challenges for going electronic and meeting HIPAA and security requirements. The first is understanding the new HIPAA 2.0 rules and applying them to patient data in the organization.

“With HIPAA, it’s all around the patient data,” said the chief compliance officer at a Northeastern medical organization. “You need to make sure patient data is not inadvertently or inappropriately accessed, but first you have to think about where that data resides and how it’s used.”

The second concern is providing management support for implementing proper security measures.

“Our top challenge is really political, not technical,” said the security head at a hospital in the Midwest. “Getting senior management buy-in to get things HIPAA requires done is hard. They see a lot of this as a hindrance to workflow and clinicians. We don’t have a problem with funding. It’s implementing simple security practices that is hardest with senior management.”
 

Related Topics:
  • DLP
  • Larry Ponemon
  • SAN Jose
  • The Ponemon Institute
  • Traverse City

Reader Comments (0)Login to Post a Comment

receive news by email

Most Popular

Latest Headlines
Most Popular
  • Five healthcare IT decisions to avoid
  • Blumenthal: EHRs will become 'an absolute requisite' for docs
  • Video program puts docs at bedside 24/7 at MassGeneral
  • FCC to promote mobile health apps
  • Spheris bankruptcy could spark bidding war, with MedQuist in the lead
  • Sankaran maps government's promotion of healthcare IT
  • North Carolina group offers help with ARRA
  • New Hampshire hospital pulls its data together
  • KLAS questions vendor claims on HIEs
  • Terso expands to Germany

Resource Central

  • White Papers
    St. Francis Care Uses Leading Edge Technology to Deliver First Class Healthcare Services
  • Web Seminars
    On-Demand--Integrated, Real-time Decision Making – A Prescription for Improving Patient Outcomes and Your Bottom Line
  • Web Seminars
    On-Demand--Part II-The Crystal Clear Healthcare Provider: How Cleveland Clinic Delivers Transparency to Stakeholders with Business Intelligence
  • Research
    Business Trends - Healthcare Technology
  • White Papers
    Solving Desktop Challenges in Healthcare with ScriptLogic's Desktop Authority
More Resources
Syndicate content

HEALTHCARE IT JOB SPOT

  • Software Engineer - GE Healthcare - Boston, MA
  • Lead Software Engineer - GE Healthcare - Boston, MA
  • Conversion Analyst - GE Healthcare - WA
  • Show Site Director - GE Healthcare - North Carolina
  • Health Information Manager - Center for Spinal Surgery - Nashville, TN
more jobs

  • Destination HIMSS

    Going to HIMSS this year? Then you can't afford to miss our Destination HIMSS site and newsletter. 

  • EHRWatch.com

    EHRWatch.com offers news, commentary and community participation on the developments in electronic health records.

  • Priming the Pump

    Priming the Pump provides practical news on the stimulus package and the incentives that it offers to healthcare providers.

  • Facebook

    Join Healthcare IT News on Facebook to connect with other readers!

  • NHINWatch

    Visit NHINWatch.com for coverage of the Nationwide Health Information Network.

  • Mobile Health Watch

    Stay up to date on the latest mobility news at Mobile Health Watch.

  • MedTech Publishing

    Visit our company Web page to learn more about MedTech Publishing.

  • LinkedIn

    Join our LinkedIn group to connect with other readers. Click here to join the group.

     

  • Healthcare IT Job Spot

    Check out the latest open positions at Healthcare IT Job Spot.

Marketplace

  • Home
  • Issues
  • Resource Central
  • Blog
  • Events
  • Subscribe
  • Advertise
  • About Us
  • Site Map
  • Privacy Policy
Healthcare IT News is a publication of MedTech Publishing Company LLC.
For more information about MedTech Publishing Company and its publications, please visit medtechpublishing.com.
©2009 MedTech Publishing
Powered by Phase2 Technology.