Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Electronic Health Records | Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

VA ramps up enforcement of contractor data security

May 20, 2010 | Mary Mosquera, Contributing Editor

WASHINGTON – The Department of Veterans Affairs will step up enforcement of its contractors to ensure they meet information security requirements for protecting veterans' personal health data.
 
VA includes a clause in its contracts requiring information security safeguards, including encryption and policies limiting who can access personal data. But that is no guarantee that vendors follow through, said VA senior IT and procurement officials at a hearing May 19 of the House Veterans Affair Committee subcommittee on oversight and investigations.
 
The challenge lies in verifying that more than 22,000 VA contractors with whom the department shares veteran information adhere to security requirements, said Roger Baker, VA's CIO. These vendors help VA provide healthcare and benefits.
 
"Our policy, which is stronger than any similarly sized private sector organization that I'm aware of, is that supply chain partners must follow VA's information protection policies, including encryption of mobile devices," he said.

Hearing follows recent theft

The hearing occurred in the aftermath of the April 22 theft in Texas of a laptop with the personal information of 644 veterans from the vehicle of an employee of a health services contractor.

VA subsequently notified the affected veterans and is providing them with precautionary credit monitoring services. The contractor reported the incident immediately to law enforcement and to the agency and disabled the user account and server access from the stolen laptop, Baker said.

"The information was not encrypted despite contracts with the company that included the required security clause and the company had certified to the VA that they were in compliance," he said.

The incident compelled VA to start auditing its supply chain partners to ensure compliance with its policies.

"While it is impossible to audit all of our partners, these steps should provide us with substantially improved insight into the level of protection provided to veterans' information anywhere it exists in our extended enterprise," Baker said.

Tightened verification

Among the steps, VA will verify that contracts where information is exchanged have the necessary information security clause, he said. Baker also expanded the authority of information security officers at VA facilities to review all contracts where information is exchanged. Previously their scope was limited to IT contracts.

VA will also randomly select a number of contracts at a facility for more in-depth audits of vendors' compliance with VA security policies.

To ensure that the contractor that reported the Texas data breach is beefing up security safeguards, VA said it would conduct an onsite assessment of the contractor's facility and its scope of compliance with all IT information and physical security and records management requirements.

VA is also examining security related to the vendor's 55 other contracts with the Veterans Health Administration and will ultimately work with the department's legal counsel to determine any consequences.

  • 1
  • 2
  • next ›
  • last »
Related Topics:
  • Department of Veterans Affairs
  • encryption
  • Frederick Downs Jr.
  • Mary Mosquera
  • Roger Baker
  • Steve Buyer
  • Texas
  • Washington
  • Electronic Health Records
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • 6 things patients want from social media
  • FCC gives green light to wireless medical devices
  • Tablet adoption by docs soars
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
  • Tablet adoption by docs soars
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
  • ON DEMAND WEBINARS
    A Smarter Approach to Healthcare PC Virtualization
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • UPCOMING WEBINARS
    June 5th @ 1PM ET--Get Control of Your Medical Images with a Cloud-Based Vendor-Neutral Archive
  • WHITE PAPERS
    The Scarborough Hospital: Establishing a Document Management Strategy for EHRs
More Resources
Syndicate content

HIMSS JOBMINE

  • Clinical Informatics Physician - Epic - Verona, WI
  • Regional Senior Quality Analyst - Memorial Medical Center - Modesto, CA
  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy