Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » Press Releases » Privacy and Security

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

HITRUST Addresses Risk Assessment Issues for Small Healthcare Organizations

May 26, 2011 | Industry News Release
Source: Healthcare IT News

Related Resources

  • West Tennessee Healthcare: Accelerating Access to Patient Records with SSO and Context Management
  • The Healthcare IT Innovation Imperative: Harnessing the Power of Technology for 21st Century Care Models
  • Unique Challenges of Health Care Networks and the Value of Wireless
  • Mobile Technology Meets Healthcare: Risks and Remedies
  • 3 Steps to Faster EMR Adoption with Desktop Virtualization & SSO

FRISCO, TX –  

The Health Information Trust Alliance (HITRUST) announced today a new component of the CSF Assurance program targeted at healthcare organizations with annual revenue less than $25 million. The new security assessment approach addresses the wide-scale inaccuracies found in assessments conducted by smaller organizations and extends the reach and value of the CSF Assurance program, the most widely used approach for documenting risk assessment information in the healthcare industry. The HITRUST CSF Assessment for Small Organizations is a practical and effective solution for organizations wanting to perform accurate assessments of their information security environment and address the requirements of meaningful use.

“Our experience shows that when small healthcare organizations are breached, it's not only their own environments that may be impacted, but potentially those of other organizations, such as hospitals, that they access and for which access information is fraudulently acquired as well”
According to HITRUST assessment data, the vast majority of smaller organizations, including more than 85 percent of U.S. physicians’ offices with fewer than 10 employees, do not have the security knowledge and devoted security personnel to perform meaningful use risk assessments and monitor and improve their security environments. The lack of current or adequate security protection for the large volume of electronic protected health information (ePHI) processed by this market segment compromises the integrity of the entire healthcare industry during a time of greater reliance upon electronic health record systems and increased adoption of health information exchanges and networks.

The CSF Assessment for Small Organizations is the result of HITRUST’s analysis of the market to identify the best techniques and methods for an automated, user-friendly solution that would increase the accuracy and comprehensiveness of assessment results and provide organizations with the information needed to address or seek the assistance they need.

“Our analysis shows smaller organizations often provide inaccurate or incomplete information when using self-assessment questionnaires to communicate the status of their security controls to third parties,” said Daniel Nutkis, Chief Executive Officer, HITRUST. “Organizations with limited staff are focused on running the day-to-day aspects of their business and must now also face meeting the requirements of meaningful use, all in an environment in which they often do not understand the significance and risks associated with conducting ineffective security assessments. Given the complexity of regulations and evolving vulnerabilities and threats, we believed that automating the identification of vulnerabilities both internally and externally was the only practical solution.”

Developed over an 18-month period in collaboration with nCircle, the leader in automated security and compliance auditing solutions, and leveraging the HITRUST Common Security Framework (CSF) and CSF Assurance program, the CSF Assessment for Small Organizations delivers a complete assessment of security risk and verification of security controls through a combination of a simple, forms-based questionnaire and automated internal and external vulnerability scans. The service, delivered through the HITRUST Assessment Portal and initially available to organizations with annual revenue less than $25 million, does not require any special skills, resources or additional hardware or software. A wizard-based process makes it possible for anyone, regardless of skill level, to provide the necessary data and receive accurate, prioritized information about network vulnerabilities and weaknesses along with information on how to fix problem areas.

The questionnaire and scan results are analyzed by HITRUST and incorporated into a HITRUST CSF Validated report, which can aid an organization in complying with the HITRUST CSF, addressing meaningful use, and meeting regulatory requirements such as HIPAA. The report also provides a consistent representation of risk exposure and benchmarking results against similar organizations. In addition to the assessment report, an organization will be provided with the detailed vulnerability scanning information collected during the assessment so it has the complete details on any gaps in its information protection environment and can address or seek assistance as appropriate.

“When HITRUST approached us, the ability to comprehensively and practically scan behind the firewall without installing software or appliances had never been done before,” said Abe Kleinfeld, President and Chief Executive Officer, nCircle. “nCircle’s experience with automated security and compliance auditing solutions combined with HITRUST’s unique requirements for assessing information security in small healthcare organizations, led us to develop a breakthrough in state-of-the-art security scanning. nCircle PureCloud, with its ability to eliminate firewall configuration changes and software or hardware deployment on a customer's internal network, is the perfect complement to the HITRUST solution. We look forward to working with HITRUST to continuously add new capabilities.”

The standard report, which is already accepted and understood by many organizations, can be used to meet the risk assessment requirements of HIPAA and meaningful use, and communicate an organization’s state of security to third parties, such as business associates and health information exchanges. The report can also be used, along with the scan results, to seek remediation assistance and solutions from third-party information security consultants and technology vendors. HITRUST is allowing organizations to run additional scans free of charge during the first 90 days following the initial scan in order to verify the status of their remediation efforts.

 

Related Topics:
  • Frisco
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

receive news by email

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • 6 things patients want from social media
  • FCC gives green light to wireless medical devices
  • Tablet adoption by docs soars
  • VeriTeQ Acquisition Corporation to offer implantable RFID Microchip
  • Kaiser Permanente adds iPhone app to its suite of mobile offerings
  • VeriTeQ Acquisition Corporation acquires implantable, FDA-Cleared VeriChip technology
  • Cooper Green Mercy Hospital implements OpenVista EHR
  • RelayHealth, Greenway accelerate health system data exchange
more Press Releases

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • WHITE PAPERS
    Driving Meaningful Use of Enterprise Content Management
  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
More Resources
Syndicate content

HIMSS JOBMINE

  • Clinical Informatics Physician - Epic - Verona, WI
  • Regional Senior Quality Analyst - Memorial Medical Center - Modesto, CA
  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy