Privacy and Security

As more providers are using digital data, privacy and security issues have become a greater concern. Protecting confidential patient information is also a priority for IT vendors, who are interested in offering solutions that come equipped with heightened security features. The industry-wide transition to HIPAA 5010 code set comes with heightened emphasis on privacy of patient data content in provider transactions, since 5010 aims to ensure that only the "minimum necessary" personal health information required for business purposes is included in a transaction.

RELATED STORIES:
Privacy hindering EHR progress, say researchers
HHS proposes new privacy, security rules

 
Healthcare institutions should emulate best-of-breed privacy polices developed by financial services firms rather than other hospitals, recommends Kaye Scholer and William Tanenbaum, technology lawyers at New York-based law firm William A. Tanenbaum.
Comments: (0)
April 25, 2013
News
After last year's mass shootings in Colorado and Connecticut, the Obama Administration has been looking for ways to address gun violence, either through new legal reforms or by working with existing policy, and one option is to clarify HIPAA provisions that may be preventing the reporting of mental health information to the national background check system.
Comments: (0)
April 23, 2013
News
More than 500 patients at the Arizona Counseling and Treatment Services are being notified of a HIPAA breach after a company laptop containing patients' personal health information was stolen from an employee's home, according to a Yuma Sun report.
Comments: (0)
April 17, 2013
News
Healthcare organizations should not assume that compliance with regulations, like HIPAA, automatically makes their organization secure, says Larry Hurtado, CEO of Digital Defense, a risk assessment firm in San Antonio, Texas.
Comments: (0)
April 16, 2013
News
Analysts pronounced health IT company Cerner's pending acquisition of PureWellness a healthy step for Cerner - one that gives it a $420 million opportunity out of the gate, serves as a driver of new bookings and differentiates the company in the marketplace.
Comments: (0)
April 15, 2013
News
The Health Information Trust Alliance (HITRUST) has announced it will establish a new working group to support the recent White House cybersecurity executive order.
Comments: (0)
April 15, 2013
News
Since HIPAA was first enacted into law in 1996, patients have had the legal right to read and even amend their own medical records. HIPAA protects patient privacy but it also heightens patient engagement. As a result, the opportunity now exists to have more informed patients than ever before in the United States. This can lead to better patient care. It's the old adage: Information is power.
Comments: (0)
April 15, 2013
News
Kentucky, a state with roughly four million people has achieved what many much more populated states have not yet been able to accomplish, according to its regional extension center leaders.
Comments: (0)
April 15, 2013
News
A packed house at the Meaningful Use Symposium held March 3 at the 2013 HIMSS Annual Conference & Exhibition couldn't help but inspire awe and possibly conjure a little concern in the hearts of those attending.
Comments: (0)
April 15, 2013
News
Greater Houston Healthconnect announced Wednesday that Irving, Texas-based CHRISTUS Health and Houston-based Legacy Community Health Services are the first two providers to begin exchanging patient health histories, in the form of continuity of care documents and HL7 feeds, via the HIE.
Comments: (0)
April 9, 2013
News
Hospice of Alamance Caswell and LifePath Home Health group in North Carolina have notified 5,370 patients affected by a HIPAA breach after three unencrypted laptops containing protected health information were stolen from a company facility.
Comments: (0)
April 5, 2013
News
A new advocacy group launched at HIMSS13 in New Orleans earlier this month. The imPatient Movement wants to change the conversation about patient engagement -- giving voice to healthcare consumers and pushing for more fruitful data exchange between patients and their physicians.
Comments: (0)
March 29, 2013
News
What are the most important questions to ask when selecting a secure texting solution? Find out what really matters by reading this whitepaper on the 10 most important things to know when evaluating a solution.
Comments: (0)
April 19, 2013
Resource
sites/default/files/resource-media/pdf/tigertext_white_paper_-_top_10_considerations_when_selecting_a_secure_text_messaging_solution.pdf
Protect
Health and Life Sciences (HLS) organizations are leveraging Microsoft Office as a clinically relevant platform that creates and optimizes a collaborative and securely connected healthcare ecosystem. With Microsoft’s commitment to enabling regulatory and mandated compliance our cloud services and solutions enable HLS organizations to reduce the costs of infrastructure, maintenance, and development; to eliminate complexity; and to increase productivity.
Comments: (0)
April 9, 2013
Resource
Do Not Protect
http://www.medtechwebinars.com/registration/webinar/how-microsoft-office-clinically-relevant-health-communities?partnerref=himsswebsite
Cloud-based Microsoft Exchange service features all the mission critical enterprise-class communication and collaboration capabilities of an in-house solution without the unpredictable costs and management headaches. With flexible customization options, healthcare organizations can seamlessly move to a cloud-based solution without compromising security or altering their current encryption approach.
Comments: (0)
April 2, 2013
Resource
sites/default/files/resource-media/pdf/apptix_whitepaper_cloudreliability_final.pdf
Protect
This report outlines the future look of Forrester's solution for security and risk (S&R) executives working on building an identity and access management strategy for the extended enterprise. This report will help you understand the major business and IT trends affecting identity and access management (IAM) during the next five years. Learn why applying a Zero Trust information security model to IAM helps security teams unify and improve access control across the extended enterprise.
Comments: (0)
March 22, 2013
Resource
sites/default/files/resource-media/pdf/forrester_navigate_the_future_of_identity_and_access_management_final.pdf
Protect
Healthcare IT departments must defend against complex internal and external threats while still maintaining compliance with HIPAA/HITCH. The same is true for businesses of all kinds – they are simply overwhelmed. Clearly, organizational risk management has reached a critical juncture. A July 2012 IDG Research Services poll of CIOs and IT managers underscores the gravity of the situation. The results provide important data about how enterprises view compliance overall, and identity management and access governance in particular.
Comments: (0)
March 22, 2013
Resource
sites/default/files/resource-media/pdf/white_paper_idg_why_it_pays_to_take_a_busines-centric_approach_to_compli.pdf
Protect
Organizations of all kinds, including those in the healthcare industry, are doing business in new ways, thanks to new IT infrastructure technologies like virtualization, cloud computing and mobility, which are changing how users interact with information and with each other. As the enterprise becomes more interconnected and distributed, business agility increases; but information security specialists face new challenges around maintaining effective security and monitoring controls.
Comments: (0)
March 22, 2013
Resource
sites/default/files/resource-media/pdf/netiq_wp_realtimesecurityintelligence_print.pdf
Protect
Organizations are consuming software-as-a-service applications at an ever-accelerating rate. While the advantages of SaaS applications are many, so are the potential pitfalls of unauthorized access. As these applications become increasingly popular, the need to manage access SaaS-hosted information becomes even more crucial. Security, compliance reporting and ease of access must be balanced to ensure that information in the cloud is protected without impacting your organizations ability to serve patients, healthcare professionals, and business partners.
Comments: (0)
March 22, 2013
Resource
sites/default/files/resource-media/pdf/netiq_wp_extending_access_control_to_cloud_usv.pdf
Protect
Given the risks throughout today's complex threat and regulatory landscapes, your need to effectively and securely manage access to critical resources has never been greater. You need to know exactly who has access to what resources and if that access is appropriate. This is as true for the healthcare industry as it is for every other, highly regulated industry. As threats become more sophisticated, so does the speed with which your organization must respond to them.
Comments: (0)
March 22, 2013
Resource
sites/default/files/resource-media/pdf/white_paper_identity_and_access_governance_bringing_business_and_it_toge.pdf
Protect
The only thing that is constant is change. This old adage has never been truer for the healthcare industry than it is today. Businesses of all kinds must manage their systems in the face of ever growing and changing complexities. Good Identity and Access Governance practices are front and center in the ongoing battle to deal with constant change effectively.
Comments: (0)
March 22, 2013
Resource
sites/default/files/resource-media/pdf/white_paper_managing_change_and_complexity_with_identity_and_access_gove._1.pdf
Protect
For provider organizations, tools that drive improved performance of legacy clinical applications as well as improve security and create efficiencies in the management of client computing are increasingly becoming critical for healthcare organizations. Desktop virtualization technology is increasingly being used by providers to realize these advantages.
Comments: (0)
March 13, 2013
Resource
sites/default/files/resource-media/pdf/netapp_hc_wp_desktop_virtualization_031213.pdf
Protect
Agility is central to delivering excellence in patient care. However, healthcare organizations have entered a new era of scale in which the amount of data captured, processed, and stored is breaking down every architectural construct in the storage industry. NetApp delivers innovative technologies and capabilities for an agile data infrastructure that address the challenges of big data scale, enabling healthcare providers to gain insight into massive datasets, move data quickly, and store important content for long periods of time.
Comments: (0)
March 13, 2013
Resource
sites/default/files/resource-media/pdf/netapp_hc_wp_patient_care_clinical_data_031213.pdf
Protect
The days of patched and piecemeal fixes to improve mobile device use, while ignoring the underlying mobility infrastructure, are nearing to an end. With the proliferation of mobile devices, application availability, increased data sharing and regulatory requirements, healthcare organizations must raise the bar on mobility with a comprehensive strategy.
Comments: (0)
February 26, 2013
Resource
Do Not Protect
http://webinars.medtechmedia.com/registration/webinar/creating-comprehensive-mobility-strategy-changing-healthcare-world?partnerref=himsswebsite
At the weekly healthcare and social media tweet chat (#HITsm), hosted by HL7 Standards, participants discussed four previously posed questions, exploring the practical use of social media in the healthcare space. Here is a roundup of the best responses.
Comments: (0)
July 6, 2012
Blog
One major issue facing private and public Health Information Exchanges (HIE) is how to ensure patients privacy preferences are respected by obtaining their consent before data is shared.
Comments: (0)
June 20, 2012
Blog
America’s population is aging, insurance enrollment is growing, healthcare utilization is increasing, and the cost of delivering medical care is rising. As a result, many companies in the healthcare industry are being challenged to serve more patients and members, to improve the quality of care, and to reduce operational costs.
Comments: (1)
June 14, 2012
Blog
As we continue the journey to protect corporate data that is accessed from personal mobile devices, we're developing increasingly rigorous policies that rebalance individual preferences with corporate compliance requirements.
Comments: (1)
May 23, 2012
Blog
The Ponemon Institute recently released their Second Annual Benchmark Survey on Patient Privacy and Data Security. The study focused on actual data loss experience from a sample of 72 healthcare organizations. Co3 Systems created a Top 10 breach/data loss objectives list that helps organizations with the necessary steps in preparation of potential data breach.
Comments: (1)
May 17, 2012
Blog
There’s a fight going on about the adoption of health information technology in our country. This fight isn’t necessary and it shouldn’t be happening, but it is happening nonetheless – and patients have a lot at stake.
Comments: (0)
May 2, 2012
Blog
The Acting General Counsel of the National Labor Relations Board released a second report on outcome investigations involving social media that were submitted by regional offices and it underscores two main points.
Comments: (1)
May 2, 2012
Blog
Todd Park (@todd_park), United States chief technology officer for the Obama Administration, engaged in a live Twitter chat as part of Big Data Week, a string of community-led events relating to big data. Here is a Twitter recap of the Q&A.
Comments: (0)
April 25, 2012
Blog
As the nation begins its pilots of pioneer Accountable Care Organizations and shares more data for care coordination and population management, IT departments will be asked to make clinical records available to increasing numbers of loosely affiliated clinicians and staff.
Comments: (0)
April 24, 2012
Blog
Healthcare organizations have avoided the use of "public cloud" because of HIPAA/HITECH privacy concerns, lack of breach indemnification/data integrity guarantees, and the unwillingness of many cloud providers to sign business associate agreements.
Comments: (0)
April 13, 2012
Blog
I was able to talk with Gary Thompson co-founder and CEO of CLOUD Inc. - also known as the Consortium for Local Ownership and Use of Data, Inc.
Comments: (0)
April 10, 2012
Blog
While many industries are reliant on information technology to deliver services and drive innovation, none is so deeply entwined in IT than healthcare. As such, it should be no surprise that the potential impact of cloud computing is being felt, with mixed feelings, most acutely in this industry.
Comments: (0)
April 6, 2012
Blog
Hannibal Regional Healthcare System, which operates a not-for-profit community hospital in northeast Missouri, has selected the Sunrise Enterprise suite of solutions from Allscripts.
Comments: (0)
May 6, 2011
Press Release
Selecting the correct software to use in a medical practice is critical for physicians, particularly now that all technology-based practices must be compliant with the government's updated standard for electronic claims transactions. The new standard, known as HIPAA Version 5010, will be required by January 1, 2012. The American Medical Association (AMA) and the Medical Group Management Association (MGMA) have made the software selection process easier by developing an online directory of software vendors that helps physicians determine whether the vendors’ practice management systems are compliant with the 5010 standard. A companion piece to the recently released Selecting a Practice Management System toolkit, the Practice Management System Software Directory provides detailed vendor profiles, enabling physicians to easily choose the software that best fits their needs.
Comments: (0)
April 28, 2011
Press Release
PhoneFactor, the leading global provider of phone-based authentication, today released the results of its recent survey on multi-factor authentication. The results indicate organizations that utilize security tokens, many of which are already frustrated with the burden tokens place on their IT departments and end users, are being driven to action by the recent RSA breach.
Comments: (0)
April 27, 2011
Press Release
CDW LLC (CDW), a leading provider of technology solutions to business, government, education and healthcare, today released the findings of its Video Conferencing Straw Poll Report. The report finds that half of companies use some form of video conferencing today and another quarter plan to implement the technology within the next two years. Video conferencing adoption, driven by reduced operating costs, improved decision making and improved communication, will branch out beyond simple peer-to-peer devices into more cutting-edge collaborative video conferencing systems, such as immersive telepresence.
Comments: (0)
April 25, 2011
Press Release
To ensure downtime access to current patient data after moving to electronic medical records (EMRs) and electronic medication administration records (eMARs), Hancock Regional Hospital in Greenfield, IN implemented NetSafe, Interbit Data's downtime protection and business continuance solution.
Comments: (0)
July 29, 2010
Press Release
Twin County Regional Hospital is expanding its McKesson Paragon hospital information system to increase efficiency and help improve patient safety across the entire medical community of Galax, Va. and surrounding areas.
Comments: (0)
January 8, 2010
Press Release