Privacy and Security

As more providers are using digital data, privacy and security issues have become a greater concern. Protecting confidential patient information is also a priority for IT vendors, who are interested in offering solutions that come equipped with heightened security features. The industry-wide transition to HIPAA 5010 code set comes with heightened emphasis on privacy of patient data content in provider transactions, since 5010 aims to ensure that only the "minimum necessary" personal health information required for business purposes is included in a transaction.

RELATED STORIES:
Privacy hindering EHR progress, say researchers
HHS proposes new privacy, security rules

 
Officials at Froedtert Health, a three-hospital health system based in Milwaukee, Wis., notified patients of a data breach Wednesday after a computer virus may have compromised the personal health information of some 43,000 people.
Comments: (0)
February 14, 2013
News
A new report from IT security assessment provider Redspin suggests some improvement with regard to healthcare data breaches in 2012, compared with previous years. Still, the study shows there's much work to be done.
Comments: (0)
February 13, 2013
News
At a Feb. 6 meeting of the Health IT Policy Committee, National Coordinator for Health Information Technology Farzad Mostashari, MD, said that, by and large, electronic health record vendors have their customers' best interests at heart. But to the few who don't, he gave a stern warning: Abide by what is "moral and right," or face more regulation.
Comments: (0)
February 7, 2013
News
Cbr Systems, Inc., a cord blood bank based in San Bruno, Calif., on Tuesday agreed to settle Federal Trade Commission charges that it failed to protect the financial and health data of nearly 300,000 consumers.
Comments: (0)
January 30, 2013
News
Despite the potential of mobile healthcare, experts say they worry about the added risks of security breaches, privacy violations and other concerns that come with the increasing use of mobile technology.
Comments: (0)
January 30, 2013
News
With the federal government's increasing oversight for HIPAA privacy breaches, more healthcare organizations have responded by bolstering their privacy and security budgets in attempts to stay on the offensive, a December HIMSS survey finds.
Comments: (0)
January 30, 2013
News
The idea of unique patient identifiers is more than a mere concept extracted from the next dystopian novel. They could very well be reality in the not-so-distant future. The question remaining, however, is whether or not the benefits of such technology outweigh constitutional privacy and patient trust concerns. Naturally, depending on whom you ask, the answer varies considerably.
Comments: (0)
January 29, 2013
News
A Georgia Congressman has released draft legislation that would regulate how the developers of mobile applications -- including mHealth apps -- collect personal data.
Comments: (0)
January 24, 2013
News
The omnibus HIPAA Privacy and Security final rule released by HHS on Jan. 17 answered some questions, provided necessary guidance in certain areas -- but some of the thorniest issues, data breach notification among those, are still cryptic enough that lawyers and privacy officers will still face difficult judgment calls every time a laptop is lost or stolen.
Comments: (0)
January 24, 2013
News
Some 57,000 patients seen at the Palo Alto, Calif.-based Lucile Packard Children's Hospital have been notified of a potential HIPAA-breach after an unencrypted company laptop containing patient medical information was stolen from a physician's car Jan. 9.
Comments: (0)
January 23, 2013
News
The enhanced set of protections finalized in the omnibus HIPAA privacy and security rule released Jan.17 now becomes the new baseline for anyone who handles health information. It doesn't change meaningful use requirements, but combined, the two may drive more providers to protect patient data, according to privacy and security experts.
Comments: (0)
January 22, 2013
News
The final rule is no longer about proving harm. Instead it places burden on covered entities to prove that improperly disclosed information has not been compromised.
Comments: (0)
January 18, 2013
News
The Middle Class Tax Relief and Job Creation Act of 2012’s planned mandate to remove the Medical Telemetry Services from the 608-614MHz WMTS spectrum is earthshaking news to the healthcare industry and has created a lot of uncertainty and questions in the North American hospital community.
Comments: (0)
August 30, 2012
Resource
Do Not Protect
http://webinars.medtechmedia.com/registration/webinar/advances-wireless-technologies-healthcare-hitting-wall-end-wmts-medical-telemet?partnerref=himsswebsite
As doctors and hospitals fight for the lives of their patients, they find themselves drowning in a sea of paperwork. Healthcare workers struggle daily to communicate patient information quickly and securely while complying with numerous insurance policies and industry regulations. Now, with demand from the White House to demonstrate "<a href="/directory/meaningful-use" target="_blank" class="directory-item-link">meaningful use</a>", the incentive to invest in communications technology has never been greater. This report by Smith Ivanson explores the top communication challenges Healthcare organizations face today, and why many of them are turning to Fax Servers to send, receive, and store <a href="/directory/electronic-health-record-ehr" target="_blank" class="directory-item-link">EHRs</a>.
Comments: (0)
August 29, 2012
Resource
sites/default/files/resource-media/pdf/security__compliance_top_drivers_for_fax_server_adoption_in_healthcare.pdf
Protect
As healthcare organizations develop strategies to comply with federal mandates and succeed in the new environment, wireless is one of the emerging technologies that can enable organizations to meet their clinical and business objectives, especially in this era of having to do more with a finite set of resources. This paper, featuring results from a Healthcare IT News online survey from June and July 2012, discusses current usage of wireless data technology in healthcare and identifies areas of demand and the potential benefits of wireless solutions and strategies.
Comments: (0)
August 29, 2012
Resource
sites/default/files/resource-media/pdf/sprint_executive_summary_august_2012.pdf
Protect
The process of managing PC, Mac, and <a href="/directory/ipad" target="_blank" class="directory-item-link">iPad</a> devices at Children’s Hospital Oakland Research Institute (CHORI) used to be a complicated affair. With a mix of Active Directory and Apple Remote Desktop, Ben Hanes, Senior Systems Analyst, and the entire IT team relied on two very different tools for deployment and system control, along with an in-house database that was difficult to keep accurate.
Comments: (0)
August 28, 2012
Resource
Do Not Protect
http://webinars.medtechmedia.com/registration/webinar/securely-manage-pcs-macs-and-ipads-single-solution?partnerref=website
Technology-enabled patient care models can help providers achieve the triple-play of healthcare: Improve outcomes, reduce cost and enable better access to healthcare. Healthcare organizations are looking to technology as a means to address these challenges and to differentiate their offerings. New technology-enabled care models, including telemedicine, remote patient monitoring, and mHealth, provide a way for the healthcare providers to address these challenges in a scalable, cost-effective manner. The new care models will come with their own challenges, and the industry is ever mindful of the need to cost-effectively deliver the capacity, security and capabilities needed across their wired and wireless infrastructures.
Comments: (0)
August 11, 2012
Resource
Do Not Protect
http://webinars.medtechmedia.com/registration/webinar/simply-connected-healthcare-architecting-network-improve-patient-outcomes?partnerref=himsswebsite
Every HIM initiative - especially clinical documentation - relies on a single common thread for success: the availability and integrity of the right data to drive the correct decisions and follow-on actions. Capturing accurate, complete quality clinical documentation is the most critical and fundamental component in providing quality care, and ultimately has the biggest connection to generating revenue. This white paper describes the risks associated with the lack of a core HIT strategy; identifies HIT strategies that can help manage the complex clinical documentation challenges associated with ICD-10, RAC and ACOs; and provides an overview of existing and emerging technologies that have significant impact on addressing these challenges.
Comments: (0)
August 2, 2012
Resource
sites/default/files/resource-media/pdf/white_paper-perfect_storm.pdf
Protect
Structured and unstructured information are valuable assets that allow companies to make informed business decisions. As a common practice, companies have adopted back office systems and CRM as part of their IT infrastructure to address structured information that’s commonly found in databases. While CRM lays the foundation for the IT infrastructure it does not address the unstructured data that can be found between core systems.
Comments: (0)
June 22, 2012
Resource
sites/default/files/resource-media/pdf/whitepaper_champaign2.pdf
Protect
The BYOD movement has been helpful to health care organizations because it increases productivity and convenience for staff while allowing cost savings for the organization. However, these employee mobile devices need to be controlled securely when used for business reasons. If not, unauthorized users could enter your network and access sensitive data. In addition, if controls are not put into place, these employee devices could provide a risk to your entire infrastructure.
Comments: (0)
June 18, 2012
Resource
Protect
http://www-01.ibm.com/common/ssi/cgi-bin/ssialias?subtype=PS&infotype=SA&appname=GTSE_SE_ZE_USEN_P&htmlfid=SEV03002USEN&attachment=SEV03002USEN.WMV
A new era in healthcare IT has arrived! Even when physicians can’t physically be there, new advances in technology allow them to always “virtually” be on the scene to save a life - whether it’s in the middle of the night or on their day off. In this short video, you’ll watch how a cardiologist prescribes a patient the medicine he needs stat at 2 a.m. You’ll see how easily you can access clinical desktops from anywhere and access real-time info about patients as they’re getting wheeled into the ER. In addition, the video will show you how to go mobile instantly with desktops that follow users, review real-time ER caseloads and enable HD face-to-face telemedicine. Also, watch how this doctor uses voice recognition to update patient records and secure patient health information (PHI) on devices. Don’t you love living in the future?
Comments: (0)
June 7, 2012
Resource
Do Not Protect
http://whitepapers.medtechmedia.com/himss-whitepapers/secure-physician-mobile-access-patient-data-virtualization
As many IT managers and HIPAA Security Officers have already discovered, HIPAA compliance requirements are daunting. The issues are so complex that some institutions have even taken a “wait and see” approach. But, sooner or later, you’ll be expected to demonstrate that your organization can detect, prevent, and respond to attacks, intrusions, or other system failures. Download this free whitepaper, HIPAA Compliance: Meeting the Security Challenge, to take a closer look at the HIPPA Compliance challenge.
Comments: (0)
May 22, 2012
Resource
sites/default/files/resource-media/pdf/solarwinds_hipaa_compliance_-_meeting_the_security_challenge.pdf
Protect
While the HIPAA Privacy Rule covers protected health information (PHI) in all forms, the HIPAA Security Rule specifically applies only to PHI that is maintained, transformed, or transmitted in electronic form (e-PHI). The Security Rule requires covered entities to meet specific objectives and presents major challenges for virtually every covered entity in the HIPAA environment, no matter how big or small. Covered entities include health plans, health care clearinghouses, and healthcare providers. In addition, business partners and associates who interact with covered entities are forced to deal with the same security issues as covered entities. IT professionals, like you, know the amount of work involved in supporting HIPAA compliance. The members of your IT team have enough on their plates without assuming the role of HIPAA police, but the team can also appreciate that adding technologies for HIPAA Security Rule compliance is an opportunity to make improvements in overall IT security that increases the organization’s bottom line. Read this white paper, including results from the HIMSS 2010 Security Survey, to learn how to fulfill HIPAA Security Rule requirements and improve overall control and performance of your IT infrastructure.
Comments: (0)
May 16, 2012
Resource
sites/default/files/resource-media/pdf/dell_fulfill_hipaa_security.pdf
Protect
As employees bring their mobile devices to the workplace, while it may increase productivity and reduce cost, it also causes security weaknesses. Download this paper to learn more about mobile security device threats and how to establish a mobile security strategy.
Comments: (0)
May 7, 2012
Resource
sites/default/files/resource-media/pdf/ibm_securing_mobile_devices.pdf
Protect
HIPAA regulations long on the books require that covered entities provide patients with accounting of disclosures of their protected health information for any purpose other than treatment, payment or health care operations (TPO). The HITECH Act upped the ante, requiring accounting of disclosures of PHI for TPO as well.
Comments: (0)
June 2, 2011
Blog
At one time or another, you may have heard a book titled, “All I Really Need To Know I Learned in Kindergarten,” by Robert Fulghum. Robert’s lessons translate into my professional world.
Comments: (0)
May 25, 2011
Blog
It's been a bad month for the cloud.
Comments: (0)
May 16, 2011
Blog
One of the biggest ongoing debates in the HIT world is how best to protect digitized health information.
Comments: (0)
May 4, 2011
Blog
While conducting research for the long overdue and nearly completed report on Personal Health Clouds (Dossia, Google Health and HealthVault) came across a recently published report by the European Network and Information Security Agency (ENISA) addressing cloud computing security.
Comments: (0)
December 10, 2009
Blog
The concepts of “security” and “privacy” of medical information (Protected Health Information, or PHI) are closely intertwined.
Comments: (0)
September 25, 2009
Blog
When I lecture about the new generation of personal health records such as Google Health and Microsoft Healthvault, I emphasize that these applications are not covered by HIPAA.
Comments: (0)
January 4, 2009
Blog
Egypt's crisis has raised alarms about national security and economic impact for Americans if regime change leads to an anti-US government controlling a strong ally in the Middle East. This crisis raises another more personal concern for Americans that has been overlooked by the national media: The security and availability of your electronic medical records in the event of a government-imposed "kill switch" for the Internet.
Comments: (3)
February 15, 2011
Blog
As we all implement Meaningful Use stages 1, 2, and 3 from 2011-2015, we will increasingly share data among payers, providers and patients. Protecting privacy is foundational and we should only exchange data per patient preference. How will we achieve that in Massachusetts?
Comments: (0)
July 26, 2010
Blog
Privacy and security are foundational to healthcare reform. Patients will trust electronic healthcare records only if they believe their confidentiality is protected via good security.
Comments: (0)
October 7, 2009
Blog
Chilmark has not been a big fan of the National Health Information Network (NHIN) concept. It was, and in large part still is, a top heavy federal government effort to create a nationwide infrastructure to facilitate the exchange of clinical information. A high, lofty and admirable goal, but one that is far too in front of where the market is today.
Comments: (1)
October 2, 2009
Blog
In my role as vice-Chair of the HIT Standards Committee, I join many of the subcommittee calls debating the standards and implementation guidance needed to support meaningful use. Over the past few months, I've learned a great deal from the Privacy and Security Working group.
Comments: (2)
September 15, 2009
Blog