Click here to create your personal news page. The news that appears on aprpeh will appear there and be constantly updated. You can then modify the page, share it with your friends, or export it and have it appear elsewhere.

You can also create a personal news page and follow the news that interests you by clicking on the tab labelled 'New page'.
 

Participate

Explore

Shopping Categories

  1. 1. Mobile Phone
  2. 2. Smartphone
  3. 3. Digital Camera
  4. 4. Laptop Computer
  5. 5. Printer
  6. 6. GPS
  7. 7. LCD Monitor
  8. 8. Graphic Card
  9. 9. Processor
  10. 10. Motherboard
  11. 11. Digital Camcorder
  12. 12. Desktop Computer
  13. 13. A/V Amplifier
  14. 14. Sound Card
  15. 15. LCD TV

Wikio Shopping

  1. 1. Automotive
  2. 2. Beauty & Fragrances
  3. 3. Car/Motor Bike
  4. 4. Clothing, Accessories & Shoes
  5. 5. Communication
  6. 6. Computers
  7. 7. Electronics
  8. 8. Flowers & Gifts
  9. 9. Gourmet & Foods
  10. 10. Health & Personal Care
  11. 11. Home & Garden
  12. 12. Household Appliances
  13. 13. Jewelry & Watches
  14. 14. Musical Instruments
  15. 15. Sports & Outdoors
  16. 16. Toys & Baby
  17. 17. Video Games

Comment on the news

  • Wikio
  • News
  • A Review of the 2008 HIMSS Analytics Report: Security of Patient Data
3Vote!

A Review of the 2008 HIMSS Analytics Report: Security of Patient Data

 

HIMSS Analytics (short for Healthcare Information and Management Systems Society); a “think-tank” for the healthcare management world has just released the 2008 HIMSS Analytics Report: Security of Patient Data .   http://www.emediawire.com/releases/kroll-healthcare-security/42008/prweb840224.htm .

This report examines the security of patient personal identifying information (PII) and protected health information (PHI).   In the current data breach crazy world, this is a timely report which tries to get beneath the surface of the needs of health professionals to balance quick access to secure patient health records and the need to protect not only patient privacy but prevent access to information which could lead to identity theft.      

In discussing PHI and PII it is important to first establish a fact.   Unauthorized access to PII no matter where it may be found could lead to identity theft.   Unauthorized access to PHI alone, will not lead to financial identity theft in most cases.   It could be used to help a fraudster identify a possible victim by placing the consumer/victim in a particular location and may give the fraudster a hint as to vulnerabilities of the consumer.   It is also unlikely to result in medical identity theft.   In terms of useful information needed to perpetrate identity theft, the date of birth and Social Security Number are far more valuable than PHI.   A consumer may feel that their privacy has been violated when PHI has been exposed but unless PII is included in the breached data, the patient is only marginally more likely to be exposed to identity theft than other non-breached consumers.        

Health care organizations or as HIPAA labels these “covered entities,” must still treat all the personal information of their clients/patients the same.   Other privacy obligations affecting the health care world are mandated from Sarbanes Oxley and Gramm-Leach-Bliley.   In some cases, the PCI Data Security standard may also apply.   Compliance with these three laws and the PCI Standard obligates a health care entity to take formal steps to implement reasonable privacy and security policies and procedures.    

The HIMSS report may reflect a gap between reasonable policies and procedures and practice.   Most healthcare facilities responding to HIMSS “indicated that their organization has a security policy in place. (p .4 of the report).”   The study continues that these policies are reviewed regularly and that “85 percent of respondents indicating that their policy was updated on an annual basis, if not more often. (p. 4 of the report).”

Yet, the report also indicates that employees are considered the greatest threat which could cause a data breach of patient information, (p. 6, p. 15 of the report).   The respondents indicated that even though part of new hire training involved security related matters, (95% of respondents) only 64% of the respondents require some form of on-going security training refreshing (p. 8).    On the surface, it is fair to conclude that health care facilities do not place much faith in their security training.   This is an area which could be addressed by implementing security mindedness to all areas of training and to every separate task performed in the facility.   Or as quoted by <?XML:NAMESPACE PREFIX = ST1 /> <?XML:NAMESPACE PREFIX = ST2 /> Brian Lapidus , Kroll Fraud Solutions Chief Operating Officer and survey sponsor in the press release:    

"There's a dangerous assumption in the healthcare industry that education leads to policy implementation and change," said Mr. Lapidus of Kroll." Best practices in data security cannot be achieved by employee training alone. Organizations must make data security a part of their DNA, reflected in every aspect of business operations."    

Maybe some of this detachment between policy and practice identified in the report can be traced to healthcare organizations focusing much of their security effort and resources on IT related security at the expense of employee training. Ninety seven percent (97%) of the respondents have implemented “Technical IT security” while only 70% have implemented formal education courses.   This disparity can be compared and contrasted to the actual reporting of how breaches occurred amongst the respondents.   The HIMSS results reveal that the health care management concern regarding employees is justified, with employee originated “unauthorized use of information” leading to 62% of all breaches followed by 32% of respondents blaming “wrongful access of paper-based patient information”, (pg. 18).    In addition, in response to the question “who was the perpetrator of the security breach?” 80% identified a current employee.   While improper release of PII or PHI may have originated with an employee 62% of the time only some of these occasions are likely the result of a blatant attempt to steal information and many of these are probably unintentional consequences of the busy and often demanding need to react with haste in a health care setting.         

Based upon this research, healthcare facilities and employers seem to understand what causes data breaches however address these concerns ineffectively.   A concentration on data security from the IT perspective is not addressing the fact that employees with authorized access to information, and causing breaches whether intentionally or unintentionally is the most significant threat to patient privacy and prevention of identity theft.     Better background screening and higher thresholds for new hires may address some of this problem.   The effort to implement a national health record access system may or may not solve this problem; however, such a solution may or may not make theft of information easier.   Healthcare management is left with the daunting task of figuring out what change is needed to that will prevent patient PII and PHI from being breached yet keep it accessible for those health care professionals who need it.   Based upon the HIMSS results, the policies and procedures at many of America ’s health care facilities need to be re-evaluated with a mind to stimulating a culture of data security.   A copy of the report can be downloaded at http://www.krollfraudsolutions.com/about-kroll/HIMSS-Patient-Data-Security-Study.aspx .

 

  • Enter your comment

  • #
     

    This test allows the site to decide whether you are human or a computer in order to protect Wikio from spam.

     

8 most recent articles from aprpeh

  • + Vote!

    Gaza Bombing Proves Israel is Right

    aprpeh | 01/02/2009 | World

      Gaza Bombing Proves Israel is Right Ha'aretz's Amira Hass pulls out the stiletto to take up the case of a poor, innocent Gaza resident, Ahmed Samur, who lost his son and business due to what Hass wants the reader to think is questionable targeting or error. Hass's information comes from 'B'tselem and the Mazan center for human rights'. There is a video of this strike which has been seen by many on  
  • + Vote!

    More- Dangers of Social Networking Sites

    aprpeh | 12/12/2008

      More- Dangers of Social Networking Sites  
  • 1 Vote!

    Her Inner Barracuda

    aprpeh | 10/03/2008

      Any questions about Governor Palin's ability to be in the big time spot light were put to rest last night. Gov. Palin succeeded in turning the tables on the main stream media's assault on her qualifications. Moderator Gwen Ifill, with wary eyes on her for not disclosing to the debate commission her forthcoming Obama book conflict of interest, behaved herself. As I was watching the much heralded debate  
  • 1 Vote!

    Employment Identity Theft and the IRS

    aprpeh | 07/15/2008 | Finance

      Ed Dickson at " "/url?id=64269208&url=D5-4380-128C2-" " FraudWar Blog reported on the IRS Taxpayer Advocate Service (TAS) Fiscal Year 2009 Objectives, report to Congress. The IRS has proposed improved processes to identify and manage consumer files where notification of identity theft has been previously made and fraud previously determined. " "/url?id=64269208&url=D5-4380-128C2-" " - Stolen Identities  
  • 1 Vote!

    The Role of Religion in Picking a President

    aprpeh | 07/10/2008 | US

      The Role of Religion in Picking a President  
  • 4 Vote!

    Barack Obama - Myths, Facts, and Obfuscating (Bloggers Beware)

    aprpeh | 06/25/2008 | Politics

      Is guilt by association fair? Many blogs and websites, including APRPEH have made an argument that Barry Obama 's true feelings towards Jews and Israel can be measured by his associations. Undeniable facts about Obama, many of them posed as questions left unanswered  
  • 3 Vote!

    Lifelock Getting Picked

    aprpeh | 04/01/2008 | Entertainment

      Lifelock Getting Picked Since February 2008, Lifelock, the company that guarantees that your identity will not be stolen has been hammered by legal problems. Lifelock charges consumers $10 a month for the privilege of allowing the company to manage your Fair Credit Reporting Act right to a free initial security alert and which automatically opts out a consumer from pre-approved credit offers for six  
  • 2 Vote!

    The Pros and Cons of a Credit Security Freeze

    aprpeh | 03/24/2008 | Finance

      Due to policy changes at the national credit repositories (Equifax, Experian, and Trans Union); American consumers are able to place a security freeze on their credit file. Before this policy change, only consumers in the 39 states where credit freeze laws had been passed could freeze their credit. Probably sensing pending Federal legislation, the slow big 3 decided (individually, of course - wink