Showing posts with label data security. Show all posts
Showing posts with label data security. Show all posts

Wednesday, April 10, 2013

Expert panel speaks about Hot Topics in Healthcare IT #HITCon13

Here at the HIMSS Southern California Chapter Health IT conference (Twitter hashtag #HITcon13), an expert panel discussed some of the key hot topics in health IT. The panel was moderated by Shadaab Kanwal, MISM, MBA, Executive Director, Research and Quality at Kaiser Permanente. Panelists included:
  • Aram Dobalian, JD, MPH, PhD, Director, Veterans Emergency Management Evaluation Center at Veterans Health Administration speaking about “HIE and EHR as enablers of Disaster Recovery”
  • Ralph Oyaga, Esq., MBA, Associate Counsel, LA Care Health Plan speaking about “e-Discovery”
  • Dale Sanders, SVP, Health Catalyst; Senior Technology Advisor, Cayman Islands Services Authority speaking about “Big Data and Predictive Analytics in Healthcare Transformation”
  • John McCawley, MS, CEO, Verecloud speaking about “Healthcare and the Cloud”
Dale reminded us that we are in an era of big data and predictive analytics. Hospitals and health systems are being graded by their level of adoption measured by the HIMSS Healthcare Analytic Adoption Model. We need to have a thorough understanding of these evolving technologies that are transforming healthcare so that we can use them effectively to improve patient care..

John spoke about how cloud computing technologies are rapidly changing the economic model of health IT. Cloud is a distribution model, not a technology. Public cloud. Private cloud. Hybrid cloud. The top 3 concerns regarding the cloud include: security, control, and reliability.

Aram spoke about disaster recovery. When we consider what happens during major disasters, the role of health IT becomes critical because we can't afford to lose access to patient data. We can see this with some examples within the VA Health System. When Hurricane Katrina hit, the New Orleans VA got flooded, damaging all the computer hardware within the hospital. In less than 3 days, all patient data were available and accessible at any VAMC.

Ralph spoke about the concept of e-Discovery in medicolegal cases. Consider all the emails that get transmitted by healthcare employees. Consider all the health records that are now stored in electronic format. We also can't forget the data generated from social media. So, when a medical case is investigated, we now have a wealth of data that is generated during the e-Discovery phase. Sifting and reviewing that data becomes a major challenge because of the volume of information.

You can follow updates from the HIMSS Southern California Chapter Health IT conference on Twitter: #HITcon13

Wednesday, November 3, 2010

Risk Analysis Focus Still Needed in Healthcare Organizations

The 3rd Annual Security Survey, sponsored by Intel and supported by the Medical Group Management Association, highlights differences in risk assessment and security control practices between hospitals and medical practices

CHICAGO (November 3, 2010) – In the year since the American Recovery and Reinvestment Act of 2009 passed, new meaningful use objectives have been identified for eligible hospitals (EH) and eligible providers (EP) to qualify for incentive funds, rules known as the Electronic Health Record Incentive Program were issued by the Centers for Medicare and Medicaid Services (CMS). One of these rules stipulates that eligible hospitals and eligible providers must protect electronic health information created or maintained by the electronic health record by conducting or reviewing a security risk analysis. And these organizations must implement necessary security updates and correct identified security deficiencies as part of the risk management process.

Wednesday, October 13, 2010

The 3 A's of IT Security

ScriptLogic is having a webinar titled, "The 3 A's of IT Security." What are those 3 A's?
  1. Assess
  2. Assign
  3. Audit
Before you can ensure security within your IT environment, you need to understand your current security (Assess). You then need to make changes to your security where it is appropriate (Assign). Finally, you need to monitor your security (Audit). It’s an endless cycle, so shouldn’t you have the solutions to make this possible?

During this webinar we will discuss how to:

* Report on current security permissions in your environment
* Identify and change over privileged user access from a simplified, centralized, console
* Track security changes and security issues in real-time

Title:"The 3 A's of IT Security"
Date: Thursday, October 14th, 2010
Time: 2:00 PM - 2:30 PM EST

Click here for more information.

Thursday, September 9, 2010

Wednesday, July 21, 2010

800,000 patient records missing?

How would you feel if your local doctor or hospital called you to say that a backup record of your digital medical record is missing? Huh?  I thought that the use of electronic health records of EHRs was supposed to improve patient care, enhance patient privacy, and reduce the risk of these types of problems. I suppose when you can cram 800,000 patient records into something really small (like a portable hard drive, a flash drive, or even a memory card), then it's feasible to "lose" such information easily.

The Boston Globe is reporting that: "Computer files from South Shore Hospital that contain personal information for about 800,000 people may have been lost when they were shipped to a contractor to be destroyed, hospital officials announced yesterday.... The information was on back-up files headed for destruction because they were in a format the hospital said it no longer used. Based on the investigation so far, the hospital said the files contained information on patients, employees, physicians, volunteers, donors, and other business partners associated with South Shore between Jan. 1, 1996, and Jan. 6 of this year."

You can read more here.

Do you still have some old computer backup files? Were you using tapes? Zip disks? CD-ROM? DVD-ROM? External hard drives? (Maybe you even have some important files on 3.5" floppy disks)

Some day, these technologies will be obsolete and you'll need a way to effectively getting rid of all this data.

Tuesday, April 13, 2010

Do we risk losing privacy by switching to electronic health records?

There are many people out there who fear that their medical data will be at greater risk for theft once we convert from a paper system to an electronic system. That's a legitimate fear. After all, we've heard many stories where hospitals and health clinics lost patient data when a laptop got stolen or when hackers infiltrated electronic medical databases. It's much more difficult for someone to break into a file room and dig out your paper medical chart.

Given that we now live in a digital era, we must leverage the latest data security measures to ensure patient privacy and data integrity. Sometimes I wonder if online health portals will have more robust IT security measures compared to online banking portals. What do you value more? Your health data privacy or your money in the bank?

It's good to know that researchers are constantly developing new ways to preserve patient privacy. Some are developing algorithms to protect the privacy of patient data while allowing clinical researchers to use the same patient data to answer clinical questions. Other companies are relying on biometric scanners like fingerprint readers and retina scanners to ensure that hackers are not able to "crack" your password and log in as you. 

As hospitals and medical offices switch to electronic health records this year, I hope that administrators and physicians are thinking about the importance of patient privacy as they handle all this electronic patient data.

Wednesday, April 7, 2010

Kroll-HIMSS Analytics on Security of Patient Data

Interested in learning more about patient data security?  Kroll Fraud Solutions has some free resources that can help. First, there's a webcast coming up on April 15 called the "Kroll-HIMSS Analytics 2010 Webcast on Security of Patient Data." The webcast will cover:
  • Patient data security practices in place
  • Patient data safety risks
  • Resources allocated to patient data safety, and costs associated with data breaches
Here are the webcast presenters:
* Jennifer K. Horowitz, MA, CPHIMS, Senior Director of Research, HIMSS Analytics
* Lisa A. Gallagher, BSEE, CISM, Senior Director, Privacy and Security, HIMSS
* Brian Klepper, Managing Principal, Healthcare Performance, Inc.
* Brian Lapidus, Chief Operating Officer, Kroll's Fraud Solutions

Click here to learn more about the webcast.

Kroll has also recently published a report called the "2010 HIMSS Analytics Report: Security of Patient Data." The 2010 HIMSS Analytics Report indicates that a false sense of security among healthcare providers – brought on by new regulations and increased compliance – is causing organizations to overlook critical gaps in policies and procedures that put patient data at risk. The report, which surveys healthcare organizations nationwide, was commissioned by Kroll Fraud Solutions.

Key findings of the 2010 report include:
  •  New regulatory activity, including the implementation of the Red Flags Rule and HITECH Act, has created a false sense of security among healthcare organizations that their facilities are secure and prepared should a breach occur.
  •  Healthcare organizations continue to underestimate the high costs of a data breach, despite new industry data which puts the average cost per industry data breach at $6.75 million.
  •  Healthcare organizations continue to think of data security in specific silos (IT, employees, etc.) and not as an organization-wide responsibility, which creates unwanted gaps in policies and procedures.
Kroll Fraud Solutions is a leading provider of data protection and identity theft response services.

Friday, November 20, 2009

Are we ready for HITECH's security breach notification rules?


There are some out there who will argue that we are not ready for HITECH's security breach notification rules. Consider this recent story on Healthcare IT News, titled, "Survey: Healthcare isn't ready for HITECH's security breach notification rules"

In that report, we see that the results of a national survey found that:
  • 50 percent of large hospitals have experienced at least one data breach this year;
  • 68 percent of all hospitals indicated that the HITECH Act's expanded breach notification requirements will result in the discovery and reporting of more incidents, and 57 percent reported that they now have a greater level of awareness of data breaches and breach risk; and
  • 90 percent indicated they have changed or plan to change policies and procedures to prevent and detect data breaches.
Data breaches are not declining. They are increasing. If your system is not secure, then you are at tremendous risk for a data breach. Don't put your patients at risk.

Wednesday, October 28, 2009

Yahoo e-mail accounts are getting hacked


Have you seen some strange looking e-mails from people who use Yahoo e-mail? Over the past few months, two of my associates have had some hack into their Yahoo e-mail accounts. The hackers are sending SPAM to everyone in the address books. The e-mails are simple: a short hyperlink (who knows where it goes. I didn't click on it)

This recent phenomenon reminds me of my Facebook story.
If you're not using a secure and unique password on all your online accounts, then you're setting yourself up for problems in the future. It's only a matter of time before some hacker decides to hack into your e-mail account. Don't let that happen. Make sure to always use a secure and unique password on all your accounts, especially in those that deal with personal and sensitive information and financial access.

Monday, October 19, 2009

Blue Cross and Blue Shield Association Data Breach Alert

If you're a physician, you should be aware that your personal data may have been compromised recently due to a laptop theft. A simple crime can cause a significant amount of havoc when the stolen device contains extremely sensitive information like social security numbers and other personal identifiers. The Blue Cross and Blue Shield Association (BCBSA) sent a notice to physicians, but many really don't understand what they're supposed to do.

My suggestion would be the following:
  • Check your credit ASAP
  • Enroll in an identity theft protection program (credit monitoring services)
  • Monitor your credit each year
You may be at risk if you don't do anything. If that laptop ends up in the wrong hands, then your personal information could be vulnerable. We can't make any assumptions when laptops get stolen.

Tuesday, August 25, 2009

This is what happens if your health data gets breached


If your health data gets breached, do you know what could happen? So many patient records are becoming digitized as more providers and hospitals rely on electronic health records (EHRs) instead of paper medical charts. Recently, the Department of Health and Human Services issued new regulations regarding the notification of patients if their electronic health information gets breached. The FTC (Federal Trade Commission) also issued final rules about how consumers ought to be notified when electronic personal health record (PHR) information gets compromised.

We hear so many stories about hospitals, clinics, and health plans having problems with data security. Highly experienced can probably break into most hospitals and health plans and compromise health data.

Under the HITECH provisions within ARRA, the Department of Health and Human Services has to perform research on privacy, security and breach-notification requirements for PHR vendors. Let's see what happens with Google Health and Microsoft Health Vault. If you keep your personal health information online, do you feel confident that it's safe and secure?

Thursday, August 6, 2009

419 Scam on Facebook


If you're on Facebook, make sure to never give (or send) money to anyone who solicits money from you. Last month, my Facebook account got compromised and someone logged into my account and started soliciting money from my list of friends. Most of my contacts were aware of the "419 scam" so they quickly disconnected. Allow me summarize by quoting CBS5 news:
Facebook has a name for the latest scam, it's called the "419" scam and works like this: A hacker takes over a users' identity and sends messages to the users' friends. The messages claim that the user is stuck in London or another foreign city, after being mugged of their cash, credit cards and phone and requests friends to wire money so the user can get back home.
You may think that people are familiar with the 419 scam on Facebook, but I'm sure you'll find people who have no idea what you're talking about. Therefore, I hope you'll join me in raising public awareness about these types of dangerous scams on Facebook.

Related posts:

Thursday, July 30, 2009

Tips on managing online passwords

My wife and I have had had several discussions about Internet security and online passwords. Why? Because my Facebook account got hacked over the weekend. We probably all know that accounts can get hacked, but can you imagine the headache if your accounts shared the same passwords? What if you couldn't get into your e-mail account anymore? What if you couldn't access your online banking accounts? (that wasn't the case in my situation, so I didn't lose control of my e-mail, blogging, Twitter, LinkedIn, eBay, PayPal, or any of my bank accounts. I was able to send a Tweet to all my followers to warn them about my Facebook situation).

If you have a common password that protects your personal health record (PHR), then you could be exposing yourself to potential hackers. Do you consider your health record more important than your banking accounts?

Many of us have a variety of online accounts. Do you use the same password on several accounts? You're putting yourself at grave risk if you do that. I admit that there was a time when I used a few passwords among different accounts. However, I now have unique passwords for every account and I use a systematic approach so that I can easily remember every one.

Allow me to share a few Internet security tips:
  • Never use the same password on multiple accounts. This may lead to someone hacking your Facebook account and then eventually getting access into other things (like your bank account, PayPal, credit card accounts, etc.)
  • Never use a dictionary word as your password. Using "wojljsdflkwe" is better than that any word that would appear in a dictionary.
  • Never use numbers that reflect your personal profile. Don't use numbers that may reflect your birthday, your address, your phone #, etc.
How can you systematically create a unique password for each website so that you can remember your password easily?

Suppose you really like the word "Amazon" as your password. It's 6 characters, so it works as a password on many websites. Let's see how we can use this word to create unique passwords for 3 different websites. We'll use the unique letter(s), common number(s), common word technique. This is a very basic technique that works quite well if you're a newbie at this.
  1. The unique letter(s) is based on the name of the website. Choose the 3rd and last letters of the website title as your unique letters and this becomes the first few letters of your password.
  2. Choose a common number. Let's choose 16 (legal driving age). This is the second component of your password.
  3. Choose a common word. Let's choose "zamazon" (I love to shop on Amazon, but we don't want to use a word that can be found in the dictionary, so we'll add a "z" to amazon). This becomes the end of your password.
When you combine these elements, we end up with 3 unique passwords for the following 3 websites:
  1. Paypal: the password would be "yl16zamazon" (y = 3rd letter; l = last letter)
  2. Chase: the password would be "ae16zamazon" (a = 3rd letter; e = last letter)
  3. Google: the password would be "oe16zamazon" (o = 3rd letter; e = last letter)
You can get really creative using this technique and you can develop unique password patterns for every website that you visit. You could end with your unique letters. You could flank your common numbers/letters around your unique letters. You could also choose different patterns for different types of websites. For instance, for banking sites, you may choose to start with the common number and end with the unique letters. For social networking sites, you may want to use the method in reverse (or change your common # or letter). You may want to have one common word for websites that start with a vowel and a different common word for websites that start in a consonant. Once you have a series of consistent patterns, you only need to remember your common number(s) and common word(s). This can reduce your risk for password theft which could lead to identity theft and a series of other major headaches. If you're married, you don't have to share your actual passwords with your spouse. You simply have to explain your method and share your common words/numbers. Let your spouse go through the exercise of coming up with a method. Sounds like fun, doesn't it?

Tuesday, July 28, 2009

Reflections on a compromised Facebook account


My personal encounter with a compromised Facebook account has taught me several (OK, maybe more than several) things:
  • Too many people use common passwords on the Internet. As a result, it can make it easy for people to "hack" into one account and then gain access to many others.
  • I used to get annoyed at banking accounts that asked you to answer a security question whenever I tried to log in using a different computer. Now, I'm grateful for that level of security and I hope that more sites (like Facebook) will adopt a higher level of Internet security.
  • You don't have to click on any phishing links to become a victim.
  • I used to have several common passwords for various websites. I didn't use a single password on more than a few sites and some were considered "low security" passwords while others were more complex and for those "higher security" sites like bank accounts. Now, thanks to my brilliant wife, I have a unique password for every website and I'm using a logical system that helps me remember each one so that I don't have to write them down anywhere. Don't worry, I'm no longer using the same password on my Facebook account.
  • There are still many people out there who are unaware of scams on Facebook (like the common story of being stranded in London or needing money for some other reason). Hence, there is a need to tell others about potential scams on Facebook.
Well, that's about it for now. I'm back on Facebook. I only lost control of the account for a few hours and I'm grateful for all my friends who reached out to me during that crazy period. I'm just glad that I wasn't on vacation when all this happened.

Sunday, July 26, 2009

My Facebook account got hacked!


Like many others, my Facebook account got hacked last night and I received many messages and phone calls about it. Just to be clear: I'm not stuck in London and I don't need money for a flight back home. This line has been used by scammers who've been using Facebook to steal money from people.

It's really a shame, but I now know so many people who have experienced similar problems with their Facebook accounts. If you'd like to learn more about compromised Facebook accounts, then I encourage you to read this article from the Business Insider.

I'm positive that I didn't click on any type of phishing links, so this hacker got into my account some other way. Fortunately, since I use different passwords for my other accounts, I was able to post messages using Twitter, LinkedIn, Plaxo, and several other social media outlets. Never use the same password for multiple accounts! You don't want to lose control of things like your e-mail account, your bank and credit card accounts, etc.

Tuesday, May 12, 2009

Health Data Hacked at UC Berkeley


This doesn't sound good. Data security breaches are occurring all over the country (see: Hacked: Medical Data on 8 Million Virginia Residents)

Hackers (or maybe there's just one hacker) have compromised personal health information on over 160,000 individuals at the University of California Berkeley. The hackers attacked restricted computer databases in the campus' health service center and probably gained access to personally identifiable information used for billing, such as Social Security numbers, and non-treatment medical information such as immunization history, UHS medical record numbers, dates of visits or names of providers seen. Image source: Health IT News

Wednesday, May 6, 2009

Hacked: Medical Data on 8 Million Virginia Residents

Healthcare IT News reports that confidential healthcare data on 8 million Virginia residents may be compromised. Hacked! Here's a tiny excerpt:
  • "The Virginia Department of Health Professions Web site has been temporarily disabled and now features a notice saying the site is "experiencing technical difficulties which affect computer and email systems." According to the department's director, Sandra Whitley Ryals, the breach is under federal investigation."
This does not sound good. 8,257,378 patient records and a total of 35,548,087 prescriptions may be compromised.