Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, April 10, 2013

Expert panel speaks about Hot Topics in Healthcare IT #HITCon13

Here at the HIMSS Southern California Chapter Health IT conference (Twitter hashtag #HITcon13), an expert panel discussed some of the key hot topics in health IT. The panel was moderated by Shadaab Kanwal, MISM, MBA, Executive Director, Research and Quality at Kaiser Permanente. Panelists included:
  • Aram Dobalian, JD, MPH, PhD, Director, Veterans Emergency Management Evaluation Center at Veterans Health Administration speaking about “HIE and EHR as enablers of Disaster Recovery”
  • Ralph Oyaga, Esq., MBA, Associate Counsel, LA Care Health Plan speaking about “e-Discovery”
  • Dale Sanders, SVP, Health Catalyst; Senior Technology Advisor, Cayman Islands Services Authority speaking about “Big Data and Predictive Analytics in Healthcare Transformation”
  • John McCawley, MS, CEO, Verecloud speaking about “Healthcare and the Cloud”
Dale reminded us that we are in an era of big data and predictive analytics. Hospitals and health systems are being graded by their level of adoption measured by the HIMSS Healthcare Analytic Adoption Model. We need to have a thorough understanding of these evolving technologies that are transforming healthcare so that we can use them effectively to improve patient care..

John spoke about how cloud computing technologies are rapidly changing the economic model of health IT. Cloud is a distribution model, not a technology. Public cloud. Private cloud. Hybrid cloud. The top 3 concerns regarding the cloud include: security, control, and reliability.

Aram spoke about disaster recovery. When we consider what happens during major disasters, the role of health IT becomes critical because we can't afford to lose access to patient data. We can see this with some examples within the VA Health System. When Hurricane Katrina hit, the New Orleans VA got flooded, damaging all the computer hardware within the hospital. In less than 3 days, all patient data were available and accessible at any VAMC.

Ralph spoke about the concept of e-Discovery in medicolegal cases. Consider all the emails that get transmitted by healthcare employees. Consider all the health records that are now stored in electronic format. We also can't forget the data generated from social media. So, when a medical case is investigated, we now have a wealth of data that is generated during the e-Discovery phase. Sifting and reviewing that data becomes a major challenge because of the volume of information.

You can follow updates from the HIMSS Southern California Chapter Health IT conference on Twitter: #HITcon13

Friday, June 1, 2012

2nd International Summit on the Future of Health Privacy

Where is health privacy going in the digital era? How well do all the stakeholders understand HIPAA in the world of digital media and mobile technology?

Don't miss the upcoming 2nd International Summit on the Future of Health Privacy. Join national and international experts on health privacy, technology, and law; patient advocates; industry experts and top government officials to discuss today's most urgent health privacy issues.

When: Wednesday, June 6, 2012 - Thursday, June 7, 2012

Where: Webinar + Georgetown Law Center in Washington, DC 20001

Learn more and register for the live event or webcast here.

Thursday, January 6, 2011

Biometric Authentication that Meets HIPPA / HITECH Requirements

Does your biometric authentication system work on a gloved finger? I'm sharing this press release about biometric authentication. Lumidigm biometrics products, which provide fingerprint access even when wearing clear surgical gloves, are the solution for hospitals that spend $100 to $200 per employee per year supporting password-based systems — and even more for token- or card-based systems — while trying to ensure the protection and safety of patient information. The Lumidigm fingerprint solution will be featured in Booth #5242 at the HIMSS11 Exhibition to be held February 21-23 at the Orange County Convention Center in Orlando, FL.

Lumidigm Showcasing Biometric Authentication that Ensures Meeting HIPPA / HITECH Requirements at HIMSS11

No Passwords, No Tokens… Provides Secure Access Via the Touch of a Finger, Even When Gloved!

ALBUQUERQUE, NM – January 6, 2011 – Lumidigm today announced that its biometrics products, which provide fingerprint access even when wearing clear surgical gloves, are the solution for hospitals that spend $100 to $200 per employee per year supporting password-based systems — and even more for token- or card-based systems — while trying to ensure the protection and safety of patient information. The Lumidigm fingerprint solution will be featured in Booth #5242 at the HIMSS11 Exhibition to be held February 21-23 at the Orange County Convention Center in Orlando, Fla.

Sunday, November 28, 2010

TSA security and medical privacy - where do we draw the line?

Two recent stories related to the new TSA security procedures have been on my mind recently. First, the story of Tom Sawyer, a 61-year-old retired special education teacher. He is a bladder cancer survivor who wears a urostomy to catch his urine. During a routine "pat-down," the TSA agent broke the seal of the urostomy, covering Sawyer in urine. "I was just so embarrassed, so humiliated," Sawyer also told The Detroit Free Press. The head of the TSA John Pistole apologized to Sawyer and Sawyer has graciously accepted the apology.

Now, what if that wasn't a urostomy bag? What if it was a colostomy bag instead? I'm sure everyone on the flight would have appreciated that.

Then, there's the story of Cathy Bossi, a flight attendant who has a removable breast prosthesis because she's a breast cancer survivor. During her screening, this is what happened:
She says two female Charlotte T.S.A. agents took her to a private room and began what she calls an aggressive pat down. She says they stopped when they got around to feeling her right breast… the one where she'd had surgery."She put her full hand on my breast and said, 'What is this?'. And I said, 'It's my prosthesis because I've had breast cancer.' And she said, 'Well, you'll need to show me that'." Bossi was asked to show her prosthetic breast, sticking her hand down her own shirt and removing the prosthesis from her bra.
Will we continue to hear more crazy stories from travelers who have a history of cancer?

Then there's the story of Amy Ascher Linde, an Atlanta mother and businesswoman who was born without a left hand and has worn a prosthetic since she was 11. For her to remove her prosthetic hand, she'd have to remove a significant amount of clothing.

Finally, there's the question of TSA agents patting down kids. Although some kids may not mind the pat down, others may have a history of sexual abuse and these types of pat-downs by strangers could trigger significant emotional trauma. I'm not sure what constitutes an "aggressive" pat-down vs. a regular pat down.

Wednesday, November 3, 2010

Risk Analysis Focus Still Needed in Healthcare Organizations

The 3rd Annual Security Survey, sponsored by Intel and supported by the Medical Group Management Association, highlights differences in risk assessment and security control practices between hospitals and medical practices

CHICAGO (November 3, 2010) – In the year since the American Recovery and Reinvestment Act of 2009 passed, new meaningful use objectives have been identified for eligible hospitals (EH) and eligible providers (EP) to qualify for incentive funds, rules known as the Electronic Health Record Incentive Program were issued by the Centers for Medicare and Medicaid Services (CMS). One of these rules stipulates that eligible hospitals and eligible providers must protect electronic health information created or maintained by the electronic health record by conducting or reviewing a security risk analysis. And these organizations must implement necessary security updates and correct identified security deficiencies as part of the risk management process.

Wednesday, October 13, 2010

The 3 A's of IT Security

ScriptLogic is having a webinar titled, "The 3 A's of IT Security." What are those 3 A's?
  1. Assess
  2. Assign
  3. Audit
Before you can ensure security within your IT environment, you need to understand your current security (Assess). You then need to make changes to your security where it is appropriate (Assign). Finally, you need to monitor your security (Audit). It’s an endless cycle, so shouldn’t you have the solutions to make this possible?

During this webinar we will discuss how to:

* Report on current security permissions in your environment
* Identify and change over privileged user access from a simplified, centralized, console
* Track security changes and security issues in real-time

Title:"The 3 A's of IT Security"
Date: Thursday, October 14th, 2010
Time: 2:00 PM - 2:30 PM EST

Click here for more information.

Thursday, September 9, 2010

Wednesday, July 21, 2010

800,000 patient records missing?

How would you feel if your local doctor or hospital called you to say that a backup record of your digital medical record is missing? Huh?  I thought that the use of electronic health records of EHRs was supposed to improve patient care, enhance patient privacy, and reduce the risk of these types of problems. I suppose when you can cram 800,000 patient records into something really small (like a portable hard drive, a flash drive, or even a memory card), then it's feasible to "lose" such information easily.

The Boston Globe is reporting that: "Computer files from South Shore Hospital that contain personal information for about 800,000 people may have been lost when they were shipped to a contractor to be destroyed, hospital officials announced yesterday.... The information was on back-up files headed for destruction because they were in a format the hospital said it no longer used. Based on the investigation so far, the hospital said the files contained information on patients, employees, physicians, volunteers, donors, and other business partners associated with South Shore between Jan. 1, 1996, and Jan. 6 of this year."

You can read more here.

Do you still have some old computer backup files? Were you using tapes? Zip disks? CD-ROM? DVD-ROM? External hard drives? (Maybe you even have some important files on 3.5" floppy disks)

Some day, these technologies will be obsolete and you'll need a way to effectively getting rid of all this data.

Thursday, May 20, 2010

Doctors using alias names on Facebook

I know several doctors who're on Facebook, but they're using an alias instead of their real names. Why?  They want to maximize their privacy from their patients.

Isn't it ironic? Patients worry about privacy because they're divulging all their medical information. Physicians also want privacy from their patients so that their patients aren't calling their cell phones or stalking them at home.

We live in a world where everyone wants privacy, even on Facebook. You can be on Facebook but you can stay off the search radar. That means that people can't find you even if they search for you on Facebook. For some doctors, that's simply not enough. They'd rather use an alias so they can stay connected with close friends and family. They want to see photos of family members. They want to write on someone's wall. But, they want maximum privacy.

So, as Facebook updates its privacy settings, more physicians may simply choose to use an alias so that they can stay off the grid. Sounds simple, doesn't it?

Tuesday, April 13, 2010

Do we risk losing privacy by switching to electronic health records?

There are many people out there who fear that their medical data will be at greater risk for theft once we convert from a paper system to an electronic system. That's a legitimate fear. After all, we've heard many stories where hospitals and health clinics lost patient data when a laptop got stolen or when hackers infiltrated electronic medical databases. It's much more difficult for someone to break into a file room and dig out your paper medical chart.

Given that we now live in a digital era, we must leverage the latest data security measures to ensure patient privacy and data integrity. Sometimes I wonder if online health portals will have more robust IT security measures compared to online banking portals. What do you value more? Your health data privacy or your money in the bank?

It's good to know that researchers are constantly developing new ways to preserve patient privacy. Some are developing algorithms to protect the privacy of patient data while allowing clinical researchers to use the same patient data to answer clinical questions. Other companies are relying on biometric scanners like fingerprint readers and retina scanners to ensure that hackers are not able to "crack" your password and log in as you. 

As hospitals and medical offices switch to electronic health records this year, I hope that administrators and physicians are thinking about the importance of patient privacy as they handle all this electronic patient data.

Wednesday, April 7, 2010

Kroll-HIMSS Analytics on Security of Patient Data

Interested in learning more about patient data security?  Kroll Fraud Solutions has some free resources that can help. First, there's a webcast coming up on April 15 called the "Kroll-HIMSS Analytics 2010 Webcast on Security of Patient Data." The webcast will cover:
  • Patient data security practices in place
  • Patient data safety risks
  • Resources allocated to patient data safety, and costs associated with data breaches
Here are the webcast presenters:
* Jennifer K. Horowitz, MA, CPHIMS, Senior Director of Research, HIMSS Analytics
* Lisa A. Gallagher, BSEE, CISM, Senior Director, Privacy and Security, HIMSS
* Brian Klepper, Managing Principal, Healthcare Performance, Inc.
* Brian Lapidus, Chief Operating Officer, Kroll's Fraud Solutions

Click here to learn more about the webcast.

Kroll has also recently published a report called the "2010 HIMSS Analytics Report: Security of Patient Data." The 2010 HIMSS Analytics Report indicates that a false sense of security among healthcare providers – brought on by new regulations and increased compliance – is causing organizations to overlook critical gaps in policies and procedures that put patient data at risk. The report, which surveys healthcare organizations nationwide, was commissioned by Kroll Fraud Solutions.

Key findings of the 2010 report include:
  •  New regulatory activity, including the implementation of the Red Flags Rule and HITECH Act, has created a false sense of security among healthcare organizations that their facilities are secure and prepared should a breach occur.
  •  Healthcare organizations continue to underestimate the high costs of a data breach, despite new industry data which puts the average cost per industry data breach at $6.75 million.
  •  Healthcare organizations continue to think of data security in specific silos (IT, employees, etc.) and not as an organization-wide responsibility, which creates unwanted gaps in policies and procedures.
Kroll Fraud Solutions is a leading provider of data protection and identity theft response services.

Friday, November 20, 2009

Are we ready for HITECH's security breach notification rules?


There are some out there who will argue that we are not ready for HITECH's security breach notification rules. Consider this recent story on Healthcare IT News, titled, "Survey: Healthcare isn't ready for HITECH's security breach notification rules"

In that report, we see that the results of a national survey found that:
  • 50 percent of large hospitals have experienced at least one data breach this year;
  • 68 percent of all hospitals indicated that the HITECH Act's expanded breach notification requirements will result in the discovery and reporting of more incidents, and 57 percent reported that they now have a greater level of awareness of data breaches and breach risk; and
  • 90 percent indicated they have changed or plan to change policies and procedures to prevent and detect data breaches.
Data breaches are not declining. They are increasing. If your system is not secure, then you are at tremendous risk for a data breach. Don't put your patients at risk.

Wednesday, October 28, 2009

Yahoo e-mail accounts are getting hacked


Have you seen some strange looking e-mails from people who use Yahoo e-mail? Over the past few months, two of my associates have had some hack into their Yahoo e-mail accounts. The hackers are sending SPAM to everyone in the address books. The e-mails are simple: a short hyperlink (who knows where it goes. I didn't click on it)

This recent phenomenon reminds me of my Facebook story.
If you're not using a secure and unique password on all your online accounts, then you're setting yourself up for problems in the future. It's only a matter of time before some hacker decides to hack into your e-mail account. Don't let that happen. Make sure to always use a secure and unique password on all your accounts, especially in those that deal with personal and sensitive information and financial access.

Thursday, September 3, 2009

Physicians, patients, and social media (Facebook)


What happens if your patient finds your profile on Facebook and requests to be your friend? What if your patient follows you on Twitter? Have you thought about how social media may impact physician-patient relationships? There's an interesting story on CNN about this topic. In that story, the president of the AMA, Dr. J. James Rohack, is quoted as saying: "Communicating with existing patients online can add value to the patient-physician relationship, however there are certain aspects of medical care that cannot be handled virtually."

There have been many recent stories where patients have looked for their physicians on Facebook. Before you know it, your patient may have access to a lot of your personal information. Phone #, e-mail address, contact list, address, etc. Do you really want your patients to know all of this? Doctors need their privacy too. If you're a single physician, do you want your patients to know that you're single and "Looking for Dating/Relationship" on Facebook?

In the New England Journal of Medicine (NEJM), Sachin H. Jain, M.D., M.B.A. (an intern at the time of writing this article) writes a perspective about "Practicing Medicine in the Age of Facebook." Click here to read the NEJM article. He shares some of his personal experiences about this social media tool and perhaps you may have some stories to share as well.

Tuesday, August 25, 2009

This is what happens if your health data gets breached


If your health data gets breached, do you know what could happen? So many patient records are becoming digitized as more providers and hospitals rely on electronic health records (EHRs) instead of paper medical charts. Recently, the Department of Health and Human Services issued new regulations regarding the notification of patients if their electronic health information gets breached. The FTC (Federal Trade Commission) also issued final rules about how consumers ought to be notified when electronic personal health record (PHR) information gets compromised.

We hear so many stories about hospitals, clinics, and health plans having problems with data security. Highly experienced can probably break into most hospitals and health plans and compromise health data.

Under the HITECH provisions within ARRA, the Department of Health and Human Services has to perform research on privacy, security and breach-notification requirements for PHR vendors. Let's see what happens with Google Health and Microsoft Health Vault. If you keep your personal health information online, do you feel confident that it's safe and secure?

Thursday, August 6, 2009

419 Scam on Facebook


If you're on Facebook, make sure to never give (or send) money to anyone who solicits money from you. Last month, my Facebook account got compromised and someone logged into my account and started soliciting money from my list of friends. Most of my contacts were aware of the "419 scam" so they quickly disconnected. Allow me summarize by quoting CBS5 news:
Facebook has a name for the latest scam, it's called the "419" scam and works like this: A hacker takes over a users' identity and sends messages to the users' friends. The messages claim that the user is stuck in London or another foreign city, after being mugged of their cash, credit cards and phone and requests friends to wire money so the user can get back home.
You may think that people are familiar with the 419 scam on Facebook, but I'm sure you'll find people who have no idea what you're talking about. Therefore, I hope you'll join me in raising public awareness about these types of dangerous scams on Facebook.

Related posts:

Tuesday, July 28, 2009

Reflections on a compromised Facebook account


My personal encounter with a compromised Facebook account has taught me several (OK, maybe more than several) things:
  • Too many people use common passwords on the Internet. As a result, it can make it easy for people to "hack" into one account and then gain access to many others.
  • I used to get annoyed at banking accounts that asked you to answer a security question whenever I tried to log in using a different computer. Now, I'm grateful for that level of security and I hope that more sites (like Facebook) will adopt a higher level of Internet security.
  • You don't have to click on any phishing links to become a victim.
  • I used to have several common passwords for various websites. I didn't use a single password on more than a few sites and some were considered "low security" passwords while others were more complex and for those "higher security" sites like bank accounts. Now, thanks to my brilliant wife, I have a unique password for every website and I'm using a logical system that helps me remember each one so that I don't have to write them down anywhere. Don't worry, I'm no longer using the same password on my Facebook account.
  • There are still many people out there who are unaware of scams on Facebook (like the common story of being stranded in London or needing money for some other reason). Hence, there is a need to tell others about potential scams on Facebook.
Well, that's about it for now. I'm back on Facebook. I only lost control of the account for a few hours and I'm grateful for all my friends who reached out to me during that crazy period. I'm just glad that I wasn't on vacation when all this happened.

Sunday, July 26, 2009

My Facebook account got hacked!


Like many others, my Facebook account got hacked last night and I received many messages and phone calls about it. Just to be clear: I'm not stuck in London and I don't need money for a flight back home. This line has been used by scammers who've been using Facebook to steal money from people.

It's really a shame, but I now know so many people who have experienced similar problems with their Facebook accounts. If you'd like to learn more about compromised Facebook accounts, then I encourage you to read this article from the Business Insider.

I'm positive that I didn't click on any type of phishing links, so this hacker got into my account some other way. Fortunately, since I use different passwords for my other accounts, I was able to post messages using Twitter, LinkedIn, Plaxo, and several other social media outlets. Never use the same password for multiple accounts! You don't want to lose control of things like your e-mail account, your bank and credit card accounts, etc.

Tuesday, March 10, 2009

RelayHealth


If you've been keeping up with the Personal Health Record (PHR) industry, then you'll be very familiar with RelayHealth. RelayHealth provides a secure way for patients and doctors to communicate online. It's been linked with Microsoft HealthVault and offers a way for patients to get access to their personal health records as well. Google Health is another PHR provider that has been gaining a lot of traction recently.

Friday, February 27, 2009

Fingerprint Laptop Security


More and more business laptops, tablets, and other mobile devices have built-in biometric fingerprint scanners. They actually work amazingly well. My Lenovo Thinkpad X200 tablet has this scanner and I use it to log into Windows. I can also use this fingerprint scanner to store all my other passwords. My old tiny Fujitsu Lifebook p1610 also had a fingerprint scanner and the Samsung Q1 Ultra UMPC comes with a scanner.