A look back at some of the best news stories (and some entertaining diversions) from the week in health care.
________________
"The number of medically disenfranchised has reached 60 million" according to a report from the National Association of Community Health Centers.
David Blumenthal, the new National Coordinator for Health Information Technology, weighs in on stimulating the adoption of health information technology. John Glaser will join David Blumenthal as an ONC advisor for 6 months, while retaining his role at Partners Healthcare.
Dr. Ashish Jha talks about the conversion to electronic medical records in this NPR interview. He found that "comprehensive" EHR systems are used by only 1.5% of hospitals and only 7.6% of hospitals have a "basic" EHR.
The California HealthCare Foundation releases a report on patient registration kiosks delivering value and increased patient satisfaction. Yet they are adopted by less than 10% of healthcare organizations.
Drs. Bates, Halamka and Middleton make the case for the effectiveness of healthcare technology.
Will IT Save Healthcare? on National Public Radio's "To the Point".
Can technology enable patients to be better advocates for their own care? The Wall Street Journal reports on how patients use "information therapy".
CCHIT plans to accelerate advanced technology certification programs in Clinical Decision Support, Interoperability, Quality and Security in order to better align with the objectives in the ARRA stimulus package.
Showing posts with label HIPAA Security. Show all posts
Showing posts with label HIPAA Security. Show all posts
Thursday, March 26, 2009
Sunday, November 2, 2008
ePHI at high risk
On October 27, the Office of the Inspector General (OIG) released their report on HIPAA Security and Electronic Protected Health Information (ePHI) compliance. The findings include:
CMS's office of e-Health Standards and Services has published the Interview and Document Request for HIPAA Security Onsite Investigations and Compliance Reviews. The audits will review policies, procedures and other evidence related to:
- Security audits in 7 hospitals nationwide show numerous, significant vulnerabilities in the administrative, technical and physical safeguard provisions of the HIPAA Security Rule.
- These vulnerabilities place the confidentiality and integrity of ePHI at high risk.
- As a result, CMS has executed a contract to conduct compliance reviews.
CMS's office of e-Health Standards and Services has published the Interview and Document Request for HIPAA Security Onsite Investigations and Compliance Reviews. The audits will review policies, procedures and other evidence related to:
- Prevention, detection, containment, and correction of security violations
- Employee background checks and confidentiality agreements
- Establishing user access for new and existing employees
- List of authentication methods used to identify users authorized to access EPHI
- List of individuals and contractors with access to EPHI to include copies pertinent business associate agreements
- List of software used to manage and control access to the Internet
- Detecting, reporting, and responding to security incidents (if not in the security plan)
- Physical security
- Encryption and decryption of EPHI
- Mechanisms to ensure integrity of data during transmission - including portable media transmission (i.e. laptops, cell phones, blackberries, thumb drives)
- Monitoring systems use - authorized and unauthorized
- Use of wireless networks
- Granting, approving, and monitoring systems access (for example, by level, role, and job function)
- Sanctions for workforce members in violation of policies and procedures governing EPHI access or use
- Termination of systems access
- Session termination policies and procedures for inactive computer systems
- Policies and procedures for emergency access to electronic information systems
- Password management policies and procedures
- Secure workstation use (documentation of specific guidelines for each class of workstation (i.e., on site, laptop, and home system usage)
- Disposal of media and devices containing EPHI
- Entity-wide Security Plan
- Risk Analysis (most recent)
- Risk Management Plan (addressing risks identified in the Risk Analysis)
- Security violation monitoring reports
- Vulnerability scanning plans and Results from most recent vulnerability scan
- Network penetration testing policy and procedure and results from most recent network penetration test
- List of all user accounts with access to systems which store, transmit, or access EPHI (for active and terminated employees)
- Configuration standards to include patch management for systems which store, transmit, or access EPHI (including workstations)
- Encryption or equivalent measures implemented on systems that store, transmit, or access EPHI
- Organization chart to include staff members responsible for general HIPAA compliance to include the protection of EPHI
- Examples of training courses or communications delivered to staff members to ensure awareness and understanding of EPHI policies and procedures (security awareness training)
- Policies and procedures governing the use of virus protection software
- Data backup procedures
- Disaster recovery plan
- Disaster recovery test plans and results
- Analysis of information systems, applications, and data groups according to their criticality and sensitivity
- Inventory of all information systems to include network diagrams listing hardware and software used to store, transmit or maintain EPHI
- List of all Primary Domain Controllers (PDC) and servers
- Inventory log recording the owner and movement media and devices that contain EPHI
Subscribe to:
Posts (Atom)



