Showing posts with label HIPAA Security. Show all posts
Showing posts with label HIPAA Security. Show all posts

I thought I would share this post from Anne Zieger, Editor at EHRoutlook.com

By: Anne Zieger
09.22.2011
Yesterday, I shared some statistics suggesting that not only are patients afraid that their electronic health data will be stolen, they're likely to drop your practice and even tell others not to visit you if they experience a security breach. Today, I bring you a real life reminder that medical practices do indeed get targeted for such attacks, even though they might have much less information to be stolen than, say, a medium-sized hospital.

A few months ago, a Birmingham, AL orthodontics practice reported that someone broke into its office and stole a bunch of equipment, including a server stocked with information on patients going back 30 years. The information included some dangerous stuff, including names and addresses of patients, Social Security numbers and at least some credit card numbers. The break in affected 20,744 individuals, according to Rape & Brooks Orthodontics, which reported the incident to the HHS Office for Civil Rights.

What makes the theft particularly nasty is that the data was "unencrypted," rather than scrambled by software for security reasons. In essence, that means the thieves could conceivably take out the server computer's hard drive, attach it to another computer, and simply read the information. And the thieves have reason to do so; data like Social Security numbers and birth dates can be used together to commit many forms of credit card.

While this incident didn't involve clinical data drawn from an EHR, it's only a matter of time before practices lose electronic patient record data in this manner. If nothing else, a practice whose computer equipment is stolen could lose clinical data, at least if the data wasn't backed up properly. Not only that, thieves are beginning to use patient data to commit medical identity fraud, in which they use a patient's information to fraudulently obtain medical care and bill it to that patient. And of course, the HIPAA implications of stolen patient data are rather ugly.

Bottom line, if you're not confident that you understand at least the basics of security, you'd better learn fast -- the stakes are high and getting higher. Tomorrow, I'll supply a sample of Web resources that can help you get up to speed.

Have you looked at your HIPAA Privacy and Security Policies Lately?

If you haven't looked at your HIPAA Privacy and Security Policies lately, NOW is the time to do so!!  There were MAJOR changes included in the HITECH which was a part of the American Recovery and Reinvestment Act (ARRA).  As a result of this, many of the policies and procedures physician practices implemented in 2003 when HIPAA went into effect, must be updated.

Some of the changes implemented are:
>Increased liability for not being in compliance with HIPAA standards (The old fine was a maximum of $25,000 per violation; NOW that's just the first level of fines and fines can now be $1.5 million for a single violation!!!)

>The HITECH act also mandates that audits be conducted on covered entities (physicians and physician practices); the federal government can walk into your office and ask to see your policies and procedures at ANY TIME even if NO complaints have been filed against you!!

>The breach notification policy states that if one patient's secured record has been breached, the patient must be notified, as well as, the Federal Government.  If more than 500 patients' secured records have been breached, you must notify the affected patients, the Federal Government and local news media!

>Also, update your Business Associates Agreements-your BA has several new policies they must implement to protect you!

Don't delay in updating or implementing your Privacy and Security Policies-the consequences greatly out way any costs!

Security Threats to EHR Systems


Security Threats to Electronic Health Records: What You Need to Know

Simply implementing an EHR and encrypting its data will not guarantee patient information is safe.  Breaches to protected health information (PHI) occur and with expensive consequences.  According to an article published in the September 2011 issue of Health Data Management, “Connecticut Health Net faced an unexpected expense when it moved to an electronic health records system: a $250,000 fine from the Connecticut Attorney General’s Office after a disk drive filled with PHI was lost.” 
Not addressing your security needs and flaws can cost you not only fines, but also loss of patients.  A report posted from the Ponemon Institute suggests that “44 percent of the cost of data loss isn’t the data loss itself, but customers heading for the exits.” 
It is imperative that you hire an IT consulting company that is aware of HIPAA Security Breach Standards and incorporates them into your security system and procedures.
We at MSO Solutions, LLC have the training, expertise and experience needed to ensure that your EHR system is secure. 
Contact us today to and ensure YOUR system is ready!!
Phone: 315-484-8885