TAKING A PULSE [SC Magazine]
| By Armstrong, Illena | |
| Proquest LLC |
Data protection concerns abound for health care professionals. Getting a sound handle on steps to address these is key, reports
Few can argue 2011 has been a banner year for frequent and massive data breaches, and health care organizations have carried their share of the burden.
Compromises encountered by the likes of
Yet, breaches are unsurprising to many in the space. At an SC Magazine Health Care Roundtable held late last year, attendees spoke frankly about their challenges. Understanding just how far their confi dential data extends, addressing more highly targeted vectors of attack, like mobile devices or cloud computing, ensuring business partners have adequate security, and getting the support they need from equipment vendors whose tools now are networked to wider corporate infrastructures, were only a few worries they voiced.
"The problem is that in health care, all data is sensitive - whether its PII or protected health information," says
In reiterating a point he made at the Roundtable, Whiteside adds that keeping track of this data is the most critical duty for health care security pros - and the most confounding.
"All I can say is due diligence," he explains. "Health care and every other vertical should ensure they are continuing to do the things they know they should in order to protect patients and their electronic information."
One top concern for Roundtable attendees is insider threats. Not only do they have to worry about the typical security vulnerabilities other types of companies face, like the provisioning (and de-provisioning) of internal applications, or too many shared accounts, but they must also deal with what Roundtable participants referred to as "neighbor snooping."
To address this problem, some pros who attended the Roundtable are in the midst of rolling out dual-factor authentication solutions. Among other technologies, they're also relying on encryption, security incident and event management (SIEM) solutions, awareness training, and identity management (IDM) to help with end-user provisioning and the deletion of shared accounts.
The problem with many of these solutions, though, is that they are based on policy, says
"We've seen that most of our customers who are really serious about user monitoring and need an authoritative source of data turn to [
The data that business partners have access to only complicates the problem more, says
"Once that initial data is used for something else, all bets are off," says Gossels. "That's the nightmare in health care right now. It's not the initial collection. It's all the uses after that."
If data security needs like these are met, then compliance with the Health Insurance Portability and Accountability Act (HIPAA) should come naturally. However, security funding still seems to stem from higher-ups' concerns about meeting mandates, as opposed to safeguarding the data. This may be one reason why many health care organizations PULSE end up failing to take a comprehensive look at their overall security management plans, says
A "fi refi ghting exercise" up until now, robust security and risk management plans in the health care space must be built fi rmly on standards, such as ISO 27001, guidance from the
Organizations need to adopt a standard prescribing reasonable and appropriate security practices in order to do a valid gap analysis as part of their risk assessment, he says.
Yet, it's not just a question of privacy. It's also one of authenticity of the data, says
Standards come in handy when undertaking this process, says HITECH's Cline. By looking to industry guidance and best practice, and then conducting an analysis of where security gaps are, organizations can establish and maintain an overarching governance, risk and compliance management plan that considers the entire corporate infrastructure.
"[HIPAA] helps and hinders," Cline says. "It helps because it got security some attention, so people were able to do some things they wanted to do after they got the money for them. It hinders because they end up focusing on compliance, and compliance doesn't equal security."
With Offi ce of Civil Rights audits coming, Cline believes 2013 will be a watershed year for health care security. After audits show that some still are clinging to ineffectual risk management plans, the industry is bound to witness action against them, he predicts.
"2013 will be the fi rst year organizations will be looking at security through the right lens, so there should be a lot of improvements," says Cline.
A longer version of this story is available at scmagazineus.com.
| Copyright: | (c) 2011 Haymarket Media, Inc. |
| Wordcount: | 1013 |


Marketing for Organizational Excellence [Firehouse]
Identity theft: A good name is more desirable than riches [New Pittsburgh Courier (PA)]
Advisor News
- How can more Americans achieve financial independence?
- Savers vs. spenders: How money management attitudes impact financial confidence
- Demonstrating the value of life insurance to Gen Z
- Poor money habits are a dealbreaker in a new relationship
- DC plan sponsors see opportunity in alternatives
More Advisor NewsAnnuity News
- The next growth phase in life/annuities depends on modernization
- CA judge certifies class action in teachers’ lawsuit over in-plan annuity fees
- Globe Life Inc. (NYSE: GL) Records 52-Week High Thursday Morning
- AM Best Managing Director Joins ‘Target Topics’ Podcast to Discuss State of Delegated Underwriting Authority Enterprises Market
- KBRA Assigns Rating to TruSpire Retirement Insurance Company
More Annuity NewsHealth/Employee Benefits News
- Findings from Yonsei University Advance Knowledge in Demography (Different Understandings of Scientific Research in the Use of De-identified Personal Sensitive Data: South Korea, in Comparative Perspectives): Science – Demography
- Data on Influenza Vaccines Discussed by Researchers at University of Lucerne (Keep Reminding Me To Get My Flu Shot): Immunization and Public Health – Influenza Vaccines
- Bobby Harrison: Rising insurance exchange costs bad for working poor
- New Managed Care Findings from Brown University Reported (Prior Authorization In Medicare Advantage: Beneficiary Exposure And Plan Disenrollment In 2021): Managed Care
- Findings on Managed Care Detailed by Researchers at Renal Research Institute (AI-Driven Interventions for Imminent Hospital Admissions in Patients with End-Stage Kidney Disease: A Medicare and EMR-Based Analysis): Managed Care
More Health/Employee Benefits NewsLife Insurance News
- Best’s Market Segment Report: AM Best Maintains Stable Outlook on South Korea’s Non-Life Insurance Market
- Horace Mann Strengthens Customer Relationships and Accelerates Long-Term Growth Through Transactions with Medical Mutual of Ohio
- Regulators: ‘No firm conclusions’ from first offshore reinsurance filings
- Allianz Life Study Finds Americans Struggle to Shift From Retirement Saving to Spending
- The next growth phase in life/annuities depends on modernization
More Life Insurance News