Tuesday, November 18, 2014



Cheryl Kraemer Module 4
Manos, D. (2014).  5 Ways to avoid health data breaches.  Healthcare IT News.  Retrieved from:
Why was this article, blog, post, or multimedia chosen?
          This article was chosen because it addresses steps healthcare organizations can take to decrease the risk of a data breach.  In one of my informatics classes last year, I read about one of Kaiser Permanente’s data breaches.  I have read of at least one other since then and am aware of the risk for healthcare organizations.  
What makes it interesting, appropriate, or reputable?
          The article indicates there was a 138% increase in data breaches in 2013.  Since 2009, 29.2 million patients have been affected by 804 breaches of healthcare information since 2009.
Is it an opinion? Case study? Research study? Product review?
          It probably fits into an opinion as it was based on information from Daniel Berger, president and CEO of Redspin, which lists itself as “the leader in penetration testing and application security testing”.
What was the need, problem, issue or trend addressed in the article, blog, post, or multimedia?
          The issue is how to minimize the risk of a HIPAA breach at your organization.  According to Berger, the most important part of minimizing the risk of a data breach is to make your employees understand the key role they play in keeping patient health information safe.  Employees need to have a personal stake in keeping patient records safe.    
What was the solution for which technology had an answer?
          There were 5 key areas to decrease the risk of a healthcare data breach:
1)     Conduct an annual HIPAA security risk analysis
2)     Insist on data encryption on all portable devices
3)     Conduct more frequent vulnerability assessments and penetration testing
4)     Invest in security awareness of employees
5)     Engage business associates in your security awareness
 
What implications might this have in healthcare delivery?
     Making everyone aware of the risk to patient records by their actions will decrease the risk of a data breach.  Also informing employees of the costs associated with a data breach because of fines, potential class action lawsuits, attorney’s fees and negative publicity might heighten awareness of the negative impact to the organization.
What did you learn from it that might have application for your practice?
     While our IS department occasionally sends fake “phishing emails” (click this link to claim your prize), I am not aware that they perform external and internal penetration testing which mimics the paths of malicious attackers.  Additionally, other than the yearly required mandatory training, there are no reminders that create a culture of security awareness.  The article suggests screen saver reminders and monthly tips to keep patient record security on everyone’s mind.

No comments:

Post a Comment