Cheryl
Kraemer Module 4
Manos, D. (2014). 5 Ways to avoid health data breaches. Healthcare IT News. Retrieved from:
Why was this
article, blog, post, or multimedia chosen?
This article was chosen because it
addresses steps healthcare organizations can take to decrease the risk of a
data breach. In one of my informatics
classes last year, I read about one of Kaiser Permanente’s data breaches. I have read of at least one other since then
and am aware of the risk for healthcare organizations.
What makes it
interesting, appropriate, or reputable?
The article indicates there was a
138% increase in data breaches in 2013.
Since 2009, 29.2 million patients have been affected by 804 breaches of
healthcare information since 2009.
Is it an
opinion? Case study? Research study? Product review?
It probably fits into an opinion as
it was based on information from Daniel Berger, president and CEO of Redspin,
which lists itself as “the leader in penetration testing and application
security testing”.
What was the
need, problem, issue or trend addressed in the article, blog, post, or
multimedia?
The issue is how to minimize the risk
of a HIPAA breach at your organization.
According to Berger, the most important part of minimizing the risk of a
data breach is to make your employees understand the key role they play in
keeping patient health information safe.
Employees need to have a personal stake in keeping patient records safe.
What was the
solution for which technology had an answer?
There were 5 key areas to decrease
the risk of a healthcare data breach:
1) Conduct an annual HIPAA security risk analysis
2) Insist on data encryption on all portable devices
3) Conduct more frequent vulnerability assessments
and penetration testing
4) Invest in security awareness of employees
5) Engage business associates in your security
awareness
What
implications might this have in healthcare delivery?
Making everyone aware of the risk to
patient records by their actions will decrease the risk of a data breach. Also informing employees of the costs
associated with a data breach because of fines, potential class action
lawsuits, attorney’s fees and negative publicity might heighten awareness of
the negative impact to the organization.
What did you
learn from it that might have application for your practice?
While our IS department occasionally sends
fake “phishing emails” (click this link to claim your prize), I am not aware
that they perform external and internal penetration testing which mimics the
paths of malicious attackers.
Additionally, other than the yearly required mandatory training, there
are no reminders that create a culture of security awareness. The article suggests screen saver reminders
and monthly tips to keep patient record security on everyone’s mind.
No comments:
Post a Comment