Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
1
2
3
4
5

Events

Articles

3 EHR Security Lessons from Anthem’s Security Breach

3 ehr security

Exclusive Article by Ronald Vatalaro at EMRIndustry.com

As the medical industry goes high-tech with the implementation of electronic health records (EHR), credit card companies are not the only targets catching the eye of cybercriminals.

A massive security breach made public in February at Anthem, the nation’s second largest health insurer, sheds light on the importance of security and vigilance as healthcare providers and others bring sensitive patient information into the world of e-healthcare.

About the Anthem Breach

The breach at Anthem, the medical insurer of one in nine Americans, occurred on Dec. 10, 2014. The compromise went undetected until Jan. 27, 2015, when a database administrator became aware of someone using his credentials to perform a suspicious query.

Just two days later, Anthem reported the findings of its internal investigation to federal authorities and the breach was made public on Feb. 4.

Anthem’s breach makes it very clear that vigilance is necessary as EHRs are implemented in practices and facilities across the country.

Safe data storage with networks and security processes designed to protect patient information that includes account numbers, names, addresses, Social Security numbers and more, must be created.

3 Key Takeaways

The highly publicized breach at Anthem teaches lessons all healthcare-related providers using EHRs can benefit from.

Three main takeaways from the cyberattack pinpoint the responsibilities providers and support agencies, such as insurance companies, have in safeguarding their patient and/or client information:

System Considerations

Selection of systems to handle the need for EHR must go beyond program features and bells and whistles. Organizations must seek out products that deliver security features consistent with their needs and the sensitivity of the information stored on patients’ behalf.

Sound EHRs offer the ability to limit access and provide screening controls so only authorized staff can access sensitive information.

In addition, user activity logging features provide audit trails that record all navigation in the system while features that require users to justify manual printing of information limit the potential for unauthorized screen printing and unauthorized downloading of information.

Seeking out and demanding informatics systems that offer these safeguards and more is fast becoming critical.

Recommendations for HIM Professionals

Health Information Management professionals find themselves in not just the role of organizing, collecting and managing patient data, but also making sure it is protected.

With that in mind, HIM professionals must ensure their EHRs offer the functionality necessary for the organization to meet regulatory and operational requirements while safeguarding patient information.

Recommendations for doing so include:

  • Identifying the location of information in the organization to verify state-specific guidelines
  • Identifying functions in the system that create risk and working to limit or restrict their use
  • Identifying security features that deliver higher levels of protection and implementing their use to safeguard sensitive information
  • When choosing an EHR system, it falls on HIM professionals to systematically and independently evaluate the system without relying on vendor information to gauge system functionality
  • Creating partnerships with IT counterparts to ensure the best functionality and security on a day-to-day basis

Security Features to Consider

Making sure EHRs deliver the necessary level of security to avoid breaches such as Anthem’s requires inclusion of a number of security features in the system itself.

These distinct features can make a difference in providing appropriate levels of protection:

  • Role-based security that restricts access to information based on pre-established categories of patients, encounters and documents based on specific job requirements of the user
  • VIP status indicators that enable restriction of identified patients and encounters to only those with VIP permissions
  • Ability to create an alias to mask patient identity
  • Ability to restrict physician access to only those patients the doctor serves as the physician of record for
  • Blocking abilities for specific progress notes or lab results
  • Ability to track and mask sensitive entries for release of information

Where to Turn for More Assistance

HIM professionals and others interested in learning more about how to safeguard sensitive patient data will find the federal government provides a clearinghouse of information on privacy and security via HealthIT.gov.

This website provides step-by-step plans for ensuring patient privacy and security, offers advice on how to integrate privacy and security into a medical practice and discusses privacy and security in regard to meaningful use, among other crucial topics.

As EHRs take the practice of medicine further into the high-tech world, cybercriminals are taking note. Safeguarding sensitive information is critical for protecting patients and their identities.

As the Anthem breach demonstrates, this brave new world is giving rise to potential pitfalls that HIM professionals must serve as sentinels against.

Ron Vatalaro works at Bisk Education with the USF Health online and writes about health informatics. Ron holds an advanced degree in Business Administration with a concentration in technology.

Take the USF Health Online 2015 Health IT Industry Survey .

HIMSS Special Part 1: HIT Visionary Zach Fox
Check out industry insight from HIT visionary and DrFirst Executive VP and GM, Zach Fox. Visit DrFirst at HIMSS Booth 6232.
We respect your privacy. Your information is safe and will never be shared.
Don't miss out. Subscribe today.
×
×
WordPress Popup
HIMSS Special Part 1: HIT Visionary David Lareau
Check out industry insight from HIT visionary and Medicomp CEO, David Lareau. Visit Medicomp at HIMSS Booth 3421
We respect your privacy. Your information is safe and will never be shared.
Don't miss out. Subscribe today.
×
×
WordPress Popup
casipoldiyarbetetabetetabetw88w88w88betfokusbetfokuslordbahisparobetparobetbuzbahisbullbahiscasino sérieuxcasino sérieuxcasino sérieuxcasino sérieuxcasino en ligne populairemeilleur site de jeux casino en lignemeilleur site de jeux casino en lignecasino en ligne en francecasino en ligne en francecasino en ligne de confiancebetbinanstwinplayistanbulbahisistanbulbahisistanbulbahisparis sportifs hors arjelonwin üyeliksahabet üyelikrestbet girişpulibetsüperbetinbtcbahiscanlı casino sitelerionline casino1xbet mobilligobet mobilcapitolbetmostbet üyelikbizbet üyelikgobahis girişmatbet girişikimisli girişbordobet girişbetcio girişalfabahisalfabahisbetgoowinxbetwinxbetwinxbetwinxbetbetkanyontaksimbetrexabetrexabetrexabetenobahisbookmaker hors arjelparis sportifs en Italieparier sur les cornersparier sur le nombre de tirsmystake chickenparis hippiques en ligneplinko francecasino diceBetzinoVasyCbetCasino Lucky8betkanyonbetkanyontaksimbettaksimbettaksimbettaksimbetbetistbetistbetistenobahisenobahisenobahisbetkolikbetkoliksmartbahissmartbahissmartbahistrendbettrendbetgamabetgamabetgamabetgamabetaspercasinoaspercasinoaspercasinonisanbetnisanbetnewbahismelbetonbahisbetonredbetonredromabettipobettipobetefes casinobetandreasfixbetbetbababetbababuzbahisbuzbahisbullbahisbullbahisbetsofbetsofall right casinokombinebetbetbinansbetbinansbetbinansmaksatbahisbetbabaorisbetorisbetbizimbahissiyahbethayalbahishayalbahishilbetsantosbettingsantosbettingsantosbettingsantosbettingnerobetnerobetswordbetswordbetswordbetinbahislevabetlevabetlevabetcasiveracasiveracasiverakordonbetkareasbetprincessbetkikbetkikbetkikbetbetmarketbetmarketbetmarketyapbahsinibetingoasyabahishipercasinocasinoperbahisnowsüpertotobetalibahisfaulbetfaulbetrelaxbahisbetingoasyabahiscasinopercasinoperbahisnowbahisnowpiyasabetpiyasabetyonjabetcasinoslotbetibombetibomredwinbitslercresus casinocresus casino aviscresus casino gratuitcresus casino connexioncresus casino connexioncresus casino connexioncresus casino applicationwild sultanwild sultan casino en lignewild sultan aviswild sultan francewild sultan bonuswild sultan vipwild sultan viptortuga casinotortuga casinotortuga casino en lignetortuga casino avistortuga casino bonus sans dépôttortuga casino applicationtortuga casino applicationmadnixmadnix casino avismadnix casino avismadnix casino en lignemadnix casino en lignemadnix casino bonus sans dépôtmadnix casino bonus sans dépôtmadnix casino retraitmadnix casino mon comptemadnix casino mon comptewinouiwinouiwinoui casinowinoui casino connexionwinoui casino connexionwinoui casino en lignemagical spinmagical spin casino50 free spins magical spinmagical spin code promomagical spin code promoazur casinoazur casinoazur casino avisazur casino en ligneazur casino en ligneazur casino mobileazur casino mobileazur casino mon comptelucky8lucky8lucky8lucky8 se connecterlucky8 avislucky8 avislucky8 mon comptebetifybetifybetifybetify avisbetify casinobetify retraitcasino jokacasino jokacasino joka vipcasino joka vipcasino joka connexionjoka casino en lignelucky31lucky31lucky31 casinolucky31 connexionlucky31 avislucky31 avislucky31 francespace fortunaspace fortunaspace fortunaspace fortuna casinospace fortuna avisspace fortuna connexionspace fortuna gmkjackpot bobjackpot bobjackpot bobjackpot bob avis777 jackpot bob777 jackpot bobjackpot bob casino bonus sans dépôtjackpot bob casino bonus sans dépôtamon casinoamon casinoamon casinoamon casinoamon casino en ligneamon casino bonus sans depotamon casino bonus sans depotamon casino applicationamon casino applicationamon casino applicationmoi casinomoi casinomoi casinomoi casino avismoi casino avismoi casino avismoi casino connexionamon casino bonus sans depotmoi casino applicationlucky8 interdit en francebetify connexionjoka casino avisjoka casino avislucky31 blackjackspace fortuna retraitjackpot bob applicationamon casino inscriptionmoi casino en lignejackpot bob inscriptionamon casino retraitamon casino retraitmoi casino inscriptionmoi casino retraitmadnix applicationmadnix inscriptiontortuga casino retraittortuga casino retraittortuga casino compte bloquétortuga casino mon compteazur casino bonusazur casino applicationmagical spin 10 eurosmagical spin retraitbetpas üyelikbetboo üyeliksüperbetin üyelikspace fortuna bonus sans dépôtspace fortuna applicationspace fortuna inscriptionbetify bonusbetify promo codebetify inscriptioncasino joka applicationcasino joka bonus sans dépôtcasino joka inscriptionlucky31 bonus sans depotlucky31 retraitmariobetbetsat üyelikpinup üyeliklucky31 applicationbetpas üyeliksüperbetin üyeliksultanbet üyeliklucky31 inscriptionwild sultan bonus sans depotwild sultan bonus sans depotwild sultan retraitwild sultan retraitwild sultan retraitwild sultan casino bonus sans dépôtcresus casino bonuscresus casino compte bloquécresus casino privéwinoui casino bonus sans dépôtwinoui casino françaiswinoui problèmewinoui applicationwinoui inscriptionbetmatik üyelikmariobet üyelikmariobet üyelikbetsat üyelikbetonred üyelikbetonred üyelikbetonred üyelikbetonred üyelik7slots üyelikstarda üyelikmaslakcasinomaslakcasinomaslakcasinobahisbeyportbetportbetportbetrbetrbetrbetrbetsahabet üyelik1xbet üyeliktipobet üyeliktipobet üyelikmostbet üyelikmostbet üyelikmostbet üyelikmostbet üyelikligobet üyelikbizbet üyelikbahsinebetsahasantabetegobetwolbetkralbetbetorspininterbahisgobahisbordobetbordobetretrobetbetciofreybetfavorisenbetboxbetmabetbetmabetbetmüzebetgitmislibetshowbahisyonjabetviplobyhedefbetlucky8 bonuslucky spinlucky8 bonus sans dépôtlucky8 compte bloquélucky8 compte bloquémakrobetilbetvdcasinomaltcasinomaltcasinoceltabitceltabitlordcasinolordcasinohızlıbahishızlıbahisprestijbetbetzmarkbetzulaenobahismedyabahiskareasbetrollbit casino