04:00 PM
Connect Directly

4 Best Practices: Combat Health Data Breaches

Senior health IT experts offer tips on how to bolster security and create a culture of privacy and compliance.

10 Wearable Health Gadgets
10 Wearable Health Gadgets
(click image for larger view and for slideshow)
Data breaches in healthcare are rising at an alarming rate, and within the past two years, nearly 20 million patient records have been compromised, according to the U.S. Department of Health and Human Services (HHS). Recently, the American Hospital Association brought together five senior executives to discuss security, compliance, and legal issues regarding best practices and how to create a culture of organizational compliance.

In the seminar, "Manage Data Breach Incidents and Improve Patient Privacy in Major Care Systems," experts discussed how to achieve organizational alignment around patient privacy across large organizations, how to mitigate the financial and reputational risks of a data breach, and specific ways to gain support from both the board and executives to create and maintain a culture of privacy. Experts included Kimberly Holmes, deputy product manager of healthcare at Chubb Group of Insurance Companies; Cheryl A. Parham, associate general counsel at New York-Presbyterian Hospital; Meredith Phillips, chief privacy officer at Henry Ford Health Systems; Marcy Wilder, co-chair of the Global Privacy and Information Group at Hogan Lovells; and Doug Pollack, chief strategy officer at ID Experts.

InformationWeek Healthcare spoke with Pollack, who recapped the four tips experts shared to make patient privacy and security part of an organization's culture.

1. Encrypt, Encrypt, Encrypt.

During the panel, Holmes outlined a core message, said Pollack, which was "simple and easy" but could substantially improve an organization's ability to maintain patient privacy. "That's encryption," said Pollack. "It’s particularly important and necessary to emphasize now because of the new device world we're moving into." Healthcare, he continued, is a "very aggressive" adopter of mobile technology, particularly tablets, and although encryption technology is often available, people might not focus on it as much as they should.

"A lot of times, when they're dealing with BYOD, they may not understand the need to maintain privacy and the importance of using encryption," said Pollack. "[We need to] get people focused on the one simple thing they can do in the security space and move the needle in terms of protecting patient privacy. Encryption is one of those rare focus areas that can make a huge difference."

2. Prepare For A Breach.

New York-Presbyterian's Parham said during the panel that when dealing with a large hospital system, the question isn't if, but when an organization will encounter a data breach. "It's a fact of life within the healthcare world that data is liquid; it needs to move around so much that it's impossible to completely eliminate breaches," said Pollack. "Her point was…it's important to have a plan in place that will dictate how you operate in the context of a breach."

Pollack added it’s important to understand who your first responders are, and, more importantly, how they will react in the situation. A common issue, though, is how often organizations will develop a response plan, "and then stick it in a file and that's it," he said. "We’re increasingly finding … hospitals are interested in testing their response plan. They'll assemble folks and do a table-top walk through of a sample data breach." By doing so, an organization can operationalize their response. "It can make a big difference as to whether you successfully or unsuccessfully deal with an incident," Pollack said.

3. Assess Privacy And Security Compliance Annually.

Even though it's required under HIPAA, said Pollack, many organizations still fail to perform a compliance assessment every year. "[Make] it part of your organizational DNA," he said. "Organizations need to get in the rhythm of doing it." Just as an organization develops its operating plan every year, it also needs to schedule and carry out a privacy and security assessment, "so they're budgeted and expected," he said. "The good news is by doing them, it'll help keep you out of trouble when you inevitably face an investigation by Office for Civil Rights (OCR), where they decide whether you've been acting poorly or not."

4. Find Gaps And Close Them.

Phillips spoke on how to find the security gaps within an organization and close them, and described what she and her team have done at Henry Ford Health System. "She talked about a natural follow-up to the assessment process, which is helpful to identify issues and do something about them," said Pollack. Phillips also said that she and her organization keep the OCR updated on the issues they have identified and are working to fix. "That’s to preempt any concerns or issues by illustrating your proactive efforts to address patient privacy," said Pollack.

Global Privacy's Wilder "wrapped a bow" around all the points executives made when it came to how to prepare for and combat against data breaches, said Pollack. To summarize, "encryption and culture come in, and organizations need to be prepared when breaches occur," he said. "[They] need to be transparent and especially transparent not only to those affected, but also to the regulatory systems, specifically OCR."

InformationWeek Healthcare brought together eight top IT execs to discuss BYOD, Meaningful Use, accountable care, and other contentious issues. Also in the new, all-digital CIO Roundtable issue: Why use IT systems to help cut medical costs if physicians ignore the cost of the care they provide? (Free with registration.)

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
3/21/2013 | 7:36:04 PM
re: 4 Best Practices: Combat Health Data Breaches
Today EMR is the best implementation of Health Care IT under the Health Insurance Portability and Accountability Act (HIPAA), which protects patient privacy and sets security standards for electronic health records.

User Rank: Apprentice
11/5/2012 | 1:35:29 PM
re: 4 Best Practices: Combat Health Data Breaches
I agree with Jeff. Encryption, preparation, annual reviews, and closing gaps are all vital components of best practices but without a concerted effort to ingrain patient data protection into the culture of an organization, efforts will be futile.
User Rank: Apprentice
11/2/2012 | 7:06:02 PM
re: 4 Best Practices: Combat Health Data Breaches
Great article except you missed one of the most important Best Practices. POLICIES and PROCEDURES, This is the easiest and best way to protect your organization. Most breaches are "Sneaker Thief" the data just walks out the door. I just competed working on the strategy for mHIMSS upcoming Roadmap on Privacy and Security. We go into detail of your 4 BP.

good work,

Jeff Brandt
Register for Dark Reading Newsletters
White Papers
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio