Risk
8/20/2010
09:19 AM
50%
50%

HHS Committee Sanctions Health IT Security Proposal

Contentious debate over how patients can opt out of data sharing nearly derailed the Department of Health and Human Services group's recommendations.




Slideshow: Who's Who In Healthcare IT
(click for larger image and for full photo gallery)
Devan McGraw and Paul Egerman, chair and co-chair, respectively, of the Department of Health and Human Services' Health IT Policy Committee's privacy and security team, entered the full committee's August meeting looking for approval of the letter and recommendations they put together over the summer. And while they got that approval in the end, it was only after more than 30 minutes of contentious debate, led on the other side by Neal Calman, MD, president and CEO of the Institute for Family Health.

The debate broke down as follows: among other things, the recommendations stated that if a provider uses a health information exchange (HIE) to share data that meets meaningful use requirements, the provider must also offer patients a choice of opting out of that exchange. As an alternative, the provider would be required to offer direct point-to-point exchange with any other parties needing to receive that patient's data.

Calman said repeatedly this would constitute an undue burden on providers and that they should be able to inform patients of how their practice shares data -- perhaps through an HIE -- and then leave the decision of whether or not to patronize that practice with the patient.

"So you are saying I can opt out of using any exchanges, but I can't say to a patient, 'This is the way we do business and, if you don't like it, you have to go elsewhere'? I can do that for every other aspect of my practice -- the way we deal with emergency calls, my hours, whether I use nurse practicioners -- but if someone wants to opt out of my data exchange program, I have to offer them another alternative?" asked Calman.

McGraw, director of the Center for Democracy & Technology, Egerman, software entrepreneur, and Christine Bechtel, VP of the National Partnership for Women & Families, gave spirited defenses of the recommendations. Eventually, the debate became mired down in the minutiae of terms like health information organization (HIO) and organized health care arrangement (OHCA), with each side questioning and stipulating what those terms meant and how each was treated under both the law and meaningful use. Terms like "business associate agreement" and "covered entity" were also discussed, debated and parsed.

The conversation even touched on the idea that the governance composition of an HIE might place it under different legal requirements for sharing information. For example, if providers participate in an HIE composed only of other providers, they would need less additional consent from patients for participation, but if the governance included non-providers or non-covered entities, other consent "triggers" could be tripped.

Though Calman, Judy Faulkner (CEO, Epic), Michael Klag (Johns Hopkins University, Bloomberg School of Public Health), and Marc Probst (CIO, InterMountain Healthcare) all expressed concerns during the debate, none voted no or abstained. Thus, the recommendations passed with the full, though seemingly lukewarm, approval of the full committee.

Anthony Guerra is the founder and editor of healthsystemCIO.com, a site dedicated to serving the strategic information needs of healthcare CIOs. He can be reached at aguerra@healthsystemCIO.com.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7402
Published: 2014-12-17
Multiple unspecified vulnerabilities in request.c in c-icap 0.2.x allow remote attackers to cause a denial of service (crash) via a crafted ICAP request.

CVE-2014-5437
Published: 2014-12-17
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php,...

CVE-2014-5438
Published: 2014-12-17
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php.

CVE-2014-7170
Published: 2014-12-17
Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.

CVE-2014-7285
Published: 2014-12-17
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.