Risk
8/20/2010
09:19 AM
50%
50%

HHS Committee Sanctions Health IT Security Proposal

Contentious debate over how patients can opt out of data sharing nearly derailed the Department of Health and Human Services group's recommendations.




Slideshow: Who's Who In Healthcare IT
(click for larger image and for full photo gallery)
Devan McGraw and Paul Egerman, chair and co-chair, respectively, of the Department of Health and Human Services' Health IT Policy Committee's privacy and security team, entered the full committee's August meeting looking for approval of the letter and recommendations they put together over the summer. And while they got that approval in the end, it was only after more than 30 minutes of contentious debate, led on the other side by Neal Calman, MD, president and CEO of the Institute for Family Health.

The debate broke down as follows: among other things, the recommendations stated that if a provider uses a health information exchange (HIE) to share data that meets meaningful use requirements, the provider must also offer patients a choice of opting out of that exchange. As an alternative, the provider would be required to offer direct point-to-point exchange with any other parties needing to receive that patient's data.

Calman said repeatedly this would constitute an undue burden on providers and that they should be able to inform patients of how their practice shares data -- perhaps through an HIE -- and then leave the decision of whether or not to patronize that practice with the patient.

"So you are saying I can opt out of using any exchanges, but I can't say to a patient, 'This is the way we do business and, if you don't like it, you have to go elsewhere'? I can do that for every other aspect of my practice -- the way we deal with emergency calls, my hours, whether I use nurse practicioners -- but if someone wants to opt out of my data exchange program, I have to offer them another alternative?" asked Calman.

McGraw, director of the Center for Democracy & Technology, Egerman, software entrepreneur, and Christine Bechtel, VP of the National Partnership for Women & Families, gave spirited defenses of the recommendations. Eventually, the debate became mired down in the minutiae of terms like health information organization (HIO) and organized health care arrangement (OHCA), with each side questioning and stipulating what those terms meant and how each was treated under both the law and meaningful use. Terms like "business associate agreement" and "covered entity" were also discussed, debated and parsed.

The conversation even touched on the idea that the governance composition of an HIE might place it under different legal requirements for sharing information. For example, if providers participate in an HIE composed only of other providers, they would need less additional consent from patients for participation, but if the governance included non-providers or non-covered entities, other consent "triggers" could be tripped.

Though Calman, Judy Faulkner (CEO, Epic), Michael Klag (Johns Hopkins University, Bloomberg School of Public Health), and Marc Probst (CIO, InterMountain Healthcare) all expressed concerns during the debate, none voted no or abstained. Thus, the recommendations passed with the full, though seemingly lukewarm, approval of the full committee.

Anthony Guerra is the founder and editor of healthsystemCIO.com, a site dedicated to serving the strategic information needs of healthcare CIOs. He can be reached at [email protected]

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.