Perform Regular Risk Assessments
No matter how static the practice, EHR exists in a constantly evolving environment. Whether it's changing operating systems, new equipment, new patients, or new suppliers, things change, and the risks associated with those things change, too.
Risk assessments performed at least annually should be part of any health practice security regimen. This might include a HIPAA audit, though that just focuses on privacy and is not a substitute for a full risk assessment. If a health organization is too small to afford its own team for risk assessment, it should hire outside consultants and make sure that the risk assessment includes both internal and external factors, based in process and technology.
Finally, the organization must not let the fragile egos of anyone on staff prevent it from honestly assessing the risks of the activities they are involved in. Risk comes bearing many different academic degrees.
(Image: Andrey_Popov VIA SHUTTERSTOCK)