Showing posts with label Data Security. Show all posts
Showing posts with label Data Security. Show all posts

Sunday, March 13, 2022

Recent cybersecurity legislation to put on your reading list

With cyberattacks on the rise, the Strengthening American Cybersecurity Act is an item not to overlook.

The Strengthening American Cybersecurity Act, which passed in the Senate on March 2, 2022, could have ramifications for the healthcare industry. First, a bit about the legislation. It is comprised of the following:
  • Cyber Incident Reporting for Critical Infrastructure Act of 2022
  • Federal Information Security Modernization Act of 2022 (FISMA 2022)
  • Federal Secure Cloud Improvement and Jobs Act of 2022
  • Cyber Incident Reporting for Critical Infrastructure Act of 2022
  • Federal Information Security Modernization Act of 2022
  • Federal Secure Cloud Improvement and Jobs Act of 2022

For those unfamiliar with the Federal Information Security Management Act of 2002 (FISMA) and the Federal Information Security Modernization Act of 2014 (also FISMA, which enhances and clarifies the 2002 FISMA), require U.S. Government agencies to implement information security controls using a federal risk-based approach to information security assessment. The primary framework for FISMA compliance is detailed in NIST SP 800-53 (rev. 5). FISMA 2022 builds on the previous FISMA laws. Importantly, FISMA applies to government contractors, if they operate federal systems, such as cloud-based platforms.

When providers sign a CMS Form 855 or its electronic counterpart PECOS, for example, there is no express requirement to adhere to FISMA. Having said that, if a cloud provider or an EHR is contracting with the State Department, the Department of Defense, or the Veteran’s Administration, then that is a different procurement process, which has an express provision for complying with FISMA. FISMA also extends to government contractors who subcontract with cloud providers and EHR vendors, so ensuring that all the requisite technical, administrative, and physical safeguards set forth in HIPAA Security Rule, as well as the NIST counterparts, are critical for making truthful attestations.

Another section includes important definition, which appears in Section 3598 of the SACA is the term "major security incident" which is distinct from a definition of "breach" under CFR §164.402 of HIPAA, which states,“[t]he acquisition, access, use, or disclosure of protected health information in a manner not permitted which compromises the security or privacy of the protected health information.” The best course of action is always to err on the side of the shorter timeframe and incorporate the requirements into relevant policies and procedures, as well as enterprise risk management programs.

While we think of critical infrastructure as being relevant to all hospitals – both private and public, neither HIPAA nor hospitals are expressly mentioned in SACA. HHS-OCR is tasked with enforcing civil liberties, as it relates to a person's protected health information. And, protecting the "civil liberties or public health, and safety of the people of the United States" is expressly stated. It is crucial to watch for the developments and guidance regarding the term "major incident."

Finally, there is a lot of chatter surrounding the shortened breach reporting periods. For those in the healthcare industry who either fall under HIPAA or the Federal Trade Commission’s Breach Notification Rule, the notion of shorter reporting periods should not come as a shock because many states have enacted shorter reporting periods. Second, it is imperative to read SACA § 3592 – Notification of Breach. SACA differs from HIPAA in its language for reporting to a government agency and to any individual potentially affected by the breach, so read it closely. In closing, this is a piece of legislation to stay apprised of. Now is a good time to ensure that an organization’s Breach Notification Policies and Procedures are updated to reflect the most current state reporting requirements, as well as ensuring that the requisite annual Risk Analysis is done to assess technical, administrative, and physical safeguards.


15% Off Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)


VIEW ALL

Thursday, June 5, 2014

Black Cloud to Silver Lining

Whether you’re a Luddite–someone who hates technology, or a technophobe–one who fears it, undoubtedly you’ve heard of cloud computing. And if you are in either of the aforementioned categories, it might be time to kick the negative feelings

  to the curb, scramble to the wagon, and hop on board. Experts agree that small businesses that embrace technology will fare far better than those who do not.
 
According to a poll of small business owners, 66% say they wouldn’t survive without wireless technology, and this is why: software/hardware costs, IT savings, and easy accessibility. And that’s just to name a few.

In a nutshell, cloud computing lets you store and access data and applications on the cloud (ie Internet) instead of having everything on your computer’s hard drive. All of your files, data and applications are stored in a virtual lockbox tucked neatly in the metaphorical cloud that you can reach from wherever you happen to be working–just make sure you’re on a secure network. So everything you do, from accounting to project management can be done remotely.

And if you become one of the 800,000 people who leave their laptop in an airport annually–all is not lost, because you’ll be able to retrieve everything you need from your cloud. That’s a silver lining right there.


Here are some things to think about when considering a move to the cloud:

Hardware: With the cloud, you pay a monthly fee to put your files on someone else’s server so you don’t have to invest in more as you grow. There are multiple free cloud options, up to a predetermined storage limit. Once you’re over the limit you can pay a monthly fee based upon how much storage you need. And other companies let you test them out before you purchase.


IT/Software Savings: With everything from files and applications stored on the cloud, there’s no need to license pricy software to any new machines in your office, or have an extensive in-house IT department.


Ease: Storing files on the cloud saves you time backing everything up, plus you’ll no longer have to email documents to your personal email address so you can work from home, or put files on a flash-drive that you inevitably leave on your work desk anyway. Everything you need to do your job, from anywhere with Internet access, can be accessed through the cloud.

But, the looming question remains–business owners always want to know about security. For now, if you have something that is top secret–say a baked bean recipe–keep it off of the cloud. Just like in nature, not all clouds are created equal–so do your due diligence, think about what it is you’ll be storing on the cloud, and see what works best for you and your business.

Some rules of thumb are to make sure the company you choose has a reputation for strong network security, they offer multiple level redundancy in the event a server fails, and they have servers in multiple geographic regions. Again, always do your research before you sign up with any cloud service provider, and always read the security and privacy fine print before you decide to come aboard the cloud bandwagon.
 

15% Off All Products!

 

Friday, April 11, 2014

How To Prevent Data Security Breaches in Your Medical Practice

Security Breaches on the Rise in 2014: Are You Ready?

data breach


If you thought this would be the year securing patient data would finally become easier, you may be in for an unpleasant surprise. A recent Experian report predicts the healthcare industry will see more large-scale security breaches affecting patient privacy in 2014.

According to Michael Bruemmer, Vice President of Experian’s Data Breach Resolution, the sheer size of the healthcare industry is what makes it vulnerable to security risks.

If you add all currently insured patients to the 7 million incoming patients resulting from the new Health Insurance Exchanges, then couple that with the haphazard manner in which Healthcare.gov was implemented, you create a larger area potentially vulnerable to attack.

At Experian, which provides recovery services for companies dealing with personal data loss, 46% of breaches in 2013 were healthcare-related. In fact, their remediation group worked on more than 2,200 healthcare breaches in 2013, compared to 1,700 in 2012.

It’s important to look at the most common occurrences of data breaches, so you can take steps to prevent them from impacting your practice.

 

Preventing Breaches

Patient information is a valuable commodity in today’s fraud market. Personal records suitable for use in identity theft can be worth between $10 and $28 depending on the income status of the victim. When enriched with health data, the value of an identity data set jumps to almost $50 per record because it can be used for medical and insurance fraud – a far more lucrative business.

However, in most cases, data breaches have less to do with advanced hacking techniques and more to do with lost laptops, failing to shred paper records and easily avoidable employee blunders.

In three out of 10 breaches Experian serviced last year, most errors were tracked to sloppy system administrator password practices like neglecting to change a default password or carelessly sharing PINs.

So what data protection methods can you implement to better protect your patients? There are several steps and precautions your practice can carry out, including:

  • Provide an up-to-date training program on handling protected health information (PHI) for employees performing health plan administrative functions.
  • Never share sensitive PHI with others who shouldn’t have access, including co-workers or personal acquaintances.
  • Avoid accessing a patient’s record unless needed for treatment or with written permission from the patient.
  • Minimize occurrences of others overhearing patient information. Do not use a patient’s whole name within hearing distance of others.
  • Secure all paperwork containing PHI by placing in a drawer or folder when not in use. Cover charts so patient names are not visible. Never leave records and other PHI unattended.
  • Close computer programs containing patient information when not in use. Practice management (PM) systems with automatic time out settings are helpful in this regard.
  • Limit e-mail transmissions of PHI exclusively to those circumstances when the information cannot be sent another way.
  • Always use a cover sheet when faxing PHI.
  • Back up all disks containing PHI. Storing your patients’ information in a HIPAA compliant cloud-based system is safer than using a client-server or paper documents.
  • Assign different levels of security clearance to specific people. This prevents employees from accidentally changing or seeing information that does not pertain to their specific duties.
  • Ban the sharing of passwords between staff members.
  • Properly dispose of information containing PHI by shredding paper files.
  • Make sure computers have updated anti-virus scanning software installed. This guarantees your practice is reasonably guarded against malicious software.
  • Ensure associated vendors and businesses are properly following HIPAA standards as well.

As the healthcare industry continues to grow, outdated administrative practices will no longer stand up to security threats. Take full advantage of technology like Meaningful Use certified EHRs and cloud-based PM systems to help keep your patient data secure.

 
_________________________________
 

For Your Practice