Chiropractic + Naturopathic Doctor - May 2018

Data Diligence

Ching Mac 2018-04-17 01:52:28

Safe keeping

Is your patient’s health data secure?

In 2017, headlines from across the world showcased hackers targeting multinational corporations, government agencies and charities, among other organizations. As executive leaders recognize the impact of cyberattacks, more organizations are prioritizing security.

TARGETING HEALTH CARE

While organizations that collect private data – for example, credit card information or home addresses – have been hit hard, a top-targeted industry for cyberattacks is health care. Hospitals, doctors’ offices and other clinics are at risk of an attack because most systems contain electronic health records (EHRs) full of valuable data, such as social security numbers, birth dates, and billing and health information. Health care organizations are most likely to pay ransom because the compromised data is time-sensitive and can damage their reputation.

Most hospitals have dedicated IT security staff, but primary care clinics often don’t have the same sophisticated IT infrastructure in place to prevent, detect and respond to breaches. Yet after a string of attacks, it’s clear security must be everyone’s business, at every endpoint.

This is complicated by the nature of the health care industry today: clinicians and health care staff are highly mobile, and a typical day means going from patient room to patient room, and from one specialization to the next. This extends outside the hospital itself since information is needed from remote locations like home offices. The data contained in EHRs often follows a long care journey – from primary care physicians, to hospitals, to specialist offices such as chiropractors – with many opportunities for tampering. So, while EHRs have enhanced the digitization required for health care, having digitized data can bring new challenges of its own.

An array of new internet-connected medical devices pose additional challenges for health care providers because they are easily hackable and can put patients at risk. Without shying away from adopting new technology, while also keeping patient information safe and making privacy a priority, what can health clinics do to secure their patient’s health data?

YOUR DIGITAL WORKSPACE

Creating a secure digital workspace ensures medical professionals get the benefits of mobility without the vulnerability. And, while completely eliminating risk is never possible, there are ways companies can manage risk in smart, secure ways.

Virtualization is one method of managing risk. Virtualization is concerned with where the data behind the desktop is stored. If a doctor can log into a work desktop from multiple computers, that means the desktop is virtual and accessible from anywhere. The data is stored on the servers, and just being accessed through the computer, nothing is stored there. So, imagine being able to access a virtual desktop from anywhere – your phone, or your laptop.

Virtualization enhances security because data remains protected at the data source – the server or the cloud – rather than the user’s device. Often these “endpoint” devices are the most vulnerable to threats like malware and phishing. This extra layer helps protect patient information by storing it in a centralized, secure data center.

ADOPTING VIRTUALIZATION

In the health care industry, more hospitals and clinics are starting to adopt virtualization for several reasons. For example, regardless of practice size, health care organizations generate copious amounts of data and don’t have the capacity to store it, or the hiring capacity to manage it with designated IT staff. Having a third-party technology vendor that specializes in virtualization allows hospitals and other health organizations, such as chiropractic offices, to store the data and get the expertise they need without having to hire.

THE BOTTOM LINE

As work becomes increasingly mobile, it is not enough to simply have access to your files; you must be able to access, sync and share files from any device to the rest of your team, at any time, and from any location. This capability is especially crucial in health care, which is time-sensitive and urgent, and where having up-to-date information is vital.

Health care operations should always be looking for ways to improve service, lower costs levied to patients, and provide ease of mind. With secure data management tools and policies, keeping patient data secure and providing a seamless user experience can complement instead of compete with one another

Have you signed up for our weekly e-newsletter yet? Sign up today at canadianchiropractor.ca

CHING MAC is responsible for the overall management of the commercial business across the Citrix product portfolio, leading teams focused on field and channel engagement with end customers. He has been at Citrix for 13 years, previously holding several leadership positions on the Canadian management team. citrix.com

TIPS FOR PROTECTING ELECTRONIC RECORDS

The Canadian Medical Protective Association’s (CMPA) October 2013 publication, “Protecting patient health information in electronic records,” suggests considering the following tips when using electronic records and other technologies:

○ Be aware of and follow relevant guidance from Colleges or other authorities, as well as the privacy legislation that applies to your practice and jurisdiction.

○ Use data sharing agreements to clarify obligations when sharing patient information.

○ Refrain from removing unencrypted, identifiable personal health information from the health care institution’s premises and from storing identifiable personal data on unencrypted mobile devices.

○ Follow the health care institution’s privacy policy and procedures, and access agreements.

○ Use encryption for patient health information stored on a desktop, a laptop, or a mobile device. Determine if better protection is needed for any mobile devices containing patient health information, including the ability to remove data remotely should the device be lost or stolen.

○ Refrain from using public wireless networks (hotspots) and free email services to access or share patient health information.

○ Remember to update electronic security measures including password protection, encryption software, and any required security patches.

○ When disposing of any device, ensure patient information is permanently deleted or irreversibly erased.

©Annex. View All Articles.

Data Diligence
https://magazine.canadianchiropractor.ca/article/Data+Diligence/3062226/489796/article.html

Menu
  • Page View
  • Contents View
  • Advertisers
  • Website

Issue List

September/October 2022

July/August 2022

June 2022

March/April 2022

January/February 2022

November/December 2021

September/October 2021

July/August 2021

May/June 2021

March/April 2021

January-February 2021

December 2020

October 2020

September 2020

July/August 2020

June 2020

May 2020

April 2020

February 2020

December 2019

October 2019

September 2019

JulyAugust 2019

June 2019

May 2019

April 2019

February 2019

December 2018

October 2018

September 2018

July/August 2018

June 2018

May 2018

April 2018

February 2018

December 2017

October 2017

September 2017

July 2017

June 2017

May 2017

April 2017

February 2017

December 2016

October 2016

September 2016

July August 2016

June 2016

May 2016

April 2016

February 2016

December 2015

October 2015

September 2015

July August 2015

June 2015

May 2015

April 2015

February 2015

December 2014

October 2014

September 2014

July August 2014

June 2014

May 2014

April 2014

February 2014

December 2013

October 2013

September 2013

July/August 2013

June 2013

May 2013

April 2013

February 2013

December 2012

October 2012

September 2012

July/August 2012

June 2012

May 2012

February 2012

December 2011

October 2011

September 2011

July/August 2011

June 2011

May 2011

April 2011

April 2012

February 2011

December 2010

October 2010

September 2010

July/August 2010

June 2010

May 2010

April 2010

February 2010

December 2009

October 2009

September 2009

July/August 2009

June 2009

May 2009

April 2009

Febuary 2009

December 08

October 08

September 2008

July-Aug 08

June 2008

May 08

April 2008

March 20008

December 2007


Library