HI 300 Unit 7 Seminar Option 2

mary89
HI300Unit7SeminarOption2.pptx

Information Security Background

FACT --- Until 1996, no uniform national standard was in place to protect privacy and security of patient information.

Question of the Day?

Who is actually collecting and seeing all this patient data?

Who has access to this patient data?

To address this concern the following came into play:

1996 - Health Insurance Portability and Accountability Act (HIPAA) --- restricted access of patient information on a need to know basis.

Notice of Privacy Practices (NOPPs) --- help patients understand how their information is being used.

Virtual Field Trip

http://www.youtube.com/watch?v=zFmPjh702gw

Information Security Background

HIPAA led to the development of data security standards on a national level.

HIPPAA made better in 2009 when the Health Information Technology for Economic and Clinical Health (HITECH) Act was enacted.

HITECH – part of the American Recovery and Reinvestment Act, includes requirements for standards development, information technology infrastructure, wanted to speed up EHR implementation

HIPPA Privacy Changes : The OMNIBUS Rule

https://www.youtube.com/watch?v=hdsO4F7dUQk

Confidentiality, Privacy, and Security

Privacy: right of individuals to limit access to information about their person.

Confidentiality: information shared by individual with a healthcare providers during the course of care will be used only for its intended purpose.

Security: protection measures and tools for safeguarding information and information systems

Elements of a Security Program

A good data security program will :

Protect the privacy of data

Safeguarding access

Ensure the integrity of data

Data should be complete, accurate, consistent and up-to-date.

Ensure the availability of data

Can the system perform as expected, without error? Can it provide information when and where needed?

Ensuring Availability of Data

Backup policies should specify what files and programs require backup, how often should you backup and how often should the back up occur.

Records should be kept of what is backed up Copies of backup media should be kept off-site.

Backed up media is only good if it can be used in case of an emergency.

Downtime procedures for both planned and unplanned system availability should be part of the IT infrastructure.

Threats Caused by People

Threats from insiders who make unintentional mistakes

Threats from insiders who abuse their access privileges to information

Threats from insiders who access information or computer systems for spite or profit

Threats from intruders who attempt to access information or steal physical resources

Threats from vengeful employees or outsiders who mount attacks on the organization’s information system

Threats Caused By Environmental And Hardware Or Software Factors

Natural disasters

Utility, hardware, and software failures

Electrical outages and power surges

Hardware or software malfunction

Malware: intentional software intrusions

Strategies For Minimizing Security Threats

Establish a security organization:

Responsible for managing security

Chief security officers

Information security committee

Implement an employee security awareness program:

Educate all new employees on confidentiality

Annual confidentiality statement

Periodic security reminders

Strategies For Minimizing Security Threats

Risk management: identification, management, and control of problematic events

Firewalls

Encryption

Digital Signatures

Web Security Protocols

Intrusion Detection Systems

Incident detection

Access safeguards

Authentication

Single Sign-On

Passwords

Components of a Security Program

Chief Security Officer

Middle or upper management

Monitor compliance with policies

Data security committee

Assist Chief Security Officer

Employees

All should have responsibilities related to security

HITECH Act Breach Notification Requirements

PHI = Protected Health Information

Unsecured PHI: PHI that has not been made unusable, unreadable or indecipherable to unauthorized persons.

PHI is secure if one or more of the following apply:

Encrypted per appropriate standards

Media stored is destroyed appropriately

Discussion Board Example

Determine why information security is so important in healthcare by analyzing at least 2 different types of safeguards for data

Elaborate on at least 2 standards about each safeguard

Identify the types of facilities these safeguards can be used in and what are the expectations.

HIPAA Security Provisions

Administrative safeguards: formal practices to manage data security

Physical safeguards: protection of computer systems from natural and environmental hazards

employee education, health information archival and retrieval systems, disaster recovery, storage media

Technical safeguards: implemented from a technical standpoint computer software

cloud computing, mobile devices to deliver health care, firewalls, encryption / decryption

Audit controls – keeping documented logs of system access attempts

Integrity controls – prevents data from destroyed or altered

Enforcement & Accountability

Each organization should follow its own policies when incidents occur.

Detection of these incidents require careful monitoring by supervisors, managers, etc.

Security plans should include how frequent system audits will take place.

Organizations should conduct their own audits of threats and vulnerabilities and other risks of misusing data.

Lots of 3rd party audit tools available to analyze data and generate reports.

http://www.youtube.com/watch?v=2DAbdXAp5OQ

Sample case study for assignment

Unit 7 Assignment: Part 1

Search the Internet for news about security breaches in healthcare in the last 3 years.

Write an essay summarizing the 2 cases.

Identify the principle threats in each case

What could have been done to minimize those threats?

Unit 7 Assignment: Part 1

Write an essay summarizing the 2 cases.

security breach, computer systems hacked, data on 4 million people stolen, affected 206 hospitals, names, birthdays, social security numbers stolen

what can patients do? Nothing

FBI warned their security is not adequate

if you provided the hospital your information in the last 5 years, your information was stolen

Unit 7 Assignment: Part 1

Identify the principle threats in each case:

Administrative safeguards: formal practices to manage data security

Malware: intentional software intrusions, hackers

Technical safeguards: implemented from a technical standpoint, computer software

Audit controls – keeping documented logs of system access attempts

Integrity controls – prevents data from destroyed or altered

What could have been done to minimize those threats?

Putting policies in place

Adding technical safeguards, administrative safeguards

Unit 7 Assignment: Part 2

Using what you learned from Part I, create a security plan for a medium sized health care facility. In your security plan, evaluate how you would approach security threats from both inside and outside the organization. Be sure that you address the following items in your security plan:

physical and administrative safeguards: employee education, health information archival and retrieval systems, disaster recovery, storage media

access safeguards: authentication, password management

network safeguards: cloud computing, mobile devices to deliver health care, firewalls, encryption / decryption

security threats of mobile devices used in health care delivery

Unit 7 Assignment: Part 2

Critique the plan you wrote:

Identify its strengths of the plan

Identify weaknesses of the plan

Part 1 and Part 2 will be composed in Word as a research paper.

Use APA formatting (title page, references)

Avoid Plagiarism! Don’t hesitate to reach out to the Writing Center if needed!

Additional Help Videos

Security Risk Analysis

http://www.youtube.com/watch?v=hNUBMLVr9z4

Security Plan

http://www.youtube.com/watch?v=61roNgguC1k

Tasks for this Week

Assignment

Discussion

Questions?