PLEASE RESPOND TO EACH STUDENTS DICUSSION POST. MINIMUM WORDS COUNT IS 100 Word Per Discussion Reply. PLEASE ANNOTATE EACH REPLY WITH THE STUDENTS NAME
PLEASE RESPOND TO EACH STUDENTS DICUSSION POST. MINIMUM WORDS COUNT IS 100 word per discussion reply. PLEASE ANNOTE EACH RELY WITH THE STUDENTS NAME.
Richard Gilbert
Week 3 discussion 1
Top of Form
Week Three, Discussion One
Standards and Interoperability
Based on this week's readings, videos, and other research, describe the overall purpose of healthcare information system standards. Research one standard discussed in more detail and elaborate on who and how it was developed, how often is it updated, which systems utilize it, and anything else you found of importance.
I looked at the Health IT site and researched the HL7 that was discussed in the second video. It was developed by a team through the Argonaut project and ONC. At least that is what I understood. Once I dug deeper into the site it showed over 10 updates just since January so I would say it is constantly being updated, The system I reviewed was used in the US only and I did not understand exactly what was meant by what system uses it. The video id of Dr. David McCallie SVP and Fellow of Health Informatics who discusses how the Jason report showed that they needed Healthcare API. He further discusses how difficult it was to create the standard for API health care. His team worked together with ONC and other companies and vendors to create and perfect the system. He noted how detailed the work is to create the product and how in sync you have to be with all the others involved to get it correct and working properly.
Reference:
Health IT (2020) Retrieved 24 July 2020 from http://www.hl7.org/Special/committees/structure/index.cfm
Jasmine Shook
Week Three, Discussion 1
Top of Form
Standards and Interoperability
The purpose of healthcare information system standards is to establish a core set of rules that protect the connection between healthcare and technology (Health IT Standards, 2019). Usually, these standards are a meaningful code that is agreed to be followed to help maintain and establish data security and provide/patient privilege. The main goal of the standards is to cover a vast majority of scenarios for solutions that ensure the system's integrity. One of the mentioned standards was the Prescription Drug Monitoring Programs (PDMP), a digital catalog that monitors the medications circulating within the state (CDC, 2020).
PDMP was started in 1918 by the state of New York in hopes of controlling the use of heroin and cocaine (PDMP TTAC, 2018). This standard allowed medical staff to make direct correlations between drugs and the patient's history before prescribing medication (CDC, 2020). This is in continuous use, often updated within 5 minutes, because pharmacists regularly use it to track drugs that enter the state and are brought to their pharmacy. States are actively looking at making PDMP more user-friendly and accessible, similar to the electronic health records integration. The most significant benefit of PDMP is that it allows the healthcare officials to look at patterns that could change the production, distribution, and abuse of prescribed drugs.
Reference:
Prescription Drug Monitoring Program Training and Technical Assistance Center (TTAC) (2018). Brandeis University. Retrieved from https://www.pdmpassist.org/pdf/PDMP_admin/TAG_History_PDMPs_final_20180314.pdf
Health IT standards. (2019). Retrieved from https://www.healthit.gov/topic/about-onc
Centers of disease control and prevention(CDC), (2020). Retrieved from https://www.cdc.gov/drugoverdose/pdmp/states.html
Bottom of Form
Bottom of Form
Faraon Solis
HIPAA
Top of Form
As I conducted my research, I could not believe how many violations and the amount of money they had to pay. One Health Insurance Portability and Accountability Act (HIPAA) violation is title “Small Health Care Provider Fails to Implement Multiple HIPAA Security Rule Requirements (HHS.gov, 2020). Basically, on June 9, 2011, a breach report was filed Metro. In the report it stated impermissible disclosure of protected heath information to an unknow email account. It affected 1,263 patients. The Office for Civil Rights OCR investigated resulting in revealing longstanding, systemic noncompliance with the HIPAA Security Rule. “Metro failed to conduct any risk analyses, failed to implement any HIPAA Security Rule policies and procedures, and neglected to provide workforce members with security awareness training until 2016” (HHS.gov, 2020). This is totally wrong. They could have prevented this by conducting risk analyses, and implementing HIPAA Security Rule policies and procedures, and conducting security awareness training. I remember training was especially important to us. We had to complete it once a year. It is our responsibility to protect our patients by complying with the HIPAA Rules. I was also glad to see in addition to the monetary settlement, Metro will would be monitored for two years.
The second HIPAA violation is title “OCR Imposes a $1.6 Million Civil Money Penalty against Texas Health and Human Services Commission for HIPAA Violations” (HHS.gov, 2019). The OCR at the U.S. Department of Health and Human Services (HHS) imposed a $1,600,000 against the Texas Health and Human Services Commission (TX HHSC). This was for HIPPAA violations between 2013 and 2017. On June 11, 2015, a report was filed by the Department of Aging and Disability Services (DADS). The report basically stated that ePHI of 6,617 individuals were viewable over the internet. DADS failed to conduct risk analysis and implement access and audit controls on its information systems and application. This could have been prevented if both have been done.
References
HHS.gov. (2019, November 7). Retrieved from OCR Imposes a $1.6 Million Civil Money Penalty against Texas Health and Human Services Commission for HIPAA Violations: https://www.hhs.gov/about/news/2019/11/07/ocr-imposes-a-1.6-million-dollar-civil-money-penalty-against-tx-hhsc-for-hipaa-violations.html
HHS.gov. (2020, July 23). Retrieved from Small Health Care Provider Fails to Implement Multiple HIPAA Security Rule Requirements: https://www.hhs.gov/about/news/2020/07/23/small-health-care-provider-fails-to-implement-multiple-hipaa-security-rule-requirements.html
Bottom of Form
Ariel Campos
Data Breach
Top of Form
Anthem is the nation’s second-largest health insurance company, providing medical care coverage through affiliated health plans, and is a part of the Blue Cross and Blue Shield Association. On March 13, 2015, Anthem filed a breach report with the Health and Human Services (HHS) Office for Civil Rights (OCR) because on January 29, 2015, cyber-attackers gained access to their IT system for the purpose of extracting data (“Anthem agrees”, 2018). After filing their breach report, Anthem discovered cyber-attackers had infiltrated their system through spear phishing after at least one employee responded to the malicious email and opened the door to further attacks. The cyber-attackers stole 79 million individuals’ electronic protected health information(ePHI), including names, social security numbers, medical identification numbers, addresses, dates of birth, email addresses, and employment information from Dec. 2, 2014, to Jan. 27, 2015 (“Anthem agrees”, 2018). This is very alarming because many people’s identities are now compromised due to the cyber-attack. This breach could have been prevented if Anthem would have established a companywide risk analysis, implemented procedures to monitor system activity, and if they had responded to the security breaches sooner.
Another data breach occurred on Feb. 9, 2016, when personal identification and private health information of more than 91,000Apple Health (Medicaid) clients had their personal information compromised. Two state employees – a woman who worked for the state Health Care Authority (HCA) and her brother, who worked for the Department of Social and Health Services (DSHS) – exchanged Apple Health client files in violation of the federal Health Insurance Portability and Accountability Act (HIPAA) for nearly two years(Harshman, 2016). The breach was discovered through a whistleblower who was involved in the investigation of the misuse of state resources. This is concerning because although the two employees were siblings and the sister was only seeking technical help from her brother, it does not excuse the fact that sharing unauthorized patient data is a breach of HIPAA. Both employees were terminated and the breach could have been prevented if the employees did not share unauthorized information. This is why it is important to know HIPAA’s rules to avoid consequences and worse, termination.
References
Anthem agrees to record $16M settlement over largest health data breach in US history (2018). Washington: The Advisory Board Company. Retrieved from nuls.idm.oclc.org/login?url=https://search-proquest-com.nuls.idm.oclc.org/docview/2120996957?accountid=25320
Bottom of Form