Discussion: The Need for Standards for Health Information Systems
The Need for Standards for Health Information Systems
Nicole Henry
Health information security plays a significant role in health care. Health systems maintain a vast amount of personal identifying information. This includes a patient’s address, payment information, social security number, employer, and private health information. Identity theft hackers will target health organization since it is holding a lot of information in one place and is usually the most current. There are national standards for safeguarding electronic health information. These include the security requirements of electronic health care transactions. These include access control and encrypting methods (HealthIT.gov, 2013) Health Insurance Portability and Accountability Act of 1996 (HIPAA) has evolved to maintain its relevancy since technology has advanced (U.S. Department of Health & Human Services [HHS], 2017). This law is what sets the national standards for health information. However, it is important that organizations stay current with present breach or cyber attacks to proactively protect health information.
Health organizations must adopt practices that demonstrate that they protect health information through administrative, technical, and physical controls and routinely conduct risk analysis (HHS, 2013). Administrative controls include limiting access to only those who have a need to know. Annual training for all employees who could potentially access health information. Physical safeguards such locked access rooms that hold health information. Technical safeguards such as codes, password protection, and encrypting information. Organizations must perform risk analysis that includes the evaluation of potential impacts of a data breach, security safeguards, and document on how the chosen measure work for the organization (HHS, 2013). Organizations must constantly access the potential of data breaches to ensure their customers and employees are protected.
U.S. Department of Health & Human Services (HHS) (2017). HIPAA for Professionals. Retrieved from: https://www.hhs.gov/hipaa/for-professionals/index.html
HealthIT.gov (2013). What Security are Designed to Prevent Electronic Health Records from being “Hacked?” Retrieved from: https://www.healthit.gov/faq/what-security-safeguards-are-designed-prevent-electronic-health-records-being-hacked
U.S. Department of Health & Human Services (HHS) (2013). Summary of the HIPAA Security Rule. Retrieved from: https://www.hhs.gov/hipaa/for-professionals/security/laws-
Steven Dean posted Sep 8, 2019 11:02 AM
In order to enforce the security of health information systems, hospitals can adopt the following strategies. Network protection. This involves the protection of hospital networks from hacking. Hospitals should adopt both perimeter security such as firewalls and antivirus software and techniques that limit the level of damage in cases of attacks such as networks segregation. Staff training and education. To avoid data breaches due to employee negligence or malice, healthcare systems security programs should include the education and training of employees regarding issues such as the HIPAA violation framework and how to avoid attacks that target employees such as phishing and social engineering. Encryption of portable devices. Hospitals need to encrypt portable devices such as laptops that have private data to avoid cases of data breaches resulting from the loss of computing or storage devices. The carrying of data on personal devices should also be avoided by using strategies such as mobile device management (MDM) software and the creation of a mobile device policy. Deletion of unnecessary data. Hospitals need to adopt a policy that ensures data that is no longer in use is deleted the regular auditing of the stored information(Martínez-Pérez, et al 2015).
References
Martínez-Pérez, B., De La Torre-Díez, I., &López-Coronado, M. (2015). Privacy and security in mobile health apps: a review and recommendations. Journal of medical systems, 39(1), 181.
Shrestha, N. M., Alsadoon, A., Prasad, P. W. C., Hourany, L., &Elchouemi, A. (2016, April). Enhanced e-health framework for security and privacy in healthcare system. In 2016 Sixth International Conference on Digital Information Processing and Communications (ICDIPC) (pp. 75-79). IEEE.