HI 300 Unit 7 Seminar Option 2
Information Security Background
FACT --- Until 1996, no uniform national standard was in place to protect privacy and security of patient information.
Question of the Day?
Who is actually collecting and seeing all this patient data?
Who has access to this patient data?
To address this concern the following came into play:
1996 - Health Insurance Portability and Accountability Act (HIPAA) --- restricted access of patient information on a need to know basis.
Notice of Privacy Practices (NOPPs) --- help patients understand how their information is being used.
Virtual Field Trip
Information Security Background
HIPAA led to the development of data security standards on a national level.
HIPPAA made better in 2009 when the Health Information Technology for Economic and Clinical Health (HITECH) Act was enacted.
HITECH – part of the American Recovery and Reinvestment Act, includes requirements for standards development, information technology infrastructure, wanted to speed up EHR implementation
HIPPA Privacy Changes : The OMNIBUS Rule
https://www.youtube.com/watch?v=hdsO4F7dUQk
Confidentiality, Privacy, and Security
Privacy: right of individuals to limit access to information about their person.
Confidentiality: information shared by individual with a healthcare providers during the course of care will be used only for its intended purpose.
Security: protection measures and tools for safeguarding information and information systems
Elements of a Security Program
A good data security program will :
Protect the privacy of data
Safeguarding access
Ensure the integrity of data
Data should be complete, accurate, consistent and up-to-date.
Ensure the availability of data
Can the system perform as expected, without error? Can it provide information when and where needed?
Ensuring Availability of Data
Backup policies should specify what files and programs require backup, how often should you backup and how often should the back up occur.
Records should be kept of what is backed up Copies of backup media should be kept off-site.
Backed up media is only good if it can be used in case of an emergency.
Downtime procedures for both planned and unplanned system availability should be part of the IT infrastructure.
Threats Caused by People
Threats from insiders who make unintentional mistakes
Threats from insiders who abuse their access privileges to information
Threats from insiders who access information or computer systems for spite or profit
Threats from intruders who attempt to access information or steal physical resources
Threats from vengeful employees or outsiders who mount attacks on the organization’s information system
Threats Caused By Environmental And Hardware Or Software Factors
Natural disasters
Utility, hardware, and software failures
Electrical outages and power surges
Hardware or software malfunction
Malware: intentional software intrusions
Strategies For Minimizing Security Threats
Establish a security organization:
Responsible for managing security
Chief security officers
Information security committee
Implement an employee security awareness program:
Educate all new employees on confidentiality
Annual confidentiality statement
Periodic security reminders
Strategies For Minimizing Security Threats
Risk management: identification, management, and control of problematic events
Firewalls
Encryption
Digital Signatures
Web Security Protocols
Intrusion Detection Systems
Incident detection
Access safeguards
Authentication
Single Sign-On
Passwords
Components of a Security Program
Chief Security Officer
Middle or upper management
Monitor compliance with policies
Data security committee
Assist Chief Security Officer
Employees
All should have responsibilities related to security
HITECH Act Breach Notification Requirements
PHI = Protected Health Information
Unsecured PHI: PHI that has not been made unusable, unreadable or indecipherable to unauthorized persons.
PHI is secure if one or more of the following apply:
Encrypted per appropriate standards
Media stored is destroyed appropriately
Discussion Board Example
Determine why information security is so important in healthcare by analyzing at least 2 different types of safeguards for data
Elaborate on at least 2 standards about each safeguard
Identify the types of facilities these safeguards can be used in and what are the expectations.
HIPAA Security Provisions
Administrative safeguards: formal practices to manage data security
Physical safeguards: protection of computer systems from natural and environmental hazards
employee education, health information archival and retrieval systems, disaster recovery, storage media
Technical safeguards: implemented from a technical standpoint computer software
cloud computing, mobile devices to deliver health care, firewalls, encryption / decryption
Audit controls – keeping documented logs of system access attempts
Integrity controls – prevents data from destroyed or altered
Enforcement & Accountability
Each organization should follow its own policies when incidents occur.
Detection of these incidents require careful monitoring by supervisors, managers, etc.
Security plans should include how frequent system audits will take place.
Organizations should conduct their own audits of threats and vulnerabilities and other risks of misusing data.
Lots of 3rd party audit tools available to analyze data and generate reports.
http://www.youtube.com/watch?v=2DAbdXAp5OQ
Sample case study for assignment
Unit 7 Assignment: Part 1
Search the Internet for news about security breaches in healthcare in the last 3 years.
Write an essay summarizing the 2 cases.
Identify the principle threats in each case
What could have been done to minimize those threats?
Unit 7 Assignment: Part 1
Write an essay summarizing the 2 cases.
security breach, computer systems hacked, data on 4 million people stolen, affected 206 hospitals, names, birthdays, social security numbers stolen
what can patients do? Nothing
FBI warned their security is not adequate
if you provided the hospital your information in the last 5 years, your information was stolen
Unit 7 Assignment: Part 1
Identify the principle threats in each case:
Administrative safeguards: formal practices to manage data security
Malware: intentional software intrusions, hackers
Technical safeguards: implemented from a technical standpoint, computer software
Audit controls – keeping documented logs of system access attempts
Integrity controls – prevents data from destroyed or altered
What could have been done to minimize those threats?
Putting policies in place
Adding technical safeguards, administrative safeguards
Unit 7 Assignment: Part 2
Using what you learned from Part I, create a security plan for a medium sized health care facility. In your security plan, evaluate how you would approach security threats from both inside and outside the organization. Be sure that you address the following items in your security plan:
physical and administrative safeguards: employee education, health information archival and retrieval systems, disaster recovery, storage media
access safeguards: authentication, password management
network safeguards: cloud computing, mobile devices to deliver health care, firewalls, encryption / decryption
security threats of mobile devices used in health care delivery
Unit 7 Assignment: Part 2
Critique the plan you wrote:
Identify its strengths of the plan
Identify weaknesses of the plan
Part 1 and Part 2 will be composed in Word as a research paper.
Use APA formatting (title page, references)
Avoid Plagiarism! Don’t hesitate to reach out to the Writing Center if needed!
Additional Help Videos
Security Risk Analysis
http://www.youtube.com/watch?v=hNUBMLVr9z4
Security Plan
http://www.youtube.com/watch?v=61roNgguC1k
Tasks for this Week
Assignment
Discussion
Questions?