Nicohwilliam

profileezalsmokey
realworldcasestudies10.1and10.2.docx

Assignment : answer real world case 10.1 and 10.2 questions; at least one

Page per case ; cite textbook

Please see chapter readings from textbook below

Real-World Case 10.1 

The Department of Health and Human Services reported on its website a $3,000,000 settlement with Touchstone Medical Imaging. One of Touchstone’s servers allowed access to ePHI via the internet. More than 300,000 patients were impacted. The ePHI included names, Social ­Security information, and more. Touchstone did not investigate the matter in a timely manner. The investigation also found that a risk analysis had not been conducted and business associate agreements were not in place (Source: HHS 2019).

Real world case 10.1 questions

   

1.         Identify a hacking or intrusion technique that would allow malware to be launched inside the hospital’s firewall undetected by the network intrusion detection system.  

2.   Identify technologies other than the network intrusion detection system, that could possibly detect abnormalities as described above in the system network.    

3.         Identify vulnerabilities that could have been exploited in order to have successfully launched malware within the network system.  

4.         Identify possibilities to keep this from happening in the future.

Real-World Case 10.2  

You are the Chief Security Officer of Anywhere Hospital. You just received a frantic email from one of your help desk employees in the Information Technology department. There is a suspected malware infection that is spreading across your computer network. You ask your staff member whether there has been data loss or corruption. Your team member responds by saying that she does not know yet; the security team has been called and will begin the investigation process, starting with the origin of the malware. A quick and thorough response to this incident is of the utmost importance and is crucial to avoid disrupting patient care systems.

A little while later, you discover that the malware was launched from within the network via email; specifically, the malware was launched on the vice president’s workstation in his office when he opened an email containing the malware. The hospital’s Network Intrusion Detection System did not pick up abnormal traffic coming through the firewall.

    Real world case 10.2 questions

1.         Identify a hacking or intrusion technique that would allow malware to be launched inside the hospital’s firewall undetected by the network intrusion detection system.  

2.   Identify technologies other than the network intrusion detection system, that could possibly detect abnormalities as described above in the system network.    

3.         Identify vulnerabilities that could have been exploited in order to have successfully launched malware within the network system.  

4.         Identify possibilities to keep this from happening in the future.

HITT 1301 CHAPTER 10

Health Information Management Technology,

An Applied Approach

Nanette Sayles, Leslie Gordon

Copyright ©2020 by the American Health Information Management Association. All rights reserved.

Except as permitted under the Copyright Act of 1976, no part of this publication may be reproduced,

stored in a retrieval system, or transmitted, in any form or by any means, electronic, photocopying,

recording, or otherwise, without the prior written permission of AHIMA, 233 North Michigan Avenue,

21st Floor, Chicago, Illinois 60601-5809 (http://www.ahima.org/reprint).

ISBN: 978-1-58426-720-1

AHIMA Product No.: AB103118

[

Privacy, as described in chapter 9, Data Privacy and Confidentiality, is a fundamental right to be undisturbed by intrusion. Privacy, within the context of one’s own personal data or the sensitive data belonging to an organization, is the ability and the right of an individual or organization to control the collection, use (how a healthcare organization avails itself of health information), and disclosure (how information is disseminated) of that personal and sensitive data. Use and disclosure are also defined in chapter 9. Security is the practice or means by which privacy is preserved and protected. Data security, on the other hand, is the process of keeping data, both in transit and at rest, safe from unauthorized access (access to data by individuals who should not have access), alteration (unauthorized modification), or unauthorized destruction (destroying data without permission). Very often, the terms data security and data privacy are used interchangeably, although they have very different meanings. Protecting the privacy of data starts with addressing the following questions:

What, if any, data should be collected?

How can it be used?

Who can have access to it?

How long should the data kept?

How does one control the access to data once it is obtained?

Once those questions are answered and standards and thresholds are put into place, security controls can be used. Security controls protect the privacy of data by limiting the access to personal and sensitive information and protecting the data from unauthorized access, use, and disclosure as well as protect the data from unauthorized alteration and destruction. Security controls include administrative, physical, and technical safeguards that will be addressed in this chapter. It is important to note that it is impossible to establish and maintain data privacy without data security. Data security ensures that the data are kept confidential and maintains data integrity and availability.

Ensuring the Integrity of Data

Data integrity means that data are complete, accurate, consistent, and up to date so the data are reliable. Reliability is a measure of consistency of data items based on their reproducibility and an estimation of their error of measurement. In other words, data are always the same. Data integrity must be maintained over the data life cycle, beginning with the design and implementation of the information systems that collect and store the data to the retrieval and, if applicable, the destruction of the data. Data integrity also ensures data recoverability and searchability by ensuring the accuracy and consistency of stored data. For example, with a database, automated error checking and data validation ensure data integrity. Data integrity is the extent to which healthcare data are complete, accurate, consistent, and timely. Data integrity ensures the data are of the best quality and accuracy throughout their life cycle. Data integrity is a part of data governance and information governance, which are covered in chapter 6, Data Management. Within the healthcare setting, data integrity ensures the completeness and accuracy of health record documentation maintained within an electronic health record (EHR) as described in chapter 1, Health Information Management Profession. Ensuring the integrity of healthcare data is important because healthcare providers use it when making decisions about patient care. ­Human error, software bugs, viruses, hardware malfunctions, storage media and server crashes, and natural disasters such as water and fire can compromise the integrity of data. Robust security programs will be able to respond to such incidences to ensure the data are recovered and data integrity is maintained.

Ensuring the Availability of Data

Ensuring data availability means making sure the organization can depend on the information system to perform as expected, and to provide information when and where it is needed.

In healthcare, it is important that patient data are accessible and available at all times. Retrieval and access problems occur when the information system is unreliable or unavailable (for example, either planned or unplanned downtime). Patient data should be available seven days a week, 24 hours a day to facilitate patient care. To keep the data available, hardware must be maintained and replaced when necessary. Software also must be updated to ensure any issues and security vulnerabilities are corrected. Healthcare organizations must have backup and downtime procedures in place to ensure patient care and business operations can continue in the event of a disruption; for example, if the computer network goes down and data cannot be accessed electronically. Backup procedures are also necessary to be in compliance with federal and state regulations. Data backup procedures may involve server redundancy (duplicate information on one or more servers) and sending data to off-site contracted vendors or data warehouses for safe and secure storage and access.

Backup policies and procedures should specify what files and programs require backup, what type of backup should be performed, how frequently it should occur, and how it is to be conducted. For example, a backup policy and procedure may require that all data operating systems, which consist of software that run the basic functions of a computer, and utility files, which are small programs that provide additional support for the operating systems, be adequately and systematically backed up, including all updates to the software which address any vulnerabilities that occur with the information system. The policy may also indicate whether a full procedure (all data at one time) or incremental procedure (only the data since the last backup) is performed and the frequency with which it should occur (such as daily or weekly).

Documentation should record what is backed up and where the backed-up data are stored. Copies of backup media and records of backups should be stored at a secure location away from the site where the original records are stored. For example, the healthcare organization located in Alabama might back their data up at a location in Kansas. This action is taken so that if a disaster such as a fire or flood occurs at the main site, backup copies will be unaffected. There are many companies that specialize in digital off-site storage.

To ensure the backups are working properly, regular tests of restoring data and software from backed-up copies should be performed to ensure the data can be restored if the data are lost. This loss can be due to hardware failure or other destruction of data or other failure.

Information systems have both planned and unplanned downtimes that affect information system availability. For example, planned downtime may occur when system upgrades are scheduled. Unplanned downtime may occur due to an unforeseen disruption such as an electrical outage or hardware failure. In either case, protocols should be developed to maintain data availability to the greatest extent possible. These protocols should be part of the regular information technology infrastructure and incorporated into the security program of the healthcare organization.

Every healthcare organization is subject to security breaches, or unauthorized data or system access, by people from both inside and outside the healthcare organization. It is essential to recognize the scope of the data security needs of the healthcare organization and to develop a systematic and comprehensive program to deal with them. Security breaches also can occur through hardware or software failures and when an intruder hacks into the information system. More often, however, the security breach occurs when an employee within a healthcare organization either accesses information without authorization or deliberately alters or destroys information. Therefore, the healthcare organization’s security program must have protections in place to monitor its employees and to keep outsiders from harming or accessing information resources. These protections will be addressed later in this chapter. A data loss prevention strategy, which assists organizations with controlling and limiting what (sensitive) data are moved or transferred outside of an organization’s information technology infrastructure by individuals, is also an essential element of data availability and contributes to the overall effectiveness of a data security program. Effective data security does not just happen. It requires planning, training, and the implementation of realistic policies and procedures that address both internal and external threats.

Data Security Threats

Before implementing a data security program, it is important to understand the potential threats to data security. Threats from a number of sources can cause the loss of data privacy, and compromise data integrity or the availability of data. All threats can be categorized as either internal threats (threats that originate within an organization) or external threats (threats that originate outside an organization) (Rinehart-Thompson 2018). Both internal threats and external threats can be caused by people or by environmental and hardware and software factors.

Threats Caused by People

Humans are the greatest threat to electronic health information. Threats to data security from people can be classified into the following five general categories:

1. Threats from insiders who make unintentional errors. Examples include employees who ­accidentally make a typographical error, ­inadvertently delete files on a computer disk, or unknowingly disclose confidential information. Unintentional error is one of the major causes of security breaches.

2. Threats from insiders who abuse their access privileges to information. Examples include employees who knowingly disclose information about a patient to individuals who do not have proper authorization; employees with access to computer files who purposefully snoop for information they do not need to perform their jobs; and employees who store information on a thumb or flash drive, remove it from the organization on a laptop or other storage device, and subsequently lose the device or have it stolen.

3. Threats from insiders who access information or computer systems for spite or profit. ­Generally, such employees seek information to commit fraud or theft. Identity theft—stealing information from patients, their families, or other employees—is on the rise and can ­result in prosecution of those employees who ­obtained that information unlawfully.

4. Threats from intruders who attempt to access ­information or steal physical resources. Individuals may physically come onto the organization’s property to access information or steal equipment such as laptop computers or printers. They also may loiter in the organization’s buildings hoping to access information from unprotected computer terminals or to read or take paper documents, computer disks, or other information.

5. Threats from vengeful employees or outsiders who mount attacks on the organization’s ­information systems. Disgruntled employees might ­destroy computer hardware or software, ­delete or change data, or enter data incorrectly into the information system. ­Outsiders might mount attacks that can harm the organization’s ­information resources. For example, malicious hackers can plant viruses in a computer ­system or break into telecommunications systems to degrade or disrupt information system availability (Olenik and Reynolds 2017).

Four of the threats listed can involve an organization’s employees; therefore, it is important for an organization to remain vigilant to ensure their employees and others with routine access to patient data appropriately use this data.

Social Engineering

Although sophisticated technological breaches of data security occur and are discussed in the media, the most common way that hackers (unauthorized individuals) breach the security of data is through the deployment of social engineering. Social engineering, within the context of data security, is the manipulation of individuals (or targets) to freely disclose personal information or account credentials to hackers. The hackers pose as someone or something that the target is familiar with to gain access to information that would otherwise be private and secure. Hackers can deploy a variety of social engineering techniques. Some of these techniques are more sophisticated in nature than others, but all of them can be highly effective when used on an unsuspecting target. Some hackers will go so far as to research and impersonate an unsuspecting target to gain access to sensitive and valuable information; for example, a hacker might pretend to be the target’s boss. Social engineering techniques will be discussed further in this chapter.

The four main types of social engineering (phishing, spear phishing, baiting, and tailgating) are the following:

1. Phishing. This is the most common type of social engineering technique. Phishing is accomplished using email. The hackers send a target what appears to be a legitimate email correspondence from a legitimate company or organization requesting that the target click a link within the email and provide, typically, log-in and password credentials to an information system or application. For example, a target may receive a phishing email from what appears to be his or her bank. The hacker develops an email that looks very similar to legitimate correspondence from the target’s bank. The hacker then would alert the target that there is something wrong with his or her account and the target must click a link and provide his or her credentials to have the matter resolved.

2. Spear Phishing. Spear phishing is similar to phishing but requires a little more work on the part of the hacker. When the hacker engages in spear phishing, the hacker researches the individual whose identity the hacker will assume by looking up social media accounts and researching the individual’s activity on the web. The hacker will typically assume the identity of an individual in a high-level leadership position of an organization. While assuming this online identity, the hacker will then target other individuals within the ­organization to try to obtain personal ­information from them.

3. Baiting. Baiting involves hackers leaving an infected USB or flash drive in a public area in the hope that someone will come by, pick it up, and use it out of curiosity. If it is used, the individual’s computer will become infected with whatever virus was loaded onto the USB or flash drive. Another version of baiting involves the hacker sending out emails with embedded links to random recipients. When the link is clicked, it loads malicious software that can then transfer sensitive data to the hacker without the ­individual’s knowledge.

4. Tailgating. Tailgating is a social engineering technique that allows a hacker, imposter, or other unauthorized individual to use an authorized individual’s access privileges to gain access to a restricted physical area. For example, an imposter, hacker, or other unauthorized individual wants to gain access to a building that requires badge access. This unauthorized individual follows closely ­behind an individual who just swiped his or her badge and gains access by simply following the other individual inside the building. It is human nature for a person to hold a door open for someone behind him or her and not let the door close on that person. The unauthorized person knows this and exploits the good nature of another individual.

Threats Caused by Environmental and Hardware or Software Factors

People are not the only threats to data security. Natural disasters such as earthquakes, tornadoes, floods, forest fires, and hurricanes can demolish physical facilities and electrical utilities.

In 2017, Hurricane Harvey devastated Texas. Hurricane Harvey affected a very large geographic area, impacting that area with tremendous flooding. Although the loss of life and property was enormous, the hospitals there were appropriately prepared and were able, for the most part to continue to care for the influx of patients from the surrounding areas due to their robust disaster recovery preparedness.

Further, a devastating tornado ripped through Florida in 2018, literally decimating many hospitals there. Despite careful disaster planning, many hospitals were terribly underprepared for the devastation and had to turn away patients in their time of need. In many cases, the hospitals were not able to access their electronic health records, possibly because they did not have backups offsite.

While this kind of devastation is not ordinary, healthcare organizations must protect themselves against the loss caused by environmental factors. Healthcare organizations across the nation should send backup information to vaults that are located many miles off-site, perhaps in a distant state, to assist in the recovery of data should a natural disaster or other catastrophic event destroy on-site computer systems. To recover from the devastation caused by nature, healthcare organizations must have backup and recovery procedures in place for both paper and electronic health records and other important organizational data.

Other causes of security breaches are operating system, software, and hardware failures. These include hardware breakdowns and software failures that cause information systems to shut down or malfunction unexpectedly. Examples include a hard-disk crash that destroys or corrupts data, and a program that has not been updated, which may make it vulnerable to attack. Another example is a failed, weak, or poorly configured firewall.

Electrical outages and power surges also can cause problems. When an electrical outage occurs, information is unavailable to the end user. Data might be corrupted or even lost. Power surges also can destroy or corrupt information. Thus, healthcare organizations must have the appropriate equipment to protect information systems from power surges and backup equipment to keep them operating during an outage.

Yet another type of threat is a hardware or software malfunction. Security breaches may be introduced when new software or hardware is added to the information system or when it is not properly tested.

While malfunctions of various software applications can corrupt data, another type of threat is caused by intentional software intrusions known as malicious software or malware. Malware is any type of software attack designed to disrupt mobile or computer operations. Malware can take partial or full control of a computer and can compromise data security and corrupt both data and hard drives. Examples of malware include the following:

· Phishing. Phishing is accomplished using email. The hackers send a target what appears to be a legitimate email correspondence from a legitimate company or organization requesting that the target click a link within the email and provide, typically, log-in and password credentials to an information system or ­application. Phishing is also considered to be social engineering, which was discussed earlier in this chapter.

· Computer virus. A computer virus is a program that reproduces itself and attaches itself to legitimate programs on a computer. A virus can be programmed to change or corrupt data. Frequently viruses can slow down the performance of a computer system.

· Computer worm. A computer worm is a program that copies itself and spreads throughout a network. Unlike a computer virus, a computer worm does not need to attach itself to a legitimate program. It can execute and run itself.

· Trojan horse. A Trojan horse is a program that gains unauthorized access to a computer and masquerades as a useful function. A Trojan horse virus is capable of compromising data by copying confidential files to unprotected areas of the computer system. Trojan horses may also copy and send themselves to email addresses in a user’s computer.

· Spyware. Spyware is a computer program that tracks an individual’s activity on a computer system. Cookies are a type of spyware. These programs can capture private information such as an individual’s password, credit card numbers, usernames, or account numbers. The following information can then be used for identity theft.

· Backdoor program. A backdoor program is a computer program that bypasses normal authentication processes and allows access to computer resources, such as programs, computer networks, or entire computer systems.

· Rootkit. A rootkit is a computer program designed to gain unauthorized access to a computer and assume control of and modify the operating system.

· Ransomware. Ransomware is malicious software that hackers employ to block access to a computer system or particular computer files. The victim of a ransomware attack will know that his or her computer has been attacked because an electronic ransom note will appear in the computer screen. Typically, the hacker will give the victim a code to gain access to the computer or computer files once a ransom is paid. The hacker will ask for the ransom to be paid in bitcoin, which is electronic currency.

Malware usually gains access to computers via the internet as attachments in emails or through browsing a website that installs the software after the user clicks on a pop-up window. To prevent the intrusion of malware, organizations establish antivirus policies and procedures that establish the use of antivirus software and specify: (1) what devices should be scanned, such as file servers, mail servers, desktop computers; (2) what programs, documents, and files should be scanned; (3) how often scans should be scheduled; (4) who is responsible for ensuring that scans are completed; and (5) what action should be taken when malware is detected. In addition, filters can be used to filter both incoming and outgoing email so that malware is quarantined.

In addition to an antivirus policy, healthcare organizations should have security awareness policies and training that deal with prevention of and identification of malware in place.

Strategies for Minimizing Security Threats

The first and most fundamental strategy in minimizing security threats is to establish a secure organization that is responsible for managing all aspects of computer security. This involves appointing someone in the organization to coordinate the development of security policies and to make certain that they are followed. Generally, this individual is called the chief security officer (CSO).

In addition to appointing someone to the CSO position, the healthcare organization appoints an advisory or policy-making group. This group is called the information security committee or a similar title. It works with the CSO to evaluate the healthcare organization’s security needs, establish a security program, develop associated policies and procedures, including monitoring and sanction policies, and ensures the policies are followed. The development and enforcement of sanction policies and procedures, which impose penalties, are important so employees understand the consequences for noncompliance with security rules.

The HIPAA Security Rule established a national standard for the protection of individually identifiable electronic health records that are created, received, and used by a covered entity. The rule does not specify the roles and composition of an information security committee, but the responsibilities extend well beyond the protection of data and involve human resources, which typically assists in workforce clearances (that is, granting appropriate data access levels to individuals), employee termination procedures (for example, eliminating an employee’s access to data immediately upon severance or notice of severance from the healthcare organization), and application of sanctions to employees who violate established policies (Miaoulis 2011). Other roles include executive-level managers who should have a high-level understanding of the data security policies and procedures and approve security budgets. In addition, the health information management (HIM) director or designee should sit on the information security committee to assist in determining levels of system access, authorization (access rights and privileges based upon policy), and audit trail reviews. Access is the ability of a subject to view, change, or communicate with an object in a computer system. Authorizations and audit trails are discussed later in this chapter. Other management positions involved in the information security committee are the chief information officer (CIO), information technology system directors, network engineers, and representatives from clinical departments (lab, nursing, pharmacy, radiology) as appropriate.

Another strategy for minimizing security threats is helping employees within a healthcare organization to be more aware of their data ­security environment. Specifically, from a social engineering perspective, employees need to be better equipped to identify potential data security threats. As described earlier, social engineering, specifically phishing, has become a problem across all industries. Since most people have ­either a business or personal email address, would-be hackers have numerous opportunities to attempt to trick someone into giving them their personal information.

Too often healthcare organizations have a data security incident. A security incident is the “attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system” (45 CFR Parts 160, 162, and 164 2013, 62). An example is when one employee uses another employee’s password. Prevention is key to averting data security incidences. Educating employees regarding what is at stake if a data security incident occurs and arming them with knowledge to identify a potential threat is of the utmost importance. Red flags that indicate an email might be a phish include the use of gmail.com rather than .org for an email from the administrator of the healthcare organization.

One of the easiest ways to identify a potential threat is to verify the sender of the email. When hackers send a phishing email to a target, they often conceal the true identity of the sender for good reason. The hacker wants to trick the target into thinking the email is coming from a legitimate sender. One way to confirm that the sender of an email is legitimate is to hover the pointer over the From display name to see what email address appears. Figure 10.1 shows a sample of a phishing attempt. In a phishing email, the display name is vastly different from the actual sender’s email address.

Figure 10.1 Sample phishing email

Source:© AHIMA.

Components of a Security Program

The HIPAA Security Rule went into effect in April 2005. The Security Rule focuses on administrative, physical, and technical safeguards (defined later in the chapter) as they relate to the protection of electronic protected health information (ePHI). Electronic protected health information is protected health information that is “created, received, or transmitted” electronically (45 CFR Parts 160, 162, and 164 2013, 61). All covered entities (CEs), as defined in chapter 9, Data Privacy and Confidentiality, have electronic data that needs to be protected from unauthorized access, disclosure, loss, and destruction. The authors of the HIPAA Security Rule made the requirements and obligations of the rule flexible to allow each CE to meet the obligations and requirements in ways that are suitable and appropriate for the size and structure of the organization. For example, more sophisticated information technology will be expected of a 1,000-bed hospital than a two-physician practice. Information technology is computer technology (hardware and software) combined with telecommunications technology (data, image, and voice networks).

The HIPAA Security Rule provisions and requirements will be addressed at length later in the chapter. To implement those requirements, a CE must establish a security program that meets the requirements of the Security Rule and is effective in doing so. Information security professionals developed the Confidentiality, Integrity and Availability (CIA) Triad of Information Security to determine if a security program is effective. The CIA Triad, presented in figure 10.2, is a baseline standard for determining whether a security program is effective. The triad allows for the implementation and evaluation of a security program based upon three goals that are guaranteed if an information system is secured. Those goals are the following:

Figure 10.2 Effective security program guarantee – CIA triad.

Source:© AHIMA.

1. Confidentiality: Only authorized and appropriate individuals access the data within an information system.

2. Integrity: The data within the system can be trusted. This was discussed at the beginning of the chapter.

3. Availability: The data within the system is available to the end user wherever and whenever it is needed.

An effective security program will be able to guarantee the triad at any given moment, even in times of disaster recovery.

An effective security program also contains the following components:

· Employee awareness including ongoing ­education and training

· Risk management program

· Access safeguards

· Physical and administrative safeguards

· Software application safeguards

· Network safeguards

· Disaster planning and recovery

· Data quality control processes (Carlon 2013)

Each component of the security program will be discussed as it relates to the establishment of a CE’s security program. Some of these same elements will also be discussed in relation to the provisions of the Security Rule later in this chapter.

Employee Awareness

As discussed previously, employees are often responsible for threats to data security. Consequently, employee awareness is a particularly important tool to reduce security breaches by wrongdoers (either intentional or unintentional) and to make employees mindful of security breaches so they can recognize them, respond to them, and report them appropriately.

The CE should offer a formal security awareness training that educates every new employee on the confidential nature of protected health ­information (discussed more in chapter 9, Data Privacy and ­Confidentiality). The program should inform employees about the CE’s security policies and the consequences of failing to comply with them. The CE should give each employee a copy of its security policies as they relate to the employee’s job function. The CE also should require every employee to sign a yearly confidentiality statement. Finally, because data security is such an important part of everyone’s job, employees should receive periodic and ongoing security reminders. The security reminders can include policy and procedure refreshers, tips on how to identify ­suspicious emails, or general information about the employees’ obligations from a data security perspective.

Included in the employee awareness program should be policies and procedures regarding mobile devices, the use of email, faxing, and scanned information, and appropriate and inappropriate use of social media.

Risk Management Program

Another strategy in protecting the CE’s data is to establish a risk management program. Risk management is a comprehensive program of activities intended to minimize the potential for injuries to occur in a facility and to anticipate and respond to ensuring liabilities for those injuries that do occur. Risk management includes the processes in place to identify, evaluate, and control risk, defined as the organization’s risk of accidental financial ­liability. CEs must take steps to prevent, detect, and mitigate both external and internal incidents. Mitigation is the steps taken to reduce the impact that a violation of the HIPAA Security Rule has on a patient. For example, the CE may purchase a year’s monitoring of a patient’s credit in the event of a security violation. A well-conceived risk management program can aid prevention, detection, and mitigation of security breaches including identity theft.

Risk Analysis

The Security Rule requires a CE to implement security measures that are sufficient to reduce risk and vulnerabilities. Risk management begins with a risk analysis, which involves assessing security threats and vulnerabilities, and the likely impact of any vulnerability.

A security threat is a situation that has the ­potential to damage a healthcare organization’s information system. In addition to threats and vulnerabilities, a CE should also identify how ePHI is created, managed, stored, and transmitted within the CE and whether vendors or consultants use or maintain ePHI. Of increasing importance is the threat created by the use of mobile devices (phones, tablets, laptops, and so forth). These ­devices are particularly at risk as they are easily lost or stolen.

Once security threats are identified, it is important for a CE to make a likelihood determination, which is an estimate of the probability of threats occurring, and an impact analysis, which is an estimate of the impact of threats on information assets. For example, a CE may be located in a ­region with frequent tornadoes (high likelihood). It is known that tornadoes can be extremely destructive (high impact). For this CE, it would make sense to implement expensive safeguards to protect and back up its information assets against tornadoes. If a threat is low likelihood and low impact (for example, a tornado on the Pacific coast), expenditure of time and money to protect against the threat is not a wise use of resources. CEs on the Pacific coast would have to address mudslides, earthquakes, and wildfires. The CE must conduct this type of analysis on every identified threat—manmade, environmental, and those caused by hardware and software factors—in order to prioritize those that should be addressed first and to which resources should be allocated.

It is essential to determine the value of information to the CE and the consequences of its loss when establishing a risk management program. For example, the CE would have to determine what impact a security breach would have on quality of care, revenue, service, and other aspects of the CE’s operations. Identification of a CE’s information assets includes an inventory of application software, hardware, networks, and other information assets. Once information assets have been identified, their value to the CE is determined. Value is determined based on a number of factors such as criticality of the asset in daily operations, degree of harm resulting if the asset is not available, legal and regulatory requirements, and loss of revenue should the asset be lost or damaged.

Incident Detection

Once possible threats and vulnerabilities are known, it is important to be able to detect whether a threat or incident or intrusion has occurred. An incident is an occurrence or an event. Incident detection methods should be used to identify both accidental and malicious events. Detection programs monitor the information systems for abnormalities or a series of events that might indicate that a security breach is occurring or has occurred. Intrusion detection systems can be used for this purpose. An intrusion detection system monitors the CE’s network and information systems to “detect and identify” suspicious activity (Dowling 2017, 5). The CE can customize the intrusion detection system to a monitoring level that is at the appropriate level for the CE (Dowling 2017). In other words, it can be made stronger or weaker depending on the needs of the CE.

Incident Response Plan and Procedures

Once a security incident has been identified, there must be a coordinated response from the CE to mitigate the incident. An incident response plan includes management procedures and responsibilities to ensure a quick response is effectively implemented for specific types of incidents. For example, in some instances the plan may call for a “watch and warn” response that includes monitoring and notification of an incident but takes no immediate action. In other instances, a “repair and report” response may be instituted, whereby immediate mitigation and repair of the issue is initiated and reported to the team of individuals responsible for responding to the issue. This type of response may be used in the case of a virus attack. A third type of response is “pursue and prosecute,” which includes monitoring an attack, minimizing the attack, collecting evidence, and involving a law enforcement agency. This last example might be used in instances of suspected identity theft. Under the Health Information Technology for Economic and Clinical Health (HITECH) Act, breach notification requirements provide for those situations when affected individuals must be notified about an information security breach affecting their PHI.

The HIPAA Security Rule requires that security incidents be identified, reported to the appropriate persons (which will include the Information ­Security Officer, leadership, and IT technicians), and documented. Responses to an incident include workforce notification, preserving evidence, mitigating harmful effects caused by the breach, and evaluating the incident as a part of the CE’s risk management process (Rinehart-Thompson 2018).

Access Safeguards

Establishing access safeguards is a fundamental security strategy. This is the identification of which employees should have access to what data. The general practice is that employees should have ­access only to data they need to do their respective jobs. For example, a registrar in the admitting office and a nurse would not have access to the same kinds of data. By establishing access safeguards, a CE is taking steps to lessen its vulnerabilities, ­although it cannot prevent them altogether because of the security threats that humans present.

Determining what data to make available to an employee usually involves identifying classes of information based on the employee’s role in the CE. So, the CE would determine what information a registrar, for example, would need to know to do his or her job. Subsequently, every individual who works as a registrar would have access to the same information.

Every role in the CE should be identified, along with the type of information required to perform it. This is role-based access control (RBAC) and is the one used most often in healthcare organizations. Additionally, user-based access control (UBAC) grants access based on a user’s individual identity. For example, every employee in the quality improvement department could potentially have a different degree of access if they have unique responsibilities in that department. Context-based access control (CBAC) limits a user’s access based not only on identity and role, but also on a person’s location and time of access (Rinehart-Thompson 2018). For example, two respiratory therapists may be given the same access based on their identical roles. However, with CBAC access, their access will be further refined (and may differ) based on the units to which they are assigned and the respective shifts they work.

Access control is the restriction of access to information and information resources (such as computers) to only those who are authorized, by role or other means. For access control to be effective, mechanisms that restrict access must be in place. There are a number of access control mechanisms that can be used (discussed later in this chapter). However, the sophistication of the method used should correspond with the value of the information being protected. In other words, the more sensitive or valuable the information, the stronger the control mechanisms need to be. For example, access to health information about patients in a behavioral health unit will only be granted to staff who work in that unit. Identification, authentication, and authorization are the foundation upon which access control mechanisms are based.

Identification

The basic building block of access control is identification of an individual who is accessing the information system. Usually identification is performed through the username or user number. Identification methods must be robust so that an imposter cannot successfully pose as a legitimate user and enter a system illegitimately.

Authentication

The second element of access control is authentication. Authentication is the act of verifying a claim of identity. There are three different types of information that can be used for authentication—something you know, something you have, or something you are. The next section will discuss methods of authentication that fall into these three categories.

Passwords Examples of something you know include such things as a personal identification number (PIN), a password, or your mother’s maiden name. Passwords are frequently used in conjunction with username. Policies and procedures should be in place to ensure passwords cannot be easily compromised. For example, passwords should be of a specific length, include special characters and numbers, should be case sensitive, and should not be words that are included in a dictionary or related to the user’s identification or personal information. For example, “password” and “12345” are weak yet popular passwords if they are allowed by the information system in which they are used. Password policies should include mandatory changes of passwords at specified intervals. These types of restrictions help to limit the chance of an intruder guessing a password or using a program called a password cracker to identify passwords. To help increase security, many information systems will lock out a user after a specified number of unsuccessful attempts to gain access to an information system. In addition, password policies should prohibit users from sharing passwords or writing or displaying passwords. While passwords provide the least amount of security compared to other methods, if properly managed and used, they can be an effective security strategy.

∘ Strengths: Long passwords are harder to compromise.

∘ Weaknesses: Passwords are easy to search and easily stolen if written down. Passwords are easily forgotten if long. Hackers can “sniff” or intercept passwords at various stages of input.

Smart Cards and Tokens Smart cards and token cards are examples of something you have. A smart card is a small plastic card with an embedded microchip that can store multiple identification factors for a specific user. Usually a smart card is used in combination with a user identification or password. A one-time password (OTP) token is a small electronic device programmed to generate and display new passwords at certain intervals. An OTP token is usually used in combination with user identification or a password. To access a system, a user puts in an identification code and the OTP token generates a one-time password that is displayed on the token.

∘ Strengths: Smart cards or tokens only require a pin to be remembered versus a password. Because there is no password, smart cards and tokens prevent dictionary attacks whereby the hacker electronically and repeatedly inputs different passwords in the hopes of guessing the correct password.

∘ Weaknesses: Smart cards and tokens can be stolen and access can be compromised if a static pin number is assigned to a specific smart card, and the user writes the static pin on the back of the smart card.

Biometrics Something you are refers to biometrics. Biometrics is identity verification based upon measurements of a person’s physical characteristics. Examples of biometrics include palm prints, fingerprints, voiceprints, and retinal (eye) scans.

∘ Strengths: Biometrics require no passwords and are very hard to replicate.

∘ Weaknesses: Biometrics can cause false rejection or false acceptance due to the technology still being somewhat new. Also, there are people who are very reluctant to have their fingerprints taken due to privacy concerns.

Strong authentication requires providing information from two of the three different types of authentication information. For example, an ­individual provides something he knows and something he has. This is called two-factor authentication. Examples of two-factor authentication include the use of smart cards or tokens with user identification. Two-factor authentication is a stronger method of protecting data access than user identification with passwords. An example of two-factor identification is being used at Walt Disney World in Florida. Guests insert their park tickets and have their index finger scanned.

Single sign-on is another authorization strategy that allows a user to log in to many separate, although related, information systems. Single sign-on allows a user to log in one time and be able to access many information systems. This prevents the user from having to log in to each information system individually; for example, an encoder and an electronic health record.

Different information systems have different requirements for usernames and passwords. This requires the single sign-on to translate and store the username and password for all of the information systems involved. When the user is finished, the single sign-off is used to log out of all of the information systems with one action.

Authorization

The third element of access control is authorization. Authorization is a right or permission given to an individual to use a computer resource, such as a computer, or to use specific applications and access specific data. It is also a set of actions that gives permission to an individual to perform specific functions such as read, write, or execute tasks.

Authorization to use an information system is usually addressed through identification and authentication as described previously. Authorization to use specific applications (for example, order entry, coding, and registration) and specific data would be different for different individuals in a CE. For example, employees in the admitting and registration department would not be given the same authorization to information systems and data as nurses.

Usually authorization is managed through special authorization software that uses various criteria to determine if an individual has authorization for access, sometimes referred to as an access control matrix. For example, authorization may be based on not only the individual’s identity but also the individual’s role (role-based) and physical location of the resource (that is, access to only certain computers), and time of day (context-based) as described earlier in this chapter.

Information systems may require verification that a human, not a computer, is accessing a website or storage portal. A Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) requires the user to respond to a question that it is assumed could not be answered by a machine. A typical example of a CAPTCHA is when access to a site requires the user to type in a string of characters that appears skewed or distorted. Another common CAPTCHA is to identify images that contain a specified item such as a sign or a vehicle.

Physical Safeguards

Physical safeguards refer to the physical protection of information resources from physical damage, loss from natural or other disasters, and theft. This includes protection and monitoring of the workplace, data center (computer room), and any type of hardware or supporting information system infrastructure such as wiring closets, cables, and telephone and data lines.

This equipment should be in secure locations and protected from natural and environmental hazards and intrusion. Environmental hazards include such things as fire, floods, moisture, temperature variations, and loss of electricity. To protect it from natural or environmental hazards, equipment should be housed in structurally sound and safe areas. There should be smoke and fire alarms, fire suppression systems, heat sensors, and appropriate monitored heating and cooling systems in place. Appropriate backup power sources such as uninterruptable power supply (UPS) devices or power generators should be available if a power outage occurs.

To protect from intrusion, there should be proper physical separation from the public. Doors, locks, audible alarms, and cameras should be installed to protect particularly sensitive areas such as data centers. Identification procedures such as the use of badges to identify employees should be in place. Processes should be established for logging into and out of computer hardware or media. For example, if a data disk or device is being transported or removed from one location to another, there should be a sign-out and sign-in procedure to track access and removal. Furthermore, sign-in and sign-out logs should be in place to track access to sensitive areas such as data centers.

Backup and recovery procedures are also a part of physical security. Backup and recovery procedures should specifically include server, data, and network policies and procedures.

Provisions must also be made to protect workstations that are more exposed to the public. For example, locking devices can be used to prevent ­removal of hardware and other devices. Automatic logouts, which are simply timed logouts that reduce the chances that one’s account will be used by someone else, can be used to prevent ­access by unauthorized individuals. For example, a user may be automatically logged out if there has been no activity within five minutes. Laptops and other mobile devices such as personal digital assistants (PDAs) pose significant threats because they can be easily lost or stolen. Documentation of the custody of such devices must be addressed. One such method is maintaining a custody log that documents who has had custody of the device, the time period of custody, and what files and data were on the device during the custody period. Policies and procedures that cover laptop or mobile device use should be in place. Other security mechanisms such as two-factor authentication (discussed previously) and full disk encryption should be used (discussed later in this chapter.) Global positioning systems (GPS) can also be installed on laptops as well as information systems to remotely locate a computer to retrieve and delete data from it, should a computer be lost or stolen. With these features, a computer can be located quickly and appropriate law enforcement officials notified.

In any security program, employee education is one of the best defenses for protection of data and computer resources. Training programs on data security should be conducted at least annually for all employees and cover applicable security responsibilities, policies, and procedures.

Administrative Safeguards

Administrative safeguards include policies and procedures that address the management of computer resources. For example, one such policy might direct users to log off the information system when they are not using it or employ automatic log-offs after a period of inactivity. Other policies include password security (inappropriate sharing, minimum password requirements, changing the frequency of updating passwords, and failed log-in monitoring) and timely removal of terminated employees’ system access. Another policy might prohibit employees from accessing the internet for purposes that are not work ­related. Finally, a CE should have a policy on Information Technology Asset Disposition (ITAD) that identifies how all data storage devices are destroyed and purged of data prior to repurposing or disposal.

Software Application Safeguards

Another security strategy is to implement application safeguards. Application safeguards are controls contained in application software or ­information systems to protect the security and integrity of information. One common application control is authentication, as previously described. Through the use of passwords, tokens, or biometrics, an information system keeps a record of end users’ identifications and authentication mechanisms and then matches the authentication mechanism to each end user’s privileges. This ensures that end users can access only the information they have permission to access.

Another application control is the audit trail. The audit trail is a software program that tracks every single access or attempted access of data in the information system. It logs the name of the individual who accessed the data, terminal location or IP address (internet protocol address which identifies the computer used), the date and time accessed, the type of data, and the action taken (for example, modifying, reading, or deleting data). System administrators examine audit trails using special analysis software to identify suspicious or abnormal system events or behavior. Because the audit trail maintains a complete log of system activity, it can also be used to help reconstruct how and when an incident or failure occurred. This information helps to identify ways to avoid similar problems in the future. Depending on the CE’s policy, audit trails are reviewed periodically, on predetermined schedules or relative to highly sensitive information.

Yet another application control is the edit check. Edit checks help to ensure data integrity by allowing only reasonable and predetermined values to be entered into the computer. For example, an information system using this feature would disallow an International Classification of Diseases, Tenth Revision, Clinical Modification (ICD-10-CM) code that does not exist. Application controls are important because they are automatic checks that help preserve data confidentiality and integrity.

Network Safeguards

Another important strategy used to guard against security breaches is to implement network safeguards. Many networks are used to transmit healthcare data today, and the data must be protected from intruders and corruption during transmission within and external to the organization. With the widespread use of the internet, network controls also are essential to prevent the threat of hackers. The following are some common safeguards.

Firewalls

A firewall (also called a secure gateway) is a part of an information system or network that is designed to block unauthorized access while permitting authorized communications. It is a software program or device that filters information and serves as a buffer between two networks, usually between a private (trusted) network like an intranet (within the organization and not accessible outside) and a public (untrusted) network like the internet. Firewalls allow internal users access to an external network while blocking malicious hackers from damaging internal systems. All messages entering or leaving the private network pass through the firewall, which examines and evaluates each message and blocks those that do not meet predefined security criteria. For example, an email message that is believed to contain a Social Security number may be prohibited from leaving the private network. An email believed to contain a virus may be prohibited from entering the private network. It may control the size of the file that is allowed through the firewall. A firewall is configured to permit, deny, encrypt, or decrypt computer traffic.

Cryptographic Technologies

Cryptography is a branch of mathematics that is based on the transformation of data by developing ciphers, which are codes that are to be kept secret. Cryptography is used as a tool for data ­security. Strong cryptography improves the security of information systems and their data. There are several types of cryptographic technologies. Cryptographic technologies—such as encryption, digital signatures, and digital certificates—are used to protect information in a variety of situations. This includes protecting data when they are in storage (data at rest), on portable devices such as laptops and flash drives, and while they are being transmitted across networks. Three of these technologies used in healthcare are discussed as follows.

Encryption Encryption is a method of encoding data, converting them to a jumble of unreadable scrambled characters and symbols as they are transmitted through a telecommunication network so that they are not understood by persons who do not have a key to transform the data into their original form. Data are usually encrypted using some type of algorithm, or a standard set of operating rules. Upon receipt, data can only be decoded and restored back to their original readable form ­(decryption) by using a special algorithm. Encryption takes the message from one computer and encodes it in a form that only the receiving computer can decode. For example, an email containing ePHI can be encrypted whereby as the message is moving from one inbox to another, the message itself is scrambled so as not to be intercepted by a would-be hacker.

One type of encryption is called private key infrastructure, or single-key encryption. In this method, two or more computers share the same secret key and that key is used both to encrypt and decrypt a message. However, the key must be kept secret. If it is compromised in any way, the security of the data is likely to be eliminated. Because the key that decodes the information is transmitted with the data, it could be intercepted (Rinehart-Thompson 2018). The best-known secret key security is called the data encryption standard (DES) published by the National Institute of Standards and Technology (NIST).

A common encryption method used over the internet is a system called Pretty Good Privacy (PGP), or public key infrastructure (PKI). This method uses both a public and a private key, which form a key pair. The sending computer uses a key to encrypt the data and it gives a key to the recipient computer to decrypt the data. With this type of encryption there is a registry of public keys, called a certificate authority. If one user wants to send an encrypted message to another, the registry is consulted, and the receiving user’s public key is used to encrypt the data. Only the recipient, who knows the private key, can decrypt the message into its original form.

Digital Signatures A digital signature or digital signature scheme is a public key cryptography method that ensures that an electronic document such as an email message or text file is authentic. This means that the receiver knows who created the document and is assured the document has not been altered in any way since it was created.

In this method data are electronically signed by applying the sender’s private key to the data. The digital signature can be stored or transmitted in the data. The receiving party can then verify the signature by using the public key of the signer.

Digital signatures are sometimes confused with e-signatures. E-signature usually means a system for signing or authenticating electronic documents by entering a unique code or password that verifies the identity of the person and creates an individual signature on a document. E-signatures do not necessarily use cryptography.

Digital Certificates Digital certificates are used to implement public key encryption on a large scale. A digital certificate is an electronic document that uses a digital signature to bind together a public key with an identity such as the name of a person or an organization, address, and so forth. The certificate can be used to verify that a public key belongs to an individual. An independent source called a certificate authority (CA) acts as the middleman who the sending and receiving computer trusts. It confirms that each computer is who it says it is and provides the public keys of each computer to the other.

Web Security Protocols

Transmission protocols that allow devices to speak to one another when on a network are another method of data security. Transport Layer Security (TLS) and its predecessor Secure Sockets Layer (SSL) are based on public key cryptography. These protocols are the most common protocols used to secure communications on the internet between a web browser and a web server. Versions of these protocols can be used for almost any application but are frequently used for electronic mail, internet faxing, instant messaging, e-commerce transactions, and voice communications over the Internet (VoIP).

These protocols allow authentication of the server. Once authentication of the server is established, secure communication can begin using symmetric encryption keys. The user’s message is encrypted in the user’s web browser using an encryption key from the host website. The message is then transported to the host website in encrypted format. Once received by the website, the message is decrypted.

Intrusion Detection Systems

Intrusion detection is the process of identifying attempts or actions to penetrate an information system and gain unauthorized access. Intrusion detection can either be performed in real time or after the occurrence of an intrusion. The purpose of intrusion detection is to prevent the compromise of the confidentiality, integrity, or availability of a resource.

Intrusion detection can be performed manually or automatically. Manual intrusion detection might take place by examining log files, audit trails, or other evidence for signs of intrusions. A system that performs automated intrusion detection is called an intrusion detection system (IDS). Procedures should be outlined in the CE’s data security plan to determine what actions should be taken in response to a probable intrusion. For example, typical actions to be taken might include notification of appropriate individuals, generating an email alert, and so on. Penetration testing may be conducted. Penetration testing is when the CE hires a hacker to try to break into their information systems in order to test the quality of the security measures in place.

Disaster Planning and Recovery

As discussed, CEs must prepare for emergencies such as natural disasters. Further, CEs must prepare both for events that cause minimal disruption (for example, short-term power outages) and for large-scale events such as tornadoes. A contingency plan and its component disaster recovery plan will guide a CE through undesirable non-routine events. In CEs, the continuation of medical services to patients is the highest priority. An important element of medical services is the protection and continued availability of health information (Rinehart-Thompson 2018).

Risk Analysis

According to the Security Rule requirements, the CE must assess the internal and external data security risk environment and evaluate vulnerabilities (internal weaknesses) the CE has with respect to ePHI. Conducting risk analysis, which allows for the identification and prioritization of those risks, helps the CE ensure it is maintaining the confidentiality, integrity, and availability of ePHI. Ongoing risk analysis allows a CE to keep up with the ever-changing threats and vulnerabilities as they happen.

When a CE prepares to conduct a risk analysis, it is important to keep in mind that the Security Rule does not stipulate or require that a particular approach be used for such an analysis. The CE is required, through the risk analysis, to identify potential threats compared to its identified vulnerabilities to determine the level of risk. Risk itself can take many forms including disruption in business, loss of privacy, and legal and financial penalties. Based on the risk analysis, CEs can implement policies, procedures, and other safeguards to counteract the risk.

Disaster Planning

Disaster planning occurs through a contingency plan—a set of procedures, documented by the CE, to be followed when responding to emergencies. The disaster plan identifies what a CE and its personnel need to do during and after security ­incidences and other events, like natural disasters, that limit or prevent access to the CE and patient information. Disaster planning typically includes policies and procedures to help the business continue operations during an unexpected shutdown or disaster. It also includes procedures the business can implement to restore its information systems and resume normal operation after the disaster.

The contingency plan is based on information gathered during the risk assessment and analysis discussed previously. The risk assessment includes the probability that an unexpected shutdown will occur. Using this information, the contingency plan is developed based on the following steps:

Step 1: Identify the minimum allowable time for system disruption

Step 2:Identify alternatives for system continuation

Step 3: Evaluate the cost and feasibility of each alternative

Step 4: Develop procedures required for activating the plan (Johns 2008)

Disaster Recovery

An immediate component of a contingency plan is the disaster recovery plan, which addresses the resources, actions, tasks, and data necessary to ­restore those services identified as critical, such as the EHR, as soon as possible, and to manage business recovery processes. The business continuity plan (BCP) is a set of policies and procedures that direct the CE how to continue its business operations during an information system shutdown. Similarly, an emergency mode of operations prescribes processes and controls to be followed until operations are fully restored. For health information, an important part of the disaster recovery plan is ensuring the availability and accuracy of data as soon as possible after a disaster. As described earlier in the chapter, ongoing data backup is critical for this reason. Restoring system integrity and ensuring that all data are recovered requires that all parts of the information system be verified after the disaster has occurred. Usually one information system or one component of an information system is brought up at a time and processes are verified to ensure they are working correctly.

A plan is only as good as its implementation. The disaster recovery plan must be tested periodically to ensure all the parts of the plan—from disaster identification to backup and recovery—work as expected (Johns 2008).

Data Quality Control Processes

Ensuring data quality is an essential part of any data security program. Responsibility for ensuring data quality is shared by many organization stakeholders. For example, data accuracy begins with any individual who enters or documents data or systems that capture and provide data such as intensive care unit monitoring systems. Monitoring and tracking systems that ensure data quality are part of a data security program.

Data availability, consistency, and definition are three data quality dimensions that are often addressed using computer tools. As described earlier, data availability means that data are easily obtainable. Chapter 6, Data Management, covers data quality characteristics in more detail. Computer tools are used to monitor unscheduled computer downtime, determine why failures occurred, and provide data to help minimize future problems. Data consistency, a component of data integrity, means that data do not change no matter how often or in how many ways they are stored, processed, or displayed. Data values are consistent when the value of any given data element is the same across applications and information systems. Procedures are usually developed to monitor data periodically to ensure they are consistent across information systems.

Data definition is describing the data. Every data element should have a clear meaning and a range of acceptable values. For example, gender should have male and female as the only acceptable values. Data definitions and their values are usually stored in a data dictionary, which is discussed in chapter 6, Data Management.

Coordinated Security Program

A CE employee with responsibility for data security can manage threats to data security with a coordinated security program. This individual should be someone at the middle or senior management level. As mentioned earlier, he or she is frequently called the CSO. Figure 10.3 lists some of the CSO’s functions.

Figure 10.3 Common functions of the chief security officer

• Conduct strategic planning for information system security

• Develop a data and information systems security policy

• Develop data security and information systems procedures

• Manage confidentiality agreements for employees and contractors

• Create mechanisms to ensure that data security policies and procedures are followed

• Coordinate employee security training

• Monitor audit trails to identify security violations

• Conduct risk assessment of enterprise information systems

• Develop a business continuity plan

Source: © AHIMA

When the data security program with policies and procedures is in place, the CSO is responsible for ensuring that everyone follows them. This is done using monitoring and evaluation systems, typically on an annual basis. Many CEs use outside information system auditing firms to conduct their security policy evaluations. In addition to the yearly audit, the CSO will establish procedures to audit and evaluate current processes randomly.

All data security policies and procedures should be reviewed and evaluated at least yearly to make sure they are up-to-date and still relevant to the organization.

HIPAA Security Provisions

The HIPAA Security Rule established standards to protect ePHI. The Department of Health and Human Services established the HIPAA Privacy Rule (discussed in chapter 9, Data Privacy and Confidentiality) and the HIPAA Security Rule. These standards apply to every health plan, healthcare clearinghouse, and healthcare provider processing financial or administrative transactions electronically. Additional changes to the Privacy and Security Rules were created as a result of the American Recovery and Reinvestment Act (ARRA) of 2009.

ARRA moved the enforcement for HIPAA ­security compliance from the Centers for Medicare and Medicaid Services’ Office of Electronic Standards and Security to the Department of Health and Human Services Office for Civil Rights (OCR). The HITECH Act under ARRA increased enforcement of the provisions of the Privacy Rule and Security Rule through tougher penalties and greater breach reporting requirements. Prior to ARRA, audits were only conducted when there was a complaint. ARRA allowed random audits to be conducted. Enforcement of the HIPAA Security Rule must be taken seriously by CEs because penalties are severe and include both financial penalties and prison.

Security Rule standards are grouped into five categories. These categories are the following:

1. Administrative safeguards

2. Physical safeguards

3. Technical safeguards

4. Organizational requirements

5. Policies and procedures and documentation requirements

Essentially, the HIPAA Security Rule provisions follow the established best practices for the development and implementation of effective security policy. The requirements of the HIPAA Security Rule enforce the protection of information and access by authorized individuals only.

General Rules

The General Rules provide the objective and scope for the HIPAA Security Rule as a whole. They specify that CEs must develop a security program that includes a range of security safeguards to protect individually identifiable health information maintained (defined in chapter 9, Data Privacy and Confidentiality) or transmitted in electronic form. The General Rules include the following:

CEs must demonstrate and document that they have done the following:

∘ Ensured the confidentiality, ­integrity, and availability of all ePHI that is ­created, received, maintained, or ­transmitted by the covered entity

∘ Protected ePHI against any reasonably anticipated threats or hazards to the ­security or integrity of ePHI

∘ Protected ePHI against any reasonable or anticipated uses or disclosures that are not permitted under the HIPAA ­Privacy Rule

∘ Ensured compliance with the HIPAA Security Rule by workforce members

The Security Rule is flexible, scalable, and technology neutral. Regarding flexibility, HIPAA allows a CE to adopt security protection measures that are appropriate and reasonable for it. For example, security mechanisms will be more complex in a large hospital than in a small group practice. In determining which security measures to use, the following must be taken into account:

∘ Size, complexity, and capabilities of the CE

∘ Technical infrastructure, hardware, and software capabilities

∘ Security measure costs

∘ Probability and criticality of the potential risks to ePHI

· Scalable means that the Security Rule is written so that it accommodates CEs of any size. Technology neutral means that specific technologies are not prescribed, allowing organizations to develop as their technological capabilities evolve (Rinehart-Thompson 2018).

· The HIPAA Security Rule identifies standards that CEs must comply with. Business associates, hybrid entities, and other related entities (discussed in chapter 9, Data Privacy and Confidentiality) are also required to comply with these standards.

· Implementation specifications define how standards are to be implemented. Implementation specifications are either required or addressable. CEs must apply all implementation specifications that are required. Addressable does not mean optional. For those implementation specifications that are labeled addressable, the CE must conduct a risk assessment and evaluate whether the specification is appropriate to its environment. After conducting a risk assessment, if the CE finds that the specification is not a reasonable and appropriate safeguard for its environment (for example, a small CE may decide not to encrypt PHI because it deems it too expensive to do so), then the CE must do the following:

1. Document why it is not reasonable and appropriate to implement the specification as written.

2. Implement an equivalent alternative method if reasonable and appropriate.

· Maintenance: HIPAA requires CEs and business associates to maintain their security measures. Maintenance requires review and modification, as needed, to comply with the provision of reasonable and appropriate protection of ePHI (45 CFR 164.306).

Administrative Safeguards

Administrative safeguards, as introduced earlier in the chapter, are documented, formal practices to manage data security measures throughout the CE. They require the CE to establish a security management process similar to the concepts discussed earlier in this chapter.

The administrative safeguards detail how the security program should be managed from the CE’s perspective. Policies and procedures should be written and formalized in a policy manual. The CE should issue a statement of its philosophy (why security is important) on data security. Further, it should outline data security authority and responsibilities throughout the CE. There are a number of ways that a CE can control the use of terminals, including user limitations such as maximum allowed log-in attempts, screen savers, and the timing out of terminals when a determined period of inactivity has been reached. Physically, computers should be able to be locked when not in use, and a CE should maintain an inventory such that all computers used within the CE can be identified.

The administrative safeguards include the following standards that CEs must implement:

· Security management process. A CE must have a defined security management process. This means that there is a process in place for creating, maintaining, and overseeing the development of security policies and procedures; identifying vulnerabilities and conducting risk analyses; establishing a risk management program; developing a sanction policy; and reviewing information system activity.

· Assigned security responsibility. Each CE must designate a security official to assume the role described earlier in this chapter.

· Workforce security. The CE must ensure appropriate clearance procedures to grant access to individually identifiable information to workforce members who need to use ePHI to perform their job duties and must maintain appropriate oversight of authorization and access. Likewise, the CE must prevent access to information to those who do not need it and have clear procedures of access termination for employees who leave the CE. These individuals must be removed from the information systems immediately to prevent disgruntled former employees from altering or otherwise harming the data. Sanction policies must also be in place. These sanction policies outline how employees are penalized when they violate the CE’s security policy and procedures.

· Information access management. This standard requires the CE to implement a program of information access management. It includes specific policies and procedures to determine who should have access to what information.

· Security awareness and training. This standard requires the CE to provide security training for all members of the workforce as described above.

· Security incident procedures. This standard requires the implementation of policies and procedures to address security incidents, including responding to, reporting, and mitigating suspected or known incidents.

· Contingency plan. This standard requires the establishment and implementation of policies and procedures for responding to emergencies or failures in systems that contain ePHI. It includes a data backup plan, disaster recovery plan, emergency mode of operation plan, testing and revision procedures, and applications and data criticality analysis to prioritize data and determine what must be maintained or restored first in an emergency.

· Evaluation. A periodic evaluation must be performed in response to environmental or operational changes affecting the security of ePHI and appropriate improvements in policies and procedures should follow.

· Business associate contracts. This standard requires business associates to appropriately safeguard information in their possession and CEs to receive satisfactory assurances that the business associates will do so (45 CFR 164.308).

identifies the HIPAA Security Rule Administrative Safeguards.

Physical Safeguards

Physical safeguards include the protection of hardware, software, and data from natural and environmental hazards and intrusion. Physical safeguards consist of the following:

· Facility access controls. Policies and procedures must be implemented to appropriately manage not only the physical security of information systems, but also the buildings that house those information systems. This is accomplished through building infrastructure as well as access management related to the individuals who are and are not permitted to access those facilities. Restoration of data is also required under this provision during and after disaster recovery as well as regular repairs and updating of physical components of the facilities with documentation to demonstrate such maintenance has taken place.

· Workstation use. Policies and procedures must relate to workstations that access ePHI and include proper functions to be performed, how they are to be performed, and the physical environment in which those workstations exist.

· Workstation security. Provisions under workstation security require that physical safeguards, as described earlier, be implemented for workstations with access to ePHI.

· Device and media controls. This standard requires the CE to specify proper receipt and removal of hardware and media with ePHI and to address items as they move within the CE. The entity must also address procedures for removal or disposal including reuse or redeployment of electronic media, data backup, and the identity of persons accountable for the process. ITAD policies are required under this standard. These policies should address end of life cycle hard drives, laptops, servers, and other media that have contained sensitive data. Because such equipment is often redeployed in the CE, all ePHI and any other sensitive data must be removed. Before hard drives, servers, or laptops are disposed of, appropriate data destruction must be carried out (45 CFR 164.310).

Figure 10.4 HIPAA Security rule administrative safeguards

Source:CMS.2007

Technical Safeguards

Of all the safeguards that are required to be implemented to some degree in compliance with the HIPAA Security Rule, the technical safeguards are the most important aspect to a secure system due to the ever-changing and advancing of technologies across all industries, especially healthcare.

Figure 10.5 HIPAA security rule physical safeguard standards

Source:CMS 2007.

The technical safeguards, which are the technology and the policies and procedures regarding the use and operation of the technology, consist of five broad categories. These provisions include those things that can be implemented from a technical standpoint using computer software, including the following:

· Access controls. The access controls standard requires implementation of technical procedures to control or limit access to health information. The procedures would be executed through some type of software program. This requirement ensures that individuals are given authorization to access only the data they need to perform their respective jobs. The implementation specifications include unique user identifications, emergency access procedures (for example, a break-the-glass capability that allows an individual who normally would not have access to the information access to it in an emergency; however the use of this access must be monitored), automatic log-off after a predetermined period of workstation inactivity, and encryption and decryption, discussed earlier in the chapter.

· Audit controls. The audit control standard requires that procedural mechanisms be implemented to record activity in systems that contain ePHI and that the output be examined to determine appropriateness of access. Audit trails were discussed earlier in this chapter.

· Integrity. The data integrity standard requires CEs to implement policies and procedures to protect ePHI from being improperly altered or destroyed. In other words, this standard requires CEs to provide proof that their data have not been altered in an unauthorized manner. Data authentication can be substantiated through audit trails and system logs that track users who have accessed or modified data via unique identifiers.

· Person or entity authentication. This standard requires that those accessing ePHI must be appropriately identified and authenticated as discussed earlier in this chapter.

· Transmission security. This standard requires the guarding of data against unauthorized access (interception) or improper modification without detection when they are in transit, whether via open networks such as the internet or private networks such as those internal to an organization. The two implementation specifications—integrity controls and encryption—are addressable. The Security Rule itself does not require encryption unless the CE deems it appropriate, but the security of ePHI transmitted over public networks or communication systems must be accomplished. Data encryption that provides protection for data across transmission lines is important because eavesdropping is easily accomplished using devices called sniffers. Sniffers can be attached to networks for the purpose of diverting transmitted data. A sniffer is a software security product that runs in the background of a network, examining and logging packet traffic and serving as an early warning device against crackers. A hacker is an individual whose job is to identify weaknesses in an information system so that they can be corrected. A cracker is an individual who exploits any weaknesses in an information system (Munson 2017). Protecting data during transmission is only one role of encryption. Data at rest can also be encrypted. Data at rest are data that are in storage such as in a database. Passwords stored in a database may also be encrypted. Thus, if a cracker breaks into the password database, the data will be unusable (45 CFR 164.312). Figure 10.6 is HIPAA Security Rule technical safeguards.

Figure 10.6 HIPAA Security Rule Technical Safeguards

Source:CMS 2007.

Organizational Requirements

This section includes the following two standards—one addresses business associates (BA) and similar entities and the other addresses group health plan requirements.

1. Business associate or other contracts. CEs must obtain a written contract with BAs or other entities (hybrid or other) that handle ePHI. The written contract must stipulate that the BA will implement HIPAA administrative, physical, and technical safeguards and procedures and documentation requirements that safeguard the confidentiality, integrity, and availability of the ePHI that it creates, receives, maintains, or transmits on behalf of the CE. The contract must ensure any agent, including a subcontractor, agrees to implement reasonable and appropriate safeguards. Specifically, HIPAA requires a BA to report to the CE any security incident or breach of ePHI of which it becomes aware. The CE must authorize termination of the contract if it determines that the BA has violated a material term of the contract.

2. Group health plan requirements. Group health plans must ensure their plan documents provide that the plan sponsor (an entity that provides a health plan for its employees) will reasonably and appropriately safeguard ePHI that is created, received, maintained, or transmitted by or to plan sponsors on behalf of the health plans (45 CFR 164.314).

Policies and Procedures and Documentation Requirements

The Security Rule requires that CEs and BAs have policies and procedures and that they be documented in writing. The following other information about any actions, assessments, or activities associated with the HIPAA Security Rule also must be in writing.

· Policies and procedures. Entities must implement reasonable and appropriate policies and procedures to comply with the HIPAA security standards, implementation specifications, and other requirements. Policies and procedures should be developed and implemented considering the section on flexibility outlined in the rule.

· Documentation. Entities must maintain their security policies and procedures in writing (this includes electronic format). Any actions, assessments, or activities related to the HIPAA Security Rule also must be documented in writing. Documentation must be retained for six years from the date of its creation or the date when it last was in effect, whichever is later. It must be made available to those individuals responsible for implementing security procedures. Further, it must be reviewed periodically and updated as needed, in response to environmental or organizational changes that affect the security of ePHI (45 CFR 164.316).

American Recovery and Reinvestment Act of 2009 Provisions

The HITECH Act, a portion of ARRA, broadened privacy and security provisions including greater individual rights and protections when third parties handle individually identifiable health information. These changes had a significant impact on the security provisions.

The single most important change was the requirement that business associates of HIPAA-covered entities must comply with most of the same rules as CEs. As noted in chapter 9, Data Privacy and Confidentiality, BAs perform functions or activities on behalf of or for a CE that involve the use or disclosure of PHI. Common BAs include consultants, billing companies, transcription companies, accounting firms, and law firms.

With the implementation of the ARRA, potential BA liability increased. BAs are now held ­directly responsible for not complying with the administrative, physical, and technical safeguards of the HIPAA Security Rule, as well as the policies and procedures and documentation requirements.

Another important change per the HITECH Act was defining breach and adding breach notification requirements. Breaches only apply to unsecured electronic protected health information, which is ePHI that has not been made unusable, unreadable, or indecipherable to unauthorized persons (AHIMA 2013a). Thus, the need for encryption is clear. With regard to security, breach notification has implications for the protection of data in all the following phases:

· Data at rest—for example, data contained in databases, file systems, or flash drives

· Data in motion—for example, data moving through a network or wireless transmission

· Data in use—for example, data in the process of being created, retrieved, updated, or deleted

· Data disposed—for example, discarded paper records or recycled electronic media. It is critical to use appropriate data destruction methods to ensure disposed data cannot be read, retrieved, or reconstructed in any way (AHIMA 2009)

Forensics

Forensics is the process of identifying, analyzing, recovering, and preserving data within an electronic environment. With appropriate policies and procedures in place, it is the responsibility of the CE and its managers, directors, CSO, and employees with audit responsibilities to review access logs, audit trails, failed log-ins, and other reports generated to monitor compliance with the policies and procedures. These types of events are usually called trigger events and include the following employees viewing:

· Records of patients with the same last name or address of the employee

· VIP records (celebrities, board members, political figures)

· Records of those involved in high-profile events in the community

· Records with little or no activity for 120 days

· Other employee’s records

· Files of minors

· Files of those treated for infectious diseases or sensitive diagnoses such as HIV/AIDS or sexually transmitted diseases

· Records of patients for whom the viewing employee did not provide care

· Records of a spouse (without the same surname)

· Records of terminated employees

· Portions of records of a discipline not ­consistent with the employee’s expertise (Walsh and Miaoulis 2014)

The CE should have specific policies and monitoring procedures in place to track employees’ ­access via sign-on and password and periodically audit all reports, especially when incidents occur or VIPs are treated. HIPAA requires a regular ­review of system activity such as monitoring new user access, reviewing system access by users in general, and testing the access of recently terminated employees to ensure they have, in fact, been removed from access roles. There have been numerous cases where employees have inappropriately accessed the hospital records of high-profile individuals. These actions have led to discipline, including termination and fines, after audit trails revealed unauthorized access.

HIM Roles

As data continue to proliferate and breaches continue to occur at an alarming rate, HIM professionals will continue to play an increasing and vital role in leading initiatives and efforts to reduce and prevent data breaches. As health information has become more electronic in nature, HIM roles in general have taken more of a technology emphasis. HIM professionals with graduate degrees can assume the role of the Chief Security Officer. HIM professionals can also conduct audits and risk assessments and otherwise participate in the security program of a CE. Additional roles will continue develop within the HIM field to meet the new needs and challenges brought about by new technology.

image1.png

image2.png

image3.png

image4.png

image5.png