1 / 7100%
BUSI 505-DO3
The U.S. Healthcare System and Health Informatics
Dr. Johnson
4/22/21
Joshua-Paul Johnian Sr.
CS-Privacy, Security and Quality Standards in Informatics
The advanced integration of technology has, in many ways, made life easier and yet vulnerable
at the same time. Routinely we read articles on massive company data breeches, hacked email or
Facebook accounts and even private banking information that has been leaked or stolen. Even in
writing this discussion post there are countless commercials advertising companies that will
monitor your private data, assist with data recovery, provide special insurance for suspected
fraud and even offer additional layers of security to protect one’s personal identity. While such
security risks have always existed since the rapid expansion of technology, through the internet
and data enabled smartphones, individual risk for data breeches have increased exponentially.
Furthermore, one’s identity, and financial history, is as important as their medical record due to
the private nature of such information and the access such data gives is some of the most
intimate portions of a person’s life. While health informatics, driven by technology, has aided
helpful healthcare reforms the expansion of such technologies has also created additional
opportunities for cyber-theft and patient security concerns. In this discussion I will explore how
health informatics addresses privacy, security and quality standards and how the State of North
Carolina is collaborating with the federal government to monitor these risks through HISPC.
In Contemporary Health Informatics Braunstein writes, “a key goal of contemporary health
informatics is the engagement of patients through web, mobile and consumer-facing
technologies.” Braunstein’s research tracks the goals and trends of people who access their PHRs
and how patient engagement, combined with Meaningful Use goals, is essential for sharing
information among patients and providers. However, while patients and the medical community
are embracing these helpful changes Braunstein also highlights, “security of their data is a
significant and legitimate patient concern. Sixty-eight percent are very or somewhat concerned
about the privacy of their medical records.”
Braunstein concludes, “This is not hard to understand since PHRs are housed in the cloud and
are accessed via the internet.” Unfortunately, patient apprehensions are not unwarranted or
unreasonable due to recent breaches in HIPPA laws, un-authorized access to patient data and
malware that his infected hospital servers and diagnostic equipment such as MRIs. Since these
challenges extend beyond the theoretical, like most technology driven industries, health
informatics is constantly trying to remain one step ahead of hackers by addressing security
measures with the highest of attention.
Within the context of health informatics, the definition of privacy and security is, “only
authorized people can see health data and data are protected from unauthorized access.”
Unfortunately, since the internet was not designed as a secure network health informatics
specialist are constantly writing security measures and standards such as SNOMED and W3C as
well and public and private key encryption to protect provider and patient information and
systems. Since these objectives highlight some of the goals of HIEs, HITECH and Meaningful
Use the ongoing development, of an integrated and secure network of data sharing, further
highlights the need for increased security and quality healthcare outcomes.
As these tests represent broad overviews of some challenges facing privacy, security and quality
standards I will turn to what cooperation and changes are utilized in North Carolina to address
these concerns. According to the Agency for Healthcare Research and Quality, “thirty-three
states and 1 territory formed the HISPC, which aims to address the privacy and security
challenges presented by electronic health information exchange through multi-state
collaboration.” The ability for the HISPC to have effective leadership, and implementation, the
state governor appointed a steering committee and a range of local stakeholders to explore the
following:
1. Assess variations in organization-level business policies and state laws that affect health
information exchange.
2. Identify and propose practical solutions, while preserving the privacy and security
requirements in applicable Federal and State laws.
3. Develop detailed plans to implement solutions.
After a two year roll out North Carolina completed phase 1 of HISPC and the North Carolina and
moved into phase 2 which implemented a multi-state collaboration to set up phase 3. According
to past data North Carolina's phase 2 project targeted 4 goals:
1. Build thought leadership by creating statewide health information privacy and security
awareness programs.
2. Actively engage consumers through workshops, town meetings, public communications, and
through the establishment of the North Carolina Consumer Advisory Council on Health
Information (NC CACHI).
3. Seek executive-level private and public sponsorship stakeholders will seek support from their
organizations, as well as public policy makers at the local and state levels, to participate in and
fund collaborative demonstration health information technology projects.
4. Reduce legal barriers to timely health information exchange. Conduct legal analyses of the
ongoing relevance and effect of North Carolina's current privacy laws as the State increases its
use of health information technology in exchanging health information.
According to HealthIT.Gov “The HISPC’s third, and final, phase comprised seven multi-state
collaborative privacy and security projects focused on analyzing consent data elements in state
law; studying intrastate and interstate consent policies; developing tools to help harmonize state
privacy laws; developing tools and strategies to educate and engage consumers; developing a
toolkit to educate providers; recommending basic security policy requirements; and developing
inter-organizational agreements. Each project was charged with developing common, replicable
multi-state solutions that could reduce variation in and harmonize privacy and security practices,
policies, and laws.” On June 30th, 2009 a report from titled, Privacy and Security Solutions for
Interoperable Health Information Exchange Perspectives on Patient Matching: Approaches,
Findings, and Challenges provided an update on the overall project findings stating, “Identity
theft and the sharing of documents, such as insurance cards, also pose challenges to matching. It
is very difficult to detect medical identity theft or document sharing in a matching system unless
a provider notices a discrepancy in the clinical data (e.g., some records indicate that a person has
diabetes, while the others do not). The use of someone else’s information need not be criminal or
malicious—it may be as simple as parents’ providing their identification credentials instead of
their child’s. Systems must include a method for resolving such issues once they are identified,
because they are difficult to prevent and detect.”
Furthermore, in another report titled, Privacy and Security Solutions for Interoperable Health
Information Exchange: Report on State Law Requirements for Patient Permission to Disclose
Health Information the following conclusions found:
“Although state statutes and regulations governing the disclosure of health information for
treatment vary widely in their details, they evince some broad common patterns or approaches
toward disclosing health information to other providers for treatment purposes. Our findings
suggest that some proposed federal approaches to harmonizing state laws are aligned with some
of the common approaches states take, particularly with respect to the disclosure of sensitive
health information. Absent a federal solution, states will need to determine a means for
implementing their laws in an electronic environment. Regardless of the means adopted, whether
it be interstate compact or rules engine or model act, implementation will require more objective
standardized rules than current statutory or regulatory language. Detailed fixed rule sets that
meet or exceed statutory or regulatory requirements for disclosure of health.”
In conclusion a March update from the North Carolina Department of Information Technology
Security and Risk Management Office (ESRMO) reminded people on the cybersecurity
programs, and safeguards, to support the ongoing infrastructure against unauthorized use,
disclosure, modification, phishing schemes or loss. Presently, ESRMO continues to collaborate
with state and private entities to manage and sustain secure information services for North
Carolina patients by reminding all patients of the following:
1. Avoid being social engineered.
2. Keep software up to date.
3. Practice good password management.
4. Physically secure your computing devices.
5. Install and maintain antivirus protections.
6. Safeguard sensitive data.
Like most scavengers, cybercriminals are like the foxes or wolves often referred to in Scripture
as thief’s who can damage crops, steal entire harvests or scale some of the highest defenses, In
Song of Solomon 2:15 and Nehemiah 4:3 Scripture reminds us to be watchful of these types of
people since their motives are to steal, deceive and rob. As the U.S. healthcare system continues
to merge further and deeper into health technology, “health information departments will
encounter new challenges as well as the number of facilities, practices, and other healthcare
settings moving electronic records to rise and as electronic exchange of health information
increases. It is imperative to put in place formal policies and procedures to ensure the privacy
and security of health information.”
Works Cited
Anderson, H. (2005-2007, 9-12 30-31). An Official website for the Department for Health and
Human Services. Retrieved from The Agency for Healthcare Research and Quality:
https://digital.ahrq.gov/ahrq-funded-projects/privacy-and-security-solutionsinteroperable-
hie-nc
Authority, N. H. (2021, March). NCDIT. Retrieved from heia.nc.gov:
https://hiea.nc.gov/blog/2021/03/29/nc-hiea-march-2021-update
Braunstein, M. (2014). Contemporary Health Informatics. Chicago: AHIMA.
Dimitropoulos, L. L. (2009). Privacy and Security Solutions for Interoperable Health
Information Exchange. Chicago: RTI International.
Joy Pritts, S. L. (2009). Privacy and Security Solutions for Interoperable Health Information
Exchange Report on State Law Requirements for Patient Permission to Disclose Health
Information. August: RTI International.
Ozanich, B. S. (2016). Health Information Management and Technology. New York: McGraw
Hill Education.
Unknown. (2018, September 6). Health IT.Gov. Retrieved from Official Website of The Office
of
the National Coordinator for Health Information Technology (ONC):
https://www.healthit.gov/topic/health-information-security-privacy-collaboration-hispc
Students also viewed