1 / 2100%
In the scenerio, the New England Healthcare Exchange Network
experienced a data breach and patient's medical information was
compromised. There are steps that will prevent this from happening
and ensure that patient privacy and safety laws are met. The
recommendation would be to conduct an assessment to address
potential dangers and vulnerabilities of the HIE. Then a risk analysis
would follow, which is a systemic process for reviewing all systems,
applications, and processes to identify potential threats and
vulnerabilities, document current controls, and understand the
likelihood of the impact (Walsh, 2013). An individual titled the HIPPA
security officer is appointed to head up the risk analysis with other
team members like HIM and human resources personnel. The
National Institute of Standards and Technology (NIST) have a nine
steps framework that institutes guidelines for risk analysis and there
are as followed: (1) System Characterization (2) Threat Identification
(3) Control Assessment (4) Vulnerability Identification (5) Likelihood
Determination (6) Impact Analysis (7) Risk Determination (8)
Recommended Controls (9) Results Documentation. The risk analysis
will show outcomes and the team will create a plan for risk
management that follows guidelines of the HIPPA regulations.
Effective privacy and security strategies can lead a healthcare
organization to a successful path by ensuring that patient
information is safe. This can increase patient's satisfaction because
knowing that their personal information is secure, patients will trust
the facility and feel a sense of security. Committing to provide the
highest quality of care to patients is the main objective to the
success of an organization. Also having the necessary privacy policies
will prevent breaches such as the one discussed in the scenerio.
Organizations will benefit from practical security measures and
having those type of polices in place will also align with the facility's
missions and values.
HIPPA Privacy Rule was disregarded in the case of NEHEN and
Codman Square Health Center and patient's information was
compromised due to a data breach. The legal guidelines of the HIPPA
law was violated because unauthorized usage of the network.
Unethical practices was committed on NEHEN behalf because they
did not notify patients but Codman did, and the network could have
dealt with the issue more urgently. The standards of an effective and
secure HIE through HIPPA rules and regulations can be applied to
this case.
References
Massachusetts clinic breach stems from unauthorized HIE access.
(2016). BECKER’S HEALTH IT. Retrieved November 18, 2021,
from https://www.beckershospitalreview.com/healthcare-
information-technology/massachusetts-clinic-breach-stems-from-
unauthorized-hie-access.html
Oachs, K.P., Watters, L.A. (2020). Health Information Management:
concepts, principles, and practice. Sixth Edition
Walsh, T. (2013). Security risk analysis and management: An
overview (updated). Journal of AHIMA 84(11). Retrieved
from http://library.ahima.org
Students also viewed