After reading about "Massachusetts Clinic Breach Stems From
Unauthorized HIE Access" I would recommend steps from "the
security rule" which are administrative safeguards such as policies
and procedures, physical safeguards such as identification, technical
safeguards such as automatic logoff and unique user identification
and organizational safeguards which comply with HIPPA Security
Rule. Within the security rule the organization can implement data
security methods such as authentication, malicious software
protection and evaluation, data encryption. Another
recommendation would be implementing security audits.
Having effective privacy and security strategies is imperative to an
organization. Organizations that don't have a secure network can
lead to many problems and compromising patients. If patients’
information are compromised it can lead to major problems including
mistrust of patients, delay in medical treatment, it could cost the
organizations millions of dollars.
When looking at the legal and ethical considerations NEHEN has a
legal obligation to protect the patient’s information. throughout the
article there was mention of Codman Square Health Centre in
Dorchester explaining the information was not misused and they
posted a breach notification and did all the necessary follow-up.
Looking at it a legal and ethical view NEHEN should have had a
system set up for this type of situation and put a plan in place.
References
Massachusetts clinic breach stems from unauthorized HIE access. (n.d.).
Becker's Hospital Review - Healthcare
News. https://www.beckershospitalreview.com/healthcare-
information-technology/massachusetts-clinic-breach-stems-from-
unauthorized-hie-access.html?oly_enc_id=5056A9915323H3J
Oachs, P., & Watters. (2020). Health information management:
Concepts, principles, and practice (6th ed.).