Codman Square Health Center experienced a nightmare scenario
that would keep you up at night. The worst thing is that the breach
did not occur internally, but from someone outside the organization
through the New England Healthcare Exchange Network (NEHEN)
and accessed patient information from other organizations (Becker's
Healthcare, 2016). In this case, it may not have been Codman Square
Health Center at fault for the breach since their own information
systems were not breached, but since their patient information was
part of the breach, they are required to alert patient of the breach
and reported to the HHS Office of Civil Rights. The NEHEN may
have been at-fault, depending on their findings, and were required to
mitigate their risks to prevent this from occurring again.
Recommendations I have to prevent this type of breach is to follow
the recommendations of the The Office of the National Coordinator
for Health Information Technology (ONC). The NEHEN, Codman
Square Health Center, and all practices associated with the NEHEN
HIE should follow the seven-step approach as a starting point, since
it helps implement a security
management process and helps address security-related
requirements, such as the EHR Incentive Programs, like Meaningful
Use (ONC, 2015). Steps 1-5, and 7 should be followed, and step 6, if
attesting for Meaningful Use and the steps are:
Step 1: Lead Your Culture, Select Your Team, and Learn
Step 2: Document Your Process, Findings, and Actions
Step 3: Review Existing Security of ePHI (Perform Security
Risk Analysis)
Step 4: Develop an Action Plan
Step 5: Manage and Mitigate Risks
Step 6: Attest for Meaningful Use Security-Related Objective
Step 7: Monitor, Audit, and Update Security on an Ongoing
Basis (ONC, 2015).
Periodically checking user audit logs periodically to see if access is
appropriate and flag suspicious activity. Any breaches a member
organization experiences should be mitigated and reported to
NEHEN immediately to see if it also affected the HIE and inform all
affected organizations if such breach occurs. Also, performing an
annual security risk assessment should be a requirement for all
member organizations of the HIE as part of their membership and
NEHEN needs to do one themselves.
Effective privacy and security strategies lead to organizational
success since patient information is more secure and patients have
trust knowing that their information is being protected from
unauthorized access. Experiencing a major security breach would
create patient distrust and may reconsider obtaining care or may go
to a different healthcare organization. This also protects an
organization from lawsuits and fines due to a security breach, which
can be very costly . A hinderance to success is that a security
strategy may lead to a burden of administrative work and additional
costs associated with maintaining the security strategy. Overall, the
benefits of having an effective privacy and security strategy
outweighs the risks associated with experiencing a security breach.
The major law associated with this scenario is violating HIPAA
privacy rules, which have major legal and ethical implications. A
healthcare organization must do what they can to protect patient
records, but there can be bad actors who purposely breach
confidentiality, or if there is a known breach and the risk is not
mitigated, it can be seen as negligence by the covered entity. As part
of the HIPAA regulation, any breaches must be reported to the
Office of Civil Rights (OCR), which they can do further investigation
and covered entities can be subjected to a corrective action plan or a
civil monetary penalty (Oachs & Watters, 2020, p. 321). Based on the
security breach experienced by NEHEN, it could be a Tier 2 (B)
Reasonable Cause, since it doesn't seem that NEHEN was willfully
neglectful and did their full diligence by informing Codman Square
Health Center. A corrective action of NEHEN and all organizations
involved would need to be performed so an incident like this would
not happen again.
Reference:
Becker's Healthcare. (2016, September 23). Massachusetts clinic
breach stems from unauthorized HIE
access. https://www.beckershospitalreview.com/healthcare-
information-technology/massachusetts-clinic-breach-stems-from-
unauthorized-hie-access.html
Oachs, P. K., & Watters, A. L. (2020). Health information
management: Concepts, principals, and practice (6th Ed). American
Health Information Management Association