Running Head: HEALTH CARE
1
6-1 Final Project Milestone Three: Ethical and Legal Considerations and Recommendations
HIM 422
SNHU
June 12,2022
HEALTH CARE
2
In the health care domain, a data breach incident can give rise to serious implications at
the legal as well as ethical levels. Seh has argued that the instances of healthcare data breach are
on the rise owing to the high integration of digital technologies (Seh et al., 2021). Such breaches
are not just a source of concern for security professionals but also for patients, healthcare
practitioners and organizations. Healthcare organizations need to be well-prepared to ensure that
data breach incidents do not take place that may lead to the compromise of healthcare quality
along with the safety of staff and patients. Stringent policies and procedures can play a key role
to minimize or mitigate risks that arise in the cyber landscape relating to data breach incidents
(Kamoun & Nicho, 2014).
Ethical and Legal Considerations:
A. Ethical and legal risks
In the specific scenario involving the healthcare facility, an ethical risk that might have
contributed to the data breach incident is the lack of respect for the confidentiality and privacy of
the patient and his or her medical information. Guddati has argued that the confidentiality
between a patient and a physician must be respected at all costs so that the basic rights of the
patient will not get violated due to data breach (Chiruvella & Guddati, 2021). However, in the
specific healthcare setting, one of the coders have revealed a neighbor’s health record data and
shared it with data. Ozair has pointed out that when the health information relating to patients is
shared without their knowledge, their autonomy is compromised (Ozair et al., 2015). In the
specific healthcare context, a key ethical risk that has occurred relates to the jeopardising of a
patient’s autonomy.
HEALTH CARE
3
According to the HIPAA Privacy Rule, the consent of patients must be taken by a healthcare
service provider in case his PHI is disclosed. In the specific scenario, the data breach shows the
non-adherence to HIPAA Privacy Rule (Chiruvella & Guddati, 2021). A key risk that is evident
in the case of the ABC Hospital is insider snooping. Such an issue arises when insiders steal
patient information due to negligence or intentional reasons. When such a HIPAA violation takes
place, a public report to the HHS Brach may be required or an investigation may take place
leading to costly fines. As a coder has violated the HIPAA Act, the lapse in legality has
significantly contributed to the data breach incident. b
B. Maintaining information compromised in data breach
The information that has been compromised during the data breach incident can be
maintained by adopting a methiodal process. Initially, it is vital to have in place a well-functional
incidence response plan. It can play a cardinal role to minimize the impact of the breach incident.
It must be followed by preserving the evidence so that valuable forensic data can be preserved
that may be of use at a later stage. The IT team must then focus on containing the breach by
isolating the affected system so that future damage can be curtailed to a considerable extent. It
must be followed by the incidence response management process. According to the HIPAA
Breach Notification Rule, entities covered under HIPAA must provide notification following a
breach incident involving unsecure patient data (Breach notification rule. HHS.gov, 2021).
Ultimately, a robust crisis communication must be implemented so that the affected individual
and relevant stakeholders can be notified of the incident immediately.
Policy Recommendations
A. Technology-based recommendations
HEALTH CARE
4
In order to prevent data breach incidents in the healthcare setting, a number of technology-
based recommendations have been made that can help to ensure data confidentiality. A key
policy recommendation is to integrate effective cybersecurity tools such as intrusion detection
systems to maintain the privacy and confidentiality of patients. Another policy recommendation
for preventing insider snooping is making it mandatory to conduct tests to identify malicious
activities by employees such as the creation of backdoor accounts, changing common passwords
to prevent access by others, etc. (Breach notification rule. HHS.gov, 2021). Such policies can
help to ensure the safety of patients is not compromised due to data breach incidents.
B. Recommendations for solving organizational challenges
For addressing organizational challenges that might have contributed to the data breach
incident in the ABC Hospital, a number of policy-based measures can be adopted. The first
policy involves the regular upgrading of the IT infrastructure of the organization by integrating
the most effective technical tools and technologies. It can ensure that a safe environment is
created where the sensitive PHI of patients is kept. The second policy recommendation involves
creating a security-based culture within the organization so that employees can value the
confidentiality and privacy of patient. The policy must focus on creating and nurturing a
cybersecurity culture within the healthcare facility (Branley-Bell et al., 2021). It can help to
minimize the risk relating to insider threat or insider snooping from the staff members.
C. Recommendations for reducing gaps in securing patient information
One of the main polices that can be introduced in the ABC Hospital for reducing gaps in
securing patient information is providing technical training to the healthcare staff. Regular
training and development sessions must be introduced, and high emphasis must be laid on
HEALTH CARE
5
cybersecurity awareness. Such a policy can play a key role to expand the knowledge of the
medical staff and minimize the gap relating to the secure storage of patient information (Pears &
Konstantinidis, 2021). Another vital policy measure that can be introduced in the hospital to
shrink the gaps in securing patient information is to adopt stringent access management rules in
place. Emphasis must be laid on authorization so that the staff members will have access to only
the specific protected health information that they are allowed to view. This step will ensure that
individuals who have limited access cannot abuse their position and manipulate sensitive patient
information for their malicious needs (Cooper & Collman, 2005). b
For effectively tackling ethical and legal risks, it is essential to introduce effective policies
relating to technologies, organizational challenges and minimizing gaps that may be exploited by
cybercriminals. By implementing the recommended policies, the ABC Hospital can ensure that
similar data breach incidents can be prevented in the future and PHI can be safely managed.
HEALTH CARE
6
References
Breach notification rule. HHS.gov. (2021, June 28). Retrieved June 8, 2022, from
https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
Branley-Bell, D., Coventry, L., & Sillence, E. (2021, June). Promoting Cybersecurity Culture
Change in Healthcare. In The 14th PErvasive Technologies Related to Assistive
Environments Conference (pp. 544-549).
Chiruvella, V., & Guddati, A. K. (2021). Ethical issues in patient data ownership. Interactive
journal of medical research, 10(2), e22269.
Cooper, T., & Collman, J. (2005). Managing information security and privacy in healthcare data
mining. Medical informatics, 95-137.
Kamoun, F., & Nicho, M. (2014). Human and organizational factors of healthcare data breaches:
The swiss cheese model of data breach causation and prevention. International Journal of
Healthcare Information Systems and Informatics (IJHISI), 9(1), 42-60.
Ozair, F. F., Jamshed, N., Sharma, A., & Aggarwal, P. (2015). Ethical issues in electronic health
records: A general overview. Perspectives in clinical research, 6(2), 73.
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity Training in the Healthcare
Workforce–Utilization of the ADDIE Model. In 2021 IEEE Global Engineering Education
Conference (EDUCON) (pp. 1674-1681). IEEE.
HEALTH CARE
7
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Khan, R.
A.(2021) Healthcare data breaches: insights and implications. Healthcare (Basel) 2020
May 13; 8 (2): 133. doi: 10.3390/healthcare8020133.