Running Head: HEALTH CARE
1
6-1 Final Project Milestone Three: Ethical and Legal Considerations and Recommendations
HIM 422
SNHU
June 12,2022
HEALTH CARE
2
In the health care domain, a data breach incident can give rise to serious implications at the
legal as well as ethical levels. Seh has argued that the instances of healthcare data breach are on the
rise owing to the high integration of digital technologies (Seh et al., 2021). Such breaches are not
just a source of concern for security professionals but also for patients, healthcare practitioners and
organizations. Healthcare organizations need to be well-prepared to ensure that data breach
incidents do not take place that may lead to the compromise of healthcare quality along with the
safety of staff and patients. Stringent policies and procedures can play a key role to minimize or
mitigate risks that arise in the cyber landscape relating to data breach incidents (Kamoun & Nicho,
2014).
Ethical and Legal Considerations:
A. Ethical and legal risks
In the specific scenario involving the healthcare facility, an ethical risk that might have
contributed to the data breach incident is the lack of respect for the confidentiality and privacy of
the patient and his or her medical information. Guddati has argued that the confidentiality between
a patient and a physician must be respected at all costs so that the basic rights of the patient will not
get violated due to data breach (Chiruvella & Guddati, 2021). However, in the specific healthcare
setting, one of the coders have revealed a neighbor’s health record data and shared it with data.
Ozair has pointed out that when the health information relating to patients is shared without their
knowledge, their autonomy is compromised (Ozair et al., 2015). In the specific healthcare context,
a key ethical risk that has occurred relates to the jeopardising of a patient’s autonomy.
According to the HIPAA Privacy Rule, the consent of patients must be taken by a healthcare
service provider in case his PHI is disclosed. In the specific scenario, the data breach shows the non-
HEALTH CARE
3
adherence to HIPAA Privacy Rule (Chiruvella & Guddati, 2021). A key risk that is evident in the
case of the ABC Hospital is insider snooping. Such an issue arises when insiders steal patient
information due to negligence or intentional reasons. When such a HIPAA violation takes place, a
public report to the HHS Brach may be required or an investigation may take place leading to costly
fines. As a coder has violated the HIPAA Act, the lapse in legality has significantly contributed to
the data breach incident. f
B. Maintaining information compromised in data breach
The information that has been compromised during the data breach incident can be maintained
by adopting a methiodal process. Initially, it is vital to have in place a well-functional incidence
response plan. It can play a cardinal role to minimize the impact of the breach incident. It must be
followed by preserving the evidence so that valuable forensic data can be preserved that may be of
use at a later stage. The IT team must then focus on containing the breach by isolating the affected
system so that future damage can be curtailed to a considerable extent. It must be followed by the
incidence response management process. According to the HIPAA Breach Notification Rule,
entities covered under HIPAA must provide notification following a breach incident involving
unsecure patient data (Breach notification rule. HHS.gov, 2021). Ultimately, a robust crisis
communication must be implemented so that the affected individual and relevant stakeholders can
be notified of the incident immediately.
Policy Recommendations
A. Technology-based recommendations
In order to prevent data breach incidents in the healthcare setting, a number of technology-
based recommendations have been made that can help to ensure data confidentiality. A key policy
HEALTH CARE
4
recommendation is to integrate effective cybersecurity tools such as intrusion detection systems to
maintain the privacy and confidentiality of patients. Another policy recommendation for
preventing insider snooping is making it mandatory to conduct tests to identify malicious activities
by employees such as the creation of backdoor accounts, changing common passwords to prevent
access by others, etc. (Breach notification rule. HHS.gov, 2021). Such policies can help to ensure
the safety of patients is not compromised due to data breach incidents.
B. Recommendations for solving organizational challenges
For addressing organizational challenges that might have contributed to the data breach
incident in the ABC Hospital, a number of policy-based measures can be adopted. The first policy
involves the regular upgrading of the IT infrastructure of the organization by integrating the most
effective technical tools and technologies. It can ensure that a safe environment is created where the
sensitive PHI of patients is kept. The second policy recommendation involves creating a security-
based culture within the organization so that employees can value the confidentiality and privacy of
patient. The policy must focus on creating and nurturing a cybersecurity culture within the
healthcare facility (Branley-Bell et al., 2021). It can help to minimize the risk relating to insider
threat or insider snooping from the staff members.
C. Recommendations for reducing gaps in securing patient information
One of the main polices that can be introduced in the ABC Hospital for reducing gaps in
securing patient information is providing technical training to the healthcare staff. Regular training
and development sessions must be introduced, and high emphasis must be laid on cybersecurity
awareness. Such a policy can play a key role to expand the knowledge of the medical staff and
minimize the gap relating to the secure storage of patient information (Pears & Konstantinidis,
HEALTH CARE
5
2021). Another vital policy measure that can be introduced in the hospital to shrink the gaps in
securing patient information is to adopt stringent access management rules in place. Emphasis must
be laid on authorization so that the staff members will have access to only the specific protected
health information that they are allowed to view. This step will ensure that individuals who have
limited access cannot abuse their position and manipulate sensitive patient information for their
malicious needs (Cooper & Collman, 2005). f
For effectively tackling ethical and legal risks, it is essential to introduce effective policies
relating to technologies, organizational challenges and minimizing gaps that may be exploited by
cybercriminals. By implementing the recommended policies, the ABC Hospital can ensure that
similar data breach incidents can be prevented in the future and PHI can be safely managed.
References
HEALTH CARE
6
Breach notification rule. HHS.gov. (2021, June 28). Retrieved June 8, 2022, from
https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
Branley-Bell, D., Coventry, L., & Sillence, E. (2021, June). Promoting Cybersecurity Culture
Change in Healthcare. In The 14th PErvasive Technologies Related to Assistive
Environments Conference (pp. 544-549).
Chiruvella, V., & Guddati, A. K. (2021). Ethical issues in patient data ownership. Interactive
journal of medical research, 10(2), e22269.
Cooper, T., & Collman, J. (2005). Managing information security and privacy in healthcare data
mining. Medical informatics, 95-137.
Kamoun, F., & Nicho, M. (2014). Human and organizational factors of healthcare data breaches:
The swiss cheese model of data breach causation and prevention. International Journal of
Healthcare Information Systems and Informatics (IJHISI), 9(1), 42-60.
Ozair, F. F., Jamshed, N., Sharma, A., & Aggarwal, P. (2015). Ethical issues in electronic health
records: A general overview. Perspectives in clinical research, 6(2), 73.
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity Training in the Healthcare
Workforce–Utilization of the ADDIE Model. In 2021 IEEE Global Engineering Education
Conference (EDUCON) (pp. 1674-1681). IEEE.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Khan, R. A.(2021)
Healthcare data breaches: insights and implications. Healthcare (Basel) 2020 May 13; 8 (2):
133. doi: 10.3390/healthcare8020133.
HEALTH CARE
7