1 / 7100%
Running Head: HEALTH CARE
1
6-1 Final Project Milestone Three: Ethical and Legal Considerations and Recommendations
HIM 422
SNHU
HEALTH CARE
2
In the health care domain, a data breach incident can give rise to serious implications
at the legal as well as ethical levels. Seh has argued that the instances of healthcare data
breach are on the rise owing to the high integration of digital technologies (Seh et al., 2021).
Such breaches are not just a source of concern for security professionals but also for
patients, healthcare practitioners and organizations. Healthcare organizations need to be well-
prepared to ensure that data breach incidents do not take place that may lead to the
compromise of healthcare quality along with the safety of staff and patients. Stringent
policies and procedures can play a key role to minimize or mitigate risks that arise in the
cyber landscape relating to data breach incidents (Kamoun & Nicho, 2014).
Ethical and Legal Considerations:
A. Ethical and legal risks
In the specific scenario involving the healthcare facility, an ethical risk that might have
contributed to the data breach incident is the lack of respect for the confidentiality and
privacy of the patient and his or her medical information. Guddati has argued that the
confidentiality between a patient and a physician must be respected at all costs so that the
basic rights of the patient will not get violated due to data breach (Chiruvella & Guddati,
2021). However, in the specific healthcare setting, one of the coders have revealed a
neighbor’s health record data and shared it with data. Ozair has pointed out that when the
health information relating to patients is shared without their knowledge, their autonomy is
compromised (Ozair et al., 2015). In the specific healthcare context, a key ethical risk that
has occurred relates to the jeopardising of a patient’s autonomy.
HEALTH CARE
3
According to the HIPAA Privacy Rule, the consent of patients must be taken by a
healthcare service provider in case his PHI is disclosed. In the specific scenario, the data
breach shows the non-adherence to HIPAA Privacy Rule (Chiruvella & Guddati, 2021). A
key risk that is evident in the case of the ABC Hospital is insider snooping. Such an issue
arises when insiders steal patient information due to negligence or intentional reasons. When
such a HIPAA violation takes place, a public report to the HHS Brach may be required or
an investigation may take place leading to costly fines. As a coder has violated the HIPAA
Act, the lapse in legality has significantly contributed to the data breach incident. aa
B. Maintaining information compromised in data breach
The information that has been compromised during the data breach incident can be
maintained by adopting a methiodal process. Initially, it is vital to have in place a well-
functional incidence response plan. It can play a cardinal role to minimize the impact of the
breach incident. It must be followed by preserving the evidence so that valuable forensic
data can be preserved that may be of use at a later stage. The IT team must then focus on
containing the breach by isolating the affected system so that future damage can be curtailed
to a considerable extent. It must be followed by the incidence response management process.
According to the HIPAA Breach Notification Rule, entities covered under HIPAA must
provide notification following a breach incident involving unsecure patient data (Breach
notification rule. HHS.gov, 2021). Ultimately, a robust crisis communication must be
implemented so that the affected individual and relevant stakeholders can be notified of the
incident immediately.
Policy Recommendations
HEALTH CARE
4
A. Technology-based recommendations
In order to prevent data breach incidents in the healthcare setting, a number of
technology-based recommendations have been made that can help to ensure data
confidentiality. A key policy recommendation is to integrate effective cybersecurity tools
such as intrusion detection systems to maintain the privacy and confidentiality of patients.
Another policy recommendation for preventing insider snooping is making it mandatory to
conduct tests to identify malicious activities by employees such as the creation of backdoor
accounts, changing common passwords to prevent access by others, etc. (Breach notification
rule. HHS.gov, 2021). Such policies can help to ensure the safety of patients is not
compromised due to data breach incidents.
B. Recommendations for solving organizational challenges
For addressing organizational challenges that might have contributed to the data breach
incident in the ABC Hospital, a number of policy-based measures can be adopted. The first
policy involves the regular upgrading of the IT infrastructure of the organization by
integrating the most effective technical tools and technologies. It can ensure that a safe
environment is created where the sensitive PHI of patients is kept. The second policy
recommendation involves creating a security-based culture within the organization so that
employees can value the confidentiality and privacy of patient. The policy must focus on
creating and nurturing a cybersecurity culture within the healthcare facility (Branley-Bell et
al., 2021). It can help to minimize the risk relating to insider threat or insider snooping from
the staff members.
C. Recommendations for reducing gaps in securing patient information
HEALTH CARE
5
One of the main polices that can be introduced in the ABC Hospital for reducing gaps in
securing patient information is providing technical training to the healthcare staff. Regular
training and development sessions must be introduced, and high emphasis must be laid on
cybersecurity awareness. Such a policy can play a key role to expand the knowledge of the
medical staff and minimize the gap relating to the secure storage of patient information
(Pears & Konstantinidis, 2021). Another vital policy measure that can be introduced in the
hospital to shrink the gaps in securing patient information is to adopt stringent access
management rules in place. Emphasis must be laid on authorization so that the staff
members will have access to only the specific protected health information that they are
allowed to view. This step will ensure that individuals who have limited access cannot abuse
their position and manipulate sensitive patient information for their malicious needs (Cooper
& Collman, 2005). aa
For effectively tackling ethical and legal risks, it is essential to introduce effective
policies relating to technologies, organizational challenges and minimizing gaps that may be
exploited by cybercriminals. By implementing the recommended policies, the ABC Hospital
can ensure that similar data breach incidents can be prevented in the future and PHI can be
safely managed.
HEALTH CARE
6
References
Breach notification rule. HHS.gov. (2021, June 28). Retrieved June 8, 2022, from
https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
Branley-Bell, D., Coventry, L., & Sillence, E. (2021, June). Promoting Cybersecurity Culture
Change in Healthcare. In The 14th PErvasive Technologies Related to Assistive
Environments Conference (pp. 544-549).
Chiruvella, V., & Guddati, A. K. (2021). Ethical issues in patient data ownership. Interactive
journal of medical research, 10(2), e22269.
Cooper, T., & Collman, J. (2005). Managing information security and privacy in healthcare
data mining. Medical informatics, 95-137.
Kamoun, F., & Nicho, M. (2014). Human and organizational factors of healthcare data
breaches: The swiss cheese model of data breach causation and prevention.
International Journal of Healthcare Information Systems and Informatics (IJHISI),
9(1), 42-60.
Ozair, F. F., Jamshed, N., Sharma, A., & Aggarwal, P. (2015). Ethical issues in electronic
health records: A general overview. Perspectives in clinical research, 6(2), 73.
HEALTH CARE
7
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity Training in the Healthcare
Workforce–Utilization of the ADDIE Model. In 2021 IEEE Global Engineering
Education Conference (EDUCON) (pp. 1674-1681). IEEE.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Khan, R.
A.(2021) Healthcare data breaches: insights and implications. Healthcare (Basel) 2020
May 13; 8 (2): 133. doi: 10.3390/healthcare8020133.
Students also viewed