1 / 22100%
Running Head: HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 1
8-2 Final Project Submission: Executive Team Policy Recommendations Briefing
HIM 422
SNHU
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 2
Contents
I. Summary of Problem ................................................................................................................. 3
II. Key Stakeholders ...................................................................................................................... 5
III. Impacts ..................................................................................................................................... 7
IV. Ethical and Legal Considerations: .......................................................................................... 9
V. Policy recommendations ......................................................................................................... 13
References ..................................................................................................................................... 18
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 3
I. Summary of Problem
A. Explanation of the nature of the data breach
In the healthcare sector, breaches of data are very commonly observed. These
breaches are occurring due to several types of incidents in the healthcare settings that
include lost laptops or other devices where the data of the patient is recorded, an insider of
the healthcare organization who either accidentally or purposefully discloses the data of the
patients to others, credential-stealing malware and others (Data breaches: In the healthcare
sector. CIS, 2021). In the present case of ABC hospital, the presence of data breach has
been alerted to the healthcare organization where I am playing the role of a health
information management (HIM) director. I have found that the data breach is identified as
protected health information (PHI). In this healthcare organization, there are 7 medical
coders who work remotely across different regions. Among them, one of the coders has
revealed a neighbour’s health record data where it has been mentioned that the patient had
an inpatient stay for complications from HIV. When the patient found that the health data
had been shared with others, the patient filed a complaint to the legal department of the
hospital. After that, the coder was terminated from the job.
B. The breach investigation
The breach investigation is considered an important part of a data breach response,
which aims to clarify the breach circumstances, assess the consequences and damages that
have occurred due to the data breaches, and, last, it will provide a further plan of action
based on the investigation results (Bassett et al., 2021). While doing the breach
investigation, I have gone through a risk assessment to identify the major issue. As a health
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 4
information management (HIM) director in the healthcare organization, I took the
responsibility to do the risk assessment by following the five steps that include identification
of the hazards, identifying who might be harmed from the data breach, and how evaluated
the risks and took a decision on precautions, recorded important findings and reviewed the
assessment and updated the necessary things. This risk assessment has identified that the
data breaches happen due to the negligence of the coder. Therefore, a communication plan
has been created to inform the stakeholders that have been mentioned below in the table 1.
Table-1: communication plan for data breaches
Targeted audiences
Goals
tools
Timeframe
Program stakeholders
Promote the
progress of the
program
Providing the
stories of the
successful persons
in the healthcare
organization
Yearly basis
Program
implementation team
Informing them
about the required
improvement and
required adjustments
during the
implementation of
the plan
Meeting and
briefing the
documents on a
monthly basis
Every 3 weeks
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 5
Thus, it is recommended for the healthcare organization to implement proper network
security and application security as well as the implementation of encryption. Here,
providing proper training on handling and usage of the PHI is essential to reduce the data
breaches by accidental disclosure or lost devices, or employee errors (Data breaches: In the
healthcare sector. CIS, 2021).
C. The short-term and long-term consequences of data breaches
In the long term of the period, the healthcare organization has more chances to get
the negative impact of data breaches. Research says that after a data breach, the healthcare
organization can lose its potential stakeholders and users as well as lose its healthcare
business. Also, unexpected expenses and legal penalties come across the healthcare
organization that affects its overall growth. Moreover, the healthcare organization can be
badly impacted because of a data breach as it affects the years of reputation that they have
achieved (Sharma et al., 2020).
In addition, the healthcare organization can also have some short-term consequences
that can include operation downtime and loss of sensitive data.
II. Key Stakeholders
A. Identification of the key internal workforce and external stakeholders
The federal law Health Insurance Portability and Accountability Act of 1996 (HIPAA)
has been set up with an aim to protect the sensitive health information of the patient from
being disclosed to others without the knowledge or consent of the patient. This federal law
has set up some national standards for this (Data breaches: In the healthcare sector. CIS,
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 6
2021). By following this federal law, I have realized that I need to inform or notify the
internal workforce and the external stakeholders about the data breach incident in the
healthcare organization. As a health information management (HIM) director of the
healthcare organization, I have identified some of the key internal workforces that include
board members and stags of the organization. Moreover, I have identified some of the
external stakeholders, such as vendors and patients, who need to be notified about the issue.
B. Identification of the key federal stakeholders
The incident of data breach needs to be informed to the federal stakeholders, who can be
the government officials. This could help the healthcare organization in many ways. Here,
the Medicare Conditions for Coverage have been set up to protect the safety and health of
the beneficiaries (Conditions for coverage (cfcs) & conditions of participation (cops). CMS,
2021). Moreover, it has aimed to achieve support from the Joint Commission to improve the
quality of health care in several ways. The state licensing regulation could help the
healthcare organization to boost its efficiency in the forecast period. However, these
regulations and standards have been negatively impacted by the data breaches.
C. Following the policy to avoid future breaches
Here, the key stakeholders who need to follow these policies are the organizational staff,
board members, and vendors to avoid future breaches in the healthcare organization. This
is because they are the pillar of the healthcare organization, and they must follow the
essential policies to maintain a good work environment with ethics.
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 7
III. Impacts
A data breach in the healthcare domain can give rise to serious implications for a
healthcare organization. The report has been designed detailing the impact of the breach
incident on the organization. In the initial section of the report, the laws that are in place to
prevent such incidents have been identified. The communication plan that will be adopted to
notify the key stakeholders has been identified. The financial and non-financial impacts of
the breach on an entity have been identified. Ultimately, appropriate federally sponsored
initiatives have been identified that can ensure the provision of the highest level of
healthcare safety, quality and data security.
Impact – Laws to prevent data breach
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is one of
the most important federal laws that has been introduced to safeguard sensitive patient health
information from being disclosed to any unauthorized parties without their consent (Centre
for Disease Control and Prevention, 2018). According to HIPAA Breach Notification Rule it
is the responsibility of healthcare entities to notify patients in case their unprotected data has
been disclosed or breached in any manner (Hipaa Breach Notification Rule. American
Medical Association, 2021). Physicians need to play a proactive role while evaluating the
severity of a data breach incident by evaluating whether it meets HIPAA’s ‘low probability
of compromise’ threshold or not.
The Federal Trade Commission’s (FTC) Health Breach Notification Rule is another
important legal element that requires companies that have a mobile application, website or
similar technology that has sensitive customer health information to notify customers about a
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 8
breach incident. This law is applicable for most of the health apps as well as similar kinds
of technologies. In the specific scenario involving the ABC hospital, the risk assessment that
was conducted revealed that both the laws were violated since the security of sensitive
patient information was compromised.
Impact – Communication plan
The implementation of a well-defined and transparent communication plan is vital to
make sure that the key stakeholders are made aware of the breach incident and its severity is
shared with them in an honest manner. The first step of the plan involves the identification
of suitable and appropriate communication channels to inform the stakeholders i.e., whose
data have been breached in the incident. In this case, direct phone calls, emails or letters can
be used as communication channels. The next step is to establish facts about what exact
information has been compromised and how the incident took place. Then the ABC hospital
must make sure to communicate directly and immediately with the stakeholder. An honest
and straightforward approach must be adopted and it is also necessary to show remorse.
Ultimately, an official statement must be released by the healthcare facility explaining the
steps that were in place and the consequences of the data breach incident (Seh et al., 2020).
The expectations that have been set to ensure that the people are notified in a timely
manner include conducting a thorough risk assessment process and correctly identifying the
medical coder who was responsible for disclosing sensitive patient information.
Impact – Financial and non-financial impacts
The key financial impact of the data breach on the organization includes the
reduction in revenue generation ability due to a decline in patient number, and the
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 9
imposition of penalties due to the violation of laws relating to data breach in the healthcare
domain. The cost relating to IT infrastructure has also increased since the facility will have
to integrate new and effective cybersecurity instruments. The main non-financial impacts of
the data breach incident on the ABC Hospital include reputational damage and a
considerable decline in patient trust on the hospital and the professionals that work in it. A
data breach incident can impact the decision-making process, such as financial decisions. For
example, responsibilities must be allocated carefully to ensure no professional can abuse his
power or position. Similarly, decisions on employee training must be made to prevent such
incidents from recurring in the future (Health Sector Cybersecurity Coordination Center,
2019).
Impact – Sponsored initiatives
In order to ensure that there is a proper provision of top-level of healthcare safety,
quality and data security, the ABC Hospital can adopt several suitable federally sponsored
initiatives. For example, the knowledge, tools and technologies offered by the Agency for
Healthcare Research and Quality (AHRQ) must be integrated. It will help to improve the
safety of care solutions provided by the facility (Kronick, 2016). The National Quality
Strategy (NQS) must be adopted to achieve better health by focusing on quality and safety
aspects.
IV. Ethical and Legal Considerations
In the health care domain, a data breach incident can give rise to serious implications
at the legal as well as ethical levels. Seh has argued that the instances of healthcare data
breach are on the rise owing to the high integration of digital technologies (Seh et al., 2021).
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 10
Such breaches are not just a source of concern for security professionals but also for
patients, healthcare practitioners and organizations. Healthcare organizations need to be well-
prepared to ensure that data breach incidents do not take place that may lead to the
compromise of healthcare quality along with the safety of staff and patients. Stringent
policies and procedures can play a key role to minimize or mitigate risks that arise in the
cyber landscape relating to data breach incidents (Kamoun & Nicho, 2014).
A. Ethical and legal risks
In the specific scenario involving the healthcare facility, an ethical risk that might have
contributed to the data breach incident is the lack of respect for the confidentiality and
privacy of the patient and his or her medical information. Guddati has argued that the
confidentiality between a patient and a physician must be respected at all costs so that the
basic rights of the patient will not get violated due to data breach (Chiruvella & Guddati,
2021). However, in the specific healthcare setting, one of the coders have revealed a
neighbour’s health record data and shared it with data. Ozair has pointed out that when the
health information relating to patients is shared without their knowledge, their autonomy is
compromised (Ozair et al., 2015). In the specific healthcare context, a key ethical risk that
has occurred relates to the jeopardising of a patient’s autonomy.
According to the HIPAA Privacy Rule, the consent of patients must be taken by a
healthcare service provider in case his PHI is disclosed. In the specific scenario, the data
breach shows the non-adherence to HIPAA Privacy Rule (Chiruvella & Guddati, 2021). A
key risk that is evident in the case of the ABC Hospital is insider snooping. Such an issue
arises when insiders steal patient information due to negligence or intentional reasons. When
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 11
such a HIPAA violation takes place, a public report to the HHS Brach may be required or
an investigation may take place leading to costly fines. As a coder has violated the HIPAA
Act, the lapse in legality has significantly contributed to the data breach incident. aa
B. Maintaining information compromised in data breach
The information that has been compromised during the data breach incident can be
maintained by adopting a methiodal process. Initially, it is vital to have in place a well-
functional incidence response plan. It can play a cardinal role to minimize the impact of the
breach incident. It must be followed by preserving the evidence so that valuable forensic
data can be preserved that may be of use at a later stage. The IT team must then focus on
containing the breach by isolating the affected system so that future damage can be curtailed
to a considerable extent. It must be followed by the incidence response management process.
According to the HIPAA Breach Notification Rule, entities covered under HIPAA must
provide notification following a breach incident involving unsecure patient data (Breach
notification rule. HHS.gov, 2021). Ultimately, a robust crisis communication must be
implemented so that the affected individual and relevant stakeholders can be notified of the
incident immediately.
Policy Recommendations
A. Technology-based recommendations
In order to prevent data breach incidents in the healthcare setting, a number of
technology-based recommendations have been made that can help to ensure data
confidentiality. A key policy recommendation is to integrate effective cybersecurity tools
such as intrusion detection systems to maintain the privacy and confidentiality of patients.
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 12
Another policy recommendation for preventing insider snooping is making it mandatory to
conduct tests to identify malicious activities by employees such as the creation of backdoor
accounts, changing common passwords to prevent access by others, etc. (Breach notification
rule. HHS.gov, 2021). Such policies can help to ensure the safety of patients is not
compromised due to data breach incidents.
B. Recommendations for solving organizational challenges
For addressing organizational challenges that might have contributed to the data breach
incident in the ABC Hospital, a number of policy-based measures can be adopted. The first
policy involves the regular upgrading of the IT infrastructure of the organization by
integrating the most effective technical tools and technologies. It can ensure that a safe
environment is created where the sensitive PHI of patients is kept. The second policy
recommendation involves creating a security-based culture within the organization so that
employees can value the confidentiality and privacy of patient. The policy must focus on
creating and nurturing a cybersecurity culture within the healthcare facility (Branley-Bell et
al., 2021). It can help to minimize the risk relating to insider threat or insider snooping from
the staff members.
C. Recommendations for reducing gaps in securing patient information
One of the main polices that can be introduced in the ABC Hospital for reducing gaps in
securing patient information is providing technical training to the healthcare staff. Regular
training and development sessions must be introduced and high emphasis must be laid on
cybersecurity awareness. Such a policy can play a key role to expand the knowledge of the
medical staff and minimize the gap relating to the secure storage of patient information
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 13
(Pears & Konstantinidis, 2021). Another vital policy measure that can be introduced in the
hospital in order to shrink the gaps in securing patient information is to adopt stringent
access management rules in place. Emphasis must be laid on authorization so that the staff
members will have access to only the specific protected health information that they are
allowed to view. This step will ensure that individuals who have limited access cannot abuse
their position and manipulate sensitive patient information for their malicious needs (Cooper
& Collman, 2005). aa
For effectively tackling ethical and legal risks, it is essential to introduce effective
policies relating to technologies, organizational challenges and minimizing gaps that may be
exploited by cybercriminals. By implementing the recommended policies, the ABC Hospital
can ensure that similar data breach incidents can be prevented in the future and PHI can be
safely managed.
V. Policy recommendations
Policies can play an instrumental role in the cybersecurity landscape to minimize the diverse
range of cybersecurity risks that arise in the cyber setting. In the health care domain,
it is vital to deploy effective and stringent policy-based measures so that the possibility of
data breach incidents can be minimized and effectively tackled. In the specific context of the
ABC Hospital, a number of policies have been recommended that can help to ensure
confidentiality and health-related data and prevent the future possibility of a breach incident.
According to the Healthcare Information and Management Systems Society (HIMSS), some
of the best practices that can be adopted in the health care domain to mitigate the risks that
arise in the cyber landscape are policies and procedures, security awareness training,
encryption, etc. (HIMSS, 2021). The following recommendations have been made that can
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 14
be introduced in the context of the ABC Hospital so that the organization can going forward
prevent additional breach incidents from occurring.
Technology-based recommendations
• The introduction of effective cybersecurity tools such as intrusion detection and
prevention systems (IDS and IPS) must be made mandatory within the health care
facility. Such a tool can ensure that any kind of suspicious activity, whether by an
insider or an external party, can be identified, and the same can be notified to the
respective authority within the organization. In the highly unpredictable cyber setting,
IDS and IPS are considered to be highly effective tools since they alert about an
impending or ongoing cybersecurity threat. These systems can play an instrumental
role in preventing similar incidents from taking place as they are designed for
detecting as well as responding to security threats (Mudzingwa & Agrawal, 2012).
• A regular audit of the IT network of the organization needs to be conducted by
internal IT professionals as well as external auditors to identify the possibility of
insider threats and insider snooping. The specific data breach incident that took place
within the health care entity was related to insider snooping. Insider snooping is
considered to be one of the most common HIPAA violations that can compromise
the data confidentiality of patients (Employee snooping is the most common cause of
HIPAA security breaches. HIPAA Journal, 2020). For ensuring that professionals
within the facility do not snoop around, a thorough audit of their online activities and
log data will be conducted. In case any evidence indicating insider snooping is
identified, it has to be reported to Office for Civil Rights (OCR) as well as the
individual whose data has been accessed (Employee snooping is the most common
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 15
cause of HIPAA security breaches. HIPAA Journal, 2020). Additionally, immediate
disciplinary measures must be taken against the identified perpetrator in the form of
termination.
• Another vital policy revolves around ‘access control.’ The access of coders and
administrative professionals must be limited by introducing measures like unique
passwords and EMR capabilities. In case they require access to sensitive information,
they would have to take prior approval from their supervisors, and they would have
to justify the reason for the same. In addition to taking approval for gaining access,
the professionals must also share a hard copy of their log that highlights their online
activities. Such a robust measure must be adopted within the health care facility so
that there would be better control over the information that coders access online
(Bera et al., 2021).
Recommendations for solving organizational challenges
• The first policy that must be implemented in ABC Hospital to address the
organizational challenges includes the regular upgrading of the IT ecosystem. As
technology is evolving at a rapid pace, it is natural for technology to get obsolete
with the passage of time, which can give rise to vulnerabilities and security gaps.
The IT department must make sure to keep the system up-to-date so that it can
function in a robust manner and the possibility of gaps within the IT infrastructure
can be reduced to a possible extent. For example, better hardware components must
be used so that the possibility of failure can be reduced. Similarly, the network must
be upgraded.
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 16
• The staff must be provided mandatory technical training that focuses on strengthening
the level of cybersecurity awareness. Additional training relating to cybersecurity
must be conducted on a periodical basis so that the staff will be aware of how to
respond in case they identify any abnormal behavior within the organization’s
network (Pears & Konstantinidis, 2021).
• The leaders within the organization must make sure that the HIPAA Security Rule is
adhered to and the safeguards relating to the administrative, technical, as well as
physical aspects have been adopted within the facility. It is vital to fulfilling each of
the three criteria so that the security relating to patient health information (PHI) can
be improved at an integrated level. Furthermore, the leaders within the ABC Hospital
must play a proactive role in promoting and nurturing an organizational culture where
high priority is given to cybersecurity and respecting the confidentiality of patients.
The adherence to the security rule is vital since it ensures integrity, confidentiality as
well as availability relating to all the electronic PHI that has been created, received,
transmitted, or maintained (Scholl et al., 2008).
Recommendations relating to hospital subscriptions for reducing gaps in security
• The tools that have been introduced by the Agency for Healthcare Research and
Quality (AHRQ) must be adopted by the ABC Hospital so that the safety, as well as
the quality of health care services that are offered to the patients, can be improved.
For example, the training program titled ‘TeamSTEPPS’ that AHRQ has introduced
along with the Department of defense must be made mandatory for health care
professionals within the facility so that communication patient safety, as well as
teamwork, can get enhanced. Such a free training can add value in the health care
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 17
setting since it can empower the staff to be more responsible and accountable so that
the possibility of cybersecurity risks and breaches can be managed in a better way.
• The ABC Hospital must make sure to integrate quality initiative elements that have
been introduced by the Centers for Medicare and Medicaid Services (CMS) so that it
can have better control over the quality aspects of its services (Quality Initiatives -
General information. CMS, 2021). For example, the ‘Meaningful Measures’ Initiative
can play an instrumental role in identifying the high priority areas pertaining to
quality measurement as well as making suitable changes so that patient safety can be
improved.
Each of the policy-based recommendations has been made in the context of the ABC
Hospital intends to improve the confidentiality and safety of the patients so that similar
kinds of cybersecurity breach incidents would not take place in the future. It is vital to
introduce policies at diverse levels such as the technology domain, organizational domain as
well as the reduction of security gaps by focusing on the hospital subscription area so that a
comprehensive solution can be adopted to address the cybersecurity problem. It is vital for
the leaders as well as the human resource professionals to make sure that the policy-based
interventions are not only introduced but also strictly implemented within the entire
organization so that a security-based culture can be created.
The policies that have been recommended for the ABC Hospital have been designed by
taking into account the key stakeholders, i.e., patients. Additionally, high emphasis has been
laid on the ethical and legal aspects so that the organization health care organization can
carry out its operations in a responsible and accountable manner without compromising the
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 18
security of the patients. The recommendations can guide the executive team to take
corrective policy-based measures to effectively manage cybersecurity risks and threats.
References
Bera, B., Das, A. K., Garg, S., Piran, M. J., & Hossain, M. S. (2021). Access control
protocol for battlefield surveillance in drone-assisted IoT environment. IEEE Internet
of Things Journal, 9(4), 2708-2721.
Breach notification rule. HHS.gov. (2021, June 28). Retrieved June 8, 2022, from
https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 19
Branley-Bell, D., Coventry, L., & Sillence, E. (2021, June). Promoting Cybersecurity Culture
Change in Healthcare. In The 14th PErvasive Technologies Related to Assistive
Environments Conference (pp. 544-549).
Bassett, G., Hylender, C. D., Langlois, P., Pinto, A., & Widup, S. (2021). Data breach
investigations report. Verizon DBIR Team, Tech. Rep.
Conditions for coverage (cfcs) & conditions of participation (cops). CMS. (2021). Retrieved
May 12, 2022, from https://www.cms.gov/Regulations-and-
Guidance/Legislation/CFCsAndCoPs
Chiruvella, V., & Guddati, A. K. (2021). Ethical issues in patient data ownership. Interactive
journal of medical research, 10(2), e22269.
Cooper, T., & Collman, J. (2005). Managing information security and privacy in healthcare
data mining. Medical informatics, 95-137.
Centers for Disease Control and Prevention. (2018, September 14). Health Insurance
Portability and accountability act of 1996 (HIPAA). Centers for Disease Control and
Prevention. Retrieved May 28, 2022, from
https://www.cdc.gov/phlp/publications/topic/hipaa.html#:~:text=The%20Health%20Insura
nce%20Portability%20and,the%20patient's%20consent%20or%20knowledge.
Data breaches: In the healthcare sector. CIS. (2021, July 14). Retrieved May 12, 2022,
from https://www.cisecurity.org/insights/blog/data-breaches-in-the-healthcare-sector
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 20
Employee snooping is the most common cause of HIPAA security breaches. HIPAA Journal.
(2020, July 8). Retrieved June 24, 2022, from https://www.hipaajournal.com/employee-
snooping-common-cause-hipaa-security-breaches/
HIMSS. (2021, December 16). Cybersecurity in Healthcare. HIMSS. Retrieved June 24,
2022, from https://www.himss.org/resources/cybersecurity-healthcare#Part3
Health Sector Cybersecurity Coordination Center. (2019). A Cost Analysis of Healthcare
Sector Data Breaches.
Hipaa Breach Notification Rule. American Medical Association. (2021). Retrieved May 28,
2022, from https://www.ama-assn.org/practice-management/hipaa/hipaa-breach-
notification-
rule#:~:text=HIPAA's%20Breach%20Notification%20Rule%20requires,and%20security%
20of%20the%20PHI.
Kamoun, F., & Nicho, M. (2014). Human and organizational factors of healthcare data
breaches: The swiss cheese model of data breach causation and prevention.
International Journal of Healthcare Information Systems and Informatics (IJHISI),
9(1), 42-60.
Kronick, R. (2016). AHRQ's role in improving quality, safety, and health system
performance. Public health reports, 131(2), 229-232.
Mudzingwa, D., & Agrawal, R. (2012, March). A study of methodologies used in intrusion
detection and prevention systems (IDPS). In 2012 Proceedings of IEEE Southeastcon
(pp. 1-6). IEEE.
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 21
Ozair, F. F., Jamshed, N., Sharma, A., & Aggarwal, P. (2015). Ethical issues in electronic
health records: A general overview. Perspectives in clinical research, 6(2), 73.
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity training in the healthcare
workforce–utilization of the ADDIE model. In 2021 IEEE Global Engineering
Education Conference (EDUCON) (pp. 1674-1681). IEEE.
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity Training in the Healthcare
Workforce–Utilization of the ADDIE Model. In 2021 IEEE Global Engineering
Education Conference (EDUCON) (pp. 1674-1681). IEEE.
Scholl, M. A., Stine, K. M., Hash, J., Bowen, P., Johnson, L. A., Smith, C. D., & Steinberg,
D. I. (2008). Sp 800-66 rev. 1. an introductory resource guide for implementing the
health insurance portability and accountability act (hipaa) security rule. National
Institute of Standards & Technology.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Ahmad
Khan, R. (2020, June). Healthcare data breaches: insights and implications. In
Healthcare (Vol. 8, No. 2, p. 133). Multidisciplinary Digital Publishing Institute.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Khan, R.
A.(2021) Healthcare data breaches: insights and implications. Healthcare (Basel) 2020
May 13; 8 (2): 133. doi: 10.3390/healthcare8020133.
Sharma, N., Oriaku, E. A., & Oriaku, N. (2020). Cost and effects of data breaches,
precautions, and disclosure laws. International Journal of Emerging Trends in Social
Sciences, 8(1), 33-41.
HIM422 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 22
Quality Initiatives - General information. CMS. (2021). Retrieved June 24, 2022, from
https://www.cms.gov/Medicare/Quality-Initiatives-Patient-Assessment-
Instruments/QualityInitiativesGenInfo
Students also viewed