1 / 22100%
Running Head: HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb 1
8-2 Final Project Submission: Executive Team Policy Recommendations Briefing
HIM 422
SNHU
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 2
Contents
I. Summary of Problem ................................................................................................................. 3
II. Key Stakeholders ...................................................................................................................... 5
III. Impacts ..................................................................................................................................... 7
IV. Ethical and Legal Considerations: ....................................................................................... 10
V. Policy recommendations ......................................................................................................... 13
References ..................................................................................................................................... 18
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 3
I. Summary of Problem
A. Explanation of the nature of the data breach
In the healthcare sector, breaches of data are very commonly observed. These
breaches are occurring due to several types of incidents in the healthcare settings that
include lost laptops or other devices where the data of the patient is recorded, an insider of
the healthcare organization who either accidentally or purposefully discloses the data of the
patients to others, credential-stealing malware and others (Data breaches: In the healthcare
sector. CIS, 2021). In the present case of ABC hospital, the presence of data breach has
been alerted to the healthcare organization where I am playing the role of a health
information management (HIM) director. I have found that the data breach is identified as
protected health information (PHI). In this healthcare organization, there are 7 medical
coders who work remotely across different regions. Among them, one of the coders has
revealed a neighbour’s health record data where it has been mentioned that the patient had
an inpatient stay for complications from HIV. When the patient found that the health data
had been shared with others, the patient filed a complaint to the legal department of the
hospital. After that, the coder was terminated from the job.
B. The breach investigation
The breach investigation is considered an important part of a data breach response,
which aims to clarify the breach circumstances, assess the consequences and damages that
have occurred due to the data breaches, and, last, it will provide a further plan of action
based on the investigation results (Bassett et al., 2021). While doing the breach
investigation, I have gone through a risk assessment to identify the major issue. As a
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 4
health information management (HIM) director in the healthcare organization, I took the
responsibility to do the risk assessment by following the five steps that include
identification of the hazards, identifying who might be harmed from the data breach, and
how evaluated the risks and took a decision on precautions, recorded important findings
and reviewed the assessment and updated the necessary things. This risk assessment has
identified that the data breaches happen due to the negligence of the coder. Therefore, a
communication plan has been created to inform the stakeholders that have been mentioned
below in the table 1.
Table-1: communication plan for data breaches
Targeted audiences
Goals
tools
Timeframe
Program stakeholders
Promote the
progress of the
program
Providing the
stories of the
successful persons
in the healthcare
organization
Yearly basis
Program
implementation team
Informing them
about the required
improvement and
required adjustments
during the
implementation of
the plan
Meeting and
briefing the
documents on a
monthly basis
Every 3 weeks
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 5
Thus, it is recommended for the healthcare organization to implement proper network
security and application security as well as the implementation of encryption. Here,
providing proper training on handling and usage of the PHI is essential to reduce the data
breaches by accidental disclosure or lost devices, or employee errors (Data breaches: In the
healthcare sector. CIS, 2021).
C. The short-term and long-term consequences of data breaches
In the long term of the period, the healthcare organization has more chances to get
the negative impact of data breaches. Research says that after a data breach, the healthcare
organization can lose its potential stakeholders and users as well as lose its healthcare
business. Also, unexpected expenses and legal penalties come across the healthcare
organization that affects its overall growth. Moreover, the healthcare organization can be
badly impacted because of a data breach as it affects the years of reputation that they have
achieved (Sharma et al., 2020).
In addition, the healthcare organization can also have some short-term consequences
that can include operation downtime and loss of sensitive data.
II. Key Stakeholders
A. Identification of the key internal workforce and external stakeholders
The federal law Health Insurance Portability and Accountability Act of 1996 (HIPAA)
has been set up with an aim to protect the sensitive health information of the patient from
being disclosed to others without the knowledge or consent of the patient. This federal law
has set up some national standards for this (Data breaches: In the healthcare sector. CIS,
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 6
2021). By following this federal law, I have realized that I need to inform or notify the
internal workforce and the external stakeholders about the data breach incident in the
healthcare organization. As a health information management (HIM) director of the
healthcare organization, I have identified some of the key internal workforces that include
board members and stags of the organization. Moreover, I have identified some of the
external stakeholders, such as vendors and patients, who need to be notified about the
issue.
B. Identification of the key federal stakeholders
The incident of data breach needs to be informed to the federal stakeholders, who can
be the government officials. This could help the healthcare organization in many ways.
Here, the Medicare Conditions for Coverage have been set up to protect the safety and
health of the beneficiaries (Conditions for coverage (cfcs) & conditions of participation
(cops). CMS, 2021). Moreover, it has aimed to achieve support from the Joint Commission
to improve the quality of health care in several ways. The state licensing regulation could
help the healthcare organization to boost its efficiency in the forecast period. However,
these regulations and standards have been negatively impacted by the data breaches.
C. Following the policy to avoid future breaches
Here, the key stakeholders who need to follow these policies are the organizational
staff, board members, and vendors to avoid future breaches in the healthcare organization.
This is because they are the pillar of the healthcare organization, and they must follow the
essential policies to maintain a good work environment with ethics.
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 7
III. Impacts
A data breach in the healthcare domain can give rise to serious implications for a
healthcare organization. The report has been designed detailing the impact of the breach
incident on the organization. In the initial section of the report, the laws that are in place
to prevent such incidents have been identified. The communication plan that will be
adopted to notify the key stakeholders has been identified. The financial and non-financial
impacts of the breach on an entity have been identified. Ultimately, appropriate federally
sponsored initiatives have been identified that can ensure the provision of the highest level
of healthcare safety, quality and data security.
Impact – Laws to prevent data breach
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is one of
the most important federal laws that has been introduced to safeguard sensitive patient
health information from being disclosed to any unauthorized parties without their consent
(Centre for Disease Control and Prevention, 2018). According to HIPAA Breach
Notification Rule it is the responsibility of healthcare entities to notify patients in case their
unprotected data has been disclosed or breached in any manner (Hipaa Breach Notification
Rule. American Medical Association, 2021). Physicians need to play a proactive role while
evaluating the severity of a data breach incident by evaluating whether it meets HIPAA’s
‘low probability of compromise’ threshold or not.
The Federal Trade Commission’s (FTC) Health Breach Notification Rule is another
important legal element that requires companies that have a mobile application, website or
similar technology that has sensitive customer health information to notify customers about
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 8
a breach incident. This law is applicable for most of the health apps as well as similar
kinds of technologies. In the specific scenario involving the ABC hospital, the risk
assessment that was conducted revealed that both the laws were violated since the security
of sensitive patient information was compromised.
Impact – Communication plan
The implementation of a well-defined and transparent communication plan is vital to
make sure that the key stakeholders are made aware of the breach incident and its severity
is shared with them in an honest manner. The first step of the plan involves the
identification of suitable and appropriate communication channels to inform the
stakeholders i.e., whose data have been breached in the incident. In this case, direct phone
calls, emails or letters can be used as communication channels. The next step is to
establish facts about what exact information has been compromised and how the incident
took place. Then the ABC hospital must make sure to communicate directly and
immediately with the stakeholder. An honest and straightforward approach must be adopted
and it is also necessary to show remorse. Ultimately, an official statement must be released
by the healthcare facility explaining the steps that were in place and the consequences of
the data breach incident (Seh et al., 2020).
The expectations that have been set to ensure that the people are notified in a
timely manner include conducting a thorough risk assessment process and correctly
identifying the medical coder who was responsible for disclosing sensitive patient
information.
Impact – Financial and non-financial impacts
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 9
The key financial impact of the data breach on the organization includes the
reduction in revenue generation ability due to a decline in patient number, and the
imposition of penalties due to the violation of laws relating to data breach in the healthcare
domain. The cost relating to IT infrastructure has also increased since the facility will have
to integrate new and effective cybersecurity instruments. The main non-financial impacts of
the data breach incident on the ABC Hospital include reputational damage and a
considerable decline in patient trust on the hospital and the professionals that work in it. A
data breach incident can impact the decision-making process, such as financial decisions.
For example, responsibilities must be allocated carefully to ensure no professional can
abuse his power or position. Similarly, decisions on employee training must be made to
prevent such incidents from recurring in the future (Health Sector Cybersecurity
Coordination Center, 2019).
Impact – Sponsored initiatives
In order to ensure that there is a proper provision of top-level of healthcare safety,
quality and data security, the ABC Hospital can adopt several suitable federally sponsored
initiatives. For example, the knowledge, tools and technologies offered by the Agency for
Healthcare Research and Quality (AHRQ) must be integrated. It will help to improve the
safety of care solutions provided by the facility (Kronick, 2016). The National Quality
Strategy (NQS) must be adopted to achieve better health by focusing on quality and safety
aspects.
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 10
IV. Ethical and Legal Considerations
In the health care domain, a data breach incident can give rise to serious
implications at the legal as well as ethical levels. Seh has argued that the instances of
healthcare data breach are on the rise owing to the high integration of digital technologies
(Seh et al., 2021). Such breaches are not just a source of concern for security professionals
but also for patients, healthcare practitioners and organizations. Healthcare organizations
need to be well-prepared to ensure that data breach incidents do not take place that may
lead to the compromise of healthcare quality along with the safety of staff and patients.
Stringent policies and procedures can play a key role to minimize or mitigate risks that
arise in the cyber landscape relating to data breach incidents (Kamoun & Nicho, 2014).
A. Ethical and legal risks
In the specific scenario involving the healthcare facility, an ethical risk that might have
contributed to the data breach incident is the lack of respect for the confidentiality and
privacy of the patient and his or her medical information. Guddati has argued that the
confidentiality between a patient and a physician must be respected at all costs so that the
basic rights of the patient will not get violated due to data breach (Chiruvella & Guddati,
2021). However, in the specific healthcare setting, one of the coders have revealed a
neighbour’s health record data and shared it with data. Ozair has pointed out that when the
health information relating to patients is shared without their knowledge, their autonomy is
compromised (Ozair et al., 2015). In the specific healthcare context, a key ethical risk that
has occurred relates to the jeopardising of a patient’s autonomy.
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 11
According to the HIPAA Privacy Rule, the consent of patients must be taken by a
healthcare service provider in case his PHI is disclosed. In the specific scenario, the data
breach shows the non-adherence to HIPAA Privacy Rule (Chiruvella & Guddati, 2021). A
key risk that is evident in the case of the ABC Hospital is insider snooping. Such an issue
arises when insiders steal patient information due to negligence or intentional reasons.
When such a HIPAA violation takes place, a public report to the HHS Brach may be
required or an investigation may take place leading to costly fines. As a coder has violated
the HIPAA Act, the lapse in legality has significantly contributed to the data breach
incident. bb
B. Maintaining information compromised in data breach
The information that has been compromised during the data breach incident can be
maintained by adopting a methiodal process. Initially, it is vital to have in place a well-
functional incidence response plan. It can play a cardinal role to minimize the impact of
the breach incident. It must be followed by preserving the evidence so that valuable
forensic data can be preserved that may be of use at a later stage. The IT team must then
focus on containing the breach by isolating the affected system so that future damage can
be curtailed to a considerable extent. It must be followed by the incidence response
management process. According to the HIPAA Breach Notification Rule, entities covered
under HIPAA must provide notification following a breach incident involving unsecure
patient data (Breach notification rule. HHS.gov, 2021). Ultimately, a robust crisis
communication must be implemented so that the affected individual and relevant
stakeholders can be notified of the incident immediately.
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 12
Policy Recommendations
A. Technology-based recommendations
In order to prevent data breach incidents in the healthcare setting, a number of
technology-based recommendations have been made that can help to ensure data
confidentiality. A key policy recommendation is to integrate effective cybersecurity tools
such as intrusion detection systems to maintain the privacy and confidentiality of patients.
Another policy recommendation for preventing insider snooping is making it mandatory to
conduct tests to identify malicious activities by employees such as the creation of backdoor
accounts, changing common passwords to prevent access by others, etc. (Breach notification
rule. HHS.gov, 2021). Such policies can help to ensure the safety of patients is not
compromised due to data breach incidents.
B. Recommendations for solving organizational challenges
For addressing organizational challenges that might have contributed to the data breach
incident in the ABC Hospital, a number of policy-based measures can be adopted. The first
policy involves the regular upgrading of the IT infrastructure of the organization by
integrating the most effective technical tools and technologies. It can ensure that a safe
environment is created where the sensitive PHI of patients is kept. The second policy
recommendation involves creating a security-based culture within the organization so that
employees can value the confidentiality and privacy of patient. The policy must focus on
creating and nurturing a cybersecurity culture within the healthcare facility (Branley-Bell et
al., 2021). It can help to minimize the risk relating to insider threat or insider snooping
from the staff members.
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 13
C. Recommendations for reducing gaps in securing patient information
One of the main polices that can be introduced in the ABC Hospital for reducing gaps
in securing patient information is providing technical training to the healthcare staff.
Regular training and development sessions must be introduced and high emphasis must be
laid on cybersecurity awareness. Such a policy can play a key role to expand the
knowledge of the medical staff and minimize the gap relating to the secure storage of
patient information (Pears & Konstantinidis, 2021). Another vital policy measure that can
be introduced in the hospital in order to shrink the gaps in securing patient information is
to adopt stringent access management rules in place. Emphasis must be laid on
authorization so that the staff members will have access to only the specific protected
health information that they are allowed to view. This step will ensure that individuals who
have limited access cannot abuse their position and manipulate sensitive patient information
for their malicious needs (Cooper & Collman, 2005). bb
For effectively tackling ethical and legal risks, it is essential to introduce effective
policies relating to technologies, organizational challenges and minimizing gaps that may be
exploited by cybercriminals. By implementing the recommended policies, the ABC Hospital
can ensure that similar data breach incidents can be prevented in the future and PHI can be
safely managed.
V. Policy recommendations
Policies can play an instrumental role in the cybersecurity landscape to minimize the
diverse range of cybersecurity risks that arise in the cyber setting. In the health care
domain, it is vital to deploy effective and stringent policy-based measures so that the
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 14
possibility of data breach incidents can be minimized and effectively tackled. In the
specific context of the ABC Hospital, a number of policies have been recommended that
can help to ensure confidentiality and health-related data and prevent the future possibility
of a breach incident. According to the Healthcare Information and Management Systems
Society (HIMSS), some of the best practices that can be adopted in the health care domain
to mitigate the risks that arise in the cyber landscape are policies and procedures, security
awareness training, encryption, etc. (HIMSS, 2021). The following recommendations have
been made that can be introduced in the context of the ABC Hospital so that the
organization can going forward prevent additional breach incidents from occurring.
Technology-based recommendations
• The introduction of effective cybersecurity tools such as intrusion detection and
prevention systems (IDS and IPS) must be made mandatory within the health care
facility. Such a tool can ensure that any kind of suspicious activity, whether by an
insider or an external party, can be identified, and the same can be notified to the
respective authority within the organization. In the highly unpredictable cyber
setting, IDS and IPS are considered to be highly effective tools since they alert
about an impending or ongoing cybersecurity threat. These systems can play an
instrumental role in preventing similar incidents from taking place as they are
designed for detecting as well as responding to security threats (Mudzingwa &
Agrawal, 2012).
• A regular audit of the IT network of the organization needs to be conducted by
internal IT professionals as well as external auditors to identify the possibility of
insider threats and insider snooping. The specific data breach incident that took
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 15
place within the health care entity was related to insider snooping. Insider snooping
is considered to be one of the most common HIPAA violations that can compromise
the data confidentiality of patients (Employee snooping is the most common cause
of HIPAA security breaches. HIPAA Journal, 2020). For ensuring that professionals
within the facility do not snoop around, a thorough audit of their online activities
and log data will be conducted. In case any evidence indicating insider snooping is
identified, it has to be reported to Office for Civil Rights (OCR) as well as the
individual whose data has been accessed (Employee snooping is the most common
cause of HIPAA security breaches. HIPAA Journal, 2020). Additionally, immediate
disciplinary measures must be taken against the identified perpetrator in the form of
termination.
• Another vital policy revolves around ‘access control.’ The access of coders and
administrative professionals must be limited by introducing measures like unique
passwords and EMR capabilities. In case they require access to sensitive
information, they would have to take prior approval from their supervisors, and they
would have to justify the reason for the same. In addition to taking approval for
gaining access, the professionals must also share a hard copy of their log that
highlights their online activities. Such a robust measure must be adopted within the
health care facility so that there would be better control over the information that
coders access online (Bera et al., 2021).
Recommendations for solving organizational challenges
• The first policy that must be implemented in ABC Hospital to address the
organizational challenges includes the regular upgrading of the IT ecosystem. As
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 16
technology is evolving at a rapid pace, it is natural for technology to get obsolete
with the passage of time, which can give rise to vulnerabilities and security gaps.
The IT department must make sure to keep the system up-to-date so that it can
function in a robust manner and the possibility of gaps within the IT infrastructure
can be reduced to a possible extent. For example, better hardware components must
be used so that the possibility of failure can be reduced. Similarly, the network
must be upgraded.
• The staff must be provided mandatory technical training that focuses on
strengthening the level of cybersecurity awareness. Additional training relating to
cybersecurity must be conducted on a periodical basis so that the staff will be aware
of how to respond in case they identify any abnormal behavior within the
organization’s network (Pears & Konstantinidis, 2021).
• The leaders within the organization must make sure that the HIPAA Security Rule
is adhered to and the safeguards relating to the administrative, technical, as well as
physical aspects have been adopted within the facility. It is vital to fulfilling each of
the three criteria so that the security relating to patient health information (PHI) can
be improved at an integrated level. Furthermore, the leaders within the ABC
Hospital must play a proactive role in promoting and nurturing an organizational
culture where high priority is given to cybersecurity and respecting the
confidentiality of patients. The adherence to the security rule is vital since it ensures
integrity, confidentiality as well as availability relating to all the electronic PHI that
has been created, received, transmitted, or maintained (Scholl et al., 2008).
Recommendations relating to hospital subscriptions for reducing gaps in security
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 17
• The tools that have been introduced by the Agency for Healthcare Research and
Quality (AHRQ) must be adopted by the ABC Hospital so that the safety, as well
as the quality of health care services that are offered to the patients, can be
improved. For example, the training program titled ‘TeamSTEPPS’ that AHRQ has
introduced along with the Department of defense must be made mandatory for
health care professionals within the facility so that communication patient safety, as
well as teamwork, can get enhanced. Such a free training can add value in the
health care setting since it can empower the staff to be more responsible and
accountable so that the possibility of cybersecurity risks and breaches can be
managed in a better way.
• The ABC Hospital must make sure to integrate quality initiative elements that have
been introduced by the Centers for Medicare and Medicaid Services (CMS) so that
it can have better control over the quality aspects of its services (Quality Initiatives -
General information. CMS, 2021). For example, the ‘Meaningful Measures’
Initiative can play an instrumental role in identifying the high priority areas
pertaining to quality measurement as well as making suitable changes so that patient
safety can be improved.
Each of the policy-based recommendations has been made in the context of the ABC
Hospital intends to improve the confidentiality and safety of the patients so that similar
kinds of cybersecurity breach incidents would not take place in the future. It is vital to
introduce policies at diverse levels such as the technology domain, organizational domain
as well as the reduction of security gaps by focusing on the hospital subscription area so
that a comprehensive solution can be adopted to address the cybersecurity problem. It is
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 18
vital for the leaders as well as the human resource professionals to make sure that the
policy-based interventions are not only introduced but also strictly implemented within the
entire organization so that a security-based culture can be created.
The policies that have been recommended for the ABC Hospital have been designed by
taking into account the key stakeholders, i.e., patients. Additionally, high emphasis has
been laid on the ethical and legal aspects so that the organization health care organization
can carry out its operations in a responsible and accountable manner without compromising
the security of the patients. The recommendations can guide the executive team to take
corrective policy-based measures to effectively manage cybersecurity risks and threats.
References
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 19
Bera, B., Das, A. K., Garg, S., Piran, M. J., & Hossain, M. S. (2021). Access control
protocol for battlefield surveillance in drone-assisted IoT environment. IEEE Internet
of Things Journal, 9(4), 2708-2721.
Breach notification rule. HHS.gov. (2021, June 28). Retrieved June 8, 2022, from
https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
Branley-Bell, D., Coventry, L., & Sillence, E. (2021, June). Promoting Cybersecurity
Culture Change in Healthcare. In The 14th PErvasive Technologies Related to
Assistive Environments Conference (pp. 544-549).
Bassett, G., Hylender, C. D., Langlois, P., Pinto, A., & Widup, S. (2021). Data breach
investigations report. Verizon DBIR Team, Tech. Rep.
Conditions for coverage (cfcs) & conditions of participation (cops). CMS. (2021). Retrieved
May 12, 2022, from https://www.cms.gov/Regulations-and-
Guidance/Legislation/CFCsAndCoPs
Chiruvella, V., & Guddati, A. K. (2021). Ethical issues in patient data ownership.
Interactive journal of medical research, 10(2), e22269.
Cooper, T., & Collman, J. (2005). Managing information security and privacy in healthcare
data mining. Medical informatics, 95-137.
Centers for Disease Control and Prevention. (2018, September 14). Health Insurance
Portability and accountability act of 1996 (HIPAA). Centers for Disease Control and
Prevention. Retrieved May 28, 2022, from
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 20
https://www.cdc.gov/phlp/publications/topic/hipaa.html#:~:text=The%20Health%20Insura
nce%20Portability%20and,the%20patient's%20consent%20or%20knowledge.
Data breaches: In the healthcare sector. CIS. (2021, July 14). Retrieved May 12, 2022,
from https://www.cisecurity.org/insights/blog/data-breaches-in-the-healthcare-sector
Employee snooping is the most common cause of HIPAA security breaches. HIPAA
Journal. (2020, July 8). Retrieved June 24, 2022, from
https://www.hipaajournal.com/employee-snooping-common-cause-hipaa-security-
breaches/
HIMSS. (2021, December 16). Cybersecurity in Healthcare. HIMSS. Retrieved June 24,
2022, from https://www.himss.org/resources/cybersecurity-healthcare#Part3
Health Sector Cybersecurity Coordination Center. (2019). A Cost Analysis of Healthcare
Sector Data Breaches.
Hipaa Breach Notification Rule. American Medical Association. (2021). Retrieved May 28,
2022, from https://www.ama-assn.org/practice-management/hipaa/hipaa-breach-
notification-
rule#:~:text=HIPAA's%20Breach%20Notification%20Rule%20requires,and%20security%
20of%20the%20PHI.
Kamoun, F., & Nicho, M. (2014). Human and organizational factors of healthcare data
breaches: The swiss cheese model of data breach causation and prevention.
International Journal of Healthcare Information Systems and Informatics (IJHISI),
9(1), 42-60.
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 21
Kronick, R. (2016). AHRQ's role in improving quality, safety, and health system
performance. Public health reports, 131(2), 229-232.
Mudzingwa, D., & Agrawal, R. (2012, March). A study of methodologies used in intrusion
detection and prevention systems (IDPS). In 2012 Proceedings of IEEE Southeastcon
(pp. 1-6). IEEE.
Ozair, F. F., Jamshed, N., Sharma, A., & Aggarwal, P. (2015). Ethical issues in electronic
health records: A general overview. Perspectives in clinical research, 6(2), 73.
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity training in the healthcare
workforce–utilization of the ADDIE model. In 2021 IEEE Global Engineering
Education Conference (EDUCON) (pp. 1674-1681). IEEE.
Pears, M., & Konstantinidis, S. T. (2021, April). Cybersecurity Training in the Healthcare
Workforce–Utilization of the ADDIE Model. In 2021 IEEE Global Engineering
Education Conference (EDUCON) (pp. 1674-1681). IEEE.
Scholl, M. A., Stine, K. M., Hash, J., Bowen, P., Johnson, L. A., Smith, C. D., &
Steinberg, D. I. (2008). Sp 800-66 rev. 1. an introductory resource guide for
implementing the health insurance portability and accountability act (hipaa) security
rule. National Institute of Standards & Technology.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Ahmad
Khan, R. (2020, June). Healthcare data breaches: insights and implications. In
Healthcare (Vol. 8, No. 2, p. 133). Multidisciplinary Digital Publishing Institute.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Khan, R.
A.(2021) Healthcare data breaches: insights and implications. Healthcare (Basel) 2020
May 13; 8 (2): 133. doi: 10.3390/healthcare8020133.
HIM422 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb b bb bb b bb bb b bb bb bb bb bb bb bb bb
bb bb bb bb b bb bb b bb bb b bb bb b bb bb b bb bb bb bb bb bb bb b bb bb bb bb bb bb bb bb bb b bb bb bb bb bb 22
Sharma, N., Oriaku, E. A., & Oriaku, N. (2020). Cost and effects of data breaches,
precautions, and disclosure laws. International Journal of Emerging Trends in Social
Sciences, 8(1), 33-41.
Quality Initiatives - General information. CMS. (2021). Retrieved June 24, 2022, from
https://www.cms.gov/Medicare/Quality-Initiatives-Patient-Assessment-
Instruments/QualityInitiativesGenInfo
Students also viewed