Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
29
1
3
4
5
7
8
10
11
12
15
16
17
18
19
21
24
25
26
27
30
31
1
2
A Behavioral Health Collision At The EHR Intersection
2014-09-30    
2:00 pm - 3:30 pm
Date/Time Date(s) - 09/30/2014 2:00 pm Hear Why Many Organizations Are Changing EHRs In Order To Remain Competitive In The New Value-Based Health Care Environment [...]
Meaningful Use and The Rise of the Portals
2014-10-02    
12:00 pm - 12:45 pm
Meaningful Use and The Rise of the Portals: Best Practices in Patient Engagement Thu, Oct 2, 2014 10:30 PM - 11:15 PM IST Join Meaningful [...]
Adva Med 2014 The MedTech Conference
2014-10-06    
All Day
Adva Med 2014 The MedTech Conference October 6-8, 2014 McCormick Place Chicago, IL For more information, visit, advamed2014.com For Registration details, click here  
Public Health Measures Meaningful Use
2014-10-09    
12:00 pm - 12:45 pm
Public Health Measures Meaningful Use: Reporting on Public Health Measures Join Meaningful Use expert Jim Tate for a three part series of webinars addressing MU [...]
2014 Hospital & Healthcare I.T. Conference
2014-10-13    
All Day
Join us at our 2014 Hospital & Healthcare I.T. Conference and experience the following: Up to 125 Hospital & Healthcare I.T. executives from America’s most prestigious [...]
Connected Health Care 2014
Key Trends That will be Discussed at the Conference! Connected Healthcare 2014 is set to explore the crucial topics that are revolutionizing the connected health industry: [...]
HealthTech Conference
2014-10-14    
All Day
HealthTech Capital is a group of private investors dedicated to funding and mentoring new "HealthTech" start ups at the intersection of healthcare with the computer [...]
Health Informatics & Technology Conference (HITC-2014)
2014-10-20    
All Day
Information technology has ability to improve the quality, productivity and safety of health care mangement. However, relatively very few health care providers have adopted IT. [...]
HIMSS Amsterdam 2014
2014-10-20    
12:00 am
About HIMSS Amsterdam 2014 This year, the second annual HIMSS Amsterdam event will be taking place on 6-7 November 2014 at the Hotel Okura. The [...]
Patient Portal Functionality and EMR Integration Demonstration
2014-10-22    
2:00 pm - 3:30 pm
This purpose of this webcast is to present a demonstration to show how the Patient Portal integrates with EMR, as well as discuss how this [...]
Connected Health Symposium 2014
Symposium 2014 - Connected Health in Practice: Engaging Patients and Providers Outside of Traditional Care Settings Collaborating with industry visionaries, clinical experts, patient advocates and [...]
CHIME College of Healthcare Information Management Executives
2014-10-28 - 2014-10-31    
All Day
The Premier Event for Healthcare CIOs Hotel Accomodations JW Marriott San Antonio Hill Country 23808 Resort Parkway San Antonio, Texas 78761 Telephone: 210-276-2500 Guest Fax: [...]
The Myth of the Paperless EMR
2014-10-29    
2:00 pm - 3:00 pm
Is Paper Eluding Your Current Technologies; The Myth of the Paperless EMR Please join Intellect Resources as we present Is Paper Eluding Your Current Technologies; The Myth [...]
Events on 2014-09-30
Events on 2014-10-02
Events on 2014-10-06
Events on 2014-10-09
Events on 2014-10-13
Events on 2014-10-14
Connected Health Care 2014
14 Oct 14
San Diego
HealthTech Conference
14 Oct 14
San Mateo
Events on 2014-10-20
HIMSS Amsterdam 2014
20 Oct 14
Amsterdam
Events on 2014-10-23
Events on 2014-10-28
Events on 2014-10-29
Articles

EHR and mobile device auditing, security requires vigilance

If you need a few reasons to adapt to the latest security advancements, just look at the calendar for September and circle the “23”. That’s compliance day for the HIPAA Omnibus Rule, which modifies the privacy, security and enforcement rules. There are 659 more reasons – one for every large patient-information breach – on the Office for Civil Rights (OCR) Breach Notification Tool as of late August.

Security today, naturally, goes beyond the traditional “shred the paper” techniques and two of the biggest issues are related to EHRs and mobile devices. HealthITSecurity.com caught up with a security officer whose organization is paying close attention to those two aspects of the securing protected health information (PHI) game. Nancy Davis, MS, RHIA, CHPS, system director of privacy and security for Ministry Health Care in Milwaukee, offered some details about some of the latest advancements her organization has made and how it ensures security.

EHR access auditing

While the jury is still out on a final rule on accounting of disclosures and proposed EHR access reports, looking into auditing in EHRs is a must for organizations, Davis said. “Face it by now most organizations have the EHRs but are lagging in the auditing area either due to the constraints of the EHR application and/or the need to finance external auditing applications,” Davis maintained.

Ministry Health Care handles EHR access auditing through a combination of internal and external auditing applications. What’s a good first step if an organization is implementing this type of auditing? Have some type of tool – you have to have this.

“It doesn’t mean you have to purchase one, but there should be some way of verifying access,” Davis says. “Most applications have this; they just don’t function as well as external products.

Next, ensure your organization stays on top of the auditing when you choose to go down that route. “Take care not to create audit reports and let them stack up without reviewing,” Davis says. “There should be a policy and auditing plan in place.”

Without a solid auditing plan, organizations could have no way of knowing whether there was unauthorized access to a patient’s PHI. “You would not be able to defend an allegation of breach,” Davis says.

Mobile-device security

Davis’ organization uses an application she said has been great for mobile devices and addressing security. The end result is no information is retained on the device used.  Davis uses this on her iPad when traveling, loves it and uses it once or twice a week based on travel and only for e-mail, which may include very limited PHI. “I feel secure when working in this application,” Davis says.

End users must first apply internally to be approved for the device. Once it is approved, they download the application to their portable devices and then authenticate it through a unique user log-in and complex password which is subject to change every six months. “It also times out automatically if not used,” she said. “We can access our e-mail.”

Mobile-device use is limited to providers, exempt staff, and non-exempt staff with leadership approval. When selecting security applications for your mobile devices, organizations need to identify the rogue programs out there. “They may not be sanctioned,” Davis said, “and may not be secure.” Source