Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
26
27
28
29
30
31
2
3
4
5
6
7
8
9
10
8:30 AM - HIMSS Europe
11
12
13
14
15
16
17
18
19
20
21
22
26
27
28
29
1
2
3
4
5
6
e-Health 2025 Conference and Tradeshow
2025-06-01 - 2025-06-03    
10:00 am - 5:00 pm
The 2025 e-Health Conference provides an exciting opportunity to hear from your peers and engage with MEDITECH.
HIMSS Europe
2025-06-10 - 2025-06-12    
8:30 am - 5:00 pm
Transforming Healthcare in Paris From June 10-12, 2025, the HIMSS European Health Conference & Exhibition will convene in Paris to bring together Europe’s foremost health [...]
38th World Congress on  Pharmacology
2025-06-23 - 2025-06-24    
11:00 am - 4:00 pm
About the Conference Conference Series cordially invites participants from around the world to attend the 38th World Congress on Pharmacology, scheduled for June 23-24, 2025 [...]
2025 Clinical Informatics Symposium
2025-06-24 - 2025-06-25    
11:00 am - 4:00 pm
Virtual Event June 24th - 25th Explore the agenda for MEDITECH's 2025 Clinical Informatics Symposium. Embrace the future of healthcare at MEDITECH’s 2025 Clinical Informatics [...]
International Healthcare Medical Device Exhibition
2025-06-25 - 2025-06-27    
8:30 am - 5:00 pm
Japan Health will gather over 400 innovative healthcare companies from Japan and overseas, offering a unique opportunity to experience cutting-edge solutions and connect directly with [...]
Electronic Medical Records Boot Camp
2025-06-30 - 2025-07-01    
10:30 am - 5:30 pm
The Electronic Medical Records Boot Camp is a two-day intensive boot camp of seminars and hands-on analytical sessions to provide an overview of electronic health [...]
Events on 2025-06-01
Events on 2025-06-10
HIMSS Europe
10 Jun 25
France
Events on 2025-06-23
38th World Congress on  Pharmacology
23 Jun 25
Paris, France
Events on 2025-06-24
Events on 2025-06-25
International Healthcare Medical Device Exhibition
25 Jun 25
Suminoe-Ku, Osaka 559-0034
Events on 2025-06-30
Articles

Is It Time for a Data Security Checkup in Your Medical Practice?

confidential information

Is It Time for a Data Security Checkup in Your Medical Practice?

As the amount of patient information stored online increases, your patients depend on you to keep their data secure. Protecting sensitive information can be a daunting task, but there are many steps you can take to ensure the information you store is safe.

Getting Started

Suppose you’ve done some initial investigation into system security and privacy best practices. In that case, you might have questions such as, “What is SSL?” and “Do I need to teach all my employees about data security?” It’s a good idea to start by breaking down security practices into two categories: protecting your system and safeguarding against insider threats.

Protecting Your System

One primary but often overlooked method of data protection is keeping your software up to date. Periodically, your system software and application manufacturers will issue updates. In many cases, you can opt to receive notifications when it’s time to update the software manually, or you can choose automatic updates. They can take time to install, and it’s easy to postpone them if you don’t want the interruption. The updates, however, often contain security patches. Schedule updates for the times your system is least active. It’s also good to install anti-virus software on your system and keep it updated.

Encryption should be part of your data protection strategy. The HIPAA Security Rule states that encryption is a “safe harbor.” What does this mean for your practice? If an encrypted device is stolen or lost, you won’t need to notify patients or report the breach.

You probably use mobile devices, such as tablets, phones, USB drives and laptops. These devices should be encrypted and password-protected to protect your data if the devices get into the wrong hands. Workstations and desktop computers should also be password-protected and encrypted. While they aren’t considered mobile, sensitive information can be compromised if someone breaks into your building.

As you protect the devices in your office, you’ll need to protect communication as well. If your staff sends text messages to patients, you can install a secure texting application to encrypt data. Email messages can also be encrypted to safeguard correspondence containing private information.

Some practices provide Wi-Fi access as a convenience to patients. If you want to allow guests to access Wi-Fi in your office, set up a separate network for them and use different passwords.

Safeguarding Against Insider Threats

No doctor wants to think they have staff members who would compromise a medical practice’s integrity. However, it does happen. Most insider data breaches result from employee error. Intentional theft, while less common, is an unfortunate reality.

It’s a good idea to set up an auditing system on your network. An auditing system will allow you to view who accessed patient records, which records were accessed and what patient information was viewed. Let your employees know you have an auditing system in place, and you will be checking reports from time to time. Finally, follow through and review the auditing logs on occasion. It’s easy to postpone this step when you have a high degree of confidence in your staff. However, you don’t want to be caught unaware if a data breach occurs.

One way to avoid an unnecessary data breach is to give contractors and staff members only the level of access they need to perform their jobs — no more, no less. Conduct a review of access levels from time to time. As employees leave or change roles, it’s easy for access creep to take over. Access or privilege creep happens when an employee maintains privileges they no longer need.

Finally, a basic but critical method of data protection is to use secure passwords on all devices. A secure password contains numbers, letters and symbols and does not appear in the dictionary. Instruct staff members not to store passwords in the open — for example, on a note taped to the monitor.

As a doctor, you know the value of protecting your patients. Taking the necessary steps to secure their data is part of a solid plan for your practice.