Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
26
27
29
30
31
1
2
5
7
8
12
13
14
16
17
21
22
23
24
25
26
27
28
1
Proper Management of Medicare/Medicaid Overpayments to Limit Risk of False Claims
2015-01-28    
1:00 pm - 3:00 pm
January 28, 2015 Web Conference 12pm CST | 1pm EST | 11am MT | 10am PST | 9AM AKST | 8AM HAST Topics Covered: Identify [...]
EhealthInitiative Annual Conference 2015
2015-02-03 - 2015-02-05    
All Day
About the Annual Conference Interoperability: Building Consensus Through the 2020 Roadmap eHealth Initiative’s 2015 Annual Conference & Member Meetings, February 3-5 in Washington, DC will [...]
Real or Imaginary -- Manipulation of digital medical records
2015-02-04    
1:00 pm - 3:00 pm
February 04, 2015 Web Conference 12pm CST | 1pm EST | 11am MT | 10am PST | 9am AKST | 8am HAST Main points covered: [...]
Orlando Regional Conference
2015-02-06    
All Day
February 06, 2015 Lake Buena Vista, FL Topics Covered: Hot Topics in Compliance Compliance and Quality of Care Readying the Compliance Department for ICD-10 Compliance [...]
Patient Engagement Summit
2015-02-09 - 2015-02-10    
12:00 am
THE “BLOCKBUSTER DRUG OF THE 21ST CENTURY” Patient engagement is one of the hottest topics in healthcare today.  Many industry stakeholders consider patient engagement, as [...]
iHT2 Health IT Summit in Miami
2015-02-10 - 2015-02-11    
All Day
February 10-11, 2015 iHT2 [eye-h-tee-squared]: 1. an awe-inspiring summit featuring some of the world.s best and brightest. 2. great food for thought that will leave you begging [...]
Starting Urgent Care Business with Confidence
2015-02-11    
1:00 pm - 3:00 pm
February 11, 2015 Web Conference 12pm CST | 1pm EST | 11am MT | 10am PST | 9am AKST | 8am HAST Main points covered: [...]
Managed Care Compliance Conference
2015-02-15 - 2015-02-18    
All Day
February 15, 2015 - February 18, 2015 Las Vegas, NV Prospectus Learn essential information for those involved with the management of compliance at health plans. [...]
Healthcare Systems Process Improvement Conference 2015
2015-02-18 - 2015-02-20    
All Day
BE A PART OF THE 2015 CONFERENCE! The Healthcare Systems Process Improvement Conference 2015 is your source for the latest in operational and quality improvement tools, methods [...]
A Practical Guide to Using Encryption for Reducing HIPAA Data Breach Risk
2015-02-18    
1:00 pm - 3:00 pm
February 18, 2015 Web Conference 12pm CST | 1pm EST | 11am MT | 10am PST | 9am AKST | 8am HAST Main points covered: [...]
Compliance Strategies to Protect your Revenue in a Changing Regulatory Environment
2015-02-19    
1:00 pm - 3:30 pm
February 19, 2015 Web Conference 12pm CST | 1pm EST | 11am MT | 10am PST | 9am AKST | 8am HAST Main points covered: [...]
Dallas Regional Conference
2015-02-20    
All Day
February 20, 2015 Grapevine, TX Topics Covered: An Update on Government Enforcement Actions from the OIG OIG and US Attorney’s Office ICD 10 HIPAA – [...]
Events on 2015-02-03
EhealthInitiative Annual Conference 2015
3 Feb 15
2500 Calvert Street
Events on 2015-02-06
Orlando Regional Conference
6 Feb 15
Lake Buena Vista
Events on 2015-02-09
Events on 2015-02-10
Events on 2015-02-11
Events on 2015-02-15
Events on 2015-02-20
Dallas Regional Conference
20 Feb 15
Grapevine
Articles

Jun 04 : Securing Mobile Healthcare Devices: Best Practices

securing mobile healthcare devices

By combining technology, best practices, and education, IT departments can safeguard even the most mobile healthcare departments.

 

10 Medical Practice Management Systems For 2014

10 Medical Practice Management Systems For 2014

(Click image for larger view and slideshow.)

Insecurities lurk beneath the surface of the fast-growing world of mobile healthcare, putting data at risk. But organizations can protect patient data by implementing a mix of technologies and best practices.

The practice of using mobile devices in healthcare is growing. More than half — 51% — of physicians use tablets for professional purposes and 74% use smartphones at work. The mobile monitoring and diagnostic medical devices market will reach $8.03 billion by 2019, compared with a mere $0.65 billion in 2013, according to Transparency Market Research. This year alone 90 million wearable health devices will ship, reported ABI Research.

Add in the growing number of patients who access their records electronically, the doctors’ offices that schedule appointments via text or app, and the offices that wirelessly share data, and the message is clear: Mobile must be secure and HIPAA-compliant. That is not, however, always the case.

“The sheer number of people and devices with access to health information expands, making it much more complex for organizations to create mobile policies, manage data leakage controls, and conduct regulatory analysis,” says Mike Raggo, security evangelist at MobileIron, in an interview. “Mobile devices are ubiquitous in healthcare organizations, supporting part-time physicians and nurses working shifts that share devices. The plethora of health information accessible on these devices makes protecting against data loss challenging.”

There are, however, steps healthcare organizations can take to decrease the possibility of data loss, which typically occurs when a device itself is lost or stolen, when rogue apps siphon off data, or when an employee undertakes well-intentioned but risky actions, such as sharing files through public cloud services, he says.

Enterprise mobile management best practices include:

  • Managing all devices, as well as constantly maintaining security settings and configurations.
  • Enabling remote lock and wipe, so unauthorized users (such as ex-employees) are easily removed from the system.
  • Full device or app-by-app encryption that’s monitored and enforced.
  • Enforcement of device-level passwords.
  • Monitoring the operating system’s integrity to avoid usage of compromised versions.
  • Implementing an auto-wipe policy to minimize the risk of attacks via lost or stolen devices.
  • Secure email and attachments to prevent malware being spread from personal accounts.
  • Protecting application data by encrypting app data for operating systems such as Android or deleting app data if a device is non-compliant.
  • Prevent untrusted file-sharing apps from accessing secure documents.
  • Log devices and actions for audit.

“Recent attacks on data have certainly reinforced the need for a new generation of data security approaches. Healthcare CIOs who focus on risk mitigation through user enablement will become more prominent in the C-suite. Those that focus on risk mitigation through restriction will lose power,” Raggo says. “The former understand that security is about behavior and they reward the right behavior. The latter inevitably encourage the wrong behavior and damage both their credibility in the C-suite and the security posture of the ‘mobile first’ organization.”

In addition to best practices and technologies that address encryption, passwords, and other traditional security measures, mobile device management plays an important role in safeguarding compliance, Paul Martini, CEO and co-founder of iboss Security Network, tells InformationWeek. MDM sales are expected to reach $3.94 billion by 2019, versus $1.01 last year, Markets and Markets estimated. The expense, which has prevented some organizations from adopting the technology, is easing — more developers are in the market — and the cost of being non-compliant is too high for healthcare facilities.

“[MDM] solutions allow an organization to get a handle on mobile devices by providing tools for grouping devices, forcing device passwords, forcing storage encryption, and wiping devices if they become lost or stolen,” says Martini. “In addition, healthcare organizations should implement a BYOD policy for devices not belonging to the organization. A combination of technology and training is required to maintain a HIPPA compliant environment.”

Mobile security requires a multi-pronged approach, says Paul Trulove, vice president of products at SailPoint, in an interview.

“The combination of MDM and identity and access management (IAM) is much more powerful, as it can help align policy and establish consistent, centralized access controls across the organization. They can also tie mobile information back to the infrastructure in terms of identity data and making it part of the on-boarding and off-boarding process,” he says. “For example, if they do not wipe a person’s device once they leave an organization, the organization can potentially be liable and at risk for any data left on a person’s device.”

Technologies are not the only defense in IT’s arsenal. An educated workforce helps reduce the possibility of breaches, Martini says.

“Healthcare professionals can do simple things such as have awareness of actions and their consequences. For example, through training, professionals can be made aware that it’s not ok to email a patient record, as the transmission may not be encrypted and the destination may not be HIPPA compliant. They should avoid storing or viewing any patient documents on their personal devices. It doesn’t require high tech in order to make a big difference.”

Source