Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
26
27
28
30
2
8
9
10
11
12
13
14
19
21
24
26
28
29
30
1
2
3
4
5
6
Neurology Certification Review 2019
2019-08-29 - 2019-09-03    
All Day
Neurology Certification Review is organized by The Osler Institute and will be held from Aug 29 - Sep 03, 2019 at Holiday Inn Chicago Oakbrook, [...]
Ophthalmology Lecture Review Course 2019
2019-08-31 - 2019-09-05    
All Day
Ophthalmology Lecture Review Course is organized by The Osler Institute and will be held from Aug 31 - Sep 05, 2019 at Holiday Inn Chicago [...]
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness
2019-09-01 - 2019-09-08    
All Day
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness is organized by Continuing Education, Inc and will be held from Sep [...]
Medical Philippines 2019
2019-09-03 - 2019-09-05    
All Day
The 4th Edition of Medical Philippines Expo 2019 is organized by Fireworks Trade Exhibitions & Conferences Philippines, Inc. and will be held from Sep 03 [...]
Grand Opening Celebration for Encompass Health Katy
2019-09-04    
4:00 pm - 7:00 pm
Grand Opening Celebration for Encompass Health Katy 23331 Grand Reserve Drive | Katy, Texas Sep 4, 2019 4:00 p.m. CDT Encompass Health will host a grand opening [...]
Galapagos & Amazon 2019 Medical Conference
2019-09-05 - 2019-09-17    
All Day
Galapagos & Amazon 2019 Medical Conference is organized by Unconventional Conventions and will be held from Sep 05 - 17, 2019 at Santa Cruz II, [...]
Mesotherapy Training (Sep 06, 2019)
2019-09-06    
All Day
Mesotherapy Training is organized by Empire Medical Training (EMT), Inc and will be held on Sep 06, 2019 at The Westin New York at Times [...]
Aesthetic Next 2019 Conference
2019-09-06 - 2019-09-08    
All Day
Aesthetic Next 2019 Conference Venue: SEPTEMBER 6-8, 2019 RENAISSANCE DALLAS HOTEL, DALLAS, TX www.AestheticNext.com On behalf Aesthetic Record EMR, we would like to invite you [...]
Anti-Aging - Modules 1 & 2 (Sep, 2019)
2019-09-07    
All Day
Anti-Aging - Modules 1 & 2 is organized by Empire Medical Training (EMT), Inc and will be held on Sep 07, 2019 at The Westin [...]
Allergy Test and Treatment (Sep, 2019)
2019-09-15    
All Day
Allergy Test and Treatment is organized by Empire Medical Training (EMT), Inc and will be held on Sep 15, 2019 at Aloft Chicago O'Hare, Chicago, [...]
Biosimilars & Biologics Summit 2019
2019-09-16 - 2019-09-17    
All Day
TBD
Biosimilars & Biologics Summit 2019 is organized by Lexis Conferences Ltd and will be held from Sep 16 - 17, 2019 at London, England, United [...]
X Anniversary International Exhibition of equipment and technologies for the pharmaceutical industry PHARMATechExpo
2019-09-17 - 2019-09-19    
All Day
X Anniversary International Exhibition of equipment and technologies for the pharmaceutical industry PHARMATechExpo is organized by Laboratory Marketing Technology (LMT) Company, Shupyk National Medical Academy [...]
2019 Physician and CIO Forum
2019-09-18 - 2019-09-19    
All Day
Event Location MEDITECH Conference Center 1 Constitution Way Foxborough, MA Date : September 18th - 19th Conference: Wednesday, September 18  8:00 AM - 5:00 PM [...]
Stress, Depression, Anxiety and Resilience Summit 2019
2019-09-20 - 2019-09-21    
All Day
Stress, Depression, Anxiety and Resilience Summit is organized by Lexis Conferences Ltd and will be held from Sep 20 - 21, 2019 at Vancouver Convention [...]
Sclerotherapy for Physicians & Nurses Course - Orlando (Sep 20, 2019)
2019-09-20    
All Day
Sclerotherapy for Physicians & Nurses Course is organized by Empire Medical Training (EMT), Inc and will be held on Sep 20, 2019 at Sheraton Orlando [...]
Complete, Hands-on Dermal Filler (Sep 22, 2019)
2019-09-22    
All Day
Complete, Hands-on Dermal Filler is organized by Empire Medical Training (EMT), Inc and will be held on Sep 22, 2019 at Sheraton Orlando Lake Buena [...]
The MedTech Conference 2019
2019-09-23 - 2019-09-25    
All Day
The MedTech Conference 2019 is organized by Advanced Medical Technology Association (AdvaMed) and will be held from Sep 23 - 25, 2019 at Boston Convention [...]
23 Sep
2019-09-23 - 2019-09-24    
All Day
ABOUT 2ND WORLD CONGRESS ON RHEUMATOLOGY & ORTHOPEDICS Scientific Federation will be hosting 2nd World Congress on Rheumatology and Orthopedics this year. This exciting event [...]
25 Sep
2019-09-25 - 2019-09-26    
All Day
ABOUT 18TH WORLD CONGRESS ON NUTRITION AND FOOD CHEMISTRY Nutrition Conferences Committee extends its welcome to 18th World Congress on Nutrition and Food Chemistry (Nutri-Food [...]
ACP & Stem Cell Therapies for Pain Management (Sep 27, 2019)
2019-09-27    
All Day
ACP & Stem Cell Therapies for Pain Management is organized by Empire Medical Training (EMT), Inc and will be held on Sep 27, 2019 at [...]
01 Oct
2019-10-01 - 2019-10-02    
All Day
The UK’s leading health technology and smart health event, bringing together a specialist audience of over 4,000 health and care professionals covering IT and clinical [...]
Events on 2019-08-29
Events on 2019-08-31
Events on 2019-09-03
Medical Philippines 2019
3 Sep 19
Pasay City
Events on 2019-09-04
Events on 2019-09-05
Galapagos & Amazon 2019 Medical Conference
5 Sep 19
Galapagos Islands
Events on 2019-09-06
Events on 2019-09-07
Events on 2019-09-15
Events on 2019-09-16
Events on 2019-09-18
2019 Physician and CIO Forum
18 Sep 19
Foxborough
Events on 2019-09-22
Events on 2019-09-23
The MedTech Conference 2019
23 Sep 19
Boston
23 Sep
Events on 2019-09-25
Events on 2019-09-27
Events on 2019-10-01
01 Oct
Articles

Jun 27 : Security Challenges of EMRs

security challenges of emrs

Under his recently unveiled fiscal stimulus plan, President Obama seeks to invest up to US$20 Billion in federal funds to achieve widespread deployment of Electronic Medical Records (EMRs). A principal reason for his initiative is to improve our nation’s health care system by reducing long term costs and increasing effectiveness of our health outlays. So what exactly is an Electronic Medical Record and what does this new direction mean for security and privacy professionals?

By Feisal Nanji

CSO — Under his recently unveiled fiscal stimulus plan, President Obama seeks to invest up to US$20 Billion in federal funds to achieve widespread deployment of Electronic Medical Records (EMRs). A principal reason for his initiative is to improve our nation’s health care system by reducing long term costs and increasing effectiveness of our health outlays. So what exactly is an Electronic Medical Record and what does this new direction mean for security and privacy professionals?

At its core, an Electronic Medical Record (EMR) is the effective capture, dissemination, and analysis of medical and health related information for a single patient. All participants in the health care delivery system have a stake in efficient information flows. They include health care providers, insurers, government agencies, claims processors, and patients. Thus the term EMR has a slightly different meaning depending on one’s perspective. Indeed, Electronic Medical Records managed by individuals are termed Personal Health Records (PHRs). PHRs capture all relevant personal health details, including diagnoses, X-Rays, and similar items into a single repository. Individuals are then empowered to make health decisions for themselves, to easily choose among providers, to selectively disclose medical conditions, and to receive optimum care during emergencies. Both Google and Microsoft offer services for individuals to create, manage, and store their PHRs. We expect that there will be an explosion in demand as the computer-savvy population ages.

The focus of this article, however, is on the secure use of EMRs by institutions and health providers in a regulatory arena rife with complexity and with strict privacy and safety requirements. Consider a typical hospital with a relatively well functioning EMR system. Using EMRs, doctors can conduct much of their business totally electronically. This is in sharp contrast to traditional care environments where paper shuffling is the norm. Using EMRs, doctors can review patient histories and charts, obtain laboratory results, generate referrals for specialist consultations, prescribe medicines, and diagnose images all without the use of paper. This sounds utopian, and in many ways it is.

But the soft underbelly of EMRs is the difficulty in adequately securing such records. Key security and privacy concerns for EMR systems include:

— Hacking incidents on EMR systems that lead to altering of patient data or destruction of clinical systems

— Misuse of health information records by authorized users of EMR systems

— Long term data management concerns surrounding EMR systems

— Government or corporate intrusion into private health care matters

At first glance, these issues do not appear to be very difficult to solve. The reality is that hospitals and other care environments are complex institutions with complex workflows. A great many staff need immediate access to medical records. These include emergency technicians, admitting staff, doctors, nurses, and back-office personnel in billing and accounting. A quick fix might be to install role based access control (RBAC) mechanisms that allow for fine-grained permissions.

But in a security and remediation effort we conducted for a large health care provider, we discovered that retrofitting RBAC mechanisms into an existing EMR system was actually quite a complex undertaking. Assigning roles is particularly tricky across various hospital departments and personnel. An inadvertent stripping of viewing rights, for example, could result in a surgeon unable to view critical images in the operating theater. That could easily lead to a catastrophe and so ease of access considerations remain paramount. In our view, this has resulted in most EMR systems implementations to have less than desirable security postures.

Take, for example, an unauthorized disclosure of medical records to the press for an individual with the HIV virus. The effect could be devastating. Unintended outcomes might include family or community ostracism, job loss and denial of medical benefits. While there are legal statutes to prevent harmful effects of such disclosures, practically these may be of little solace to the individual whose record was released. One can imagine an insurer denying claims by insisting that the condition was pre-existing. These situations can and do occur in real life, and hospitals and care providers must take heed.

The probability of a large security breach (of the network or EMR application) also leaves many hospital administrators and compliance officers shuddering over the specter of privacy violations. Health Information Portability and Accounting Act (HIPAA) violations can have severe consequences, and new state regulations such as in California impose considerable penalties for the errant disclosure of medical records.

From our work at a large health care provider, we found that security breaches could be relatively easy to accomplish. Many EMRs are now connected to web applications (or are web applications themselves) making for relatively easy targets. We also found diagnostic systems that have direct connections to the hospital networks. Since these systems also have remote diagnostic capabilities for troubleshooting or downloading new software, installing a worm on the network that incapacitates, for example, all networked X-Ray machines is not out of the realm of possibility.

At one facility, observations that subsequently led us to a focused remediation path included:

1. The compliance organization at the facility was hampered by inadequate technology, resources and processes for monitoring and acting on potential privacy violations.

2. Application security vulnerability identification and management by the EMR vendor was inadequate and sorely needed

3. Security monitoring especially at the application and database level needed substantial improvement.

4. Secure data lifecycle management was not a priority during EMR system deployment. As a result items of specific concern included:

– Haphazard long term data storage and archiving approach

– Inappropriate data purging

– Murky data ownership responsibilities

– Inadequate procedures and systems for information asset discovery

– Inadequate data classification

– Insecure handling of physical media

While contemplating doomsday scenarios alone is not helpful, we believe that hospitals and large health institutions must tackle the notion of security and privacy in a very diligent and holistic way–almost akin to what the financial industry did to secure their transaction systems in the mid 2000’s. Without a concerted effort at every layer of the information infrastructure (device, network, and application), strict policies and use guidelines, and accurate monitoring capabilities, EMR deployments could crawl to a halt. The country needs better answers for securing EMRs. With the imminent outlays proposed by our new President to modernize our health care system, security professionals must step to the fore.

Source