Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
27
29
30
1
2
3
14
15
17
18
19
20
21
22
23
24
25
26
27
29
30
31
1
2
3
4
5
18th Annual Conference on Urology and Nephrological Disorders
2019-11-25 - 2019-11-26    
All Day
ABOUT 18TH ANNUAL CONFERENCE ON UROLOGY AND NEPHROLOGICAL DISORDERS Urology 2019 is an integration of the science, theory and clinical knowledge for the purpose of [...]
2nd World Heart Rhythm Conference
2019-11-25 - 2019-11-26    
All Day
ABOUT 2ND WORLD HEART RHYTHM CONFERENCE 2nd World Heart Rhythm Conference is among the World’s driving Scientific Conference to unite worldwide recognized scholastics in the [...]
Digital Health Forum 2019
ABOUT DIGITAL HEALTH FORUM 2019 Join us on 26-27 November in Berlin to discuss the power of AI and ML for healthcare, healthcare transformation by [...]
2nd Global Nursing Conference & Expo
ABOUT 2ND GLOBAL NURSING CONFERENCE & EXPO Events Ocean extends an enthusiastic and sincere welcome to the 2nd GLOBAL NURSING CONFERENCE & EXPO ’19. The [...]
International Conference on Obesity and Diet Imbalance 2019
2019-11-28 - 2019-11-29    
All Day
ABOUT INTERNATIONAL CONFERENCE ON OBESITY AND DIET IMBALANCE 2019 Obesity Diet 2019 is a worldwide stage to examine and find out concerning Weight Management, Childhood [...]
40th SICOT Orthopaedic World Congresses
2019-12-04 - 2019-12-07    
All Day
With doctors attending from all over the world, it is fitting that this is taking place here, in a region that has served as a [...]
17th World Congress on Pediatrics and Neonatology
2019-12-04 - 2019-12-05    
All Day
Pediatrics 2019 welcomes attendees, presenters, and exhibitors from all over the world to Dubai. We are delighted to invite you all to attend and register [...]
6th Annual Gulf Obesity Surgery Society Meeting (GOSS)
2019-12-05 - 2019-12-07    
All Day
The Gulf Obesity Surgery Society is proud to announce the 6th Annual Gulf Obesity Surgery Society Meeting (GOSS) to be hosted by the Emirates Society [...]
AES 2019 Annual Meeting
2019-12-06 - 2019-12-10    
All Day
ABOUT AES 2019 ANNUAL MEETING As the largest gathering on epilepsy in the world, the American Epilepsy Society’s Annual Meeting is the event for epilepsy [...]
Manhattan Primary Care (Upper East Side Manhattan)
2019-12-07    
All Day
ABOUT MANHATTAN PRIMARY CARE (UPPER EAST SIDE MANHATTAN) Manhattan Primary Care is a dynamic internal medicine practice delivering high quality individualized primary care in Manhattan. [...]
Healthcare Facilities Design Summit 2019
2019-12-08 - 2019-12-10    
All Day
ABOUT HEALTHCARE FACILITIES DESIGN SUMMIT 2019 Healthcare design has transformed over the years and Opal Group’s Healthcare Facilities Design Summit is addressing pertinent issues in [...]
09 Dec
2019-12-09 - 2019-12-10    
All Day
ABOUT WORLD EYE AND VISION CONGRESS The World Eye and Vision Congress which brings together a unique and international mix of large and medium pharmaceutical, [...]
The 2nd Saudi International Pharma Expo 2019
2019-12-10 - 2019-12-13    
All Day
SAUDI INTERNATIONAL PHARMA EXPO 2019 offers you an EXCELLENT opportunity to expand your business in Saudi Arabia and international pharma industry : Join the industry [...]
Emirates Society of Emergency Medicine Conference 2019
2019-12-11 - 2019-12-14    
All Day
ABOUT EMIRATES SOCIETY OF EMERGENCY MEDICINE CONFERENCE 2019 Organized by the Emirates Society of Emergency Medicine (ESEM), the 6th edition of the conference has become [...]
Advances in Nutritional Science, Healthcare and Aging
2019-12-12 - 2019-12-14    
All Day
ABOUT ADVANCES IN NUTRITIONAL SCIENCE, HEALTHCARE AND AGING Good nutrition is critical to overall health from disease prevention to reaching your fitness goals. High quality, [...]
27th Annual World Congress
2019-12-13 - 2019-12-15    
All Day
Join us from December 13-15 for our 27th Annual World Congress in Las Vegas, marking over a quarter of a century since A4M began its [...]
International Forum on Advancements in Healthcare IFAH Dubai 2019
2019-12-16 - 2019-12-18    
All Day
International Forum on Advancements in Healthcare - IFAH (formerly Smart Health Conference) USA, will bring together 1000+ healthcare professionals from across the world on a [...]
2nd International Conference on Advanced Dentistry and Oral Health
2019-12-28 - 2019-12-30    
All Day
ABOUT 2ND INTERNATIONAL CONFERENCE ON ADVANCED DENTISTRY AND ORAL HEALTH We are pleased to invite you to the 2nd International Conference on Advanced Dentistry and [...]
5th International Conference On Recent Advances In Medical Science ICRAMS
2020-01-01 - 2020-01-02    
All Day
2020 IIER 775th International Conference on Recent Advances in Medical Science ICRAMS will be held in Dublin, Ireland during 1st - 2nd January, 2020 as [...]
01 Jan
2020-01-01 - 2020-01-02    
All Day
The Academics World 744th International Conference on Recent Advances in Medical and Health Sciences ICRAMHS aims to bring together leading academic scientists, researchers and research [...]
03 Jan
2020-01-03 - 2020-01-04    
All Day
Academicsera – 599th International Conference On Pharma and FoodICPAF will be held on 3rd-4th January, 2020 at Malacca , Malaysia. ICPAF is to bring together [...]
The IRES - 642nd International Conference On Food Microbiology And Food SafetyICFMFS
2020-01-03 - 2020-01-04    
All Day
The IRES - 642nd International Conference on Food Microbiology and Food SafetyICFMFS aimed at presenting current research being carried out in that area and scheduled [...]
World Congress On Medical Imaging And Clinical Research WCMICR-2020
2020-01-03 - 2020-01-04    
All Day
The WCMICR conference is an international forum for the presentation of technological advances and research results in the fields of Medical Imaging and Clinical Research. [...]
Events on 2019-11-26
Digital Health Forum 2019
26 Nov 19
Marinelli Rd Rockville
Events on 2019-11-28
Events on 2019-12-05
Events on 2019-12-06
AES 2019 Annual Meeting
6 Dec 19
Baltimore
Events on 2019-12-07
Events on 2019-12-08
Events on 2019-12-09
09 Dec
Events on 2019-12-10
Events on 2019-12-11
Events on 2019-12-12
Advances in Nutritional Science, Healthcare and Aging
12 Dec 19
Merivale St & Glenelg Street
Events on 2019-12-13
27th Annual World Congress
13 Dec 19
Las Vegas
Events on 2019-12-28
Latest News

May 02: How SaaS and EHR Providers Can Make Architectural Changes for Better HIPAA Compliance

electronic medical records

Guest post by Scott Walters, client services, INetU.

Whether they are cloud providers, EHR services firms or SaaS providers, technology companies that market to healthcare organizations are considered “business associates” under HIPAA. In the past, that meant customers often asked them to sign agreements assuring that they were employing best practices and would provide breach notifications to help customers maintain compliance.

As of September 13, 2013. however, changes to the guidelines were implemented that mean technology providers are now directly liable to the U.S. Department of Health & Human Services (HHS) for securing any PHI that they’re entrusted with. In addition to the increase in accountability, this first-hand responsibility also brings technology providers under the threat of fines that can now reach well into the millions of dollars.

The Cost of a Breach

The HHS Office for Civil Rights (OCR), the main enforcement body for HIPAA, has been gradually increasing fines for organizations that violate HIPAA compliance. The penalties have totaled well into the millions, with several organizations in the past few years receiving fines in excess of $1.5 million from OCR. In fact, according to data from the Department of Health and Human Services, HIPAA-covered entities and now business associates have paid more than $18.6 million to date to settle alleged federal HIPAA violations with $3.7 million of that coming from organizations in the last year alone. On top of this, there are often state and private legal settlements involved.

The Massachusetts Eye and Ear Infirmary (MEEI) is among the organizations that have experienced dramatic penalties firsthand, incurring fines of $1.5 million in 2012 after the theft of a laptop from an MEEI doctor who was traveling to Asia ended up exposing PHI. Blue Cross Blue Shield of Tennessee also paid $1.5 million in the same year following a breach of 1 million patient records stemming from the theft of 57 unencrypted hard drives from a leased training facility.

These two examples not only show the potential cost of a breach, they also demonstrate another quality that reaches across many of the violations to date – the fact that many of the biggest healthcare and HIPAA breaches are caused by unencrypted data and local storage of PHI. As technology providers offer services to manage this type of data, the onus to meet HIPAA regulations is more frequently falling on their shoulders. The upside to this is that, with some forethought, SaaS and EHR providers have the opportunity to make their cloud services even more HIPAA ready than their customers’ on-premise solutions.

Building the Cloud for HIPAA Compliance

The advantage that SaaS providers have when it comes to HIPAA compliance rests primarily in their ability to control cloud architecture. With insecure local storage of information serving as one of the main sources for HIPAA breaches, SaaS providers have the opportunity to eliminate many compromises by designing their architecture to inhibit local storage of PHI on the devices used to access that information in the cloud.

For this solution to work, SaaS providers must have adequate security measures within their own cloud infrastructure, and strong encryption for data-in-motion. This means classifying customer data and segmenting networks and systems containing sensitive PHI away from lower-risk parts of their infrastructure. Technology providers should also be instituting the strongest forms of encryption on these sensitive PHI databases, and ensuring control over who can access the information – both within their healthcare clients’ organizations and with the administrators at their own company via strong privileged access controls.

Just as important as ensuring this level of security is the ability to log and report on data to prove compliance. SaaS providers must offer their customers strong and flexible access control connectors so they can know who is looking at what data, and should have some means of collecting their logs in order to demonstrate compliance for both clients and auditors.

Finding Support

Maneuvering the intricacies and nuances of the data privacy provisions to achieve HIPAA compliance may seem daunting for busy SaaS and EHR providers, but there are a number of resources available to help guide them through the process.

For more technological and tailored guidance, hosting providers can often provide counsel on cloud architecture for SaaS and EHR companies. Far from the early days of straight technology provision, experienced hosting providers today are well acquainted with HIPAA and HITECH requirements and are able to help technology providers comply with regulations so they can focus on other aspects of growing their business.

However, not all hosting providers are created equal. When choosing a hosting provider to work with, SaaS and EHR companies should inquire about its network security and network controls, patch management services for hosted assets, systems and applications monitoring and reporting capabilities in case of an audit. In addition – particularly for smaller businesses or those with over-burdened internal resources – SaaS and EHR providers should ask about hosting companies’ teams’ expertise in HIPAA, willingness to provide counsel and how involved they would be willing to get in the case of an OCR audit.

More than 30.6 million individuals have had their PHI compromised in a large HIPAA privacy or security breach to date, and for the companies looking to provide technology to the healthcare industry, few things are more frightening than the idea of finding that they’re the ones liable in a breach. With proper architectural changes however, SaaS and EHR providers have an opportunity to turn liability into a new security competitive advantage and establish new streams of revenue for their business. Source