Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
1
2
3
4
5
6
7
9
11
12
13
14
16
17
19
20
21
27
28
1
2
3
4
5
6
7
Psychiatry and Psychological Disorders
2021-02-08 - 2021-02-09    
All Day
Mental health Summit 2021 is a meeting of Psychiatrist for emerging their perspective against mental health challenges and psychological disorders in upcoming future. Psychiatry is [...]
Nanotechnology and Materials Engineering
2021-02-10 - 2021-02-11    
All Day
Nanotechnology and Materials Engineering are forthcoming use in healthcare, electronics, cosmetics, and other areas. Nanomaterials are the elements with the finest measurement of size 10-9 [...]
Dementia, Alzheimers and Neurological Disorders
2021-02-10 - 2021-02-11    
All Day
Euro Dementia 2021 is a distinctive forum to assemble worldwide distinguished academics within the field of professionals, Psychology, academic scientists, professors to exchange their ideas [...]
Neurology and Neurosurgery 2021
2021-02-10 - 2021-02-11    
All Day
European Neurosurgery 2021 anticipates participants from all around the globe to experience thought provoking Keynote lectures, oral, video & poster presentations. This Neurology meeting will [...]
Biofuels and Bioenergy 2021
2021-02-15 - 2021-02-16    
All Day
Biofuels and Bioenergy biofuel is a fuel that is produced through contemporary biological processes, such as agriculture and anaerobic digestion, rather than a fuel produced [...]
Tropical Medicine and Infectious Diseases
2021-02-15 - 2021-02-16    
All Day
Tropical Disease Webinar committee members invite all the participants across the globe to take part in this conference covering the theme “Global Impact on infectious [...]
Infectious Diseases 2021
2021-02-15 - 2021-02-16    
All Day
Infection Congress 2021 is intended to honor prestigious award for talented Young Researchers, Scientists, Young Investigators, Post-Graduate Students, Post-Doctoral Fellows, Trainees in recognition of their [...]
Gastroenterology and Liver Diseases
2021-02-18 - 2021-02-19    
All Day
Gastroenterology and Liver Diseases Conference 2021 provides a chance for all the stakeholders to collect all the Researchers, principal investigators, experts and researchers working under [...]
World Kidney Congress 2021
2021-02-18    
All Day
Kidney Meet 2021 will be the best platform for exchanging new ideas and research. It’s a virtual event that will grab the attendee’s attention to [...]
Agriculture & Organic farming
2021-02-22 - 2021-02-23    
All Day
                                                  [...]
Aquaculture & Fisheries
2021-02-22 - 2021-02-23    
All Day
We take the pleasure to invite all the Scientist, researchers, students and delegates to Participate in the Webinar on 13th World Congress on Aquaculture & [...]
Nanoscience and Nanotechnology 2021
2021-02-22 - 2021-02-23    
All Day
Conference Series warmly invites all the participants across the globe to attend "5th Annual Meet on Nanoscience and Nanotechnology” dated on February 22-23, 2021 , [...]
Neurology, Psychiatric disorders and Mental health
2021-02-23 - 2021-02-24    
12:00 am
Neurology, Psychiatric disorders and Mental health Summit is an idiosyncratic discussion to bring the advanced approaches and also unite recognized scholastics, concerned with neurology, neuroscience, [...]
Food and Nutrition 2021
2021-02-24    
All Day
Nutri Food 2021 reunites the old and new faces in food research to scale-up many dedicated brains in research and the utilization of the works [...]
Psychiatry and Psychological Disorders
2021-02-24 - 2021-02-25    
All Day
Mental health Summit 2021 is a meeting of Psychiatrist for emerging their perspective against mental health challenges and psychological disorders in upcoming future. Psychiatry is [...]
International Conference on  Biochemistry and Glyco Science
2021-02-25 - 2021-02-26    
All Day
Our point is to urge researchers to spread their test and hypothetical outcomes in any case a lot of detail as could be ordinary. There [...]
Biomedical, Biopharma and Clinical Research
2021-02-25 - 2021-02-26    
All Day
Biomedical research 2021 provides a platform to enhance your knowledge and forecast future developments in biomedical, bio pharma and clinical research and strives to provide [...]
Parasitology & Infectious Diseases 2021
2021-02-25    
All Day
INFECTIOUS DISEASES CONGRESS 2021 on behalf of its Organizing Committee, assemble all the renowned Pathologists, Immunologists, Researchers, Cellular and Molecular Biologists, Immune therapists, Academicians, Biotechnologists, [...]
Tissue Science and Regenerative Medicine
2021-02-26 - 2021-02-27    
All Day
Tissue Science 2021 proudly invites contributors across the globe to attend “International Conference on Tissue Science and Regenerative Medicine” during February 26-27, 2021 (Webinar) which [...]
Infectious Diseases, Microbiology & Beneficial Microbes
2021-02-26 - 2021-02-27    
All Day
Infectious diseases are ultimately caused by microscopic organisms like bacteria, viruses, fungi or parasites where Microbiology is the investigation of these minute life forms. A [...]
Stress Management 2021
2021-02-26    
All Day
Stress Management Meet 2021 will be a great platform for exchanging new ideas and research. It’s an online event which will grab the attendee’s attention [...]
Heart Care and Diseases 2021
2021-03-03    
All Day
Euro Heart Conference 2020 will join world-class professors, scientists, researchers, students, Perfusionists, cardiologists to discuss methodology for ailment remediation for heart diseases, Electrocardiography, Heart Failure, [...]
Gastroenterology and Digestive Disorders
2021-03-04 - 2021-03-05    
All Day
Gastroenterology Diseases is clearing a worldwide stage by drawing in 2500+ Gastroenterologists, Hepatologists, Surgeons going from Researchers, Academicians and Business experts, who are working in [...]
Environmental Toxicology and Ecological Risk Assessment
2021-03-04 - 2021-03-05    
All Day
Environmental Toxicology 2021 you can meet the world leading toxicologists, biochemists, pharmacologists, and also the industry giants who will provide you with the modern inventions [...]
Dermatology, Cosmetology and Plastic Surgery
2021-03-05 - 2021-03-06    
All Day
Market Analysis Speaking Opportunities Speaking Opportunities: We are constantly intrigued by hearing from professionals/practitioners who want to share their direct encounters and contextual investigations with [...]
Events on 2021-02-08
Events on 2021-02-18
Events on 2021-02-24
Events on 2021-03-03
Events on 2021-03-05
Latest News

May 02: How SaaS and EHR Providers Can Make Architectural Changes for Better HIPAA Compliance

electronic medical records

Guest post by Scott Walters, client services, INetU.

Whether they are cloud providers, EHR services firms or SaaS providers, technology companies that market to healthcare organizations are considered “business associates” under HIPAA. In the past, that meant customers often asked them to sign agreements assuring that they were employing best practices and would provide breach notifications to help customers maintain compliance.

As of September 13, 2013. however, changes to the guidelines were implemented that mean technology providers are now directly liable to the U.S. Department of Health & Human Services (HHS) for securing any PHI that they’re entrusted with. In addition to the increase in accountability, this first-hand responsibility also brings technology providers under the threat of fines that can now reach well into the millions of dollars.

The Cost of a Breach

The HHS Office for Civil Rights (OCR), the main enforcement body for HIPAA, has been gradually increasing fines for organizations that violate HIPAA compliance. The penalties have totaled well into the millions, with several organizations in the past few years receiving fines in excess of $1.5 million from OCR. In fact, according to data from the Department of Health and Human Services, HIPAA-covered entities and now business associates have paid more than $18.6 million to date to settle alleged federal HIPAA violations with $3.7 million of that coming from organizations in the last year alone. On top of this, there are often state and private legal settlements involved.

The Massachusetts Eye and Ear Infirmary (MEEI) is among the organizations that have experienced dramatic penalties firsthand, incurring fines of $1.5 million in 2012 after the theft of a laptop from an MEEI doctor who was traveling to Asia ended up exposing PHI. Blue Cross Blue Shield of Tennessee also paid $1.5 million in the same year following a breach of 1 million patient records stemming from the theft of 57 unencrypted hard drives from a leased training facility.

These two examples not only show the potential cost of a breach, they also demonstrate another quality that reaches across many of the violations to date – the fact that many of the biggest healthcare and HIPAA breaches are caused by unencrypted data and local storage of PHI. As technology providers offer services to manage this type of data, the onus to meet HIPAA regulations is more frequently falling on their shoulders. The upside to this is that, with some forethought, SaaS and EHR providers have the opportunity to make their cloud services even more HIPAA ready than their customers’ on-premise solutions.

Building the Cloud for HIPAA Compliance

The advantage that SaaS providers have when it comes to HIPAA compliance rests primarily in their ability to control cloud architecture. With insecure local storage of information serving as one of the main sources for HIPAA breaches, SaaS providers have the opportunity to eliminate many compromises by designing their architecture to inhibit local storage of PHI on the devices used to access that information in the cloud.

For this solution to work, SaaS providers must have adequate security measures within their own cloud infrastructure, and strong encryption for data-in-motion. This means classifying customer data and segmenting networks and systems containing sensitive PHI away from lower-risk parts of their infrastructure. Technology providers should also be instituting the strongest forms of encryption on these sensitive PHI databases, and ensuring control over who can access the information – both within their healthcare clients’ organizations and with the administrators at their own company via strong privileged access controls.

Just as important as ensuring this level of security is the ability to log and report on data to prove compliance. SaaS providers must offer their customers strong and flexible access control connectors so they can know who is looking at what data, and should have some means of collecting their logs in order to demonstrate compliance for both clients and auditors.

Finding Support

Maneuvering the intricacies and nuances of the data privacy provisions to achieve HIPAA compliance may seem daunting for busy SaaS and EHR providers, but there are a number of resources available to help guide them through the process.

For more technological and tailored guidance, hosting providers can often provide counsel on cloud architecture for SaaS and EHR companies. Far from the early days of straight technology provision, experienced hosting providers today are well acquainted with HIPAA and HITECH requirements and are able to help technology providers comply with regulations so they can focus on other aspects of growing their business.

However, not all hosting providers are created equal. When choosing a hosting provider to work with, SaaS and EHR companies should inquire about its network security and network controls, patch management services for hosted assets, systems and applications monitoring and reporting capabilities in case of an audit. In addition – particularly for smaller businesses or those with over-burdened internal resources – SaaS and EHR providers should ask about hosting companies’ teams’ expertise in HIPAA, willingness to provide counsel and how involved they would be willing to get in the case of an OCR audit.

More than 30.6 million individuals have had their PHI compromised in a large HIPAA privacy or security breach to date, and for the companies looking to provide technology to the healthcare industry, few things are more frightening than the idea of finding that they’re the ones liable in a breach. With proper architectural changes however, SaaS and EHR providers have an opportunity to turn liability into a new security competitive advantage and establish new streams of revenue for their business. Source