Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
31
1
4
5
10
11
12
17
24
25
26
28
29
30
1
2
3
30 Mar
2020-03-30 - 2020-03-31    
All Day
This Cardio Diabetes 2020 includes Speaker talks, Keynote & Poster presentations, Exhibition, Symposia, and Workshops. This International Conference will help in interacting and meeting with diabetes and [...]
Trending Topics In Internal Medicine 2020
2020-04-02 - 2020-04-04    
All Day
Trending Topics in Internal Medicine is a CME course that will tackle the latest information trending in healthcare today.   This course will help you discuss options [...]
2020 Summit On National & Global Cancer Health Disparities
2020-04-03 - 2020-04-04    
All Day
The 2020 Summit on National & Global Cancer Health Disparities is planned with the goal of creating a momentum to minimize the disparities in cancer [...]
2020 Primary Care Kauai- Caring For The Active And Athletic Patient
2020-04-06 - 2020-04-10    
All Day
CMX Travel and Meetings programs meetings and group conferences for physicians and medical professionals throughout the United States. CMX Travel and Meetings programs meetings and [...]
ISER- 787th International Conference On Science, Health And Medicine ICSHM
2020-04-07 - 2020-04-08    
All Day
ISER- 787th International Conference on Science, Health and Medicine (ICSHM) is a prestigious event organized with a motivation to provide an excellent international platform for the academicians, [...]
RW- 801st International Conference On Medical And Biosciences ICMBS
2020-04-08 - 2020-04-09    
All Day
About the EventConference : RW- 801st International Conference on Medical and Biosciences ICMBS is a prestigious event organized with a motivation to provide an excellent [...]
Palliative Care 2020
2020-04-08 - 2020-04-09    
All Day
ABOUT PALLIATIVE CARE 2020 Palliative Care 2020 welcomes attendees, presenters, and exhibitors from all over the world to Dubai, UAE. We are glad to invite [...]
The 4th Annual Dubai International Paediatric Neurology Congress
2020-04-09 - 2020-04-11    
All Day
Based on the sound success of previous Dubai International paediatric Neurology congresses the 4th Annual Dubai International paediatric Neurology Conference expects to attract over 400 delegates devoted [...]
13 Apr
2020-04-13 - 2020-04-14    
All Day
IASTEM - 814th International Conference on Medical, Biological and Pharmaceutical Sciences (ICMBPS) will be held on 13th - 14th April, 2020 at Dammam, Saudi Arabia . ICMBPS is to bring together [...]
Patient Engagement USA At Eyeforpharma Philadelphia
2020-04-14 - 2020-04-15    
All Day
As we enter election year in 2020, the pressure has never been higher on our industry to justify what we add to the cost of [...]
28th International Conference On Clinical Pediatrics
2020-04-15 - 2020-04-16    
All Day
It is our great pleasure to invite you to participate in the 28th International Conference on Clinical Pediatrics Clinical Pediatrics 2020 which will take place [...]
5th World Congress On Public Health And Health Care Management
2020-04-16 - 2020-04-17    
All Day
We would like to invite you all people to take part in our Public Health and Health Care Management-2020 Conference in Miami, USA during 16-17 [...]
Topics In Emergency Medicine, Pain Management, And Palliative Care CME Cruise
2020-04-18 - 2020-04-25    
All Day
These set of lectures is designed to provide important updates in emergency medicine with a focus on anticoagulation and the management of venous thromboembolism as [...]
RW- 809th International Conference On Medical And Biosciences ICMBS
2020-04-19 - 2020-04-20    
All Day
RW- 809th International Conference on Medical and Biosciences (ICMBS) is a prestigious event organized with a motivation to provide an excellent international platform for the academicians, researchers, [...]
RF - 627th International Conference On Medical & Health Science - ICMHS 2020
2020-04-20 - 2020-04-21    
All Day
Welcome to the Official Website of the  627th International Conference on Medical & Health Science - ICMHS 2020. It will be held during 20th-21st April, 2020 at San [...]
30th Annual Art And Science Of Health Promotion Conference
2020-04-20 - 2020-04-24    
All Day
Integrating Health Promotion into the Organization’s and Community’s Core Values A common element of virtually every successful health promotion program in workplace, clinical and community [...]
ISER- 796th International Conference On Science, Health And Medicine ICSHM
2020-04-21 - 2020-04-22    
All Day
ISER- 796th International Conference on Science, Health and Medicine ICSHM is a prestigious event organized with a motivation to provide an excellent international platform for [...]
Biomolecular Condensates Summit
2020-04-21 - 2020-04-23    
All Day
An ever-increasing amount of evidence points towards the importance of Biomolecular Condensates function to health and disease. However, with many of the fundamental questions behind [...]
The Middle East Pharma Cold Chain Congress
2020-04-22 - 2020-04-23    
All Day
The pharma sector in the MENA region has witnessed rapid development, which has been largely fueled by high population growth, increased life expectancy coupled with [...]
45th Annual Regional Anesthesiology And Acute Pain Medicine Meeting
2020-04-23 - 2020-04-25    
All Day
ASRA was officially "re-founded" in 1975, led by Alon P. Winnie, MD, who had a dream of a society devoted to teaching regional anesthesia. (An [...]
25th International Conference on Dermatology & Skin Care
2020-04-27 - 2020-04-28    
All Day
About Conference Derma 2020 Derma 2020 welcomes all the attendees, lecturers, patrons and other research expertise from all over the world to 25th International Conference on Dermatology & [...]
Events on 2020-03-30
Events on 2020-04-02
Events on 2020-04-03
Events on 2020-04-08
Events on 2020-04-14
Events on 2020-04-15
Events on 2020-04-22
Events on 2020-04-23
Events on 2020-04-27
Latest News

May 02: How SaaS and EHR Providers Can Make Architectural Changes for Better HIPAA Compliance

electronic medical records

Guest post by Scott Walters, client services, INetU.

Whether they are cloud providers, EHR services firms or SaaS providers, technology companies that market to healthcare organizations are considered “business associates” under HIPAA. In the past, that meant customers often asked them to sign agreements assuring that they were employing best practices and would provide breach notifications to help customers maintain compliance.

As of September 13, 2013. however, changes to the guidelines were implemented that mean technology providers are now directly liable to the U.S. Department of Health & Human Services (HHS) for securing any PHI that they’re entrusted with. In addition to the increase in accountability, this first-hand responsibility also brings technology providers under the threat of fines that can now reach well into the millions of dollars.

The Cost of a Breach

The HHS Office for Civil Rights (OCR), the main enforcement body for HIPAA, has been gradually increasing fines for organizations that violate HIPAA compliance. The penalties have totaled well into the millions, with several organizations in the past few years receiving fines in excess of $1.5 million from OCR. In fact, according to data from the Department of Health and Human Services, HIPAA-covered entities and now business associates have paid more than $18.6 million to date to settle alleged federal HIPAA violations with $3.7 million of that coming from organizations in the last year alone. On top of this, there are often state and private legal settlements involved.

The Massachusetts Eye and Ear Infirmary (MEEI) is among the organizations that have experienced dramatic penalties firsthand, incurring fines of $1.5 million in 2012 after the theft of a laptop from an MEEI doctor who was traveling to Asia ended up exposing PHI. Blue Cross Blue Shield of Tennessee also paid $1.5 million in the same year following a breach of 1 million patient records stemming from the theft of 57 unencrypted hard drives from a leased training facility.

These two examples not only show the potential cost of a breach, they also demonstrate another quality that reaches across many of the violations to date – the fact that many of the biggest healthcare and HIPAA breaches are caused by unencrypted data and local storage of PHI. As technology providers offer services to manage this type of data, the onus to meet HIPAA regulations is more frequently falling on their shoulders. The upside to this is that, with some forethought, SaaS and EHR providers have the opportunity to make their cloud services even more HIPAA ready than their customers’ on-premise solutions.

Building the Cloud for HIPAA Compliance

The advantage that SaaS providers have when it comes to HIPAA compliance rests primarily in their ability to control cloud architecture. With insecure local storage of information serving as one of the main sources for HIPAA breaches, SaaS providers have the opportunity to eliminate many compromises by designing their architecture to inhibit local storage of PHI on the devices used to access that information in the cloud.

For this solution to work, SaaS providers must have adequate security measures within their own cloud infrastructure, and strong encryption for data-in-motion. This means classifying customer data and segmenting networks and systems containing sensitive PHI away from lower-risk parts of their infrastructure. Technology providers should also be instituting the strongest forms of encryption on these sensitive PHI databases, and ensuring control over who can access the information – both within their healthcare clients’ organizations and with the administrators at their own company via strong privileged access controls.

Just as important as ensuring this level of security is the ability to log and report on data to prove compliance. SaaS providers must offer their customers strong and flexible access control connectors so they can know who is looking at what data, and should have some means of collecting their logs in order to demonstrate compliance for both clients and auditors.

Finding Support

Maneuvering the intricacies and nuances of the data privacy provisions to achieve HIPAA compliance may seem daunting for busy SaaS and EHR providers, but there are a number of resources available to help guide them through the process.

For more technological and tailored guidance, hosting providers can often provide counsel on cloud architecture for SaaS and EHR companies. Far from the early days of straight technology provision, experienced hosting providers today are well acquainted with HIPAA and HITECH requirements and are able to help technology providers comply with regulations so they can focus on other aspects of growing their business.

However, not all hosting providers are created equal. When choosing a hosting provider to work with, SaaS and EHR companies should inquire about its network security and network controls, patch management services for hosted assets, systems and applications monitoring and reporting capabilities in case of an audit. In addition – particularly for smaller businesses or those with over-burdened internal resources – SaaS and EHR providers should ask about hosting companies’ teams’ expertise in HIPAA, willingness to provide counsel and how involved they would be willing to get in the case of an OCR audit.

More than 30.6 million individuals have had their PHI compromised in a large HIPAA privacy or security breach to date, and for the companies looking to provide technology to the healthcare industry, few things are more frightening than the idea of finding that they’re the ones liable in a breach. With proper architectural changes however, SaaS and EHR providers have an opportunity to turn liability into a new security competitive advantage and establish new streams of revenue for their business. Source