Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
27
29
30
1
2
3
14
15
17
18
19
20
21
22
23
24
25
26
27
29
30
31
1
2
3
4
5
18th Annual Conference on Urology and Nephrological Disorders
2019-11-25 - 2019-11-26    
All Day
ABOUT 18TH ANNUAL CONFERENCE ON UROLOGY AND NEPHROLOGICAL DISORDERS Urology 2019 is an integration of the science, theory and clinical knowledge for the purpose of [...]
2nd World Heart Rhythm Conference
2019-11-25 - 2019-11-26    
All Day
ABOUT 2ND WORLD HEART RHYTHM CONFERENCE 2nd World Heart Rhythm Conference is among the World’s driving Scientific Conference to unite worldwide recognized scholastics in the [...]
Digital Health Forum 2019
ABOUT DIGITAL HEALTH FORUM 2019 Join us on 26-27 November in Berlin to discuss the power of AI and ML for healthcare, healthcare transformation by [...]
2nd Global Nursing Conference & Expo
ABOUT 2ND GLOBAL NURSING CONFERENCE & EXPO Events Ocean extends an enthusiastic and sincere welcome to the 2nd GLOBAL NURSING CONFERENCE & EXPO ’19. The [...]
International Conference on Obesity and Diet Imbalance 2019
2019-11-28 - 2019-11-29    
All Day
ABOUT INTERNATIONAL CONFERENCE ON OBESITY AND DIET IMBALANCE 2019 Obesity Diet 2019 is a worldwide stage to examine and find out concerning Weight Management, Childhood [...]
40th SICOT Orthopaedic World Congresses
2019-12-04 - 2019-12-07    
All Day
With doctors attending from all over the world, it is fitting that this is taking place here, in a region that has served as a [...]
17th World Congress on Pediatrics and Neonatology
2019-12-04 - 2019-12-05    
All Day
Pediatrics 2019 welcomes attendees, presenters, and exhibitors from all over the world to Dubai. We are delighted to invite you all to attend and register [...]
6th Annual Gulf Obesity Surgery Society Meeting (GOSS)
2019-12-05 - 2019-12-07    
All Day
The Gulf Obesity Surgery Society is proud to announce the 6th Annual Gulf Obesity Surgery Society Meeting (GOSS) to be hosted by the Emirates Society [...]
AES 2019 Annual Meeting
2019-12-06 - 2019-12-10    
All Day
ABOUT AES 2019 ANNUAL MEETING As the largest gathering on epilepsy in the world, the American Epilepsy Society’s Annual Meeting is the event for epilepsy [...]
Manhattan Primary Care (Upper East Side Manhattan)
2019-12-07    
All Day
ABOUT MANHATTAN PRIMARY CARE (UPPER EAST SIDE MANHATTAN) Manhattan Primary Care is a dynamic internal medicine practice delivering high quality individualized primary care in Manhattan. [...]
Healthcare Facilities Design Summit 2019
2019-12-08 - 2019-12-10    
All Day
ABOUT HEALTHCARE FACILITIES DESIGN SUMMIT 2019 Healthcare design has transformed over the years and Opal Group’s Healthcare Facilities Design Summit is addressing pertinent issues in [...]
09 Dec
2019-12-09 - 2019-12-10    
All Day
ABOUT WORLD EYE AND VISION CONGRESS The World Eye and Vision Congress which brings together a unique and international mix of large and medium pharmaceutical, [...]
The 2nd Saudi International Pharma Expo 2019
2019-12-10 - 2019-12-13    
All Day
SAUDI INTERNATIONAL PHARMA EXPO 2019 offers you an EXCELLENT opportunity to expand your business in Saudi Arabia and international pharma industry : Join the industry [...]
Emirates Society of Emergency Medicine Conference 2019
2019-12-11 - 2019-12-14    
All Day
ABOUT EMIRATES SOCIETY OF EMERGENCY MEDICINE CONFERENCE 2019 Organized by the Emirates Society of Emergency Medicine (ESEM), the 6th edition of the conference has become [...]
Advances in Nutritional Science, Healthcare and Aging
2019-12-12 - 2019-12-14    
All Day
ABOUT ADVANCES IN NUTRITIONAL SCIENCE, HEALTHCARE AND AGING Good nutrition is critical to overall health from disease prevention to reaching your fitness goals. High quality, [...]
27th Annual World Congress
2019-12-13 - 2019-12-15    
All Day
Join us from December 13-15 for our 27th Annual World Congress in Las Vegas, marking over a quarter of a century since A4M began its [...]
International Forum on Advancements in Healthcare IFAH Dubai 2019
2019-12-16 - 2019-12-18    
All Day
International Forum on Advancements in Healthcare - IFAH (formerly Smart Health Conference) USA, will bring together 1000+ healthcare professionals from across the world on a [...]
2nd International Conference on Advanced Dentistry and Oral Health
2019-12-28 - 2019-12-30    
All Day
ABOUT 2ND INTERNATIONAL CONFERENCE ON ADVANCED DENTISTRY AND ORAL HEALTH We are pleased to invite you to the 2nd International Conference on Advanced Dentistry and [...]
5th International Conference On Recent Advances In Medical Science ICRAMS
2020-01-01 - 2020-01-02    
All Day
2020 IIER 775th International Conference on Recent Advances in Medical Science ICRAMS will be held in Dublin, Ireland during 1st - 2nd January, 2020 as [...]
01 Jan
2020-01-01 - 2020-01-02    
All Day
The Academics World 744th International Conference on Recent Advances in Medical and Health Sciences ICRAMHS aims to bring together leading academic scientists, researchers and research [...]
03 Jan
2020-01-03 - 2020-01-04    
All Day
Academicsera – 599th International Conference On Pharma and FoodICPAF will be held on 3rd-4th January, 2020 at Malacca , Malaysia. ICPAF is to bring together [...]
The IRES - 642nd International Conference On Food Microbiology And Food SafetyICFMFS
2020-01-03 - 2020-01-04    
All Day
The IRES - 642nd International Conference on Food Microbiology and Food SafetyICFMFS aimed at presenting current research being carried out in that area and scheduled [...]
World Congress On Medical Imaging And Clinical Research WCMICR-2020
2020-01-03 - 2020-01-04    
All Day
The WCMICR conference is an international forum for the presentation of technological advances and research results in the fields of Medical Imaging and Clinical Research. [...]
Events on 2019-11-26
Digital Health Forum 2019
26 Nov 19
Marinelli Rd Rockville
Events on 2019-11-28
Events on 2019-12-05
Events on 2019-12-06
AES 2019 Annual Meeting
6 Dec 19
Baltimore
Events on 2019-12-07
Events on 2019-12-08
Events on 2019-12-09
09 Dec
Events on 2019-12-10
Events on 2019-12-11
Events on 2019-12-12
Advances in Nutritional Science, Healthcare and Aging
12 Dec 19
Merivale St & Glenelg Street
Events on 2019-12-13
27th Annual World Congress
13 Dec 19
Las Vegas
Events on 2019-12-28
Articles

Nov 13: Five EHR security considerations for healthcare CIOs, CISOs

healthcare cios

Though EHR security is just one component of a healthcare C-level executive’s job description, securing EHRs has various sub-components and best practices as well. Depending on which day it is, a healthcare CIOs or CISO may focus on the EHR Meaningful Use Program’s certification standards, data encryption methods or how the organization technical infrastructure is going to affect data security. Read through these five EHR security considerations and learn the different approaches organizations take to data security.

1. Auditing for EHR Meaningful Use Certification Standards

Many healthcare organizations have already taken advantage of the federal EHR Meaningful Use Program and will continue to do so. But a key aspect to EHR certification under this program is data security. For example, David Sheidlower, CISO of Health Quest, recently told HealthITSecurity.com that Health Quest is well into Stage 1 Meaningful Use and completed some go-lives with our hospital EMR, it has a little more breathing room to work on the security framework for Stage 2 Meaningful Us. Any initiative around meaningful use is centered around meaningful use-compliant applications, balancing responsibilities isn’t easy. “With a risk assessment, evaluation of controls and a security framework, while I’m laser-focused on meaningful use requirements, I need to make sure I’m not ignoring other parts of the organization,” he said.

For Shafiq Rab, CIO and Vice President of Hackensack University Medical Center, meaningful use audits serve as a solid baseline for his overall security program. Rab explained that Hackensack University Medical Center has been through Stage 1 Meaningful Use security analyses and now it’s getting ready for Stage 2 Meaningful Use.

“We know that one day we’ll be audited and because of that we look to see if there are any deficiencies. From a few different risk assessments to multiple penetration tests to data loss prevention (DLP), we have put all those things in place,” he said. “And through those tests, we have a risk mitigation process where a committee meets every month and helps [uphold high security standards].”

2. Endpoint security

Every EHR security framework is (or should be) multi-layered and, as Ron Mehring, director of information security for Texas Health Resources, explained back in February, securing end points is an important consideration. Texas Health Resources views its architecture in layers and then applies non-technical and technical security approaches to each layer to protect information and systems.

We have a boundary layer security area with firewalls and intrusion prevention systems and an endpoint security layer where we’re securing different end points such as desktops, servers and mobiles devices.  We have that layer that resides, more or less, in between the boundary and endpoint security layers where we’re doing things such as database activity monitoring, managing privileged access, and integrity monitoring on specific high-value systems.

How does endpoint security fit into your architecture?

3. Going virtual

Infrastructure plans effect EHR security and vice-versa and C-level executives need to make the best operational and security decisions possible. Bruce Forman, Chief Information Security Officer (CISO) of UMass Memorial Medical Center, for example, said that UMass is moving toward a virtual desktop environment (VDI). This decision grants him more centralized access to the information, as it essentially never leaves the data center. But it also helps with UMass’s BYOD security initiative for laptops and for tablets since they will enter the environment in the same manner.

We encrypt all of our laptops and USB devices and have even started encrypting desktop devices because they’re getting smaller and smaller and easy enough to walk away with. With VDI, though, it matters less that the device is encrypted because you don’t attach to your own internal network and you can’t download the data virtually.

4. Encrypting data at rest and in motion

The onus is on a CIO or CISO to encrypt EHR data in a strong manner. There are a number of routes that these organizations can take toward encrypting data at rest and in motion. Vic Wadhawan, Chief Security Officer at the Drayer Physical Therapy Institute, said he uses a security vendor that supports Secure/Multipurpose Internet Mail Extensions (S/MIME) email encryption and Privacy (PGP) to alleviate some burden of managing keys and certificates.

But if organizations are looking for firm guidance on encryption, they can look at National Institute of Standards and Technology (NIST) publications on encryption. For example, the Department of Health and Human Services (HHS) uses NIST Special Publication 800-52 Revision 1 as a foundation for encrypting healthcare data in motion. And HHS still employs NIST Special Publication 800-111 for full disk encryption, volume and virtual disk encryption and file/folder encryption best practices.

5. EHR security audits

Just who’s going in and out of a healthcare organization’s network and potentially gaining access to EHR data? Nancy Davis, system director of privacy and security for Ministry Health Care, explained that her organization does EHR access auditing through a combination of internal and external auditing applications. Davis said step one should be to have an external auditing tool and then to continually examine audit reports. “Take care not to create audit reports and let them stack up without reviewing,” Davis said. “There should be a policy and auditing plan in place.”  source