Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
1
2
3
4
5
6
7
8
9
10
14
15
16
17
18
19
20
21
22
24
25
27
31
12:00 AM - EXPO.health
1
2
3
4
11 Jul
2019-07-11 - 2019-07-13    
All Day
2019 Annual Meeting and Scientific Seminar is Oraganized by American College of Neuropsychiatrists/American College of Osteopathic Neurologists and Psychiatrists (ACN/ACONP) and will be held from [...]
Breast Cancer: New Horizons, Current Controversies 2019
2019-07-11 - 2019-07-13    
All Day
Breast Cancer: New Horizons, Current Controversies is organized by Harvard Medical School (HMS) and will be held from Jul 11 - 13, 2019 at Boston [...]
11 Jul
2019-07-11 - 2019-07-12    
All Day
Pediatric Colorectal Scientific Meeting (PCSM) is organized by Intermountain Healthcare Interprofessional Continuing Education (IPCE) and will be held from Jul 11 - 12, 2019 at [...]
12 Jul
2019-07-12 - 2019-07-14    
All Day
Infectious Disease for Primary Care is organized by Medical Education Resources (MER) and will be held from Jul 12 - 14, 2019 at Disney's Contemporary [...]
12 Jul
2019-07-12 - 2019-07-14    
All Day
Dermatology for Primary Care is organized by Medical Education Resources (MER) and will be held from Jul 12 - 14, 2019 at Disney's Grand Californian [...]
12 Jul
2019-07-12 - 2019-07-14    
All Day
Office Orthopedics for Primary Care is organized by Medical Education Resources (MER) and will be held from Jul 12 - 14, 2019 at Bellagio Hotel [...]
13 Jul
2019-07-13 - 2019-07-19    
All Day
Association for Healthcare Philanthropy (AHP) Madison Institute is organized by Association for Healthcare Philanthropy (AHP) and will be held during Jul 13 - 19, 2019 [...]
13 Jul
2019-07-13 - 2019-07-14    
All Day
Red Cells Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Jul 13 - 14, 2019 at Salve [...]
47th Annual Institute and Conference - "Advancing Nursing Practice: Innovation, Access and Health Equity"
2019-07-23 - 2019-07-28    
All Day
47th Annual Institute and Conference - "Advancing Nursing Practice: Innovation, Access and Health Equity" is organized by National Black Nurses Association (NBNA), Inc. and will [...]
2nd International Conference on  Medical and Health Science
2019-07-26 - 2019-07-27    
All Day
Date: July 26-27, 2019 Melbourne, Australia Theme: Scrutinize the Modish of Medical and Health Science "2nd International Conference on Medical and Health Science" on July [...]
Pediatric and Adolescent Medicine, Pediatric Critical Care, Developmental Pediatrics, and ADHD
2019-07-26 - 2019-08-02    
All Day
Pediatric and Adolescent Medicine, Pediatric Critical Care, Developmental Pediatrics, and ADHD is organized by Continuing Education, Inc and will be held from Jul 26 - [...]
Cosmetic Pearls for the General Dental Practitioner
2019-07-26 - 2019-08-02    
All Day
Cosmetic Pearls for the General Dental Practitioner is organized by Continuing Education, Inc and will be held from Jul 26 - Aug 02, 2019 at [...]
Neuroethology: Behavior, Evolution and Neurobiology Gordon Research Conference (GRC) 2019
2019-07-28 - 2019-08-02    
All Day
Neuroethology: Behavior, Evolution and Neurobiology Gordon Research Conference (GRC) is organized by Gordon Research Conferences (GRC) and will be held from Jul 28 - Aug [...]
Molecular and Cellular Biology of Lipids Gordon Research Conference (GRC) 2019
2019-07-28 - 2019-08-02    
All Day
Molecular and Cellular Biology of Lipids Gordon Research Conference (GRC) is organized by Gordon Research Conferences (GRC) and will be held from Jul 28 - [...]
37th Annual Conference on Pediatric Infectious Diseases
2019-07-28 - 2019-08-02    
All Day
37th Annual Conference on Pediatric Infectious Diseases is organized by Children's Hospital Colorado and will be held from Jul 28 - Aug 02, 2019 at [...]
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics
2019-07-29 - 2019-08-02    
All Day
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics is organized by University of Washington School of Medicine (UWSOM) Continuing Medical Education (CME) [...]
3-Day Physician Assistant PANCE / PANRE Board Review Course by Certified Medical Educators (CME) - Salt Lake City
2019-07-29 - 2019-07-31    
All Day
3-Day Physician Assistant PANCE / PANRE Board Review Course is organized by Certified Medical Educators (CME) and will be held from Jul 29 - 31, [...]
Four Week Radiologic Pathology Correlation Course (Jul 29 - Aug 23, 2019)
2019-07-29 - 2019-08-23    
All Day
Four Week Radiologic Pathology Correlation Course is organized by American Institute for Radiologic Pathology (AIRP) and will be held from Jul 29 - Aug 23, [...]
Third Annual Philadelphia Trauma Training Conference
2019-07-30 - 2019-08-01    
All Day
Third Annual Philadelphia Trauma Training Conference is organized by Thomas Jefferson University (TJU) and will be held from Jul 30 - Aug 01, 2019 at [...]
IDAA Annual Meeting 2019
2019-07-31 - 2019-08-04    
All Day
International Doctors in Alcoholics Anonymous (IDAA) 70th Annual Meeting 2019 is organized by International Doctors in Alcoholics Anonymous (IDAA) and will be held from Jul [...]
EXPO.health
2019-07-31 - 2019-08-02    
All Day
EXPO.health Schedule July 31 - August 2, 2019 - Location: Boston, MA Join us at EXPO.health (Formerly Healthcare IT Expo – HITExpo) 2019 happening July [...]
01 Aug
2019-08-01 - 2019-08-03    
All Day
UCSF CME: Neurosurgery Update 2019 is organized by The University of California, San Francisco (UCSF) Office of Continuing Medical Education and will be held from [...]
PBI Medical Ethics & Professionalism (ME-22) - Irvine
2019-08-02 - 2019-08-03    
All Day
PBI Medical Ethics & Professionalism (ME-22) is organized by Professional Boundaries, Inc. (PBI) and will be held from Aug 02 - 03, 2019 at Wyndham [...]
The 8th Beijing International Top Health & Medical Exhibition (BIHM)
2019-08-02 - 2019-08-04    
All Day
The 8th Beijing International Private Health and Medical Exhibition will be held at the China International Exhibition Center from August 2nd to August 4th, 2019. [...]
Angiogenesis Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
12:00 am
Angiogenesis Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, 2019 at Salve Regina [...]
Lung Development, Injury and Repair Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
All Day
Lung Development, Injury and Repair Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, [...]
Platelet Rich Plasma for Aesthetics Course - Miami (Aug 2019)
Platelet Rich Plasma for Aesthetics Course is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at GALLERYone - [...]
Physician Medical Weight Loss Training (Aug 04, 2019)
2019-08-04    
All Day
Physician Medical Weight Loss Training is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at The Platinum Hotel [...]
Events on 2019-07-11
Events on 2019-07-30
Events on 2019-07-31
IDAA Annual Meeting 2019
31 Jul 19
Knoxville
EXPO.health
31 Jul 19
Boston
Events on 2019-08-01
01 Aug
Articles

Nov 13: Five EHR security considerations for healthcare CIOs, CISOs

healthcare cios

Though EHR security is just one component of a healthcare C-level executive’s job description, securing EHRs has various sub-components and best practices as well. Depending on which day it is, a healthcare CIOs or CISO may focus on the EHR Meaningful Use Program’s certification standards, data encryption methods or how the organization technical infrastructure is going to affect data security. Read through these five EHR security considerations and learn the different approaches organizations take to data security.

1. Auditing for EHR Meaningful Use Certification Standards

Many healthcare organizations have already taken advantage of the federal EHR Meaningful Use Program and will continue to do so. But a key aspect to EHR certification under this program is data security. For example, David Sheidlower, CISO of Health Quest, recently told HealthITSecurity.com that Health Quest is well into Stage 1 Meaningful Use and completed some go-lives with our hospital EMR, it has a little more breathing room to work on the security framework for Stage 2 Meaningful Us. Any initiative around meaningful use is centered around meaningful use-compliant applications, balancing responsibilities isn’t easy. “With a risk assessment, evaluation of controls and a security framework, while I’m laser-focused on meaningful use requirements, I need to make sure I’m not ignoring other parts of the organization,” he said.

For Shafiq Rab, CIO and Vice President of Hackensack University Medical Center, meaningful use audits serve as a solid baseline for his overall security program. Rab explained that Hackensack University Medical Center has been through Stage 1 Meaningful Use security analyses and now it’s getting ready for Stage 2 Meaningful Use.

“We know that one day we’ll be audited and because of that we look to see if there are any deficiencies. From a few different risk assessments to multiple penetration tests to data loss prevention (DLP), we have put all those things in place,” he said. “And through those tests, we have a risk mitigation process where a committee meets every month and helps [uphold high security standards].”

2. Endpoint security

Every EHR security framework is (or should be) multi-layered and, as Ron Mehring, director of information security for Texas Health Resources, explained back in February, securing end points is an important consideration. Texas Health Resources views its architecture in layers and then applies non-technical and technical security approaches to each layer to protect information and systems.

We have a boundary layer security area with firewalls and intrusion prevention systems and an endpoint security layer where we’re securing different end points such as desktops, servers and mobiles devices.  We have that layer that resides, more or less, in between the boundary and endpoint security layers where we’re doing things such as database activity monitoring, managing privileged access, and integrity monitoring on specific high-value systems.

How does endpoint security fit into your architecture?

3. Going virtual

Infrastructure plans effect EHR security and vice-versa and C-level executives need to make the best operational and security decisions possible. Bruce Forman, Chief Information Security Officer (CISO) of UMass Memorial Medical Center, for example, said that UMass is moving toward a virtual desktop environment (VDI). This decision grants him more centralized access to the information, as it essentially never leaves the data center. But it also helps with UMass’s BYOD security initiative for laptops and for tablets since they will enter the environment in the same manner.

We encrypt all of our laptops and USB devices and have even started encrypting desktop devices because they’re getting smaller and smaller and easy enough to walk away with. With VDI, though, it matters less that the device is encrypted because you don’t attach to your own internal network and you can’t download the data virtually.

4. Encrypting data at rest and in motion

The onus is on a CIO or CISO to encrypt EHR data in a strong manner. There are a number of routes that these organizations can take toward encrypting data at rest and in motion. Vic Wadhawan, Chief Security Officer at the Drayer Physical Therapy Institute, said he uses a security vendor that supports Secure/Multipurpose Internet Mail Extensions (S/MIME) email encryption and Privacy (PGP) to alleviate some burden of managing keys and certificates.

But if organizations are looking for firm guidance on encryption, they can look at National Institute of Standards and Technology (NIST) publications on encryption. For example, the Department of Health and Human Services (HHS) uses NIST Special Publication 800-52 Revision 1 as a foundation for encrypting healthcare data in motion. And HHS still employs NIST Special Publication 800-111 for full disk encryption, volume and virtual disk encryption and file/folder encryption best practices.

5. EHR security audits

Just who’s going in and out of a healthcare organization’s network and potentially gaining access to EHR data? Nancy Davis, system director of privacy and security for Ministry Health Care, explained that her organization does EHR access auditing through a combination of internal and external auditing applications. Davis said step one should be to have an external auditing tool and then to continually examine audit reports. “Take care not to create audit reports and let them stack up without reviewing,” Davis said. “There should be a policy and auditing plan in place.”  source