Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
26
27
28
30
2
8
9
10
11
12
13
14
19
21
24
26
28
29
30
1
2
3
4
5
6
Neurology Certification Review 2019
2019-08-29 - 2019-09-03    
All Day
Neurology Certification Review is organized by The Osler Institute and will be held from Aug 29 - Sep 03, 2019 at Holiday Inn Chicago Oakbrook, [...]
Ophthalmology Lecture Review Course 2019
2019-08-31 - 2019-09-05    
All Day
Ophthalmology Lecture Review Course is organized by The Osler Institute and will be held from Aug 31 - Sep 05, 2019 at Holiday Inn Chicago [...]
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness
2019-09-01 - 2019-09-08    
All Day
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness is organized by Continuing Education, Inc and will be held from Sep [...]
Medical Philippines 2019
2019-09-03 - 2019-09-05    
All Day
The 4th Edition of Medical Philippines Expo 2019 is organized by Fireworks Trade Exhibitions & Conferences Philippines, Inc. and will be held from Sep 03 [...]
Grand Opening Celebration for Encompass Health Katy
2019-09-04    
4:00 pm - 7:00 pm
Grand Opening Celebration for Encompass Health Katy 23331 Grand Reserve Drive | Katy, Texas Sep 4, 2019 4:00 p.m. CDT Encompass Health will host a grand opening [...]
Galapagos & Amazon 2019 Medical Conference
2019-09-05 - 2019-09-17    
All Day
Galapagos & Amazon 2019 Medical Conference is organized by Unconventional Conventions and will be held from Sep 05 - 17, 2019 at Santa Cruz II, [...]
Mesotherapy Training (Sep 06, 2019)
2019-09-06    
All Day
Mesotherapy Training is organized by Empire Medical Training (EMT), Inc and will be held on Sep 06, 2019 at The Westin New York at Times [...]
Aesthetic Next 2019 Conference
2019-09-06 - 2019-09-08    
All Day
Aesthetic Next 2019 Conference Venue: SEPTEMBER 6-8, 2019 RENAISSANCE DALLAS HOTEL, DALLAS, TX www.AestheticNext.com On behalf Aesthetic Record EMR, we would like to invite you [...]
Anti-Aging - Modules 1 & 2 (Sep, 2019)
2019-09-07    
All Day
Anti-Aging - Modules 1 & 2 is organized by Empire Medical Training (EMT), Inc and will be held on Sep 07, 2019 at The Westin [...]
Allergy Test and Treatment (Sep, 2019)
2019-09-15    
All Day
Allergy Test and Treatment is organized by Empire Medical Training (EMT), Inc and will be held on Sep 15, 2019 at Aloft Chicago O'Hare, Chicago, [...]
Biosimilars & Biologics Summit 2019
2019-09-16 - 2019-09-17    
All Day
TBD
Biosimilars & Biologics Summit 2019 is organized by Lexis Conferences Ltd and will be held from Sep 16 - 17, 2019 at London, England, United [...]
X Anniversary International Exhibition of equipment and technologies for the pharmaceutical industry PHARMATechExpo
2019-09-17 - 2019-09-19    
All Day
X Anniversary International Exhibition of equipment and technologies for the pharmaceutical industry PHARMATechExpo is organized by Laboratory Marketing Technology (LMT) Company, Shupyk National Medical Academy [...]
2019 Physician and CIO Forum
2019-09-18 - 2019-09-19    
All Day
Event Location MEDITECH Conference Center 1 Constitution Way Foxborough, MA Date : September 18th - 19th Conference: Wednesday, September 18  8:00 AM - 5:00 PM [...]
Stress, Depression, Anxiety and Resilience Summit 2019
2019-09-20 - 2019-09-21    
All Day
Stress, Depression, Anxiety and Resilience Summit is organized by Lexis Conferences Ltd and will be held from Sep 20 - 21, 2019 at Vancouver Convention [...]
Sclerotherapy for Physicians & Nurses Course - Orlando (Sep 20, 2019)
2019-09-20    
All Day
Sclerotherapy for Physicians & Nurses Course is organized by Empire Medical Training (EMT), Inc and will be held on Sep 20, 2019 at Sheraton Orlando [...]
Complete, Hands-on Dermal Filler (Sep 22, 2019)
2019-09-22    
All Day
Complete, Hands-on Dermal Filler is organized by Empire Medical Training (EMT), Inc and will be held on Sep 22, 2019 at Sheraton Orlando Lake Buena [...]
The MedTech Conference 2019
2019-09-23 - 2019-09-25    
All Day
The MedTech Conference 2019 is organized by Advanced Medical Technology Association (AdvaMed) and will be held from Sep 23 - 25, 2019 at Boston Convention [...]
23 Sep
2019-09-23 - 2019-09-24    
All Day
ABOUT 2ND WORLD CONGRESS ON RHEUMATOLOGY & ORTHOPEDICS Scientific Federation will be hosting 2nd World Congress on Rheumatology and Orthopedics this year. This exciting event [...]
25 Sep
2019-09-25 - 2019-09-26    
All Day
ABOUT 18TH WORLD CONGRESS ON NUTRITION AND FOOD CHEMISTRY Nutrition Conferences Committee extends its welcome to 18th World Congress on Nutrition and Food Chemistry (Nutri-Food [...]
ACP & Stem Cell Therapies for Pain Management (Sep 27, 2019)
2019-09-27    
All Day
ACP & Stem Cell Therapies for Pain Management is organized by Empire Medical Training (EMT), Inc and will be held on Sep 27, 2019 at [...]
01 Oct
2019-10-01 - 2019-10-02    
All Day
The UK’s leading health technology and smart health event, bringing together a specialist audience of over 4,000 health and care professionals covering IT and clinical [...]
Events on 2019-08-29
Events on 2019-08-31
Events on 2019-09-03
Medical Philippines 2019
3 Sep 19
Pasay City
Events on 2019-09-04
Events on 2019-09-05
Galapagos & Amazon 2019 Medical Conference
5 Sep 19
Galapagos Islands
Events on 2019-09-06
Events on 2019-09-07
Events on 2019-09-15
Events on 2019-09-16
Events on 2019-09-18
2019 Physician and CIO Forum
18 Sep 19
Foxborough
Events on 2019-09-22
Events on 2019-09-23
The MedTech Conference 2019
23 Sep 19
Boston
23 Sep
Events on 2019-09-25
Events on 2019-09-27
Events on 2019-10-01
01 Oct
Articles

Preserving EHR security and collaborating on BYOD policy

practice fusion guarantees

Similar to many healthcare organizations these days, Shafiq Rab, CIO and Vice President of Hackensack University Medical Center in Hackensack, NJ, uses an all-in approach when it comes to data security. While Rab understands security is a learning process and best practices are developed over time, having best-of-breed products in place on top of regular privacy and security examinations is a must for a 771-bed hospital.

Rab knows that patient’s data is in Hackensack’s hands during care and in turn, they put their privacy in its control. A big part of ensuring patient data is safe and secure is locking down their EHRs with high-level privacy and security controls while being vigilant of internal and external threats by performing security audits. Hackensack University Medical Center has been through Stage 1 Meaningful Use security analyses and now it’s getting ready for Stage 2 Meaningful Use, which has put it in a good position from a security standpoint.

We know that one day we’ll be audited and because of that we look to see if there are any deficiencies. From a few different risk assessments to multiple penetration tests to data loss prevention (DLP), we have put all those things in place. And through those tests, we have a risk mitigation process where a committee meets every month and helps [uphold high security standards].

Rab said Hackensacks uses, for example, McAfee Deep Defender, which runs on Intel, so it can secure the data at the root level. When a user tries to connect a device, the product checks the other root key first and only if it’s can information be saved on [a device]. The organization has EpicCare Links for role-based accesses. For example, if a nurse who works 7-4 p.m. and accesses data she doesn’t need to after 5 p.m., Rab and Hackensack will know about it. Because Hackensack does audits internally and externally, role-based access is important. This level of scrutiny also applies to administrators, as it continually determines who has all access and why they have that kind of access.

In addition to in-house audit tools, we generally don’t ask the consultants who have helped us in the past to do the audit. We instead ask people who we haven’t worked with yet. (The next audit will be in December). They tell us what we need to do better and then we make those changes.

Furthermore, Rab said the organization uses a real-time data locator that ensures all the data ports are locked from, for example, virus-ridden USB sticks. And on a daily basis, Hackensack looks at who’s trying to attack and penetrate in from the outside and ensure there are no distributed denial-of-service attacks (DDoS attacks).

We also have a malware mitigation plan that can help avoid problems from people bringing viruses from home. Part of this is blocking USB drive ports, which upset some people but in the end the IT department supplied internal USB sticks [to be used in the hospital]. That was a little tough for us and we’re still not over it because there are some physicians or nurses who go elsewhere to give presentations.

Hackensack BYOD policy: A collaborative effort

Rab has also learned through years of healthcare industry experience that “Thou shalt not…” policies don’t work when applied to clinical staff. This is especially true for mobile security and BYOD policy. Rab and Hackensack instead choose to embrace the security challenge and adopt it as part of the organization’s culture.

Hackensack allows users to access its network through a BYOD program, but through trial and error the organization has collaborated with clinical staff and developed a policy that fits everyone’s needs. In addition to handing out corporate-owned devices, Rab and Hackensack allowed physicians and nurses to bring in their iPhone or Android device into the hospital to implement device management (MDM) solution from Mobile Iron and Airwatch that’s integrated into its BYOD policy. “The [BYOD] line was about 50-60 people deep throughout the three-day period and my CEO asked me if I was handing out candy,” he said.

For the BYOD phones, Hackensack put the MDM solution with a bubble around it on the device so when they would open the clinical applications, they don’t touch the rest of the data. If a staff member ever lost the device, Rab can control of the application and wipe the app from the phone without losing the rest of the data.

We also asked if we could put controls on the device (such as a laptop or phone) so that we can monitor it to ensure there’s no malicious activity. Instead of us shoving the policy down physicians’ throats, they willingly gave us the opportunity to control the hardware. There was one instance in which someone lost a phone and we quickly initiated “Defense Protocol No. 23″ and in two seconds, we knew where the phone was and the physician was able to get to his phone exactly where he left it.

Putting healthcare applications and data into a bubble on BYOD devices is becoming the norm now, but you have to have good WiFi, a good MDM solution and security policy. But at the same time, you have to have willing people to work with you and trust you.

Rab is a member of the College of Healthcare Information Management Executives (CHIME).

Source