Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
29
1
3
4
5
7
8
10
11
12
15
16
17
18
19
21
24
25
26
27
30
31
1
2
A Behavioral Health Collision At The EHR Intersection
2014-09-30    
2:00 pm - 3:30 pm
Date/Time Date(s) - 09/30/2014 2:00 pm Hear Why Many Organizations Are Changing EHRs In Order To Remain Competitive In The New Value-Based Health Care Environment [...]
Meaningful Use and The Rise of the Portals
2014-10-02    
12:00 pm - 12:45 pm
Meaningful Use and The Rise of the Portals: Best Practices in Patient Engagement Thu, Oct 2, 2014 10:30 PM - 11:15 PM IST Join Meaningful [...]
Adva Med 2014 The MedTech Conference
2014-10-06    
All Day
Adva Med 2014 The MedTech Conference October 6-8, 2014 McCormick Place Chicago, IL For more information, visit, advamed2014.com For Registration details, click here  
Public Health Measures Meaningful Use
2014-10-09    
12:00 pm - 12:45 pm
Public Health Measures Meaningful Use: Reporting on Public Health Measures Join Meaningful Use expert Jim Tate for a three part series of webinars addressing MU [...]
2014 Hospital & Healthcare I.T. Conference
2014-10-13    
All Day
Join us at our 2014 Hospital & Healthcare I.T. Conference and experience the following: Up to 125 Hospital & Healthcare I.T. executives from America’s most prestigious [...]
Connected Health Care 2014
Key Trends That will be Discussed at the Conference! Connected Healthcare 2014 is set to explore the crucial topics that are revolutionizing the connected health industry: [...]
HealthTech Conference
2014-10-14    
All Day
HealthTech Capital is a group of private investors dedicated to funding and mentoring new "HealthTech" start ups at the intersection of healthcare with the computer [...]
Health Informatics & Technology Conference (HITC-2014)
2014-10-20    
All Day
Information technology has ability to improve the quality, productivity and safety of health care mangement. However, relatively very few health care providers have adopted IT. [...]
HIMSS Amsterdam 2014
2014-10-20    
12:00 am
About HIMSS Amsterdam 2014 This year, the second annual HIMSS Amsterdam event will be taking place on 6-7 November 2014 at the Hotel Okura. The [...]
Patient Portal Functionality and EMR Integration Demonstration
2014-10-22    
2:00 pm - 3:30 pm
This purpose of this webcast is to present a demonstration to show how the Patient Portal integrates with EMR, as well as discuss how this [...]
Connected Health Symposium 2014
Symposium 2014 - Connected Health in Practice: Engaging Patients and Providers Outside of Traditional Care Settings Collaborating with industry visionaries, clinical experts, patient advocates and [...]
CHIME College of Healthcare Information Management Executives
2014-10-28 - 2014-10-31    
All Day
The Premier Event for Healthcare CIOs Hotel Accomodations JW Marriott San Antonio Hill Country 23808 Resort Parkway San Antonio, Texas 78761 Telephone: 210-276-2500 Guest Fax: [...]
The Myth of the Paperless EMR
2014-10-29    
2:00 pm - 3:00 pm
Is Paper Eluding Your Current Technologies; The Myth of the Paperless EMR Please join Intellect Resources as we present Is Paper Eluding Your Current Technologies; The Myth [...]
Events on 2014-09-30
Events on 2014-10-02
Events on 2014-10-06
Events on 2014-10-09
Events on 2014-10-13
Events on 2014-10-14
Connected Health Care 2014
14 Oct 14
San Diego
HealthTech Conference
14 Oct 14
San Mateo
Events on 2014-10-20
HIMSS Amsterdam 2014
20 Oct 14
Amsterdam
Events on 2014-10-23
Events on 2014-10-28
Events on 2014-10-29
Articles

Using the cloud data life cycle to protect patient privacy

cloud data life cycle

Using the cloud data life cycle to protect patient privacy

In an ideal world, technology would maximize individual benefits while also protecting privacy.

But in practice, the pivot to digital-first healthcare has sometimes left personal information vulnerable to attack – as evidenced by the recent spike in targeting of health systems.

One example of this paradigm, says Dr. James Angle, product manager for IT services in information security, at Trinity Health, involves the migration of increased amounts of data to the cloud.

“Before the use of cloud, PHI was stored either in the [health delivery organization’s] data center or a third-party data center,” noted Angle, who will be presenting on the subject at HIMSS21 in August.

“With cloud, data is stored in multiple data centers in multiple jurisdictions,” Angle continued. “The increase [in] data storage locations gives attackers more targets.”

“In addition, having multiple jurisdictions means more, as well as different, requirements. This adds complexity, which is the enemy of privacy and security,” he added.

During his HIMSS21 presentation, Angle will discuss the process of analyzing how an organization collects, uses, shares and maintains personal identifying information, as well as how to best protect that information.

“Ensuring privacy for our patients is a process that starts with privacy engineering and includes conducting privacy risk assessments and understanding the data life cycle,” he said. “If these processes are followed, we will enhance our ability to protect our patients’ information.”

Angle will also explain how HIPAA’s privacy rule functions in the context of security and information sharing.

“The purpose of the privacy rule is to give patients more control over their health information. The HIPAA Privacy Rule creates national standards to protect individuals’ medical records and other protected health information,” he said.

“Additionally, the privacy rule defines and limits the circumstances in which an individual’s PHI can be used or disclosed by a covered entity or its business associates,” he continued.

Returning to the matter of the cloud, Angle notes that the data life cycle gives the analyst a structured way to look at privacy.

“There are six phases in the cloud data life cycle: create, store, use, share, archive and destroy. Each phase has different requirements and issues that must be addressed,” he said.

The “create” phase, which involves the generation or acquisition of new data or the modification of existing data, can be a useful example of this.

“When personal data is collected, it is important to remember that the individual whose data is being collected has the right to know what data is being collected, what the data will be used for, and if it will be shared,” Angle said. “The collector must obtain consent, which means asking users for permission to process their data.

“Healthcare delivery organizations must explain their data collection practices in clear and simple language, and then users must explicitly agree to them. Additionally, it defines who can collect PHI/PII data and map the data to access rights for everyone who has access,” he added.

Even as the cloud has enabled innovation, Angle notes that it also adds complexity to an organization’s data protection plan.

“Data must not only be protected inside the HDO’s network but also in transit and in the cloud,” he said. “The HDO needs to know where the data will be stored, who has access to the data, and what controls are in place to protect the data.”

“Using the data life cycle, the analyst can look at the requirements for each phase and ensure the correct controls are in place to protect the patient’s privacy throughout the entire data life cycle,” he continued.

“By using the data life cycle, you are answering who, what, when, why, and how the data is treated in each phase. This will give you a clear picture of the data and, in turn, how to protect the data.