8 Security Essentials for Managing Business Operations

  

Date : 7 Sep 2015

Organisation : (ISC)2

Writer : Chuan-Wei Hoo

 

According to the 2015 (ISC)² Global Information Security Workforce Study, 62 percent of nearly 14,000 respondents believe that their organizations have too few information security professionals. Signs of strain within security operations due to the workforce shortage are materializing while companies and organizations are increasingly struggling to manage threats, avoid errors and are taking longer to recover from cyberattacks. The strategies of investing in security technologies, personnel and outsourcing will be insufficient to materially reduce the workforce shortage instantly. An expansion of security awareness and accountability throughout the organization is required. A more impactful approach is to embed real security accountability into other departments; and for the IT and security departments to function more collaboratively. Solving the problem will not just require the orchestration of information security leaders, but all cyber-enabled organizations to elevate the level of importance and ownership of security amongst all employees. Here are some key security essentials that everyone at a business operations should observe.

1. Asset Security — protect the company jewels
Every company has information that it considers to be crown jewels. Perhaps it’s scientific and technical data or documents regarding possible mergers and acquisitions, or clients’ non-public financial information. This is why we must address the policies and processes around the collection, handling and protection of information throughout its lifecycle. Each enterprise should carry out an inventory, with the critical data getting special treatment. Each priority item should be guarded, tracked and encrypted as if the company’s survival hinged on it. In some cases, it may. The concepts, principles, structures and standards used to monitor and secure assets is crucial to the enforcement of various levels of confidentiality, integrity and availability.

2. Security and Risk Management — build a risk-aware culture
The idea is elementary. Every person within an organization can infect it; whether it’s from clicking a dubious attachment or failing to install a security patch on a smart phone. So the effort to create a secure enterprise must include everyone. Building a risk-aware culture involves setting out the risks and goals, and then spreading the word throughout the entire company. But the important change is cultural. Think of the knee-jerk reaction — the horror — that many experience if they see a parent yammering on a cell phone while a child runs into the street. The information security leaders who try to nurture risk-aware cultures should have a broad spectrum understanding of general information security and risk management topics, beginning with the fundamental security principles of confidentiality, availability and integrity.

3. Software Development Security — embed security in design
Imagine if the auto companies manufactured their cars without seat belts or airbags, and then added them later, following scares or accidents. It would be both senseless and outrageously expensive. Similarly, one of the biggest vulnerabilities in information systems — and wastes of money — comes from implementing services first, and then adding security on as an afterthought. The only solution is to build in security from beginning, and to carry out regular automated tests to track compliance. This also saves money. If it costs an extra $60 to build a security feature into an application, it may cost up to 100 times as much — $6,000 — to add it later.

4. Communication and Network Security — establish secure communication channels
Consider urban crime. Policing would be far easier if every vehicle in a city carried a unique radio tag and traveled only along a handful of thoroughfares, each of them lined with sensors. The same is true of data. Companies that channel registered data through monitored access points will have a far easier time spotting and isolating malware. Cybercriminals are constantly probing for weaknesses. Each work station, laptop or smart phone provides a potential opening for malicious attacks. The settings on each device must not be left up to individuals or autonomous groups. They must all be subject to centralized management and enforcement. And the streams of data within an enterprise have to be classified, each one with its own risk profile and routed solely to its circle of users. Securing the workforce means vanquishing chaos and replacing it with confidence.

5. Identity and Access Management — track who’s who
Say a contractor gets hired full time. Six months pass and he/she gets a promotion. A year later, a competitor swoops in and hires him/her. How does the system treat that person over time? It must first give him/her limited access to data, then open more doors before finally cutting him/her off. This is managing the identity lifecycle. It’s vital. Companies that mismanage it are operating in the dark and could be vulnerable to intrusions. This risk can be addressed by implementing meticulous systems to identify the people, manage their permissions and revoke them as soon as they depart.

6. Security Assessment and Testing — patrol the neighborhood
Say a contractor needs access to the system. How do you make sure he/she has the right passwords? Leave them on a notepad? Send them on a text message? Such improvisation has risk. An enterprise’s culture of security must extend beyond company walls to establish best practices among its contractors and suppliers. This is a similar process to the drive for quality control a generation ago. And the logic is the same: Security, like excellence, should be infused in the entire ecosystem. The ruinous effects of carelessness in one company can convulse entire sectors of society.

7. Security Operations — manage incidents and respond
Say that two similar security incidents take place: One in Brazil, the other in Pittsburgh. They may be related. But without the security intelligence needed to link them, an important pattern — one that could indicate a potential incident — may go unnoticed. A company-wide effort to implement intelligent analytics and automated response capabilities is essential. Creating an automated and unified system will enable an enterprise to monitor its operations — and respond quickly.

8. Security Engineering — access and mitigate vulnerabilities
It happens all the time. People stick with old software programs because they know them, and they’re comfortable. But managing updates on a hodgepodge of software can be next to impossible. Additionally, software companies sometimes stop making patches for old programs. Cyber criminals know this all too well. In a secure system, administrators can keep track of every program that’s running, be confident that it’s current, and have a comprehensive system in place to install updates and patches as they’re released. Balance managing risk and enabling innovation. The administrator and/or security leaders should know the practice of building information systems and related architecture that continue to deliver the required functionality in the face of threats that may be caused by malicious acts, human error, hardware failure and natural disasters.

To download a copy of 2015 (ISC)2 Global Information Security Workforce Study, please go to www.isc2cares.org/IndustryResearch/GISWS/

[Cyber Security Information Portal]

Mitigating the Quantum Risk to Cybersecurity

One of the most fundamental pillars of cybersecurity is cryptography, and most of the cryptography tools used today rely on computational assumptions, such as the difficulty of factoring 2048 bit numbers.

Two decades ago, we learned that the quantum paradigm implies that essentially all of the deployed public key cryptography will be completely broken by a quantum computer, and brute force attacks of symmetric ciphers can also be sped up significantly. Fortunately, quantum computers did not exist at the time.

Today, the wait-and-see approach is no longer a responsible option. Protecting against quantum risk takes many years of planning and deployment. The realistic timelines for evolving to a quantum-safe infrastructure are comparable to the timelines for the quantum risk to become a reality. If one is responsible for providing medium- or long-term confidentiality, the risk of waiting is even more acute.

Research advances in the past decade have brought security experts close to having a blueprint of a robust scalable quantum computing system, which will be followed by a focused engineering effort to build large-scale quantum computers. While it is hard to predict how long these final stages will take, there is no reason for people to be confident that it will take much more than a decade or so.

At present, I estimate a 1 in 7 chance of breaking RSA 2048 by 2026 and a 1 in 2 chance of breaking it by 2031. Recently, the US National Security Agency (NSA) announced preliminary plans for transitioning to quantum-resistant algorithms.

In my recent Journal article, “Cybersecurity in the Quantum World,” I explain quantum technologies and how they threaten cybersecurity. The article also discusses timelines for managing this quantum risk and the kinds of approaches an organization can take.

Read Michele Mosca’s recent Journal article:
Cybersecurity in the Quantum World,” ISACA Journal, volume 5, 2015.

[ISACA Journal Blog]

Health IT’s Most Pressing Issues (Part 4)

Health IT’s most pressing issues may be so prevalent that they can’t be contained to a single post, as is obvious here, the fourth installment in the series detailing some of the biggest IT issues. There are differing opinions as to what the most important issues are, but there are many clear and overwhelming problems for the sector. Data, security, interoperability and compliance are some of the more obvious, according to the following experts, but those are not all, as you likely know and we’ll continue to see.

Here, we continue to offer the perspective of some of healthcare’s insiders who offer their opinions on health IT’s greatest problems and where we should be spending a good deal, if not most, of our focus. If you’d like to read other installments in the series, go here: Health IT’s Most Pressing Issues, Health IT’s Most Pressing Issues (Part 2) and Health IT’s Most Pressing Issues (Part 3). Also, feel free to let us know if you agree with the following, or add what you think are some of the sector’s biggest boondoggles.

Charles A. “Drew” Settles, product analyst, TechnologyAdvice

Charles A. “Drew” Settles

First and foremost, of all the issues facing healthcare technology, I believe the top issue is the interoperability (or lack thereof) of most electronic medical records systems. Interfacing systems from disparate vendors usually takes expensive custom development, but hopefully the push for free access to EMR/EHR APIs in Stage 3 of the Meaningful Use Incentive program will finally bring semantic interoperability to health IT.

Paul Cioni, senior vice president, Healthcare & Infor Solutions Sales, Velocity Technology Solutions
The top issue facing healthcare CIOs is that there is simply too much for them to do, including major initiatives involving information security, patient confidentiality, and revenue cycle management and reimbursement. Most are focusing on what’s urgent, rather than on what’s important. All of these issues are not only competing for a CIO’s budget, but also for his/her time. With so many things on the “as soon as possible” priority list, healthcare CIOs barely have time to strategically plan. It’s difficult for CIOs to create a five-year plan for the organization’s IT when they’re trying to figure out the next five months. A disaster recovery plan, for example, may not get created when CIOs are more concerned with downtime of clinical applications or the reporting of a data breach to the regulatory authorities.

Paul Cioni

The use of the cloud — with a comprehensive but flexible portfolio of service options- helps relieve CIOs from what I call the “tyranny of the urgent.” By allowing a cloud provider to manage a variety of back-office and ERP-related functions, the CIO can shift his focus to systems that affect clinical outcomes. Extending the secure, private cloud approach to clinical systems liberates key resources — budget and people — to focus on achieving meaningful use or embracing population health initiatives. Cloud deployment options like disaster recovery as a service or desktop as a service can conserve capital dollars and speed time to outcome. It’s not one issue – it’s all of them.

Lynn O’Connor Vos, CEO, Grey Healthcare Group (ghg):
The rapid acceleration of advancements in health information technology is leading to greater efficiency and productivity in the industry. At the same time, while technology has improved healthcare delivery in certain respects, significant challenges remain, particularly in areas related to the collection and transfer of health information and the user experience of healthcare providers and patients throughout this process. A perfect example of this is EHR/e-Prescribe systems, which are being adopted to solve a number of problems, including inaccurate prescriptions and portability of patient data, but which have also introduced other issues, in that healthcare providers (HCPs) are now burdened with time-consuming data entry that may be impacting their efficiency with chart updates.

With the goal of improving outcomes, patient adherence to medication is a critical factor in achieving the outcomes needed in chronic disease. At present, paper prescriptions leave too much to chance and it is well known that a significant number of prescriptions never get filled, and about six out of 10 patients report that they do not always take their medication as directed (according to the American Academy of Family Physicians). Health IT can play a vital role in supporting the healthcare process at every stage of a patient’s journey. However, true, efficient interoperability between healthcare systems is still a goal, rather than a reality, and immediate solutions are required to meet the needs of patients, caregivers, their healthcare providers and other stakeholders. A relevant example of this is the process of filling a prescription. As payers make efforts to control costs in the marketplace, an increasing number of prescriptions now require prior authorization (PA). Incredibly, even with the latest advancements in health IT, a patient generally doesn’t learn that their prescription has been rejected because of a PA requirement until they are standing at the pharmacy attempting to pick it up. The subsequent process to obtain a completed PA and successful submission is labyrinthine, and unfortunately, a number of drop off points exist, leading to a significant gap between PAs required and PAs successfully submitted. According to market research, upwards of 40 percent of patients who receive a PA forego treatment altogether, and only 30 percent of patients receiving a PA receive the originally prescribed medication. These data indicate that significant barriers to care exist as patients denied prescriptions at the pharmacy as a result of PA requirement are less likely to get that prescription filled at all.

Lynn O’Connor Vos

Given the barriers with PAs, services have emerged to facilitate the process and attempt to improve the outcome. The challenge is that the complexity of forms and information required and the submission process itself present obstacles that are often difficult for busy healthcare providers to overcome. Administrative and logistical barriers include failure to notify the HCP about the PA requirement, incorrect form submission, submission of incomplete or inaccurate information, and confusion in completing a non-standard form. Numerous handoffs along the way also increase the likelihood that the form may never be successfully completed or submitted. To date, Health IT has not provided a seamless solution to these challenges.

The administrative onus for PAs falls heavily on physicians and pharmacies, and can bring significant effort and frustration for them. It can take an average of 30 to 45 minutes to complete a prior authorization, while denial rates can be high, often because of minor errors and omissions, and appeal processes can be cumbersome. In an environment that increasingly aligns health outcomes to reimbursement rates, unsuccessful prior authorization submissions can result in fewer patients receiving the medicine they need, poor outcomes and lost revenue. Fortunately, the prior authorization process does not have to rely solely on technology and automation. PARx Solutions provides a concierge approach to the problem, engaging clinical staff to work one-on-one with physician offices and pharmacies to help streamline prior authorization processes and improve success rates. The company’s holistic solution, which combines automated software systems with clinical staff attention and follow through, ensures a higher success rate of submission than wholly automated solutions.

Health IT has come a long way in automating many important healthcare processes; however, instant data exchange and true interoperability are still future goals, and meeting the user experience needs of healthcare constituents is still a significant challenge. Healthcare stakeholders must focus on providing immediate solutions to bridge these gaps, and some of these may require a combination of technology and human attention. To become a true service industry, healthcare must provide patients with personalized care, not systematic care. For some, this may include tangible incentives to keep to care plans, such as reduced monthly contributions to individual’s health plans by agreeing to certain commitments. For others, it may be decision-making support. Regardless of the approach, the challenge for health IT is to better support physicians and patients in more personalized ways that allow them the flexibility to drive the health care needs of each patient effectively.

Eric Rice

Eric Rice, chief technology officer, Mach7 Technologies
Many of the current Health IT issues are around interoperability and the ability to provide a “complete” patient record. The majority of HIT systems don’t communicate with one another effectively, if at all. A single unified platform upon which to plug in best-of-breed or specialty/departmental solutions can enable communication across an enterprise, IDN or region, consolidating storage of the data.

Key issues:

— Achieving MU 2 and 3, image enabling the EMR
— Providing access and sharing of patient imaging data across the enterprise, IDN, region
— Ability for providers and clinicians to select their best-of-breed visualization solutions
— Consolidating storage / controlling storage cost
— No system in place to effectively and efficiently manage growth (i.e. organic, M&A…); need a scalable, highly-available platform

John Matthews, CIO, ExtraHop

John Matthews

Healthcare IT organizations are being bombarded from all sides. Not only are they tasked with managing complex, diverse and disparate IT environments of any industry, they must often do so on a budget and with limited human capital. Compounding these pressures is the fact that clinicians and business stakeholders rely heavily on IT systems to manage patient care and outcomes.

Take the ICD-10 migration, for example. Working with our customers, we’ve realized that one of the foundational challenges of this migration has simply been the ability to quickly and easily identify the components in their environment that interact with ICD codes. HDOs need this information in order to understand how these codes flow through the organization, and to develop a roadmap for migration. Incomplete migration when the new standards go into effect on October 1 of this year will have a major impact on the business side of healthcare, impacting billing and reimbursement. It will also impact patient care if patient conditions are improperly coded, making it more difficult to provide proper care and deliver good outcomes.

[Electronic Health Reporter]

Health IT’s Most Pressing Issues (Part 3)

Health IT’s most pressing issues may be so prevalent that they can’t be contained to a single post, as is obvious here, the third installment in the series detailing some of the biggest IT issues. There are differing opinions as to what the most important issues are, but there are many clear and overwhelming problems for the sector. Data, security, interoperability and compliance are some of the more obvious, according to the following experts, but those are not all, as you likely know and we’ll continue to see.

Here, we continue to offer the perspective of some of healthcare’s insiders who offer their opinions on health IT’s greatest problems and where we should be spending a good deal, if not most, of our focus. If you’d like to read the first installment in the series, go here: Health IT’s Most Pressing Issues and Health IT’s Most Pressing Issues (Part 2). Also, feel free to let us know if you agree with the following, or add what you think are some of the sector’s biggest boondoggles.

Reuven Harrison, CTO and co-founder, Tufin

Reuven Harrison

The healthcare industry has undoubtedly become a bigger target for security threats and data breaches in recent years and in my opinion that can be attributed in large part to the industry’s movement to virtualization and the cloud. By adopting these agile, effective and cost-effective modern technological trends, it also widens the network’s attack surface area, and in turn, raises the potential risk for security threats.

We actually conducted some research recently that addresses evolving security challenges, including those impacting the healthcare industry, with the introduction of cloud infrastructures. The issue is highlighted by the fact that the growing popularity of cloud adoption has been identified as one of the key reasons IT and security professionals (57 percent) find securing their networks more difficult today than two years ago.

Paul Brient

Paul Brient, CEO, PatientKeeper, Inc.
No industry on Earth has computerized its operations with a goal to reduce productivity and efficiency. That would be absurd. Yet we see countless articles and complaints by physicians about the fact that computerization of their workflows has made them less productive, less efficient and potentially less effective. An EHR is supposed to “automate and streamline the clinician’s workflow.” But does it really? Unfortunately, no. At least not yet. Impediments to using hospital EHRs demand attention because physicians are by far the most expensive and limited resource in the healthcare system. Hopefully, the next few years will bring about the innovation and new approaches necessary to make EHRs truly work for physicians. Otherwise, the $36 billion and the countless hours hospitals across the country have spent implementing electronic systems will have been squandered.

Mounil Patel, strategic technology consultant, Mimecast

Email security is one of healthcare’s top IT issues, thanks, in part, to budget constraints. Many healthcare organizations have already allocated the majority of IT dollars to improving systems that manage electronic patient records in order to meet HIPAA compliance. As such, data security may fall to the wayside, leaving sensitive customer information vulnerable to sophisticated cyber-attacks that combine social engineering and spear-phishing to penetrate organizations’ networks and steal critical data. Most of the major data breaches that have occurred over the past year have been initiated by this type of email-based threat. The only defense against this level of attack is a layered approach to security, which has evolved beyond traditional email security solutions that may have been adequate a few years ago, but are no longer a match for highly-targeted spear-phishing attacks.

Dr. Rae Hayward, HCISPP, director of education and training at (ISC)²

Dr. Rae Hayward

According to the 2015 (ISC)² Global Information Security Workforce Study, global healthcare industry professionals identified the following top security threats as the most concerning: malware (77 percent), application vulnerabilities (74 percent), configuration mistakes/oversights (70 percent), mobile devices (69 percent) and faulty network/system configuration (65 percent). Also, customer privacy violations, damage to the organization’s reputation and breach of laws and regulations were ranked equally as top priorities for healthcare IT security professionals.

So what do these professionals believe will help to resolve these issues? Healthcare respondents believe that network monitoring and intelligence (76 percent), along with improved intrusion detection and prevention technologies (73 percent) are security technologies that will provide significant improvements to the security posture of their organizations. Other research shows that having a business continuity management plan involved in remediation efforts will help to reduce the costs associated with a breach. Having a formal incident response plan in place prior to any incident decreases the average cost of the data breach. A strong security posture decreases not only incidents, but also the loss of data when a breach occurs.

Terry Edwards, CEO, PerfectServe

Terry Edwards

One of the major challenges the healthcare industry is navigating is how to enable more effective communication and collaboration across care teams, while also being HIPAA compliant. Physicians, nurses and all care team members need to be able to send and receive information on a patient’s condition in real-time, without compromising protected health information.

Providers often try to address secure communication with point solutions (secure texting), yet these tools are incomplete and the kind of collaboration that needs to occur doesn’t happen. In many cases, it’s just too hard for one clinician to connect with other care team members because the initiator needs to know the workflow of the person they need to reach.

For example, a physician who admits a patient into a hospitalist service may be listed in the EHR as the attending doctor. However, the patient is likely to be reassigned to a different hospitalist, say one of seven in the group, within a few hours. In the EHR, the name of the admitting doctor does not change. So, the question becomes, “Who is the hospitalist covering the patient right now?” An effective communication solution will address this variable as part of the communications process. Building on this, rotating schedules and multiple communication modalities creates uncertainty for how to reach a clinician at any given point. All of this contributes to delays in patient care.

As an industry, we’re making strides to facilitate more efficient and secure communication and collaboration, but the challenge needs to be addressed at the root – which is about process and workflow.

Dwain Wright, senior security consultant, ControlScan
From an IT security standpoint, poorly managed third-party relationships continue to create multiple points of vulnerability for healthcare organizations. These relationships include application management, installation of services and the management of security infrastructure (firewalls, malware systems, etc.).

There are three primary reasons today’s third-party relationships are unnecessarily risky:

Lack of due diligence in up-front discussions — When purchasing a piece of software or a service, many HIT professionals are walking away from the table without a clear understanding of what’s required to maintain the security posture of the product once it’s installed in their environment. Similarly, while the third-party may be providing a service, you still have to be knowledgeable on how that service will be performed such that it won’t impact the security posture or practices of your organization. It’s also essential to properly vet the service provider based upon their own security posture and credentials.

Lack of oversight during implementation — All software is “customizable” to some extent. At best, the third-party provider will establish initial settings that conform to their understanding of your IT organization. Unfortunately, we see many instances where settings have been incorrectly configured or left at their defaults. It is the HIT professional’s responsibility to ensure that all software, apps and services are implemented in accordance with data security and privacy best practices and standards.

Lack of formal, defined processes for maintenance and updates – As mentioned in #1 above, many HIT professionals are behind from the very beginning because they don’t ask important security-related questions early in the relationship. Consequently, we see many instances where patches and updates aren’t applied in a timely manner, or even at all. This is especially prevalent when internal and external roles and responsibilities aren’t pre-defined.

Recently I was on-site with an organization that manages a network of hospitals and clinics. We were discussing the settings of a specific application and determined that it was necessary to contact the third-party vendor for clarification. While we were talking with the vendor, they remotely accessed the application before our very eyes-without any granting of access on the client side! The client was completely unaware that the vendor had this capability.

Third-party relationships are not bad in and of themselves; in fact, they are essential to organizational growth. The key is to build those relationships on strong communication and knowledge sharing so that your organization and the information it works with remain secure.

Dr. Donald Donahue, Lieutenant Colonel, U.S. Army (Ret.)

Dr. Donald Donahue JR.

The single greatest issue facing health IT is interoperability. When health systems cannot share data — or worse, when functions within a healthcare facility cannot share information — the promise of improved outcomes and lower costs evaporates.

 [Electronic Health Report]

 

Health IT’s Most Pressing Issues (Part 2)

Health IT’s most pressing issues may be so prevalent that they can’t be contained to a single post, as is obvious here, the second installment in the series detailing some of the biggest IT issues. There are differing opinions as to what the most important issues are, but there are many clear and overwhelming problems for the sector. Data, security, interoperability and compliance are some of the more obvious, according to the following experts, but those are not all, as you likely know and we’ll continue to see.

Here, we continue to offer the perspective of some of healthcare’s insiders who offer their opinions on health IT’s greatest problems and where we should be spending a good deal, if not most, of our focus. If you’d like to read the first installment in the series, go here: Health IT’s Most Pressing Issues. Also, feel free to let us know if you agree with the following, or add what you think are some of the sector’s biggest boondoggles.

Michael Fimin

Michael Fimin, CEO and co-founder, Netwrix
The largest concern of any healthcare organization is protecting patient personal data. Every year healthcare entities of all sizes become victims of data leaks, fresh examples are both Anthem and Premera Blue Cross, and lose thousands of dollars mainly because of employee misbehave or human error. Being not an easy one to prevent, human factor sets IT pros a number of challenges to cope with:

1. Insider threat. Unfortunately, privilege abuse is a primary root cause for many data breaches. No matter if an employee is breaking bad or his credentials were stolen, sensitive data is put at risk. The only way to prevent insider threats is to have visibility into the IT infrastructure and be able to track any changes made to both security configurations and data. Monitor user activity and establish rigorous control over accounts with extended privileges. Regularly review all access rights to ensure that permissions are granted adequately to employees’ business needs.

2. Security of devices. In 2014 healthcare organizations suffered from physical theft or loss of electronic devices more than any other industry, said the Verizon 2014 DBIR. Without proper identity and authentication management personal data stored on these devices can be easily accessed by adversaries, leading to financial and reputational losses. If your employees’ laptop or tablets end up in the wrong hands, encryption, two-factor authentication and ability to manage the device remotely will protect your data, or at least will make hacker’s job much harder.

3. Employees’ negligence. Deliberate or accidental mistakes pose more danger to data integrity than you might think. A simple email with confidential data sent to the wrong address may lead to a huge data leak. Make sure that your employees are familiar with the company’s security policy and are aware of what they should do to maintain security each person in the company should clearly understand that integrity of information assets is their personal responsibility.

Barry Chaiken

Dr. Barry Chaiken, chief medical information officer,Infor
Healthcare providers organizations invested billions of dollars purchasing and implementing electronic medical records with this investment driven by the economic incentives provided by the HITECH Act. Now that these systems are installed an up and running, organizations struggle to obtain real value from these investments. These systems were implemented with speed in mind rather than clinical transformation that improved quality and reduced costs. Now, organizations must embrace clinical transformation and change management to redo workflows and processes to effectively impact care. Organizations cannot justify their investment in EMRs unless they rework their EMR implementations to obtain true value from their deployment.”

Matthew Fisher, co-chair, health law group, Mirick O’Connell

Matthew Fisher

One of the top health IT issues that I encounter is meeting compliance requirements with the HIPAA Security Rule. Security is a hot issue for health IT in light of the numerous breaches and other attacks that have occurred in order to gain access to protected health information. Health IT is at the forefront of these issues because the conversion to predominantly electronic data formats has created a number of vulnerabilities. Foremost among the vulnerabilities is the often outdated security systems or measures that may be in place. From a regulatory compliance perspective, particularly HIPAA, organizations must perform a comprehensive risk analysis of their operations. The results of the risk analysis, which should include identification, likelihood and threat level associated with each issue, form the backbone of an organization’s security policies. Under HIPAA, the Security Rule is designed to be somewhat flexible and scalable to each organization’s needs. As the brief description of the risk analysis shows, the results help an organization to determine how to meet the addressable elements of the Security Rule.

All of this places a lot of pressure on health IT to meet demands and protect organizations. As can be seen from breach fallouts, health IT can be at the top of the blame list. However, proactive attention to these issues can help alleviate the pain and put a organization ahead.

Dr. David Kibbe, president and CEO, DirectTrust

For me, the top issue for health IT is interoperability of information exchange: It should be very easy for health care professionals to move data and information across organizational boundaries and IT platforms, without extra effort, and in a manner that is electronic, secure, and identity-validated. Data exchange has to be vendor agnostic. That we don’t have this capability deployed everywhere in health care is less a problem of standards than a problem of business models and culture.

The reason this one issue is on the top of my list is because the lack of interoperable exchange of health information is a by-product of fee-for-service payment to doctors and hospitals; payment for volume not payment for quality. If you get paid by insurers even when tests and procedures need to be duplicated, because the data aren’t readily available to your “silo” of information from someone else’s “silo” of information, why bother to change? But health care payers are moving toward “value-based care” in which quality and efficiency are rewarded, providers are put at some level of risk for the costs of the care they deliver, and those who do poorly on such metrics as readmissions to hospital and patient satisfaction are penalized and paid less.

Value-based payment success requires that providers communicate with one another in a distinctly multi-vendor environment, one in which doctors and hospitals use EHRs from over 300 vendors. Yet many members of care coordination teams, such as those in long-term post-acute care and home health, don’t use EHRs at all.

Providers engaged in value-based payment simply can’t fumble the transitions of care made by their patients as they did under fee-for-service; if they do they’ll fail financially. The challenge they are facing is how to move data and information wherever and to whomever the patient goes to next, and regardless of which vendor’s EHR the next provider organization is using, so that care becomes much more coordinated and outcomes more predictable.

Direct exchange is an example of a standard that is open and available for use in over 40,000 health care organizations that use EHRs certified by ONC; that certification includes that the EHRs are Direct-enabled to both send and receive messages, and file attachments of any kind, and to and from any other certified EHR user. Direct messages are sent encrypted end-to-end, and the relying parties know precisely the identity of one another even before the message is transmitted. Attachments can be in any type of file format, including structured XML, Word, PDF, and in common file image file formats like .jpg and DICOM.

Why don’t we hear more about direct exchange in the media and press? Well, that’s because new technologies take time to become adopted, even when there are federal standards built into certifications. And, as the recent ONC report to Congress on Information Blocking pointed out, “… some [provider and EHR] business practices, though they may arguably advance legitimate individual economic interests, interfere with the exchange of electronic health information in ways that raise serious information blocking concerns.” Put even more simply, there still exist business and cultural incentives in health care to restrict information flows to protect private economic gain, even at the expense of the patients and the public at large.

As the incentives change because of value-based purchasing contracts becoming more widespread, we will see more and more health care providers and hospitals choosing to use interoperable health IT tools.

[Electronic Health Report]

English
Exit mobile version