Saturday, 22 August 2015

John Halamka: 3 areas healthcare should address in 2016

It’s already almost time to plan for a new year, and as 2015 heads toward its final stretch, stakeholders in the healthcare industry already are looking at what areas to focus on in 2016.

In a recent post to his Life as a Healthcare CIO blog, Beth Israel Deaconess Medical Center CIO John Halamka outlines some of the things learned this year that could shape planning at his and other facilities in 2016.

Three areas to address in next year include:

  • Lessening the workload: Currently, Meaningful Use, reaching quality measures, population health, patient engagement and more are overwhelming healthcare professionals, Halamka writes. In 2016, there should be a focus on making workflows and workloads easier through projects and innovation.
  • Increasing use of the cloud: “The cloud is clearly the way that people want to work,” Halamka writes. There are a lot of forces driving its use, such as easier file sharing, convenience and device support. As the cloud’s use increases, the health industry must learn as much as it can about the tool, and services like Amazon Web Services.
  • Paying attention to the user: Large-scale projects like ICD-10 and the Affordable Care Act can be hard on users, “forcing them to accept decreased short-term service for long-term gains,” he writes. Initiatives like Meaningful Use Stage 3 need to be delayed and providers need to be given more time to catch up with all the project thrown their way.

Many in the industry have called for a delay of MU Stage 3, including the American Medical Association, the Medical Group Management Association and a slew of chief information officers.

View the original content and more from this author here: http://ift.tt/1PFZrnI



from health IT caucus http://ift.tt/1E9r47b
via IFTTT

OIG to VA: Online collaboration tool an insecure time-waster

The Department of Veterans Affairs Office of Inspector General has chastised the VA for the improper use of the use of the Yammer social network, according to a recent report.

Yammer, a collaboration tool meant to help increase productivity, was not approved for employee use and had vulnerable security features, according to the report. It also led to individuals wasting time and resources, OIG said.

The report chides Stephen Warren, former executive in charge of information technology and CIO, for using Yammer in a 2014 open chat forum, giving the false impression that the VA approved its use.

Warren, who will leave the VA at the end of this month, according toFierceGovernmentIT, in a July call with reporters, called security a “cultural” responsibility, one that requires that every employee in the organization understands that security is part of his or her job.

There were about 50,000 VA email addresses registered on Yammer as of Aug. 3, with half of those being active users, according to the report. Yammer also allows users to create private groups, which managers could not screen. OIG investigators were able to access only the public groups.

Yammer users violated VA policy when they shared files, videos and images from the site, risking introducing malware or viruses that could quickly spread.

“We found numerous user posts that were non-VA related, unprofessional, or had disparaging content that reflected a broad misuse of time and resources,” the report said.

In addition, the non-VA video and other large files the employees were using had the potential to congest the VA network and cause degradation of service. The Yammer website also had no administrator or system to ensure the removal access for former VA or contractor employees and to remove any inappropriate content, which could include protected health information or other sensitive data.

Disabling accounts when an employee leaves an organization is one of the key pieces of data governance policy cited as essential in the Institute for Critical Infrastructure Technology’s review of the U.S. Office of Personnel Management hack. Meanwhile, the VA recently failed its cybersecurity audit for the 16th consecutive year.

View the original content and more from this author here: http://ift.tt/1MEptrl



from health IT caucus http://ift.tt/1PFYaNl
via IFTTT

Chronic disease, elderly patients to fuel growth of home health technologies market

Increased use of remote medical consultations to improve healthcare for chronic disease and elderly patients, particularly as cost models shift in the industry, will fuel steady growth of the global home health technologies market, according to a new report.

Efforts in the U.S., in particular, will boost the market, which will grow from $3.4 billion in 2014 to $13.7 billion by 2020, according to Tractica’s latest report, “Home Health Technologies.” The number of consumers taking advantage of such tools will increase more than five-fold, from 14.3 million in 2014 to 78.5 million by 2020.

“Many of the application segments within the broader home health technologies market are complementary, and are being combined to enable strong return on investment, in addition to allowing the patient to be a more active participant in their healthcare,” says Tractica Principal Analyst Charul Vyas in a statement; he adds that providers are seeing “strong results” from the use of such tools

The report’s authors note that because the landscape for such tools is still developing, adoption and use challenges remain. Interoperability issues also must be a priority as use of the technology becomes more ubiquitous, they say.

Industry growth this year has been particularly noticeable, thanks in part to the success of companies like Teladoc, for which an initial public offering in late June raised $157 million. While the company reported a loss of about $17.1 million just prior to the IPO, CEO Jason Gorevic seemed buoyed by the strong performance of his company during its first quarter as a public company; revenue during Q2 grew 78 percent to 18.3 million.

Employers in the U.S. are taking notice of the growth; a survey published earlier this month by the National Business Group on Health found that roughly 74 percent of employers nationwide plan to offer telehealth to its employees in 2016. The survey also noted, however, that of the companies that currently offer telehealth services, only 12 percent of employees are taking advantage of such programs.

View the original content and more from this author here: http://ift.tt/1MEptrk



from health IT caucus http://ift.tt/1PFYaNe
via IFTTT

AHRQ director: We continue ‘to make substantial investments in research’ on health IT

While the future of the Agency for Healthcare Research and Quality remains unclear after draft congressional spending bills for 2016 proposed eliminating funding for the agency, director Richard Kronick, Ph.D, touted the work the organization does in healthcare and health IT.

In an interview with the Journal of the American Medical Association, Kronick spoke about the agency’s role and how it differs from the work of other federal entities.

Kronick also addressed AHRQ’s position on health IT, saying the organization continues “to make substantial investments in research to figure out how health information technology can be used to improve quality and safety, how it can be used to improve outcomes for patients and to improve the delivery of health care.”Interview

View the original content and more from this author here: http://ift.tt/1PFYawV



from health IT caucus http://ift.tt/1MEpr2H
via IFTTT

How the role of CISO in healthcare will mature

The role of chief information security officer will continue to mature, and has already seen great change as people in the position move to a more risk-based approach to tackling security challenges.

Previously, CISOs were more focused on compliance with regulations and policies like HIPAA, but now they’re viewing privacy and security through a larger lens, Raj Mehta, a partner in Deloitte Cyber Risk Services, tells HealthITSecurity.com.

“[T]hey’re starting to see more of a risk type of consideration,” Mehta says. “What do we do about cybersecurity? What are other issues we need to worry about?”

As security threats against healthcare organizations proliferate, the role of chief information security officers is gaining more visibility, FierceHealthIT previously reported.

Mehta says CISOs in healthcare and beyond now are looking at security from a business risk management perspective. They might soon take more active steps in areas like biometric security.

However, there also will be challenges for CISOs to face, Mehta says, such as being able to communicate effectively with executives, and dealing with the safety of information in an industry where sharing data is growing in scope and in complexity.

CISOs have their work cut out for them when it comes to being seen as more than a scapegoat when breaches occur. Seventy-five percent of respondents to a recent survey didn’t think CISOs deserved to be part of an organization’s leadership team, according to the report by security vendor ThreatTrack.

View the original content and more from this author here: http://ift.tt/1MEpr2C



from health IT caucus http://ift.tt/1PFYawP
via IFTTT

Friday, 21 August 2015

Health breach lawsuit dismissals could prove relevant to similar cases

An appellate court’s decision to uphold a pair of class-action lawsuit dismissals related to a 2013 hospital data breach could prove relevant to similar current lawsuits, according to a HealthcareInfoSecurity article.

The lawsuits, brought by individuals impacted by a 2013 incident in which four unencrypted laptop computers were stolen from Park Ridge, Illinois-based Advocate Medical Group, alleged that parent company Advocate Health and Hospitals Corp. was in violation of the Fair Credit Reporting Act. The theft compromised personal information for more than four million patients–including names, addresses, Social Security numbers and birthdates–but not medical records or personal financial information.

The lawsuits initially were dismissed this past May and July, respectively, according to HealthcareInfoSecurity. Then, earlier this month, an appellate court upheld the rulings, although a hearing to reconsider the May ruling is scheduled for early September. The judge called the allegation that plaintiffs were harmed because of the breach “speculative.”

Attorney Brad Rostolsky of Philadelphia-based firm Reed Smith toldHealthcareInfoSecurity the ruling could mean that courts don’t want to apply the Fair Credit Reporting Act to such cases. The case was dismissed, he said, primarily “because Advocate was determined not to meet the definition of ‘consumer reporting agency.'”

Class-action lawsuits have been filed in several recent data breach cases. For instance, UCLA Health faces a pair of lawsuits following a breach announced last month in which personal and medical information for as many as 4.5 million patients may have been compromised. One of the lawsuits accuses the health system of fraud, invasion of privacy, breach of contract, negligence and a violation of California laws such as the Confidentiality of Medical Information Act.

And five class-action lawsuits have been filed against Mountlake Terrace, Washington-based health insurer Premera following the announcement of acyberattack that compromised information for roughly 11 million customers.

In April, a judge dismissed a class-action lawsuit against Horizon Blue Cross Blue Shield of New Jersey stemming from a 2013 data breach in which laptops of Horizon members were stolen. Meanwhile last fall, two class-action lawsuits against a pair of hospitals that suffered breaches were dismissed in California

View the original content and more from this author here: http://ift.tt/1h01kPV



from health IT caucus http://ift.tt/1K9UCmd
via IFTTT

Keeping Mobile Security A Priority in Connected Networks

As more healthcare organizations implement and use connected devices, it is essential that they have comprehensive mobile security measures in place. No covered entity wants to experience a data breach, especially one that could have been prevented through proper mobile security policies.

From a mobility perspective, there are a number of different challenges, according to Institute for Critical Infrastructure Technology (ICIT) fellow Michael McNeil. Everything is extremely connected, he said in an interview with HealthITSecurity.com, and there are many traditional areas of focus that have been affected by that change.

“What used to be a stationary or contained type of a device or tool that would be used, now has mobility attached to it,” said McNeil, who is also the global product security and services officer for Phillips Healthcare. “Because of the mobility and its interconnections, the integrity of that data and the accuracy of the information could be at risk.”

McNeil added that another tremendous focus point for healthcare organizations is ensuring that they are in alignment with the appropriate legal and regulatory efforts.

“When you look at the fact that there’s clinical data, the transmission of that data, the flexibility of that data, and certain individuals could intercept or manipulate that information, that creates some of our biggest risk and or complexities that hit the dynamics of the ecosystem,” he said.

Looking at the entire healthcare infrastructure

One common mistake that McNeil sees is that healthcare organizations do not always look beyond their own contained network. However, with increased interconnectivity through options such as health information exchanges (HIE), that oversight could have consequences.

“Because organizations typically look at infrastructure of a hospital or a particular setting, traditionally they have stated, ‘Because that is contained in somebody else’s network and environment, our liability and vulnerability and chances of any activities is very low,’” McNeil said. “And because it’s in someone else’s contained network, they sort of push the potential direction of the potential risk off into other parts of the ecosystem.”

McNeil explained that the “ecosystem” includes everyone from medical device manufacturers to healthcare providers, and even regulators.

“The better that we can align with other types of industries, and other types of standards,  making sure that we are deploying solutions within this space, then we also have the ability to make sure that from a mobile perspective it’s designed with the security of their products and solutions,” he said. “That needs to be key.”

The mistake comes when mobile devices, and even connected systems themselves, are not designed with the larger picture in mind, he said. Facilities will think that a certain type of vulnerability is low, so the control is the actual network or system.

“That is more of a fallacy of the past that needs to be corrected in terms of the future,” McNeil stated.”

Moreover, organizations need to conduct appropriate risk assessments and look at the different types of interconnectivity because that raises a number of concerns as well, he added. They need to align with the appropriate regulatory standards that are coming out specifically for the definitions from a mobile perspective.

Prioritizing employee training and awareness

According to McNeil, having internal awareness campaigns and programs that are specific around the care and feeding of a mobile device and how individuals would interact with them is essential. For example, employees need to understand how information is actually captured in the device and how that interconnectivity works within the networks of hospitals or other organizations.

“I think also there’s the physical attributes of how to report and maintain if something happens because of the device itself and it’s ease of accessibility,” he said. “Some of those types of threats or breach capabilities, by demonstrating it in some of the education or awareness pieces, I think that is a powerful and very much real to life types of examples that can be exhibited.”

Having an external stakeholder component in the education and awareness aspect is also important, McNeil said. Training needs to be thought of from an internal and external perspective. Employees need to understand their organization’s brand and reputation, but patients, regulators and others that have an impact on a certain solution or offering need to understand how they tie into that security.

Learning from large health data breaches

When large health data breaches, such as what happened with Anthem or Premera take place, it is essential for organizations to review their metrics and effectiveness of their overall privacy or product security program, according to McNeil.

“Are you doing annual tabletop or incident management case scenarios? I think every organization should be creating that type of ‘What happens if?’ threat environment and exercising it so they understand what they need to do in the event that something could happen or in the event that there’s a breach.”

McNeil added that organizations should clearly have key metrics in their security and overall program to understand where there might have been risk or activity that took place in other companies. Entities need to ask how something could affect them, and if they are tracking metrics to understand any potential risk that they need to overcome.

“Knowing the flow of that information and where it’s contained, and having appropriate processes and policies around guarding and detecting it more frequently are critical areas of focus.”

View the original content and more from this author here: http://ift.tt/1U3l01S



from health IT caucus http://ift.tt/1TXsEQV
via IFTTT