SlideShare uma empresa Scribd logo
1 de 13
HIPAA Compliance Dangers for Digital Doctors Robert Rowley, MD Practice Fusion, Chief Medical Officer
HIPAA Landscape As doctors across the country switch from paper charts to electronic medical records – new questions and regulations around patient privacy are emerging.   EMR systems are changing the way health data is managed – creating risks and opportunities.
Portability HIPAA has a reputation for privacy – but the goal is really portability.  Portable health data has the power to improve the safety, efficiency and quality of healthcare.
Positive Perspective Let’s turn the HIPAA question around from the “don’t step on land mines” approach to a positive one – how can HIPAA create a framework of privacy and security in order to gain trust from patients and from the public?
Rights Under HIPAA The new HIPAA rules expand individual rights to: Access their information Restrict disclosures of PHI to health plans Extend applicability of Privacy and Security Rules to business associates Establish new limitations on use and disclosure of PHI for marketing and fundraising purposes Prohibit sale of PHI without patient authorization (Source: ONC for Health Information Technology)
What Does It Mean? This is all designed to promote patient trust in the security and privacy on PHI, necessary to build the HIT infrastructure envisioned for health delivery improvement.   What does it mean for healthcare providers?
Security at Rest Security: PHI must remain secure wherever it is encountered. At rest: Servers Local workstations Data backup media Other devices (i.e. faxes and copy machines) Most PHI breaches have been from theft of computers with unencrypted PHI on them
Security in Transit In transit: Web-based Local Avoid using non-secure communications for PHI exchange: Standard email Avoiding public portals
Privacy PHI exchange must be for a documented reason (like clinical care), and must be via permission. The principle of “limited data set”  Challenges for clinical data exchange  Data sharing Survey results show that patients want their data available and portable
Trust Around PHI What do “digital doctors” need to do to help build the trust relationship around PHI? Make sure that data security breach risks are minimized: Encrypt data on servers Destroy local copies of PHI after upload Make sure any data backup is encrypted Make sure that all “trashed” PHI is securely destroyed
Trust Around PHI Avoid using insecure methods of communication when it comes to PHI Avoid standard emails that disclose PHI Avoid social networking sites around PHI Use secure web tools for communicating with patients
Trust Around PHI Make sure that HIPAA Business Associate agreements are in place with everyone who handles your PHI downstream Hosting web-based EHRs  If there is an in-house EHR, have BA agreements in place Shredding companies If there is any doubt about sharing PHI with someone else, get the patient’s specific permission.
Conclusion Conclusion:  Risk vs. benefit Most important things to remember for 	protecting data What HIPAA can unlock for the future of 	healthcare Q&A

Mais conteúdo relacionado

Mais procurados

Confidentiality
ConfidentialityConfidentiality
Confidentiality
mshaner
 
Confidentiality 9.26.13
Confidentiality 9.26.13Confidentiality 9.26.13
Confidentiality 9.26.13
pneville0629
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentiality
ptamayo1958
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
shydoll414
 
Hipaa basics
Hipaa basicsHipaa basics
Hipaa basics
mlireton
 
Hipaa privacy rule
Hipaa privacy ruleHipaa privacy rule
Hipaa privacy rule
MsBelleA
 
Hipaa basics pp2
Hipaa basics pp2Hipaa basics pp2
Hipaa basics pp2
martykoepke
 

Mais procurados (20)

Confidentially in the workplace
Confidentially in the workplaceConfidentially in the workplace
Confidentially in the workplace
 
Joint Commission Inservice Hipaa
Joint Commission Inservice HipaaJoint Commission Inservice Hipaa
Joint Commission Inservice Hipaa
 
Are Orthopedics Justified in Embracing HIPAA Compliant Orthopedic Billing to ...
Are Orthopedics Justified in Embracing HIPAA Compliant Orthopedic Billing to ...Are Orthopedics Justified in Embracing HIPAA Compliant Orthopedic Billing to ...
Are Orthopedics Justified in Embracing HIPAA Compliant Orthopedic Billing to ...
 
Application Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA ComplianceApplication Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA Compliance
 
TaylorWk1d2assignment
TaylorWk1d2assignmentTaylorWk1d2assignment
TaylorWk1d2assignment
 
HIPAA
HIPAA HIPAA
HIPAA
 
Phi masella
Phi masellaPhi masella
Phi masella
 
PROTECTED HEALTH INFORMATION_PATIENT PRIVACY
PROTECTED HEALTH INFORMATION_PATIENT PRIVACYPROTECTED HEALTH INFORMATION_PATIENT PRIVACY
PROTECTED HEALTH INFORMATION_PATIENT PRIVACY
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
HIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An OverviewHIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An Overview
 
Enhancing Your Data Security: Closing the Gap on Unsecured Communications
Enhancing Your Data Security: Closing the Gap on Unsecured CommunicationsEnhancing Your Data Security: Closing the Gap on Unsecured Communications
Enhancing Your Data Security: Closing the Gap on Unsecured Communications
 
Confidentiality 9.26.13
Confidentiality 9.26.13Confidentiality 9.26.13
Confidentiality 9.26.13
 
Patient confidentiality
Patient confidentialityPatient confidentiality
Patient confidentiality
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Hipaa basics
Hipaa basicsHipaa basics
Hipaa basics
 
3 Steps to Automate Compliance for Healthcare Organizations
3 Steps to Automate Compliance for Healthcare Organizations3 Steps to Automate Compliance for Healthcare Organizations
3 Steps to Automate Compliance for Healthcare Organizations
 
Hipaa privacy rule
Hipaa privacy ruleHipaa privacy rule
Hipaa privacy rule
 
MHA690 W1D2
MHA690 W1D2MHA690 W1D2
MHA690 W1D2
 
Hipaa basics pp2
Hipaa basics pp2Hipaa basics pp2
Hipaa basics pp2
 

Semelhante a HIPAA Compliance Dangers for Digital Doctors

Training on confidentiality MHA690 Hayden
Training on confidentiality MHA690 HaydenTraining on confidentiality MHA690 Hayden
Training on confidentiality MHA690 Hayden
haydens
 
HIPPA---Chantel Artis Spencer
HIPPA---Chantel Artis SpencerHIPPA---Chantel Artis Spencer
HIPPA---Chantel Artis Spencer
shay1234
 
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudPerspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Cheryl Goldberg
 
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudPerspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Cheryl Goldberg
 
Priv&security&profin electrcommunicationsrev9 23
Priv&security&profin electrcommunicationsrev9 23Priv&security&profin electrcommunicationsrev9 23
Priv&security&profin electrcommunicationsrev9 23
Deven McGraw
 
Running head Information security threats 1Information secur.docx
Running head Information security threats 1Information secur.docxRunning head Information security threats 1Information secur.docx
Running head Information security threats 1Information secur.docx
wlynn1
 

Semelhante a HIPAA Compliance Dangers for Digital Doctors (20)

Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdfUnderstanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
 
HIPAA Compliance For Small Practices
HIPAA Compliance For Small PracticesHIPAA Compliance For Small Practices
HIPAA Compliance For Small Practices
 
Training on confidentiality MHA690 Hayden
Training on confidentiality MHA690 HaydenTraining on confidentiality MHA690 Hayden
Training on confidentiality MHA690 Hayden
 
HIPAA Compliant Video Conferencing Software
HIPAA Compliant Video Conferencing SoftwareHIPAA Compliant Video Conferencing Software
HIPAA Compliant Video Conferencing Software
 
Negative Economic Impacts On Healthcare From Inefficient Communication
Negative Economic Impacts On Healthcare From Inefficient CommunicationNegative Economic Impacts On Healthcare From Inefficient Communication
Negative Economic Impacts On Healthcare From Inefficient Communication
 
HIPPA---Chantel Artis Spencer
HIPPA---Chantel Artis SpencerHIPPA---Chantel Artis Spencer
HIPPA---Chantel Artis Spencer
 
Modernizing Patient Records
Modernizing Patient RecordsModernizing Patient Records
Modernizing Patient Records
 
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudPerspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
 
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudPerspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
 
Priv&security&profin electrcommunicationsrev9 23
Priv&security&profin electrcommunicationsrev9 23Priv&security&profin electrcommunicationsrev9 23
Priv&security&profin electrcommunicationsrev9 23
 
What Are The HIPAA Rules And How To Ensure HIPAA Compliance
What Are The HIPAA Rules And How To Ensure HIPAA ComplianceWhat Are The HIPAA Rules And How To Ensure HIPAA Compliance
What Are The HIPAA Rules And How To Ensure HIPAA Compliance
 
Constructing a HIPAA-compliant healthcare app from scratch
 Constructing a HIPAA-compliant healthcare app from scratch Constructing a HIPAA-compliant healthcare app from scratch
Constructing a HIPAA-compliant healthcare app from scratch
 
An Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdfAn Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdf
 
How Safe is Your Patient Data?
How Safe is Your Patient Data?How Safe is Your Patient Data?
How Safe is Your Patient Data?
 
Get Rid of Fax Machines - Increasing the Speed of Health Information Exchange
Get Rid of Fax Machines - Increasing the Speed of Health Information ExchangeGet Rid of Fax Machines - Increasing the Speed of Health Information Exchange
Get Rid of Fax Machines - Increasing the Speed of Health Information Exchange
 
Improving Healthcare Interoperability.
Improving Healthcare Interoperability. Improving Healthcare Interoperability.
Improving Healthcare Interoperability.
 
Running head Information security threats 1Information secur.docx
Running head Information security threats 1Information secur.docxRunning head Information security threats 1Information secur.docx
Running head Information security threats 1Information secur.docx
 
Marc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentationMarc etienne week1 discussion2 presentation
Marc etienne week1 discussion2 presentation
 
How to Build HIPAA Compliant Healthcare Apps: Everything You Should Know!
How to Build HIPAA Compliant Healthcare Apps: Everything You Should Know!How to Build HIPAA Compliant Healthcare Apps: Everything You Should Know!
How to Build HIPAA Compliant Healthcare Apps: Everything You Should Know!
 
Data systems web_integration_v0 1
Data systems web_integration_v0 1Data systems web_integration_v0 1
Data systems web_integration_v0 1
 

Último

Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
adilkhan87451
 
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
chetankumar9855
 

Último (20)

Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
 
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
 
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
 
Call Girls Rishikesh Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Rishikesh Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Rishikesh Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Rishikesh Just Call 8250077686 Top Class Call Girl Service Available
 
9630942363 Genuine Call Girls In Ahmedabad Gujarat Call Girls Service
9630942363 Genuine Call Girls In Ahmedabad Gujarat Call Girls Service9630942363 Genuine Call Girls In Ahmedabad Gujarat Call Girls Service
9630942363 Genuine Call Girls In Ahmedabad Gujarat Call Girls Service
 
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
 
Jogeshwari ! Call Girls Service Mumbai - 450+ Call Girl Cash Payment 90042684...
Jogeshwari ! Call Girls Service Mumbai - 450+ Call Girl Cash Payment 90042684...Jogeshwari ! Call Girls Service Mumbai - 450+ Call Girl Cash Payment 90042684...
Jogeshwari ! Call Girls Service Mumbai - 450+ Call Girl Cash Payment 90042684...
 
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
 
Call Girls Raipur Just Call 9630942363 Top Class Call Girl Service Available
Call Girls Raipur Just Call 9630942363 Top Class Call Girl Service AvailableCall Girls Raipur Just Call 9630942363 Top Class Call Girl Service Available
Call Girls Raipur Just Call 9630942363 Top Class Call Girl Service Available
 
Trichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service Available
Trichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service AvailableTrichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service Available
Trichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service Available
 
Call Girls Service Jaipur {9521753030} ❤️VVIP RIDDHI Call Girl in Jaipur Raja...
Call Girls Service Jaipur {9521753030} ❤️VVIP RIDDHI Call Girl in Jaipur Raja...Call Girls Service Jaipur {9521753030} ❤️VVIP RIDDHI Call Girl in Jaipur Raja...
Call Girls Service Jaipur {9521753030} ❤️VVIP RIDDHI Call Girl in Jaipur Raja...
 
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any TimeTop Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
 
Call Girls Vasai Virar Just Call 9630942363 Top Class Call Girl Service Avail...
Call Girls Vasai Virar Just Call 9630942363 Top Class Call Girl Service Avail...Call Girls Vasai Virar Just Call 9630942363 Top Class Call Girl Service Avail...
Call Girls Vasai Virar Just Call 9630942363 Top Class Call Girl Service Avail...
 
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
 
Call Girls Kolkata Kalikapur 💯Call Us 🔝 8005736733 🔝 💃 Top Class Call Girl Se...
Call Girls Kolkata Kalikapur 💯Call Us 🔝 8005736733 🔝 💃 Top Class Call Girl Se...Call Girls Kolkata Kalikapur 💯Call Us 🔝 8005736733 🔝 💃 Top Class Call Girl Se...
Call Girls Kolkata Kalikapur 💯Call Us 🔝 8005736733 🔝 💃 Top Class Call Girl Se...
 
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
 
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
 
Call Girls Jaipur Just Call 9521753030 Top Class Call Girl Service Available
Call Girls Jaipur Just Call 9521753030 Top Class Call Girl Service AvailableCall Girls Jaipur Just Call 9521753030 Top Class Call Girl Service Available
Call Girls Jaipur Just Call 9521753030 Top Class Call Girl Service Available
 
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
 
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
 

HIPAA Compliance Dangers for Digital Doctors

  • 1. HIPAA Compliance Dangers for Digital Doctors Robert Rowley, MD Practice Fusion, Chief Medical Officer
  • 2. HIPAA Landscape As doctors across the country switch from paper charts to electronic medical records – new questions and regulations around patient privacy are emerging. EMR systems are changing the way health data is managed – creating risks and opportunities.
  • 3. Portability HIPAA has a reputation for privacy – but the goal is really portability. Portable health data has the power to improve the safety, efficiency and quality of healthcare.
  • 4. Positive Perspective Let’s turn the HIPAA question around from the “don’t step on land mines” approach to a positive one – how can HIPAA create a framework of privacy and security in order to gain trust from patients and from the public?
  • 5. Rights Under HIPAA The new HIPAA rules expand individual rights to: Access their information Restrict disclosures of PHI to health plans Extend applicability of Privacy and Security Rules to business associates Establish new limitations on use and disclosure of PHI for marketing and fundraising purposes Prohibit sale of PHI without patient authorization (Source: ONC for Health Information Technology)
  • 6. What Does It Mean? This is all designed to promote patient trust in the security and privacy on PHI, necessary to build the HIT infrastructure envisioned for health delivery improvement. What does it mean for healthcare providers?
  • 7. Security at Rest Security: PHI must remain secure wherever it is encountered. At rest: Servers Local workstations Data backup media Other devices (i.e. faxes and copy machines) Most PHI breaches have been from theft of computers with unencrypted PHI on them
  • 8. Security in Transit In transit: Web-based Local Avoid using non-secure communications for PHI exchange: Standard email Avoiding public portals
  • 9. Privacy PHI exchange must be for a documented reason (like clinical care), and must be via permission. The principle of “limited data set” Challenges for clinical data exchange Data sharing Survey results show that patients want their data available and portable
  • 10. Trust Around PHI What do “digital doctors” need to do to help build the trust relationship around PHI? Make sure that data security breach risks are minimized: Encrypt data on servers Destroy local copies of PHI after upload Make sure any data backup is encrypted Make sure that all “trashed” PHI is securely destroyed
  • 11. Trust Around PHI Avoid using insecure methods of communication when it comes to PHI Avoid standard emails that disclose PHI Avoid social networking sites around PHI Use secure web tools for communicating with patients
  • 12. Trust Around PHI Make sure that HIPAA Business Associate agreements are in place with everyone who handles your PHI downstream Hosting web-based EHRs If there is an in-house EHR, have BA agreements in place Shredding companies If there is any doubt about sharing PHI with someone else, get the patient’s specific permission.
  • 13. Conclusion Conclusion: Risk vs. benefit Most important things to remember for protecting data What HIPAA can unlock for the future of healthcare Q&A

Notas do Editor

  1. For the purposes of this talk, we’ll use the terms EMR and EHR interchangeably. There are nuanced differences, but we’ll ignore that for now.EMR use elevates health data:from: simple individual-patient medical recordkeeping (just like with paper)to: tools that can aggregate data from many different patient charts and help us conduct population management (can’t do that with paper)
  2. HIPAA was initially about standardizing data interchange for electronic claims submission, claims payment and adjudication.But it is the Privacy and Security elements that have drawn most of our attention.
  3. To quote from the HHS web site on Health Information Privacy:Widespread use of health IT within the health care industry will improve the quality of health care, prevent medical errors, reduce health care costs, increase administrative efficiencies, decrease paperwork, and expand access to affordable health care.  It is imperative that the privacy and security of electronic health information be ensured as this information is maintained and transmitted electronically.
  4. On July 8, 2010, HHS announced proposed regulations under HIPAA, with an open comment period that just finished on September 13th.In addition, the ONC and the Office for Civil Rights (OCR) – in charge of enforcing privacy and security – established a new Chief Privacy Officer (Joy Pritts, JD) to help the ONC design new policies.The ONC has convened a privacy and security workgroup (known as the “Tiger Team”) of the Health Information Technology Policy Committee (HITPC) with strong consumer participation to hold public deliberations and make recommendations about patient choice of how health information is exchanged.
  5. Let’s look at the issues: Privacy and Security, and what that means at the individual practice level (more than the national-policy level)We’ll look at Security first
  6. PHI needs to be encrypted wherever it is housed.The encryption key should NOT be on the same machine where the encrypted data resides (that would be like leaving the keys in the car).There is a safe haven around the theft of devices with PHI on it:if it is sufficiently encrypted (there are NIST standards for this), and the keys are not on the same machine, then the PHI has been rendered unreadable and unusablein this case, theft does not need to be reported (it has been completely scrambled, and the keys are still safe)Otherwise, PHI loss needs to be reported to the individuals affected. If >500 records are involved, then the loss needs to be reported to HHS as well.
  7. PHI that is exchanged needs to be encrypted too. This is true for sending data across the web. Fortunately, good security tools for this have already been developed (thanks to internet banking with a 15+ year history of experience doing this)sending data within a local network, if the EMR is locally housed and uses workstations within a LANthere is an option to have in-LAN data exchange be unencrypted, if the LAN can be demonstrated to be completely walled off from the outside world – however, many LANs may have leaks to outside sources that could compromise thisit is preferable to have EMR data traffic within a secure LAN be encrypted too.
  8. I’m making a distinction here between Clinical Data Exchange and Data Sharing.Clinical Data Exchange involves packaging up a piece of PHI (like a CCD or CCR file) and sending it from one EMR system to another one across secure channels. Like mailing a letter.Data Sharing has to do with allowing additional people the right to see a single, shared data source. Chart Sharing (possible with web-based EHRs) – one patient, one chart – deals with this.The idea of “limited data set” has been mostly applied to sending medical information to insurance plansyou only send the minimum amount of info needed to pay a billIt also pertains to chart sharing, and determining how a patient can grant permission for what elements of the chart to be shared with which specialists. Highly granular chart-element sharing is at the forefront of technology right now, and is not yet mainstream.
  9. Bottom line: how do we build trust?By creating a secure framework that will EARN public trust.Banking had to go through this 15-20 years agoHealth IT is just starting on this journey
  10. Risk: do it badly, and Private Health Information leaks out.Benefit: medical data is shared between elements of the health care system, so they work in a coordinated fashion (patients want this). No more “filling out the same form over and over again”Doctors need to:keep data secure when housed in-housekeep data secure when exchanging itunderstand privacy. As physicians, we are CUSTODIANS of the patient’s health data – patients are the owners of it. When in doubt, ask permission.The vision for the future of healthcare is to promote a coordinated system of care, where health information can follow the patient wherever and whenever it is needed. HIPAA represents a framework for enabling this to happen.As the title of the joint statement on privacy and security (between the ONC and OCR) states, it’s about “building trust in health information exchange”