Showing posts with label EHR Privacy. Show all posts
Showing posts with label EHR Privacy. Show all posts

Tuesday, July 4, 2017

CHIME provides new certification program for industry executives

The College of Healthcare Information Management Executives (CHIME) is launching a new certification program that seeks to appreciate the expertise of executives who work for companies that give products or services to the healthcare industry.

The Ann Arbor, Mich.-based professional organization has initiated the CHIME Foundation Certified Healthcare Executive program (CFCHE) for information technology experts who are not CIOs, but are at a senior level and have other achievements in the HIT industry.

Experts who may seek the new designation may be consultants, implementers, sales representatives or in other roles, claims Keith Fraidenburg, executive vice president and COO at CHIME.

CHIME considers the new designation will facilitate interactions within the healthcare IT industry, he states. For instance, when a CIO or other technology professional discusses technology with a person with a CFCHE designation, the CIO will know the other person has passed a tough exam and has studied the challenges confronting CIOs, other healthcare leaders and payers, along with other IT experts outside a healthcare organization, Fraidenburg says.

CHIME has experience developing professional designations for the healthcare IT industry. In the year of 2009 it started a new certification program for IT executives called the Certified Healthcare CIO (CHCIO) program. Currently, more than 350 CHIME members have studied for and acquired the CHCIO title. Becoming a CHCIO is a demonstration of knowledge, skill and competency earned over various years and is the CIO equivalent of being a “black belt,” Fraidenburg asserts.

For CHIME’s newest program, after an individual has registered to participate in the CFCHE certification program, a candidate will get an extensive list of reading materials, and will take a sample exam that is not like the real exam but written in the similar way as the CIO exam to ascertain where the candidate did well and where he or she requires improving.

 

Thursday, June 29, 2017

Ransomware Strucks Princeton Community Hospital in West Virginia

Princeton Community Hospital in West Virginia is attempting to resolve a ransomware attack through a total rebuild of its computer network.

The reconstruction of its networks is a precaution to stop potential reinfection, and includes replacing almost 1,200 hard drives, Rose Morgan, vice president of patient care services, told MetroNews, the local newspaper.

A message on computers at the facility when they were turned on the morning of June 27 read: “If you see this text, then your files are no longer accessible because they have been encrypted,” MetroNews reported.

The rebuild started after IT staff evaluated that a ransom couldn’t be paid for reasons that were not specified, in accordance with the Wall Street Journal. The degree to which a ransom payment was considered is unclear, and the Princeton Community hospital is declining further comment.

Executives say they believe that backup records will restore patient files. There is no indication that data has been removed from the facility.

Workers were capable to get some patient data from four computers, like allergies, medications and medical history, but the hospital’s electronic health records (EHRs) system currently isn’t accessible, and the hospital has reverted to paper documentation. Complete restoration could take a week.

Workers in several departments can’t use their computers so they are ferrying physician orders and other information among hospital departments as the pneumatic tube system is not working, Morgan told the Wall Street Journal.

 

Thursday, June 15, 2017

Approximately half of agencies using Internet of Things struck by breaches

Almost half of U.S.-based companies using an Internet of Things (IoT) network have been struck by a recent security breach, in accordance with a new survey data released by strategy consulting firm Altman Vilandrie & Company.

The April survey of 397 IT executives across nineteen industries showed that 48% of agencies have experienced at least one IoT security breach. It disclosed the significant financial exposure of weak IoT security for companies of all sizes, with almost half of the businesses with yearly revenues above $2 billion assumed the potential cost of one Internet of Things breach at more than $20 million.

“While traditional cyber security has grabbed the nation’s attention, Internet of Things (IoT) security has been somewhat under the radar, even for few companies that have a lot to lose through a breach,” claimed Stefan Bewley, director of Altman Vilandrie and author of the study.

“IoT attacks reveal companies to the loss of information and services and can render connected devices dangerous to customers, workers and the public at large,” Bewley said. “The potential vulnerabilities for firms of all sizes will sustain to grow as more devices become Internet dependent.”

The study demonstrated that preparedness helps. Companies that haven’t experienced a security incursion have invested 65% more on IoT security than those who have been breached. Other key findings: 68% of respondents think about IoT security as a distinct category, yet only 43% have a standalone budget.

 

Wednesday, May 31, 2017

Beacon Health System notifies data breach from worker snooping

A worker at Beacon Health System in South Bend, Ind., who for 3 years was accessing patient emergency department (ED) records without permission or a reason to analyze them, has been blamed for a breach of protected health information at the facility.

An audit by Beacon Health found the unwarranted access of patient information, which occurred from the time period of March 2014 to March 2017.

“While the worker might have had authorizations to view records in certain circumstances, the employee viewed patient records without a permissible reason,” the 3-hospital delivery system pointed out in a press release to local media.

“The worker refused taking or misusing any information, and we’ve no evidence that any data was used to commit fraud or otherwise misused,” the statement continued, demonstrating that the employee is no longer employed at Beacon Health System.

Compromised information involves patient names, Social Security numbers, ages, diagnoses, room numbers, acuity of sickness, chief complaints and some financial and insurance coverage information.

Beacon Heath System is reviewing training materials and putting in place new processes to decrease the likelihood of a similar tragedy occurring again. Affected individuals are being offered 1 year of identity monitoring and identity restoration services from Experian, and they are being asserted to monitor account statements and credit reports.

This is the 2nd major breach of protected health information for Beacon Health System, which operates 3 hospitals, home care services and a medical group practice. A hacking tragedy in May 2015 affected 306,789 people.

Beacon Health refused to give more information on the most recent tragedy, but sent the following statement about the incident:

“Beacon Health System’s Information Security and Privacy Team monitor worker access to records 24/7 and investigate potential issues for appropriateness on a daily basis. After an anomaly outside of Beacon’s routine monitoring was traced, upon further review, there was proof that records other than those that were required to complete this individual’s job duties were viewed. A third party forensic review validated that no data was electronically downloaded or transferred. Out of an abundance of caution, Beacon took the most conservative route to report the tragedy and notify those involved.”

 

Wednesday, March 1, 2017

Patient transport department causes Vanderbilt security breach

In the month of late December, executives at the institute of Vanderbilt University Medical Center discovered that 2 employees in the patient transport department were inappropriately accessing the electronic medical records (EHRs) of patients, obtaining more data than they required doing their jobs, in accordance to the hospital.

An audit learned that the activity had been going on for twenty months with 3,247 patients affected. For a smaller but unrevealed number of patients, their Social Security numbers were viewed by those two employees in the patient transport department.

The university doesn’t consider information was printed, forwarded or downloaded, and so far there is no indication that personal patient information was utilized in any way, a spokesman says.

Patients are being notified and provided information on how to review account statements and their credit status. Sufferers whose Social Security numbers were accessed are being automatically enrolled for one year of credit monitoring and identity protection services from Experian. Also, other sufferers that request protective services will get it.

“We take the responsibility to secure the privacy of our patients very seriously and are doing all that we can do to deal this problem,” Howser claims. “We’ve implemented alternative procedures for patient transport staff to obtain the information they require for their jobs in a way that no longer involves access to patients’ electronic medical records.”

Disciplinary action was taken with the 2 workers, and other transport employees have been retrained on suitable access to patient information, in accordance to the hospital.

 

Wednesday, February 15, 2017

Why DirectTrust secure messaging technology is at crisis

The DirectTrust secure messaging technology developed by industry stakeholders is inquiring electronic health records (EHRs) companies and other health information technology (HIT) vendors to up their game.

Utilization of the DirectTrust secure messaging technology protocols has been ramping up over the years, but increased significantly in the year of 2016 with 98 million message transactions, which is the bulk of the 165 million transactions since being started in the year of 2013.

In large part, electronic health records (EHRs) and other health information technology products have been certified under the EHR meaningful use program to send and get Direct messages, “but the issue with certification is it does not test usability and certain features,” claims David Kibbe, MD, president and CEO at DirectTrust.

In a new report, DirectTrust secure messaging technology gives a series of suggestions for better functionality of Direct messaging covering transitions of care, clinical messaging and administration of the program. Direct works, Kibbe asserts, “but EHR usability is largely variable.”

For example, some suggestions for improving transitions of care involve all Direct messages sent in real-time and never batched for timed sends, certain kinds of messages might be automatically triggered by specific events like discharges or referrals, automated sending of messages to providers of record with Direct accounts in the sending system, and inclusion of patient-specific attachments.

The recently enacted 21st Century Cures Act involves provisions to measure EHR interoperability and usability in real episodes of use and Kibbe hopes framers of the act will look at Direct’s suggestions. The agency also might work with medical specialty groups to establish an EHR vendor grading system.

“We need to give vendors a great idea of what improvements are required to take better care of patients,” he adds.

Representatives of the HIMSS Electronic Health Record Association weren’t instantly available for comment. The report is available here.

 

Monday, February 6, 2017

Pennsylvania Superior Court finds UPMC not responsible for data breach

The Pennsylvania Superior Court has ruled that the institute of University of Pittsburgh Medical Center has no duty under state law to secure employee information and dismissed a class action lawsuit against the delivery system.

The ruling, which is in reaction to a February 2014 tragedy that instantly affected all of UPMC’s 62,000 present and former employees, has ramifications not just for healthcare agencies, but for all businesses in the state, observers claims.

Data compromised in the breach involve names, dates of birth, Social Security numbers, tax information, addresses, and salary and bank information. In the year of April, 2014, UPMC confirmed compromised data for as many as 27,000 workers with at least 788 employees becoming victims of tax fraud, and a month later confirmed all workers were compromised, in accordance to the Pennsylvania Superior Court filings.

Attorneys for the employees argued in the Pennsylvania Superior Court that UPMC had a legal duty to secure employee information and that the organization didn’t properly encrypt data, develop firewalls and implement appropriate user authentication protocols.

A trial court ruled that UPMC didn’t owe a duty of reasonable care in gathering and storing employee information. The Superior Court agreed, pointing put the pervasiveness of electronic storage of information with an obvious social utility to promote efficiency. Moreover, the Pennsylvania Superior Court in its opinion said the mere duty that Pennsylvania’s legislature has enforced on companies in the state is notification of a data breach, and it is not for the courts to change the direction of the legislature because public policy is a matter for the legislature.

“While a data breach (and its ensuring harm) is basically foreseeable, we don’t consider that this possibility outweighs the social utility of electronically storing employee information,” the Pennsylvania Superior Court pointed out in its decision. “In the modern era, more and more data is stored electronically and the days of keeping documents in file cabinets are long gone. Without doubt, workers and consumers alike derive substantial benefits from efficiencies resulting from the transfer and storage of electronic data.”

The Superior Court doubled down on its assertions, saying a judicially created duty of care is not required to incentivize companies to secure their confidential information. “We find it unimportant to need employers to incur potentially significant charges to increase security measures when there is no true way to stop data breaches altogether. Employers strive to run their businesses efficiently, and they have an incentive to secure employee information and stop these types of occurrences.”

Appellants, the court ruled, didn’t provide their information to UPMC for the consideration of its safe keeping but for employment purposes. The full ruling is available here.

 

Tuesday, January 17, 2017

Rise of Blockchain technology merits full-day conference at HIMSS17

The growth of blockchain technology as a potential tool within healthcare will rate closer examination during a day-long conference during HIMSS17 in the region of Orlando, Fla.

The conference, termed as Blockchain in Healthcare, a Rock Stars of Technology Event, will be on the day of Wednesday, February 22, at the HIMSS Annual Conference and Exhibition.

The event is being provided by the IEEE Computer Society and is being co-hosted with the Personal Connected Health Alliance. Organizers say the event will give healthcare business and Information technology professionals with the knowledge they require protecting and secure data; electronic health records (EHRs), connected devices and health information exchanges with blockchain technologies.

Proponents of blockchain technology consider that it could have wide applicability in healthcare. It enables the collection of data from a variety of sources, and keeps an audit trail of transactions, hence developing accountability and transparency in the data exchange procedure.

The utilization of blockchain in healthcare is emerging as one of the most controversial technologies of 2017, providing the promise of dealing security and data integrity problems related to the increasing volume of patient data handled by physicians, hospitals and insurance companies.

Key topics of the blockchain event at HIMSS17 involve:

  • Advancing Progress towards a Safe and Secure Nationwide System of Interoperable Health IT

  • Blockchain Use-Cases and Opportunities in Healthcare

  • Blockchains: Revealing the Hidden Cost of Trust

  • Blockchain and Its Practical Use-Cases in Healthcare

  • Computing the Contract: Why Smart Contracts are the Asset

  • Defining a Minimum Viable Product (MVP) with Blockchain in Healthcare: Challenge and Opportunities


The event at HIMSS17 will run from 9 a.m. to 5 p.m. February 22 in room 414B, discovered on level 4 of the West Concourse of the Orange County Convention Center.

Further knowledge on the event, and links for registration can be found here.

 

Sunday, January 8, 2017

Patients Doubtful at Health IT Due to Privacy and Security Concerns

More than half of customers, 57%, with contact experience to hospital, physician or ancillary provider's technology this last year report being doubtful at the overall benefits of health information technology (IT) due to security concerns like patient portals, mobile apps, and electronic health records (EHRs) mainly because of the recently reported data hacking and a perceived deficiency of privacy protection by providers, in accordance to a Black Book survey.

For the survey, Black Book surveyed 12,090 customers with the target of judging sufferer adoption and acceptance of technology.

The survey results discovered that the amount of available health data is increasing so is the hesitancy for customers to share that information because of industry privacy and security concerns. The unwillingness of sufferers to comprehensively divulge all their medical information increased to 87% in the fourth quarter of 2016.

“Fewer consumers at this point in time don’t need their digital health histories to extend beyond their physician and hospital, initially measured in the year of 2013 at 66% who were willing to divulge entire personal health data to acquire enhanced care,” the study authors wrote. “Particularly alarming to respondents were the uncertainties that their pharmacy prescriptions (90%), mental health notes (99%) and chronic condition (81%) data is being shared beyond their selected provider and payer to retailers, employers, and or the government without their acknowledgement.”

Because of these security concerns, the survey discovered that 89% of consumers with 2016 provider visits report withholding health information during visits. 93% expressed security concerns over their financial information. 69% of sufferers confirm their belief that their current primary care physician doesn’t demonstrate enough technology prowesses for them to trust divulging all their personal information.

At the similar time, the survey respondents related that more technology the physician is perceived as using to handle the patient's healthcare, the higher the trust level sufferers had in their provider. 84% of patients said their trust in their provider is influenced by how the provider utilizes the technology, instead of merely 5% of consumers had any issue in trusting in the actual technology.

Among the highlights from the survey:

  • Hospitals over 400 beds have the most success with patient technology satisfaction and usability.

  • Sufferer from hospitals under 200 beds are the most challenged by the patient portals, engagement tools and monitoring systems offered at discharge. 92% of sufferers express difficulty understanding the instructions or use of the technological applications.

  • 96% of physician office patients claimed that they left their visit with poorly communicated or miscommunicated instructions on patient portal use.

  • 91% of individuals with wearables consider their physician practice's medical record system should store that health related data as requested.

  • 72% of sufferers that have used patient portals and healthcare information sites in the year of 2016 state they believe their primary care doctor has less technology acumen then they do.

  • 94% of sufferers with health or activity trackers said their physician, when inquired, informed them the practice had no capability or interest in coordinating their outcomes currently through their EHR.

  • Four in 10 patients attempted to utilize the portal given by their physician, but 83 found it difficult to navigate when at home.

  • 91% of sufferers who find their apps and devices relevant to their health improvement felt slighted by their primary care physician and staff. 24% of those consumers are considering changing to a physician more experienced in newer technologies.


"In this age of healthcare consumerism people need to receive care via technologically enabled alternatives such as telemedicine visits, secure email communications with their practitioner, and access to records and scheduling," the survey report authors wrote.

 

 

Friday, October 21, 2016

CMS selects security vendor to secure information systems


  • The Centers for Medicare and Medicaid Services (CMS) will utilize software from Okta to more protectively secure information systems. The product, known as Okta Identity Cloud, reinforces and supports identity management and authorization of users of email, Salesforce, social networks, ADP and other approved applications to secure information systems. The software will integrate and interact with CMS’s current off-the-shelf commercial software for the purpose of identity and access control, enabling consumers to have one password that manages entire applications they work with to secure information systems.



  • Midland Health in the region of Midland, Texas, has selected the trifecta suite of clinical, financial and population health management software from Cerner to integrate and support care across the continuum of care, make a single patient record and support patient engagement through a portal. The delivery system is anchored by the 474-bed Midland Memorial Hospital.



  • 2-hospital Olathe Health System, serving 4 counties in the region of Miami, also has turned to Cerner, purchasing the Millennium Revenue Cycle software and integrating it with the vendor’s existing enterprise EHR. Oncology software of Cerner also is going in to handle complicated medication orders, and the health system further will execute RxStation, which is an automated medication dispensing tool.



  • Baylor Scott & White Health in the region of Texas is live on the dbMotion interoperability software of Allscripts. The product is made to support the exchange of EHR formation across disparate EHR systems. More than 3,800 physicians serve 2.7 million sufferers in the delivery system.



  • 3-hospital Inspira Health Network serving the region of southern New Jersey has initiated a store-and-forward telemedicine program utilizing technology from Zipnosis. The service, utilizing Inspira clinicians, enables consultations through smartphones, tablets or computers and treats more than a dozen usual and normal medical conditions. Customers complete a questionnaire and an Inspira physician reviews the data and gives a diagnosis and treatment plan.


 

Friday, August 5, 2016

Several health records stolen in greatest health care breach yet

Hackers targeting hospitals and sufferers are increasing epidemic, hence doing health care breach. Records that involve names, Social Security numbers, birthdates, and payment data are merely few of the things they’re stealing.


A recently founded huge attack of health care breach has put the records of millions of sufferers at risk. This article will tell you which health care contributor was hacked, how they founded it and if you require being worried.


We have reported on cybercriminals going after hospitals in the past times. In fact, one of the most shocking stories was when a critical care facility in the states of Kentucky had to announce a state of emergency because of a ransomware attack.


Banner Health is the recent health care contributor to fall victim to a cyberattack. Near to 3.7 million records of sufferers, health insurance policy members, cafeteria clients and even doctors were compromised. Banner workers are also likely to be the victims of the attacks.


Banner Health tracked strange suspicious activity on its servers in the month of June that led to the discovery of 2 attacks. Hackers were capable to approach the records of both sufferers and payment data of individuals making purchases in their cafeteria.


Medical records can be worth more to criminals in contrast to the Social Security numbers and credit card data alone. It is because medical records have distinctive identifiers that could permit criminals to do medical identity theft. That opens the door to health insurance deception.


Banner Health claims that there’re no reports of the stolen data being misused as of yet. They’re also giving victims of the cyberattack a free 1 year membership to a credit monitoring service.


The health care contributor will be mailing notification letters to all of the almost four million persons affected. The letters will provide the victims details of the cyberattack along with measures they should take to stay secured.


Banner Health is yet seeking into the attack to analyze how widespread it really is. At this point, they do not know how far back the data violation goes. It could affect months or even year's worth of sufferer records.


Affected clients are being motivated to appeal new debit and credit cards from their financial institutions. They should also keep an eye on bank statements to evaluate there is no unauthorized task.


 

Wednesday, July 13, 2016

FBI observes growing cyber threats to healthcare

The Federal Bureau of Investigation observes rising pressure from hackers attempting to access patient data from contributors.


Recent occasions recommend that the pressure might be rising, as offers to sell sufferer records with protected health data on the “Dark Web” market represent a new level of threat for healthcare agency trying to protect health data.


In the month of late June, a hacker called as “The Dark Overlord” reported the theft of almost 10 million sufferer medical records from contributors and a huge insurer and put them on the Dark Web market where hackers conduct buy and sell information taken from a variation of sources. As of this writing, the records haven’t been sold, and the seller might be having trouble selling the treasure trove of protected health data.


The extent of the data theft hasn’t been verified by outside sources. But the formulation of a new market for sufferer records will only expand, cybersecurity professionals believe.


Contacted for data regarding the Dark Overlord incident, the FBI refused to comment on any ongoing inquiries, but it did release guidance for contributors on steps they should take to make better their security profile.


The FBI’s guidance on best practices for securing healthcare data re-emphasizes some famous precautions, but also involving the others that might not be widely utilized by several contributors and payers.


The FBI recommends that healthcare agencies:




  • Patch the operating system, software and firmware on devices. Entire endpoints should be patched as vulnerabilities are founded. This precaution can be made convenient through a centralized patch management system.

  • Enhance worker awareness about malware risks and train suitable individuals on data security principles and techniques.



  • Handle the utilization of privileged accounts by executing the principle of least privilege. No users should be assigned administrative approach unless absolutely required.



  • Those with a requirement for administrator accounts should merely use them when necessary; they should operate with standard user accounts at all other times.

  • Make sure the anti-virus and anti-malware solutions are set to automatically update and that regular scans are conducted.



  • Configure access controls with least privilege in mind. If a user just requires reading particular files, he or she should not have “write” access to those files, directories or shares.



  • Disable macro scripts from office files transmitted through e-mail.



  • Regularly back up information and verify the integrity of those backups.

  • Execute software restriction plans or other controls to stop the execution of programs in common malware sites.



  • Protect backups and make sure that backups aren’t connected to the computers and networks they’re backing up. Instances might be securing backups in the cloud or physically storing them offline.



  • Utilize virtualized atmospheres to execute operating systems or particular programs.



  • Categorize information based on organizational value and implement physical/logical separation of networks and information for different agency units. For instance, sensitive research or business information should not reside on the similar server or network segment as an agency’s e-mail environment.

  • Execute application white listing. Only permit systems to execute programs known and allowed by security policy.



  • Need user interaction for end user applications communicating with Web sites uncategorized by the network proxy or firewall. Instances involve requiring users to type data or enter a password when their system interacts with an uncategorized Web site.


 

Friday, May 6, 2016

Earlier HIPAA Audits Assist Healthcare Data Breach Prevention

Brookings Institution recommends earlier HIPAA audits, better communication, and cyber insurance as tools for improved healthcare data breach prevention.


Using better communication, implementing a universal HIPAA audit certification system, and embracing cyber insurance are merely some of the recommendations for better healthcare data breach prevention recently put forth by the Brookings Institution.


Brookings Institution’s Center for Technology Innovation Fellow Niam Yaraghia explained some of the underlying factors in healthcare data breaches, as well as present obstacles organizations are facing.


Yaraghia and fellow researchers performed 22 in-depth interviews with “key personnel at a variety of health care providers, health insurance companies, and their business associates,” in accordance to the report.


The healthcare industry is more vulnerable to privacy breaches because it holds more valuable data for hackers, the paper explained, and that information is being stored in large volumes for a long time. Moreover, healthcare embraced information technology too late and too fast, and did not have powerful financial incentives at first to stop privacy breaches.

Wednesday, April 20, 2016

Report to Congress recommends product guidance post for ONC

The Office of the National Coordinator for Health Information Technology has sent a report to Congress analyzing the feasibility of assisting the contributors to compare and choose certified EHRs (electronic health records) products.


The report was mandated and conducted under the authority of Medicare Access and CHIP Reauthorization Act (MACRA), but with the EHR Incentive and Regional Extension Center programs winding down, ONC is observing how contributors can sustain to get critical support with executing the IT (information technology).


Support is yet necessary, ONC considers, as various contributors are upgrading or replacing EHRs they purchased to gain meaningful use, and they are retooling as they get prepared for reforms in healthcare.


“Improving providers’ capability to compare and choose certified health IT will need several mechanisms that reply on support from both the federal government and private sector,” in accordance to the report.


But the extent to which ONC can offer this level of support is not still clear, appreciates a senior advisor at ONC, talking on background. But the report puts concepts on the table.


ONC already provides a Health IT Playbook to assist in choosing products, and regional extension centers, which have gave contributors technical and care transformation support, are yet functioning, however funding for the REC program is running out. The other various federal resources could come from MACRA technical assistance, as well as the Agency for Healthcare Quality, the Office of Minority Health MACRA technical assistance and Research’s Evidence Now program.


The CMS (Centers for Medicare and Medicaid Services), which is ramping up the latest Transforming Clinical Practices Initiative, is observing at support for physicians changing into value-based care, like providing tools at a 1-stop shop to compare vendor items. For now, the ONC report provides merely a recommendation, with no firm concepts for how it could be funded, in accordance to the OCR senior advisor.


“ONC could operate with the healthcare community to seek feedback on comparison tool requirements and share great practices with the comparison tool community,” the agency stated in its report to Congress.


In a proposed transparency initiative that could be of real value, ONC during this time of spring is releasing information from its Certified Health IT Product List under what it terms “open data” CHPL. The expectation is that the private sector and expert societies or associations will make product rankings and reviews. Also under the act of “open data” CHPL, HIT vendors were need by the day of April 13 to submit the proposed attestations that they’ll be transparent in their transaction fees and not involve in data blocking.


 

Monday, April 18, 2016

Time to Confront the Ransomware Issues in U.S. Healthcare: Industry Experts Speak Out

The 1st nationally reported mainstream media news story in this drama was that nearly Hollywood Presbyterian Medical Center. On the day of Friday, February 12, NBC4News, the regional affiliate of the NBC network in Los Angeles, reported in its noon and evening broadcasts, and then online, this story: “Hollywood Hospital ‘Victim of Cyber Attack.’” As the online version of the story, by Jason Kandel and Robert Kovacik, said, “A Southern California hospital was a victim of a cyber-attack, interfering with day-to-day operations, the hospital’s president and CEO said. Staff at Hollywood Presbyterian Medical Center started noticing ‘significant IT problems and announced an internal emergency’ on the day of Friday, said hospital President and CEO Allen Stefanek. A doctor who did not need to be identified said the system was hacked and was being held for ransom.”


In the days that followed, more news reports appeared, confirming that, among other things, the electronic health record (EHR) and other clinical information systems at Hollywood Presbyterian Medical Center had been shut down for more than a week, and confirming that a ransomware attack had taken place, and claiming that the cybercriminals behind it were demanding $3.6 million to restore the system.

Tuesday, April 5, 2016

Vulnerabilities Discovered in Medical Tools: Health Care Security Sustains to Be Flawed

Health care has endured dozens of violations in hospitals and insurance offices that put medical and other personal data of sufferers at threat. Recently, medical facilities have been the goal of ransom ware threats that have knocked networks completely offline.


Now, the recent bit of news is the foundation of more than 1,400 security errors founded in CareFusion’s Pyxis SupplyStation automated medical equipment. More threatening is that these susceptibilities are so convenient to crack that even an inexperienced hacker can gain approach. In accordance to SC Magazine:


“Out of the 1,418 rarely exploitable errors, 715 of those susceptibilities in ‘automated supply cabinets utilized to dispense medical supplies’ have a severity amount of high or critical”.


Perhaps not shockingly, the susceptibilities are founded in devices that sustain to run outdated operating networks such as Windows XP. In accordance to the ThreatPost blog, the researchers who founded the susceptibilities said the errors exist in a software version that has not been updated since the year 2010. The blog went on to state:


Since CareFusion thinks these vulnerable versions end-of-life, it has no policies to patch them, but is giving anyone yet running them mitigations to decrease the threat of exploitation. The company is emphasizing users to isolate the networks from the Internet, but if they have to connect them, it is stressing they loop them via a VPN, check the network for any suspicious task, and make it close any unused ports.


One of the security researchers who founded the susceptibilities, Mike Ahmadi, informed ThreatPost that this is yet another tragedy of depending on third-party software without paying attention to potential security problems. I also think this case indicates that too many industries continue to take the threat of utilizing outdated software instead than spending the money and addressing with the stress of upgrading to something new. Microsoft stopped supporting Windows XP 2 years ago, after all, and in the situation of the CareFusion susceptibilities, we are looking at software beyond XP.


We are reaching a serious point with security within the health care company, and it seems to get worse, as we will observe later this week. And I completely agree with what Zeljka Zorz wrote in the Help Net Security blog:


But with more and more researchers focusing on finding susceptibilities in medical devices and systems (systems discovered exposed online, sporting hard-coded passwords, etc.), it is becoming clear that cyber threats can – and inevitably someday will – give results in physical harm.

Wednesday, March 16, 2016

Nicklaus Children’s Hospital receives HIMSS Stage 7 award

Nicklaus Children’s Hospital in the state of Miami is the new acute care facility to be award a Stage 7 designation of EHRs achievement from HIMSS Analytics.


The award program is deployed on the 7-stage Electronic Medical Record Adoption Model (EMRAM) and calculates maturity in the utilization of clinical information systems. Stage 7 depicts an advanced patient record setting.


“Very early on in this tour, we analyzed the significance that digitization places on the sufferers and families in our care, from decreasing costs, improving care and making better the service to our clients,” claimed Edward Martinez, senior vice president and Chief Information Officer at Miami Children’s Health System. “We are honored to be identified for our capability to adopt and accept a digitized healthcare workplace.”


Nicklaus Children’s Hospital is the mere licensed specialty hospital especially for children in the state of southern Florida, and it owns 650 attending physicians and more than 130 pediatric subspecialists.


The hospital is also hosts the greatest pediatric teaching program in the southeastern U.S and has been termed as American Nurses Credentialing Center (ANCC) Magnet facility, the nursing profession’s most prestigious institutional honor.


The procedure of assessing if a hospital has reached Stage Seven involves a site visit by a HIMSS Analytics executive, as well as previous or present chief information officers, chief medical information officers or chief nursing informatics officers.


“Nicklaus Children’s Hospital is believed to be on the leading edge of technology use in various ways,” claimed John H. Daniels, global vice president of the healthcare advisory services group of HIMSS Analytics. “For instance, they have repurposed their previous medical records storage room into an international telehealth center to serve pediatric sufferers around the world.”


HIMSS will honor Nicklaus Children’s Hospital, along with other hospitals that receive Stage 7 this very year, at the 2017 HIMSS Conference in the state of Orlando. HIMSS Analytics also has a same program to identify the HER accomplishments of ambulatory practices.


Tuesday, March 8, 2016

Providers must empower vigilance to limit the EHR threats

When it comes to EHRs, a deficiency of planning could lead to sufferer death, which is why hospitals must execute the policies and procedures to decrease the EHR threats.


While the health IT movement is acquiring traction across the nation, it yet has a long way to go and problems still exist within EHRs, states Trish Lugtu, associate director of research at MMIC Insurance.


Discussing at an educational session at HIMSS16 previous week, Lugtu claimed that in the past, persons were not paying attention to health information technology and it “scared her.” As an instance, she shared research on 2 sufferers who died as a result of mistakes within their records, involving a sufferer who died following an anaphylactic reaction to known allergies because notifications were turned off in the patient record, and a sufferer who died following a failure to diagnose and treat a small bowel obstruction when an X-ray wasn’t routed properly.


To control these issues, healthcare IT executives require to form partnerships and collaborations with the right persons, involving risk management, Lugtu claimed.


3 steps to decrease risks regarded to EHR usage involve:


Utilize a common language. Both IT and medical fields utilize various acronyms, few of which have different meanings. “Languages [often] do not sync up and we do not realize it,” she claimed.


Develop rights and responsibilities. To date, there has been great work done on setting rules on what should and should not be implemented within an EHR. But it is significant that rights and responsibilities between the clinician and IT team be clearly explained. “To make better the healthcare quality, a balance must be acquired,” she stated. As an instance, if clinicians need to access records, there must be assurances that they follow security practices.


A simplified access. This includes not missing problems and electronic routing of data. It includes events that persons do not consider about, Lugtu stated. “It is all components of how to utilize technology, how we interact with technology, and how we communicate with technology,” she elaborated. “Make certain that you have those. Ensure that you have paper forms and downtime processes.”


In the end, it is about planning. “Find partners in the agency to collaborate, so IT and clinicians are at the table,” she stated. “Failing to plan is planning to fail. If we are not aware of these things and do not have a strategy to secure these problems, we will sustain in the status quo,” she added. “These are not unintended consequences; these are sufferer lives.”


Thursday, March 3, 2016

Hurley Medical’s EHR analysis is playing a primary role in Flint’s water issues

Without the power of EHRs, the discovery of great levels of lead in the water supply of Flint, Mich.—and subsequent proof that its kids were collecting high levels of lead in their blood—is a tragic story that might not even be known to this day


Acting on a hunch, a pediatrician at Hurley Medical Center decided and ordered an analysis of blood test records that made a comparison of blood lead levels in small kids before and after the city changed its water supply from Lake Huron to the Flint River in a cost-saving step.


The outcomes, calculated from hundreds of particular records that were recognized and then geographically mapped, took merely 2 weeks. The stark evidence demonstrated a doubling, and in few places a tripling, of lead levels in one- and two-year-olds—ages in which the neurotoxin can cause important developmental damage. Those outcomes led to a shutdown of the Flint water supply and redeveloped the lake water source.


“We daily check blood lead levels, and there is no protective level of lead exposure,” claims Mona Hanna-Attisha, M.D., the pediatrician who acted on the hunch that bared the findings. “But particularly underserved minority communities have a pre-existing disparity in relations to lead exposure.” The Medicaid-mandated checks created the information, and their presence in an EHR from Epic that went into operation in the year 2011 made the pinpoint analysis possible.


The story is far from over. The next issue is to isolate and tag the records of 9,000 to 10,000 kids under the age of 6, whose brains are still progressing, and manage to track them long term to try to reduce the ill impacts that are likely to appear.


That is where the limits of the present healthcare IT infrastructure will be felt, claims Michael Roebuck, M.D., Hurley’s chief medical information officer. “This is a good case instance of the present capabilities and the future deficiencies of medical records.”


Everyone knew there was something in the water from the beginning. Days after the change, complaints about the odor, color, and increases in skin rashes all erupted. “But we were reassuring our families, because we were being reassured by government, that the water was secure,” claims Hanna-Attisha.


Then a research crew from Virginia Tech took measurements at several sites along the river and discovered high levels of lead. Hanna-Attisha took the report as a template for mapping records of blood levels geo coded to evaluate where they were greatest, as well as the highest before-and-after increases. “Where the water [lead] levels were the greatest was the exact similar place as (where) the blood levels were the greatest.”


Overall, the percentage of kids with elevated blood lead levels--described as 5 micrograms per deciliter or greater--went from 2.4% in the year 2013 to 4.9% in the year 2015. The water source was changed in the year of April 2014. In 1 ward, the percentage spiked from 4.8% to nearly 16%. The Virginia Tech outcomes recorded the greatest water lead levels in that similar ward—30% of the tested samples exceeded 15 parts per billion, which is the threshold for action by the Environmental Protection Agency.


This was the 1st increase in water lead levels in various years, claims Hanna-Attisha. “We set ourselves back decades in terms of where our blood lead levels are.”


The conclusions were even more important when contrasted with a trend of steadily reducing lead exposure in Flint and around the state. This was the 1st increase in various years, claims Hanna-Attisha. “We set ourselves back decades in terms of where our blood lead levels are.”


Unlike the proof of dirty water, lead exposure has no instant signs or symptoms. Merely by doing population-level investigation, “which is robust in systems such as Epic,” did the trends show up, she asserts. “If we had still been on paper, we possibly would still be poring through records.”


The power of the contemporary EHR is its capability to “grab information from various databases and combine information in a way that lets you do population-level analysis,” claims Roebuck. “As an instance, it is 1 thing to get a lab system to spit out a bunch of lead levels--I think that’s pretty easy. It’s another thing to get a lab system to spit out lead levels and addresses and primary care doctor and contact number . . . that then you can utilize to do population-level analysis.”


“If you need to geo-map them, you require their addresses. If you need to contact them, you require their PCPs and contact numbers. And modern-day data analytics makes that very convenient,” he adds.


The clear profit of population health analysis goes further. The rapid work staved off other threats that would have sustained, like public health advisories to boil water following episodes of large amounts of bacteria discovered in periodic samplings. For lead, it was the worst thing they could do.


“Even today, there are persons who consider, and rightly so, that boiling the water is the safest thing,” claims Hanna-Attisha. But boiling evaporates water while leaving behind all the lead. “That lead is going to focus in whatever you are boiling.” There were 3 boil advisories merely in the time before the lead was found.


However the lead discoveries kept things from getting worse, destruction is already done. Exposure reduces IQ and causes attention deficit, hyperactivity, impulse and conduct disorders. Nutrition options can reduce the effects, and services like universal preschool and mental health approach can counter few of the known affects on cognition and behavior, claims Hanna-Attisha. “We are definitely looking at a twenty-year lifespan tracking these kids.”


For Roebuck, “that is been the issue. The health IT infrastructure nationally is not in a spot still that tagging these children for the duration of their lifetime is convenient.”


Regionally, it may be doable in conjunction with the regional health data exchange, he claims. “As long as they stay in the city of Flint, we can handle the majority of that tagging; but as soon as few kid graduates high school and goes to college, or as soon as certain family member gets a latest job in a different state and the kid leaves the state, maintaining that information connection with that individual at that time is not something that is easily done.”


The tracking of developmental milestones and lead-linked health results will be the simple part, at least under the aegis of Hurley Medical Center and its EHR system. 1 necessary set of data will come from issue lists, those computerized details needed by the HITECH Act’s Meaningful Use program. The EHR also will have medical history and a diagnosis that may involve the cognitive and attitude changes most concerning to healthcare contributors, states Roebuck. “It is quite simple to get those out of the record.”


Monday, February 29, 2016

Protection soars as top spending preference for health IT execs

Threatened with the increasing issue of health data breaches, IT leaders at healthcare agencies are growing investments this year in their security infrastructures, in accordance to outcomes of a new survey from IT staffing firm TEKsystems.


Security is a progressive area in the year 2016 in terms of healthcare organization IT budgets, respondents demonstrated. When inquired which technology categories will have the greatest effect on their agencies this year, 60% of respondents demonstrated that security was the top priority in their budgets this year, up from 54% in the year 2015.


In the survey, security edged out business intelligence and big data, highlighted by 58% of respondents; mobility (55%); cloud computing (49%); and consumerization of IT/bring your own device (47%).


“Security is one of our fastest developing technology places because nobody needs their company’s name in the paper linked with a data breach,” claims Mitch Gardner, northeast regional director for TEKsystems Healthcare Services. “If you observe at the other 4 areas—BI/big data, mobility, cloud computing, and BYOD—they all have a huge security component.”


Gardner contends that initiatives regarded to mobile health and sufferer engagement are also drivers for sustained spending in security, provided that wearables and the Internet of Things are beginning to shift how contributors care for their sufferers, bringing with them inherent security susceptibilities.


Securing data and networks has never been more significant for these agencies, because 2015 was a watershed year for healthcare hacking tragedies. In fact, healthcare records for one in 3 Americans were breached previous year, with records of 111 million persons potentially approached by hackers, compared with merely about 1.8 million individuals in the year 2014, in accordance to data analysis released previous month by cybersecurity vendor Bitglass.


And, with an 80% increase in the number of hacks in the year 2015, health IT leaders are not taking chances as they look to beef up security and increase staffing. When TEKsystems inquired HIT executives if they hope 2016 security spending to change, the percentage of IT leaders expecting increases was 73%, compared with 70% in the year 2015.


Karsten Scherer, an analyst with TEKsystems, analyzes that healthcare agencies were definitely concerned about security susceptibilities previous year, but many were not making it a top priority. “It was not that it wasn’t on their radar in the year 2015, but now they are legitimately doing something about it and executing tools for intrusion detection and monitoring, while dealing improper use and access,” Scherer claims. Additionally, he analyzes mHealth and medical devices getting more attention from contributors.


An August 2015 research published in Communications of the ACM discovered that security remains 1 of the most significant concerns because of to the potential threats of cyberattacks on medical devices. For instance, more than two-thirds (69%) of respondents claimed their agency’s IT security does not meet expectations for FDA-approved medical tools.


Although, as healthcare agencies try to increase staffing to bolster security, Scherer discusses that they are having an increasingly complex time finding security professionals with the requisite qualities and experience. Respondents to this year’s TEKsystems survey claimed it was toughest to find information security executives, eclipsing project managers, which was previous year’s hardest position to fill.


Not astonishingly, when inquired whether they hope their IT staff’s security salaries to change this year versus previous year, the percentage of IT leaders expecting increases in the year 2016 was 62% versus 59% in the year 2015.


“While core builder positions are both critical and complicated t to fill, security—critical for all levels of a healthcare IT initiative—has continually increased in significance, and as a result, sustains to maintain its priority as the place where the greatest percentage of healthcare IT leaders are allocating salary increases,” claims TEKsystems’ annual IT forecast, which is deployed on a survey of nearly 100 HIT leaders involving CIOs, vice presidents, directors, as well as hiring managers at healthcare agencies that averaged about $50 million in revenue.


Scherer point out that as security takes on increasing significance for healthcare agencies; there are “few interesting tensions that are initiating to crop up between business executives and conventional IT executives for control.” He summarizes that the “old school CIOs are going to have to rise to the issues or get left behind.”