Government  Health IT
TwitterFacebookLinkedIn
  • Home
  • Topics
    • Cloud Computing
    • Election 2012
    • Electronic Health Record
    • ePrescribing
    • Health Information Exchange (HIE)
    • Meaningful Use
    • Medicaid
    • Medicare
    • Military Health
    • Mobile/ Wireless
    • NHIN
    • Policy & Legislation
    • Population Health
    • Privacy and Security
    • Quality and Safety
    • Telehealth
    • Workforce Management
  • Issues
    • Sept/Oct 2011
    • July/August 2011
    • May/June 2011
    • March/April 2011
    • Jan/Feb 2011
    • Nov/Dec 2010
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • Jobs
  • RSS
  • Slideshows
  • Videos
  • Podcasts
  • Newsletters
  • Advertise
  • LOGIN
  • REGISTER
  • SUBSCRIBE
Home » News » Mobile/ Wireless | Privacy and Security
Receive News
By Email

  • del.icio.us
  • Digg
  • Facebook
  • Google
  • Reddit
  • StumbleUpon
  • RSS Icon
  

Tweet

ONC to offer mobile device security tips

June 13, 2012 | Mary Mosquera

Suggested Content

  • Info security is critical when VA allows iPhone, iPad
  • Q&A: Why IT security grows more complex
  • Kathleen Sebelius turns to Twitter
  • 3 tips for safeguarding against data breaches
  • VA expects to award MDM tool by Sept. 30
  • Coast Guard will add mobile interface to EHR
  • 13 ways to guard against mobile device risks
  • The lifecycle of PHI and mobile device insecurity

Related Resources

  • Easier Ways for PACS/RIS End Users to Manage Applications and Desktop Environments
  • Enabling Data as a Service in Healthcare
  • BYOD in Healthcare Organizations: Top 6 Risks & How to Avoid Them
  • Better Patient Care: Virtually There
  • Realizing the Promise of Health Information Exchange

WASHINGTON – The Office of the National Coordinator for Health IT (ONC) will help small providers who use smart phones and other mobile devices learn how to easily secure them using simple steps explained in plain language.

Research shows that about 81 percent of physicians use smart phones or tablet devices. The small size of these devices make them easy to lose on subways and airplanes or stolen. Yet very few safeguard them, such as using encryption, making it easy for unauthorized users to access information.

ONC has conducted research on mobile endpoint security, where they take devices out of the box from the local electronics stores and apply manual configuration for better controls to support security, said Will Phelps, an IT security specialist in ONC’s Office of the Chief Privacy Officer.

“You have to make sure that the devices are able to apply the appropriate security controls to make sure that the patient records are protected. We want to reach out to the provider community to make sure that they are able to do these things,” he said at the June 11 Government Health IT conference sponsored by HIMSS.

[See also: CMS chief optimistic Supreme Court will uphold heathcare reform.]

ONC studies of out-of-the-box security configuration found that most mobile phones did not meet more than 40 percent of security requirements, such as the ability to encrypt information, he said.

After manual configuration, test results improved significantly, especially for the iPhone and Blackberry models, which met 60 percent of the security requirements. Other phones did not fare as well after manual configuration.

Initially, ONC will focus on small and medium-sized providers. “They may not have an IT staff or third-party vendor to manage their devices for them. So we want to get them to a point where their devices are operating as securely as possible,” Phelps said, adding that the security configurations are available on the devices right out of the box but must be manually configured.

ONC will describe scenarios or use cases around which to offer practical information for mobile device security, said Kathryn Marchesini, an attorney in ONC’s Office of the Chief Privacy Officer. 

These will include remote use from a coffee shop, sending e-mail, or what to do if providers bring their own devices, which may not necessarily be credentialed in the organization, and whether they should be allowed to connect to the system’s network or not.

Some providers may not realize they need a policy around the use of mobile devices, or that they need to take an inventory of mobile devices. “It may seem basic, but we hear every day that practicing providers are struggling with these issues,” she said.

[See also: OCR tells patients to use legal right to health data access.] 

The Health Insurance Portability and Accountability Act (HIPAA) provides security guidance around remote use. The proposed rule for meaningful use stage 2 also calls for encryption of data at rest.

In its next phase, ONC will test third-party vendor security tools applied to devices to see how well they score on information protection. Overall, ONC plans to design outreach for vendors, providers and patients for security awareness around mobile devices and training to follow.

ONC is also incorporating in its mobile security outreach the regional health IT extension centers, which offer technical assistance in providers’ offices “to make sure we identify real scenarios and practical solutions,” Marchesini said.

ONC plans to develop best practices for securing mobile devices to be available online in the fall.
 

Mary Mosquera
Senior Editor for Healthcare Finance News
Follow Mary on Twitter @GovHITreporter
Related Topics:
  • Online Only
  • Mobile/ Wireless
  • Privacy and Security
  • Washington
  • Contact Details
  • Person Career
  • Quotation
  • electronics
  • encryption
  • http://www.govhealthit.com/news/cms-chief-optimistic-supreme-court-will-uphold-heathcare-reform
  • http://www.govhealthit.com/news/ocr-tells-patients-use-legal-right-health-data-access
  • http://www.healthit.gov
  • iPhone
  • Kathryn Marchesini
  • mobile device
  • mobile devices
  • mobile phones
  • OCR
  • smart phones
  • Supreme Court
  • Will Phelps

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • Commentary: How data sharing between AHLTA and VistA is possible
  • Why modernizing state IT infrastructures is crucial for HIX
  • NYeC PHR design winners to shape public portal
  • Report: HIT market will swell to $56B by 2017
  • ONC launches cancer care app challenge
  • 10 health reform benefits at risk in the election
  • Would Romney kill meaningful use?
  • CMS circulates final 2014 MU clinical quality measures
  • HIE is critical public utility in Sandy disaster
  • HIMSS: The intangibles of HIT employee retention
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    HIE Interoperability case study: Health-e-cITi-NJ
  • WHITE PAPERS
    Key Benefits to a Secure & Elastic Private Cloud
  • WHITE PAPERS
    New World Order: Effectively Securing Healthcare Data Through Secure Information Exchanges
  • WHITE PAPERS
    Your Cloud in Healthcare - How to Use the Cloud to Achieve Greater Business Agility
  • WHITE PAPERS
    The VNA Strategy: Balancing Workflow and Enterprise Imaging Management
More Resources
Syndicate content

HIMSS JOBMINE

  • Director of Clinical Applications - MidMichigan Health - Midland, MI
  • Information Services Director - Central Peninsula Hospital - Soldotna, AK
  • Director, Marketing and Business Development - Vermont Information Technology Leaders, Inc. - Burlington, VT
  • CIO - Bend Memorial Clinic - Bend, Oregon
  • Director of Clinical Transformation - Agnesian Healthcare - Fond du Lac, WI
more jobs
receive news by email

Marketplace

  • Home
  • Resource Central
  • Blog
  • Events
  • Jobs
  • Mobile Site
  • Advertise
  • RSS
  • About
  • Site map
  • Privacy Policy
Follow Government Health IT on TwitterLike Government Health IT on FacebookJoin Government Health IT on LinkedInRSS Subscriptions
BlogEvents
JobsMobile SiteMobile App
 
Healthcare IT NewsHealthcare Finance NewsHealthcare Payer NewsHIEWatch ICD10Watch mHIMSS PhysBizTech
©2013 MedTech Media Government Health IT is a publication of MedTech Media
Advertise About Us Privacy Policy