Government  Health IT
TwitterFacebookLinkedIn
  • Home
  • Topics
    • Cloud Computing
    • Election 2012
    • Electronic Health Record
    • ePrescribing
    • Health Information Exchange (HIE)
    • Meaningful Use
    • Medicaid
    • Medicare
    • Military Health
    • Mobile/ Wireless
    • NHIN
    • Policy & Legislation
    • Population Health
    • Privacy and Security
    • Quality and Safety
    • Telehealth
    • Workforce Management
  • Issues
    • Sept/Oct 2011
    • July/August 2011
    • May/June 2011
    • March/April 2011
    • Jan/Feb 2011
    • Nov/Dec 2010
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • Jobs
  • RSS
  • Slideshows
  • Videos
  • Podcasts
  • Newsletters
  • Advertise
  • LOGIN
  • REGISTER
  • SUBSCRIBE
Home » News » Electronic Health Record | Health Information Exchange (HIE) | Privacy and Security
Receive News
By Email

  • del.icio.us
  • Digg
  • Facebook
  • Google
  • Reddit
  • StumbleUpon
  • RSS Icon
  

Tweet

PHI Project: Don't ignore breach consequences

March 05, 2012 | Bernie Monegain, Contributing Editor

Suggested Content

  • ACA at 3: HHS's regulatory balance
  • 13 states work up telehealth legislation
  • CMS offers respite for HIPAA transaction standards
  • Maine tops states for provider rate of EHRs, meaningful use
  • 12 states file insurance exchange blueprints early
  • White House town hall touts EHR success stories
  • 6 states receive $181M health insurance exchange funds
  • Why HAI health IT should fall under meaningful use

Related Resources

  • Proactive Security and Privacy Monitoring for Modern Healthcare Networks
  • Best Practices to Deploy ECM Technologies: Ensure Decisions are Made Based on all the Information, not a Portion of it
  • Store and Organize All Types of Healthcare Data on a Single Information Infrastructure
  • Beyond the EHR: Seamlessly Connecting Nurses and Physicians Using an EHR-Extender (EHR-e)
  • The State of EHR Adoption: On The Road to Improving Patient Safety

Several healthcare groups have joined together to demand a tightening of security for protected health information. And they're making a financial case for it.

With the release of “The Financial Impact of Breached Protected Health Information: A Business Case for Enhanced PHI Security,” healthcare organizations now have a new method to evaluate the “at risk” value of protected health information (PHI) that will enable them to make a business case for appropriate investments to better protect it, say the leaders of the PHI Project.

[See also: HHS names Rodriguez chief health data privacy enforcer.]

The group, made up of standards organization ANSI, the Santa Fe Group/Shared Assessments Program Healthcare Working Group and the Internet Security Alliance, released the report March 5 and also held a press conference at  the National Press Club in Washington.

As the PHI Project leaders put it, the healthcare delivery system is founded upon trust – a trust that those receiving health information will keep it confidential and secure. This trust is now being tested as the healthcare industry moves to adopt electronic health records, access federal incentives, and facilitate better patient care. PHI is now more susceptible than ever to accidental or impermissible disclosure, loss or theft. Health care organizations (providers, payers, and business associates) are not keeping pace with the growing risks of exposure as a result of EHR adoption, the increasing number of organizations handling PHI, and the growing rewards of PHI theft.

PHI data breaches are growing in frequency and in magnitude with huge financial, legal/regulatory, operational, clinical and reputational repercussions on the breached organization, they say. The report provides CISOs, CIOs, IT security, privacy, and compliance personnel with information to help them better understand the potential risks and liabilities resulting from data breaches.

[See also: Stanford hospital breach shows danger of losing data control.]

Healthcare organizations reading this report can take immediate action, they say, using PHIve – the PHI Value Estimator – a five-step method for assessing security risks and evaluating the “at risk” value of an organization’s PHI. This tool estimates overall potential data breach costs, and provides a methodology for determining an appropriate level of investment needed to strengthen privacy and security programs and reduce the probability of a breach occurrence.

“No organization can afford to ignore the potential consequences of a data breach,” said Rick Kam, president and co-founder of ID Experts, and chair of the PHI Project. “We assembled this working group to drive a meaningful dialogue on appropriate levels of investment to better protect healthcare organizations and PHI.”

“Healthcare is one of the most-breached industries,” said Larry Ponemon, chairman and founder, Ponemon Institute. “Healthcare providers and supporting organizations don’t currently have sufficient security and privacy budgets, including adequate processes and resources, to protect sensitive patient data. This report will help them understand what they need to do to augment their efforts.”

Bernie Monegain
Bernie Monegain is Editor of Healthcare IT News
Follow Bernie on Twitter @Bernie_HITN
Related Topics:
  • Online Only
  • Electronic Health Record
  • Health Information Exchange (HIE)
  • Privacy and Security
  • Washington
  • ID Experts
  • Santa Fe Group
  • Shared Assessments Program Healthcare Working Group
  • Alliance
  • Person Career
  • Quotation
  • National Press Club
  • Ponemon Institute
  • Stanford hospital
  • healthcare
  • Larry Ponemon
  • Rick Kam
  • Stanford

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • Commentary: How data sharing between AHLTA and VistA is possible
  • Why modernizing state IT infrastructures is crucial for HIX
  • Report: HIT market will swell to $56B by 2017
  • OIG lets state Medicaid fraud units use federal funds for analytics
  • ONC launches cancer care app challenge
  • 10 health reform benefits at risk in the election
  • Would Romney kill meaningful use?
  • CMS circulates final 2014 MU clinical quality measures
  • HIE is critical public utility in Sandy disaster
  • HIMSS: The intangibles of HIT employee retention
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    A Reference Architecture for Healthcare Benefit Exchange
  • WHITE PAPERS
    The VNA Strategy: Balancing Workflow and Enterprise Imaging Management
  • WHITE PAPERS
    When Evolution Drives Revolution: The Cloud as a Business Model
  • WHITE PAPERS
    Shadow IT's Impact on the Federal Government
  • WHITE PAPERS
    Beyond the EHR: Seamlessly Connecting Nurses and Physicians Using an EHR-Extender (EHR-e)
More Resources
Syndicate content

HIMSS JOBMINE

  • Director of Clinical Applications - MidMichigan Health - Midland, MI
  • Information Services Director - Central Peninsula Hospital - Soldotna, AK
  • Director, Marketing and Business Development - Vermont Information Technology Leaders, Inc. - Burlington, VT
  • CIO - Bend Memorial Clinic - Bend, Oregon
  • Director of Clinical Transformation - Agnesian Healthcare - Fond du Lac, WI
more jobs
receive news by email

Marketplace

  • Home
  • Resource Central
  • Blog
  • Events
  • Jobs
  • Mobile Site
  • Advertise
  • RSS
  • About
  • Site map
  • Privacy Policy
Follow Government Health IT on TwitterLike Government Health IT on FacebookJoin Government Health IT on LinkedInRSS Subscriptions
BlogEvents
JobsMobile SiteMobile App
 
Healthcare IT NewsHealthcare Finance NewsHealthcare Payer NewsHIEWatch ICD10Watch mHIMSS PhysBizTech
©2013 MedTech Media Government Health IT is a publication of MedTech Media
Advertise About Us Privacy Policy