Government  Health IT
TwitterFacebookLinkedIn
  • Home
  • Topics
    • Cloud Computing
    • Election 2012
    • Electronic Health Record
    • ePrescribing
    • Health Information Exchange (HIE)
    • Meaningful Use
    • Medicaid
    • Medicare
    • Military Health
    • Mobile/ Wireless
    • NHIN
    • Policy & Legislation
    • Population Health
    • Privacy and Security
    • Quality and Safety
    • Telehealth
    • Workforce Management
  • Issues
    • Sept/Oct 2011
    • July/August 2011
    • May/June 2011
    • March/April 2011
    • Jan/Feb 2011
    • Nov/Dec 2010
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • Jobs
  • RSS
  • Slideshows
  • Videos
  • Podcasts
  • Newsletters
  • Advertise
  • LOGIN
  • REGISTER
  • SUBSCRIBE
Home » News » Electronic Health Record | Health Information Exchange (HIE) | Mobile/ Wireless | Privacy and Security | Telehealth
Receive News
By Email

  • del.icio.us
  • Digg
  • Facebook
  • Google
  • Reddit
  • StumbleUpon
  • RSS Icon
  

Tweet

8 tactics for mobile data privacy and security

July 20, 2011 | Mary Mosquera

Suggested Content

  • 13 ways to guard against mobile device risks
  • The lifecycle of PHI and mobile device insecurity
  • 11 data security tips for a healthy organization in 2013
  • Q&A: How a health 'data spill' could be more damaging than what BP did to the Gulf
  • 3 ways to make data protection more patient-centric
  • What is your PHI worth?
  • 5 steps to protect patient privacy
  • 3 ingredients of successful risk assessment

Related Resources

  • A Roadmap for BYOD Adoption
  • Securing Mobile Devices in the Business Environment
  • Accelerate Healthcare Reform with Information Technology
  • Medical Imaging in the Cloud
  • Advanced Text Mining Improves Medicare Advantage Coding

With the sweeping use of mobile devices by healthcare providers, physicians and hospitals need to embrace best practices for protecting sensitive patient data, privacy experts say. For example, encrypt sensitive data when it is necessary to store on wireless devices.

Sixty-four percent of physicians own a smartphone and one third of them have an iPad, with another 28 percent planning to buy one within six months, according to research cited by ID Experts, which offers data protection and response services, in a July 20 announcement.

[MobileHealthWatch guest blog: Tips for tablet maintenance.]

Many of the current 10,000 mobile healthcare applications were designed to enable their users to access to electronic health records (EHRs). At the same time, in the past two years, the Office of Civil Rights has reported that 116 data breaches of 500 records or more were the direct result of the loss or theft of a mobile device and led to the exposure of the personal health information of 1.9 million patients, which started many consumers questioning the security of EHR systems and the data they house.

The Office of Civil Rights oversees health information privacy in the Health and Human Services Department and publishes on its website incidents involving the sensitive information of at least 500 individuals.

To more effectively protect patient data, Rick Kam, president of ID Experts recommended the following practices:

1. Don’t store sensitive data on wireless devices. If required, encrypt data.
2. Enable password protection on wireless devices and configure the lock screen to come on after a short period of inactivity.
3. Turn on the “remote wipe” feature of wireless devices.
4. Enable Wi-Fi network security. Do not use wired equivalent privacy (WEP). Wi-Fi protected access (WPA-1) with strong passphrases offers better security. Use WPA-2 if possible.
5. Change the default service set identifier (SSID) and administrative passwords.
6. Don’t transmit your wireless router’s SSID.
7. Only allow devices to connect by specifying their hardware media access control (MAC) address.
8. Establish a wireless intrusion prevention system.

“Many Wi-Fi networks in hospitals and doctor’s offices are not secure," Kam cautioned, "and coupled with the increased mobile device usage, patient data is at risk."

And as more and more mobile health applications emerge, including smartphone apps from federal government agencies including the VA and DoD, that risk will continue to grow.

Mary Mosquera
Senior Editor for Healthcare Finance News
Follow Mary on Twitter @GovHITreporter
Related Topics:
  • Online Only
  • Electronic Health Record
  • Health Information Exchange (HIE)
  • Mobile/ Wireless
  • Privacy and Security
  • Telehealth
  • ID Experts
  • Person Career
  • healthcare
  • Department of Defense
  • http://www.govhealthit.com/blog/risk-assessment-no-risk-proposition
  • http://www.govhealthit.com/news/consumer-confidence-about-health-data-safety-key-ehr-adoption
  • http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html
  • mobile device
  • mobile devices
  • Rick Kam
  • Smartphone
  • Virginia
  • WEP
  • Wi-Fi
  • wireless devices

Reader Comments (1)Login to Post a Comment

SellYourCell says: Cell Phone Data Security
January 31, 2012 | 4:50PM GMT
Don't forget about end of life security. I work with SellYourCell.com, an internet site where we buy used cell phones. It is very common for people to send us cell phones full of private data that has not been erased. Even if your organization has the ability to remotely wipe data off a users phone, this capability can be lost if the user switches to a new phone prior to a security wipe. Consider using an outside service, like SellYourCell, that can buy your phones and make sure that the phone is reset to factory settings with data erased, and SIM and/or data cards removed. In addition to data security, you or your staff also benefits with a little cash.

Most Popular

Latest Headlines
Most Popular
  • Why modernizing state IT infrastructures is crucial for HIX
  • Report: HIT market will swell to $56B by 2017
  • OIG lets state Medicaid fraud units use federal funds for analytics
  • $1M grant bringing HIE to rural CA providers
  • Hagel says DoD to adopt commerical EHR
  • 10 health reform benefits at risk in the election
  • Would Romney kill meaningful use?
  • CMS circulates final 2014 MU clinical quality measures
  • HIE is critical public utility in Sandy disaster
  • HIMSS: The intangibles of HIT employee retention
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    When Evolution Drives Revolution: The Cloud as a Business Model
  • WHITE PAPERS
    Cloud Computing in the Healthcare Environment
  • WHITE PAPERS
    Key Benefits to a Secure & Elastic Private Cloud
  • WHITE PAPERS
    Shadow IT's Impact on the Federal Government
  • WHITE PAPERS
    Enterprise-class API Patterns for Cloud & Mobile
More Resources
Syndicate content

HIMSS JOBMINE

  • Director of Clinical Applications - MidMichigan Health - Midland, MI
  • Information Services Director - Central Peninsula Hospital - Soldotna, AK
  • Director, Marketing and Business Development - Vermont Information Technology Leaders, Inc. - Burlington, VT
  • CIO - Bend Memorial Clinic - Bend, Oregon
  • Director of Clinical Transformation - Agnesian Healthcare - Fond du Lac, WI
more jobs
receive news by email

Marketplace

  • Home
  • Resource Central
  • Blog
  • Events
  • Jobs
  • Mobile Site
  • Advertise
  • RSS
  • About
  • Site map
  • Privacy Policy
Follow Government Health IT on TwitterLike Government Health IT on FacebookJoin Government Health IT on LinkedInRSS Subscriptions
BlogEvents
JobsMobile SiteMobile App
 
Healthcare IT NewsHealthcare Finance NewsHealthcare Payer NewsHIEWatch ICD10Watch mHIMSS PhysBizTech
©2013 MedTech Media Government Health IT is a publication of MedTech Media
Advertise About Us Privacy Policy