Most Popular Stories
- For perspective on mHealth challenges, look to developing countries
- Smartphone-powered monitoring to hit 3M users by 2016
- Texting helps with at-risk pregnancies, Partners plans to expand program
- Healthcare jobs will grow the fastest of all industries
- Interview: Behind WellPoint's $1B primary care initiative
- Study: E-prescribing improves medication adherance
Featured Jobs
-
ICD-10 Revenue Cycle, Manager
Meditology Services - Atlanta, GA -
Epic Ambulatory Beacon Consultant
Meditology Services - NC -
Electronic Health Records Application Support Manager RN-New Year New Career
Avanti on behalf of Respected Health System - San Francisco, CA
Events
- IHI's Breakthrough Series College
April 11-13, 2012 — Cambridge, MA - 3rd Healthcare IT Innovation Asia
Mar 14-15 2012 — Singapore - From IHI: The Patient Experience Seminar
March 27-28 — Boston, MA - AHIP's Institute 2012
June 20-22 — Salt Lake City, UT
Paid Research Reports
- Electronic health records: getting it right first time
- Cloud Computing Adoption In The APAC Life Sciences Industry
- Stakeholder Opinions: Ophthalmology - Leading brands under threat
- Genomics, Proteomics and Metabolomics in Diagnostics: Market landscape, innovative technologies and future outlook
- Healthcare Regulatory Update: The United Arab Emirates
- Point of Care Testing: Evaluating the return to evidence based medicine, novel technologies and the competitive landscape
Latest News
Free Newsletter
FierceHealthIT is the leading source of Healthcare IT news with a special focus on CPOE, EMR adoption, HIPAA compliance and other critical areas. Join 44,00 healthcare industry insiders who get FierceHealthIT via daily email for their must know IT news. Sign up today!
About | View Sample | Privacy
Top Tags
Whitepapers
- Meaningful Use Requirements for Patient Education
- Information Security in Health Care- Four Critical Errors
- EMR Return on Investment: Improving Efficiency and Quality with an Electronic
- Open Source and Healthcare IT
- Leveraging Uptime and Availability to Improve Productivity with EMR/EHR
- Invaluable insight led us to $2.5 million in savings in less than one-year
Time to become a security advocate

![]()
Folks, please note, you're not going to open up FierceHealthIT and find that I'm arguing for hospitals to spend less time on HIPAA. While it's easy to argue the details in how it's implemented, I think that HIPAA compliance is a good thing for the industry. For one thing, if people don't trust that their data is safe even in their own provider's offices, health data exchanges are pretty much doomed.
That being said, the study summarized in today's issue makes an interesting point. In the study, researchers found that hospitals were spending so much time making sure that they were compliant with HIPAA privacy mandates, they were losing site of other key security risks.
If you're an HIT manager, it's entirely appropriate that you also spend part of your time making sure your systems can ensure that patient records are only being accessed by appropriate parties.
At the same time, I'm sure you spend a meaningful part of your professional life worrying about malicious intruders, lost laptops with unencrypted data and other potential security disasters. But with the huge burden that privacy compliance imposes on hospital executives, you might not.
The truth is, security is one of those painful issues that only seems important to non-specialists once a disaster happens. When a bridge collapses, everyone wants to increase infrastructure funding. And when a health data system break-in happens? By God, go ahead and buy the latest and greatest security suite, Mr./Ms. HIT manager!
The problem is, as you folks know, it's really imprudent to wait until something bad happens to shore up your security infrastructure. Once a break-in happens, your organization could face consequences for years to come. Not only that, since security threats evolve daily, you can't just patch it and forget it the way you could a collapsed beam or broken pipe--so it's critical to think about security systematically. My impression is that hospital CEOs, in a word, don't.
So, HIT pros, I think it's time for you to engage in some serious and systematic research on the problem. By all means, print articles like the one I cited below. Gather statistics on the pervasiveness of HIT threats. And gather a few security nightmare scenarios in your pocket--what could happen to your facility if you're unlucky, and what it would cost. The truth is, if you don't advocate for tough security, it seems nobody will. - Anne
Related Stories
- U.S. hospitals have security 'blind spot'
- New Hampshire EMR privacy rule struck down
- HHS plans surprise HIPAA audits
- SPOTLIGHT: Hospitals face ID security holes
- WA state hospital exposes patient info on Web
- Patient webcam raises privacy issues
- GAO: Gov't HIT efforts lack privacy, security
- Hospitals more cautious about cloud adoption than physician practices
- Remote users often lax with health data protection
- California fines 7 facilities for privacy breaches
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site Map
| Editors | List in Marketplace | Supplier in MarketplaceTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |
