<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.fiercehealthit.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>security risks</title>
 <link>http://www.fiercehealthit.com/tags/security-risks</link>
 <description></description>
 <language>en</language>
<item>
 <title>Time to become a security advocate</title>
 <link>http://www.fiercehealthit.com/story/time-to-become-a-security-advocate/2008-04-14?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FHI0</link>
 <description>&lt;p&gt;
&lt;img src=&quot;http://static.fiercemarkets.com/public/newsletter/fiercehealthcare/anne_headshot.gif&quot; border=&quot;0&quot; alt=&quot;&quot; align=&quot;right&quot; /&gt;&lt;img src=&quot;http://static.fiercemarkets.com/public/newsletter/assets/editors_corner_small.gif&quot; border=&quot;0&quot; alt=&quot;&quot; width=&quot;136&quot; height=&quot;29&quot; /&gt;&lt;br /&gt;
Folks, please note, you&#039;re not going to open up &lt;em&gt;FierceHealthIT&lt;/em&gt; and find that I&#039;m arguing for hospitals to spend less time on HIPAA. While it&#039;s easy to argue the details in how it&#039;s implemented, I think that HIPAA compliance is a good thing for the industry. For one thing, if people don&#039;t trust that their data is safe even in their own provider&#039;s offices, health data exchanges are pretty much doomed.&lt;br /&gt;
&lt;br /&gt;
That being said, the study summarized in today&#039;s issue makes an interesting point. In the study, researchers found that hospitals were spending so much time making sure that they were compliant with HIPAA privacy mandates, they were losing site of other key security risks.&lt;br /&gt;
&lt;br /&gt;
If you&#039;re an HIT manager, it&#039;s entirely appropriate that you also spend part of your time making sure your systems can ensure that patient records are only being accessed by appropriate parties.&lt;br /&gt;
&lt;br /&gt;
At the same time, I&#039;m sure you spend a meaningful part of your professional life worrying about malicious intruders, lost laptops with unencrypted data and other potential security disasters. But with the huge burden that privacy compliance imposes on hospital executives, you might not.&lt;br /&gt;
&lt;br /&gt;
The truth is, security is one of those painful issues that only seems important to non-specialists once a disaster happens. When a bridge collapses, everyone wants to increase infrastructure funding. And when a health data system break-in happens? By God, go ahead and buy the latest and greatest security suite, Mr./Ms. HIT manager!&lt;br /&gt;
&lt;br /&gt;
The problem is, as you folks know, it&#039;s really imprudent to wait until something bad happens to shore up your security infrastructure. Once a break-in happens, your organization could face consequences for years to come. Not only that, since security threats evolve daily, you can&#039;t just patch it and forget it the way you could a collapsed beam or broken pipe--so it&#039;s critical to think about security systematically. My impression is that hospital CEOs, in a word, don&#039;t.&lt;br /&gt;
&lt;br /&gt;
So, HIT pros, I think it&#039;s time for you to engage in some serious and systematic research on the problem. By all means, print articles like the one I cited below. Gather statistics on the pervasiveness of HIT threats. And gather a few security nightmare scenarios in your pocket--what could happen to your facility if you&#039;re unlucky, and what it would cost. The truth is, if you don&#039;t advocate for tough security, it seems nobody will. - &lt;a href=&quot;mailto:anne@fiercemarkets.com&quot;&gt;Anne&lt;/a&gt;
&lt;/p&gt;
</description>
 <comments>http://www.fiercehealthit.com/story/time-to-become-a-security-advocate/2008-04-14#comments</comments>
 <category domain="http://www.fiercehealthit.com/tags/hipaa-compliance-15">HIPAA Compliance</category>
 <category domain="http://www.fiercehealthit.com/channel/hipaa-compliance">HIPAA Compliance</category>
 <category domain="http://www.fiercehealthit.com/tags/hospitals">hospitals</category>
 <category domain="http://www.fiercehealthit.com/tags/patient-records-0">patient records</category>
 <category domain="http://www.fiercehealthit.com/tags/patient-privacy-0">privacy</category>
 <category domain="http://www.fiercehealthit.com/tags/security-breaches-0">security breaches</category>
 <category domain="http://www.fiercehealthit.com/tags/security-holes-0">security holes</category>
 <category domain="http://www.fiercehealthit.com/tags/security-risks">security risks</category>
 <category domain="http://www.fiercehealthit.com/tags/security-threats-1">Security Threats</category>
 <pubDate>Mon, 14 Apr 2008 06:59:59 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">7900 at http://www.fiercehealthit.com</guid>
</item>
<item>
 <title>SPOTLIGHT:  Vendor names top five health data security risks</title>
 <link>http://www.fiercehealthit.com/story/spotlight-vendor-names-top-five-health-data-security-risks/2008-03-24-0?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FHI0</link>
 <description>&lt;P&gt;So what are the top five health data security risks? According to security software vendor Absolute Software Corp., which makes firmware-based solutions, top risks include failure to protect sensitive data past encryption, inability to mange mobile assets and exposing sensitive information on public terminals. &lt;A href=&quot;http://www.healthcareitnews.com/story.cms?id=8913&quot;&gt;Article&lt;/a&gt;&lt;/p&gt;

</description>
 <comments>http://www.fiercehealthit.com/story/spotlight-vendor-names-top-five-health-data-security-risks/2008-03-24-0#comments</comments>
 <category domain="http://www.fiercehealthit.com/tags/public-terminals">public terminals</category>
 <category domain="http://www.fiercehealthit.com/tags/security-risks">security risks</category>
 <category domain="http://www.fiercehealthit.com/tags/sensitive-data-0">sensitive data</category>
 <pubDate>Mon, 24 Mar 2008 07:59:52 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">7869 at http://www.fiercehealthit.com</guid>
</item>
<item>
 <title>SPOTLIGHT:  Vendor names top five health data security risks</title>
 <link>http://www.fiercehealthit.com/story/spotlight-vendor-names-top-five-health-data-security-risks/2008-03-24?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FHI0</link>
 <description>&lt;p&gt;
So what are the top five health data security risks? According to security software vendor Absolute Software Corp., which makes firmware-based solutions, top risks include failure to protect sensitive data past encryption, inability to mange mobile assets and exposing sensitive information on public terminals. &lt;a href=&quot;http://www.healthcareitnews.com/story.cms?id=8913&quot;&gt;Article&lt;/a&gt;
&lt;/p&gt;
</description>
 <comments>http://www.fiercehealthit.com/story/spotlight-vendor-names-top-five-health-data-security-risks/2008-03-24#comments</comments>
 <category domain="http://www.fiercehealthit.com/tags/absolute-software-corp">Absolute Software Corp.</category>
 <category domain="http://www.fiercehealthit.com/tags/managing-mobile-assets">managing mobile assets</category>
 <category domain="http://www.fiercehealthit.com/tags/public-terminals">public terminals</category>
 <category domain="http://www.fiercehealthit.com/tags/security-risks">security risks</category>
 <category domain="http://www.fiercehealthit.com/tags/sensitive-data-0">sensitive data</category>
 <pubDate>Mon, 24 Mar 2008 07:59:52 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">7870 at http://www.fiercehealthit.com</guid>
</item>
</channel>
</rss>
