Security Safeguards Privacy

執筆者
Caron Carlson
Caron Carlson
Published: Dec 22, 2003
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

The nexus between network security and consumer privacy is increasingly being seen in measures health care organizations are taking to comply with the federal Health Insurance Portability and Accountability Act. Systems deployed last April to meet HIPAAs privacy deadline will help achieve compliance with a security deadline in April 2005.

At Childrens Hospital, in Boston, the IT department this year implemented an integrated system of password management and user provisioning that meets HIPAAs privacy mandates without impeding the staffs access to data, said Scott Ogawa, chief technology officer at the hospital.

“We were stuck between a rock and a hard place,” Ogawa said last week at the Inside ID conference here. “Our job is not to stand in the way of the caregiving process. Clinicians demand immediate access to their data.”

One of the greatest challenges the hospital faced was securing the network password system, which, according to Ogawa, presents one of the top 10 threats to security. Easy-to-guess passwords are common, he said.

“It would probably shock you, but before HIPAA, youd walk around in ICU, and you would see several notes [with passwords] on each of the monitors,” Ogawa said, adding that resetting passwords costs the hospital $160,000 per year and that employees who forgot passwords could face long delays before regaining access to the network.

The integrated password management and user provisioning system not only improves security, it also improves access to data, Ogawa said. Overall help desk calls dropped by 80 percent, and the hospital is saving $207,000 per year.

Enterprise identity management for public-facing systems can be more complicated, and the growing pool of users alone creates new challenges for privacy, said Paula Arcioni, identity management services manager at the New Jersey Office of Information Technology, in Trenton.

Most services provided by the New Jersey government—the equivalent of a $25 billion enterprise—are not available online. For the services that are online, New Jersey provides single-sign-on anonymous access, maintaining minimal user information, Arcioni said. The system logs a users IP address and host name and the server accessed, but it does not require real names. This system is not practical for many enterprise-level online activities.

Advertisement

“Anonymous access is not easily achievable in your typical high-value transaction,” Arcioni said.

Large organizations in all sectors are increasingly examining new systems of network and plant access. By 2006, one-third of all Fortune 500 companies plan to use smart cards, according to smart-card maker Gemplus International SA. In a survey of 69 Fortune 500 senior executives, Gemplus found that 30 percent of the companies are testing or using smart cards.

Caron Carlson

Caron Carlson

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。