Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • Mobile
    • Storage

    Implement Data-Leak Prevention

    By
    Brian T. Horowitz
    -
    August 14, 2012
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      PrevNext

      1Implement Data-Leak Prevention

      1

      Since data breaches are costly and damaging to any organization’s reputation, health care providers should implement data-leak prevention (DLP) measures to prevent unauthorized leaks of sensitive patient information, Justin Pirie, vice president of cloud strategy at email management firm Mimecast, told eWEEK. Health care providers need to consider deploying a DLP gateway to manage the flow of data in and out, he said. “By implementing a DLP gateway for email, you significantly reduce risks of patient email data leaking,” said Pirie.

      2Encrypt Data in Transit and at Rest

      2

      With mobile devices in doctors’ pockets, sharing patient data is too easy these days, but encryption is essential. “You don’t want to send off patient data over the Internet,” said Pirie. “Email is like a postcard: Anybody can read it unless you encrypt it.” If doctors are using an email management service like Mimecast, they should encrypt email data to avoid packets of information being “sniffed,” he said.

      3Provide HIPAA Training

      3

      Rules such as the Health Insurance Portability and Accountability Act (HIPAA) govern the release of patient information and the more stringent rules for reporting breaches enacted under the 2009 Health Information Technology for Economic and Clinical Health Act. For this reason, health care providers need to provide training for their clinical staff on how to work with data to avoid penalties, Lisa A. Gallagher, senior director for privacy and security at the Healthcare Information and Management Systems Society (HIMSS), told eWEEK in an email. HIMSS is an organization that provides this training to health care providers and security officers.

      4Use Two-Factor Authentication

      4

      A simple username and password aren’t sufficient, according to Drchrono, which offers cloud-based EHR applications for the iPhone and iPad. The company recommends using two-factor authentication and announced on Aug. 13 it had added this functionality to its EHR products. In a two-factor log-in system, clinicians enter a one-time security code before logging in to their Drchrono account with a username and password. Two-factor log-ins will become the industry standard for doctors within five years, Drchrono’s Nusimow predicted.

      5Hire a Chief Privacy Officer

      5

      Health care organizations should add the role of a chief privacy officer (CPO), said Jared Rhoads, a senior research specialist with CSC’s Global Institute for Emerging Healthcare Practices. The CPO would monitor IT systems, establish privacy policies and provide training on maintaining secure data. “A lot of places don’t have a single person whose job it is to oversee this,” Rhoads told eWEEK. The responsibility often lies with the IT department rather than a C-level office, he said. “It’s important when you’re considering changing your health IT environment,” said Rhoads. “By naming a chief privacy officer, you can keep privacy at the forefront, and it’s easy to make privacy and security always part of the discussion.”

      6Perform Security Risk Assessments

      6

      Health care providers should conduct a security risk assessment before they suffer a breach or are audited by compliance authorities, said Rhoads. Organizations should document any risks to a data center or server within 15 days of a federal audit request, he said. “You want to have all of your material written down and up to date,” said Rhoads. “Do remediation along the way so you can save yourself a headache.”

      7Update Policies for Mobile Devices

      7

      With the bring-your-own-device (BYOD) trend catching on in health care, providers need to reestablish policies for mobile devices in medical facilities. Policies on the use of mobile devices may not fit current needs with new smartphones and tablets entering the market. “With iPhones and smartphones having come to the mass audience and integrated into hospitals the last two years, revisiting that [policy] and coming up with basic ideas, things to tell your employees, is a helpful thing to do,” said Rhoads.

      8Limit Local Laptop Storage

      8

      “You can limit certain things on the laptop side,” said Rhoads. He advised using technology that can limit the number of records stored locally. “There isn’t a whole a lot of reason for a nurse to come home with protected health information anyway,” he said.

      9Maintain Policies on Social Media

      9

      Without a clear policy on social media, patient data could end up on Facebook, Twitter or YouTube, Rhoads noted. Health organizations must establish a policy on use of social media. Gossip about patients and bad days at the office doesn’t belong on public online forums, advised Jordan Battani, managing director of CSC’s Global Institute for Emerging Healthcare Practices Group.

      10Use a Certified EHR Application

      10

      When implementing EHR software, providers should use an EHR certified by the Department of Health and Human Services, said Mac McMillan, CEO of CynergisTek, a health care security firm and a former director of security at the Defense Department. For a list of EHRs on the Certified HIT Product List (CHPL), go to HealthIT.HHS.gov.

      PrevNext

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×