Skip to main content

The Privacy & Security Mobile Device Project

Recently, ONC’s Office of the Chief Privacy Officer (OCPO), in collaboration with the HHS Office for Civil Rights (OCR), launched a Privacy & Security Mobile Device project.

The project goal is to better secure and protect health information on mobile devices (e.g., laptops, tablets, and smartphones). Building on the existing HHS HIPAA Security Rule - Remote Use Guidance, the project is designed to identify privacy and security best practices for devices that are are used outside healthcare facilities or not directly under IT department control.

The HHS Remote Use Guidance may not be familiar to clinicians and IT professionals.   It was issued on 12/28/2006 and includes specific recommendations for the use of Electronic Protected Health Information (EPHI) on mobile devices, specifically (1) the use of portable media/devices (such as USB flash drives) that store EPHI and (2) offsite access or transport of EPHI via laptops, smart phones, home computers or other non corporate equipment.

The report groups its recommendations into three areas: access, storage and transmission.

Access

Username/password protection -  to reduce the risk of keystroke loggers or stolen passwords, it recommends two factor authentication - something that you know and something that you have.

Remote access - to minimize the risk of privacy breaches, it recommends role-based access control for remote data access in combination with policies which delineate who is authorized use remote access methods.

Unattended devices - to minimize the risk of privacy breaches by those who may find a lost or unattended device, it recommends timeouts on any software used to access EPHI

Malware -  to minimize the damage done by the increasing flood of malware on the internet, it recommends personal firewalls and appropriate use of up to date anti-virus tools

Storage

Theft risk mitigation - to reduce the risk of breach when a device is lost or stolen, it recommends encryption, biometric authentication methods, and strong mobile device storage policies

Lifecycle management - to reduce the risk of data loss when a mobile device is retired it recommends  deletion/physical destruction of devices

Data cached on non-owned device - to minimize the risk that data will be left on public computers used to access EPHI remotely, it recommends training, prohibition on downloading  files containing EPHI, and application software configurations that eliminate browser caching

Transmission 

Off network transmission - to minimize the risk of interception, it recommends that all data transmissions require SSL, TLS, or VPN in addition to policies requiring encryption of all data in motion between organizations.

These are guidelines, not regulations, but you can bet the next time CMS/OCR investigates a breach, they will ask if you have followed the published recommendations for  access, storage and transmission.  Thus, I highly recommend you read the HHS guidance and incorporate their suggestions into your overall security program.

Comments

Popular posts from this blog

clip on magnetic sunglasses visit here

Save with prescription glasses and sunglasses. Prescription eyeglasses with magnetic clip on sunglasses. A wide selection of colors and styles for every budget! -GlassesPoint. Prescription eyeglasses with magnetic clip on sunglasses. A wide selection of colors and styles for every budget! Free magnetic clip on with every pair of glasses.  The operator should contact lens Plano glasses a few days of Sun and Rx on the other person. Many people choose single vision lenses, designed for a specific use, such as prescription sunglasses. Clip-ons magnetic magnetic clip ons often come with their prescription glasses frames. Prescription glasses Goggles4u dollars from 29.99 with free shipping. Takumi neodium magnet glass features recipes that are light, strong and in. The combination of some normal prescription glasses and a pair of polarized glasses that glare-resistant to outdoor activities. clip on magnetic sunglasses visit here

t shirt maker visit here

Who doesn't love the Tunnock tea cake? Crea mola foam? Pride of Scotland only bread ... with square sausage sandwiched in the segment of Sunday morning? I would love to meet your custom tshirt supplier and I just discovered jumping stable in Glasgow's Central St. Gillian Kyle is a young artist in Glasgow who develop custom t-shirts and other products that are worth a look. t shirt maker visit here

t shirt maker cheap online visit here

Design your own t-shirts online and custom shirt maker online Exclusive collection for women's clothing in the West at http://t-shirt-Maker.Page.TL/, photo t-shirts in India, send a photo t-shirt to write India slogan t-shirts, custom t-shirts online, order photo t-shirts, printed t-shirts online.    t shirt maker cheap online visit here