Skip to main content

The Privacy & Security Mobile Device Project

Recently, ONC’s Office of the Chief Privacy Officer (OCPO), in collaboration with the HHS Office for Civil Rights (OCR), launched a Privacy & Security Mobile Device project.

The project goal is to better secure and protect health information on mobile devices (e.g., laptops, tablets, and smartphones). Building on the existing HHS HIPAA Security Rule - Remote Use Guidance, the project is designed to identify privacy and security best practices for devices that are are used outside healthcare facilities or not directly under IT department control.

The HHS Remote Use Guidance may not be familiar to clinicians and IT professionals.   It was issued on 12/28/2006 and includes specific recommendations for the use of Electronic Protected Health Information (EPHI) on mobile devices, specifically (1) the use of portable media/devices (such as USB flash drives) that store EPHI and (2) offsite access or transport of EPHI via laptops, smart phones, home computers or other non corporate equipment.

The report groups its recommendations into three areas: access, storage and transmission.

Access

Username/password protection -  to reduce the risk of keystroke loggers or stolen passwords, it recommends two factor authentication - something that you know and something that you have.

Remote access - to minimize the risk of privacy breaches, it recommends role-based access control for remote data access in combination with policies which delineate who is authorized use remote access methods.

Unattended devices - to minimize the risk of privacy breaches by those who may find a lost or unattended device, it recommends timeouts on any software used to access EPHI

Malware -  to minimize the damage done by the increasing flood of malware on the internet, it recommends personal firewalls and appropriate use of up to date anti-virus tools

Storage

Theft risk mitigation - to reduce the risk of breach when a device is lost or stolen, it recommends encryption, biometric authentication methods, and strong mobile device storage policies

Lifecycle management - to reduce the risk of data loss when a mobile device is retired it recommends  deletion/physical destruction of devices

Data cached on non-owned device - to minimize the risk that data will be left on public computers used to access EPHI remotely, it recommends training, prohibition on downloading  files containing EPHI, and application software configurations that eliminate browser caching

Transmission 

Off network transmission - to minimize the risk of interception, it recommends that all data transmissions require SSL, TLS, or VPN in addition to policies requiring encryption of all data in motion between organizations.

These are guidelines, not regulations, but you can bet the next time CMS/OCR investigates a breach, they will ask if you have followed the published recommendations for  access, storage and transmission.  Thus, I highly recommend you read the HHS guidance and incorporate their suggestions into your overall security program.

Comments

Popular posts from this blog

clip on magnetic sunglasses visit here

Save with prescription glasses and sunglasses. Prescription eyeglasses with magnetic clip on sunglasses. A wide selection of colors and styles for every budget! -GlassesPoint. Prescription eyeglasses with magnetic clip on sunglasses. A wide selection of colors and styles for every budget! Free magnetic clip on with every pair of glasses.  The operator should contact lens Plano glasses a few days of Sun and Rx on the other person. Many people choose single vision lenses, designed for a specific use, such as prescription sunglasses. Clip-ons magnetic magnetic clip ons often come with their prescription glasses frames. Prescription glasses Goggles4u dollars from 29.99 with free shipping. Takumi neodium magnet glass features recipes that are light, strong and in. The combination of some normal prescription glasses and a pair of polarized glasses that glare-resistant to outdoor activities. clip on magnetic sunglasses visit here

The Tragedy of Underfunded Mental Health Care

Today’s Managing Health Care Costs Indicator is   19,900 The NY Times  on Friday had a deeply disturbing article on a murder that stunned the mental health community here in Massachusetts.    A long-term schizophrenic man, off his medicine and spiraling into incoherence, killed a young female counselor who was the sole worker at a group home in a Boston suburb.   His mother, who works at a Boston teaching hospital, was frantic with worry as her adult son, who had been arrested for assault multiple times, was becoming more psychotic.    It was hard for her to get anyone’s attention. The counselor was the first in her family to get a college degree, and had just decided to go to nursing school.    Now she’s dead – and her family had trouble scraping together the resources for a burial.   The schizophrenic will be imprisoned for the rest of his life – which ironically could be the best chance for him to get appropriate medical care. Both...

How a Well-Intended FDA Policy on Colchicine is Harming Patients

The road to hell is paved with good intentions. The FDA has reaffirmed the truth of this aphorism with its policy about Colchicine. Here's the story: I recently spoke with a friend who has a family member suffering from Familial Mediterranean Fever (FMF), an auto-inflammatory disorder, most commonly seen in eastern Mediterranean populations. The condition is characterized by recurrent painful inflammation of the abdomen, chest and joints, accompanied by fever. FMF is associated with mutation of a gene on chromosome 16 involved with regulating Pyrin, a protein that is part of the inflammatory response. There is no specific test for the disease. Diagnosis is made on the basis of symptoms, family history, and ruling out other conditions. Since the 1960s, Colchicine, a plant extract first used for treatment of gout two thousand years ago, has been used for treating FMF. As an ancient treatment widely used prior to formation of the FDA, Colchicine did not require FDA approval as a new ...