Healthcare Executive - September/October 2013 - 24

Protecting Patient Medical Data
evaluations; and daily huddles to discuss patients on the floor who might
spark curiosity—and inappropriate
intrusion into their health information.

business agreements cover how information is protected and when policies
and procedures should be reviewed?”
she says.

Still, “no matter how many safeguards
you have in place, there is always room
for improvement,” Gordon adds. “And if
you find a problem, you have to dig.
Where there’s smoke, there’s fire. It might
be just one department, but you need to
know. That’s why you need to audit.”

Failure among providers to perform the
security risk analysis required by HIPAA
since 2003 also persists, Pritts says.
Surveys during the past 10 years consistently show compliance hovering at 75
percent. “That’s the good news. But
where are the other 25 percent?” she says.

The federal requirement for patient
data breach notification—in place
since 2009 and which became more
stringent this year with the new
HIPAA Omnibus Rule—has shed
valuable light on where providers can
do better, reports Pritts. Device loss
and theft is a major one. So is encryption, particularly the encryption of
mobile devices. Tablet and smart
phone use in healthcare has exploded,
but mobile device security lags seriously behind, she says.

To spotlight the problem, ONC
worked with the Centers for Medicare
& Medicaid Services to incorporate
the HIPAA Privacy and Security Rule
into the meaningful use requirements
for EHRs. “If we’re going to pay you
to adopt EHRs, this is one thing we
want to make sure you do,” Pritts says.
She expects to see a rise in compliance
when data on Stage 2 meaningful use
implementation become available
within the next two years.

According to Gordon, agreements
with business associates warrant careful attention as well. “Are you making
sure, as vendors come in and information is passed back and forth, that your

Providence Health
& Services
Providence Health & Services,
Renton, Wash., has embedded a cadre
of privacy officers and information
security officers in the organization’s

business units and regional operations,
which include 32 hospitals in five states.
These professionals guide privacy and
security policy and procedure implementation at the local and regional levels
with an eye on data protection as well
as consideration for clinicians’ special
needs.
“Having these people out there as part
of how we operate has made a huge
difference,” says Eric Cowperthwaite,
chief security officer. “It’s not just me
sitting in an ivory tower at system
headquarters sending out policies from
on high. These are people with whom
hospital and regional executives can
interact every day.”
That degree of attention to patient
data protection did not happen overnight. “We came to the conclusion
six or seven years ago that we had to
be part of the hospital-level culture
in order to be effective,” he says. The
process started with the development
of regional security teams. It also
involved a great deal of collaboration
with regional staff to gain their
trust that privacy and security would
protect patient information without
interfering with the delivery of care.

“t’seasytoseethereturnoninvestmentwhenyou’regettingmedicalalerts
I
thatcansavelives.It’snotsoeasytoidentifythebenefitsofprivacyand
security.Whenthey’reworking,youdon’thearaboutit.”
Joy Pritts
OfficeoftheNationalCoordinatorforHealthInformationTechnology,
U.S.DepartmentofHealthandHumanServices

24

Healthcare Executive
SEPT/OCT 2013



Healthcare Executive - September/October 2013

Table of Contents for the Digital Edition of Healthcare Executive - September/October 2013

Healthcare Executive - September/October 2013
Contents
ACHE Online
Take Note
Perspectives
Health Information Exchange: Achieving Coordinated Care
Protecting Patient Medical Data: The C-Suite’s Role
Global Lessons for U.S. Healthcare Leaders
Professional Pointers
Healthcare Management Ethics
Satisfying Your Customers
Community Health Innovations
Public Policy Update
Careers
Governance Insights
Improving Patient Care
On Physician Relations
Executive News
CEO Survey
On the Move
Member Accolades
Board Highlights
Chapter News
Professional Development Calendar
Policy Statements
Healthcare Executive - September/October 2013 - Healthcare Executive - September/October 2013
Healthcare Executive - September/October 2013 - Cover2
Healthcare Executive - September/October 2013 - Contents
Healthcare Executive - September/October 2013 - 2
Healthcare Executive - September/October 2013 - 3
Healthcare Executive - September/October 2013 - ACHE Online
Healthcare Executive - September/October 2013 - 5
Healthcare Executive - September/October 2013 - Take Note
Healthcare Executive - September/October 2013 - 7
Healthcare Executive - September/October 2013 - Perspectives
Healthcare Executive - September/October 2013 - 9
Healthcare Executive - September/October 2013 - Health Information Exchange: Achieving Coordinated Care
Healthcare Executive - September/October 2013 - 11
Healthcare Executive - September/October 2013 - 12
Healthcare Executive - September/October 2013 - 13
Healthcare Executive - September/October 2013 - 14
Healthcare Executive - September/October 2013 - 15
Healthcare Executive - September/October 2013 - 16
Healthcare Executive - September/October 2013 - 17
Healthcare Executive - September/October 2013 - 18
Healthcare Executive - September/October 2013 - 19
Healthcare Executive - September/October 2013 - Protecting Patient Medical Data: The C-Suite’s Role
Healthcare Executive - September/October 2013 - 21
Healthcare Executive - September/October 2013 - 22
Healthcare Executive - September/October 2013 - 23
Healthcare Executive - September/October 2013 - 24
Healthcare Executive - September/October 2013 - 25
Healthcare Executive - September/October 2013 - 26
Healthcare Executive - September/October 2013 - 27
Healthcare Executive - September/October 2013 - 28
Healthcare Executive - September/October 2013 - 29
Healthcare Executive - September/October 2013 - 30
Healthcare Executive - September/October 2013 - 31
Healthcare Executive - September/October 2013 - Global Lessons for U.S. Healthcare Leaders
Healthcare Executive - September/October 2013 - 33
Healthcare Executive - September/October 2013 - 34
Healthcare Executive - September/October 2013 - 35
Healthcare Executive - September/October 2013 - 36
Healthcare Executive - September/October 2013 - 37
Healthcare Executive - September/October 2013 - 38
Healthcare Executive - September/October 2013 - 39
Healthcare Executive - September/October 2013 - 40
Healthcare Executive - September/October 2013 - 41
Healthcare Executive - September/October 2013 - Professional Pointers
Healthcare Executive - September/October 2013 - 43
Healthcare Executive - September/October 2013 - 44
Healthcare Executive - September/October 2013 - 45
Healthcare Executive - September/October 2013 - 46
Healthcare Executive - September/October 2013 - 47
Healthcare Executive - September/October 2013 - Healthcare Management Ethics
Healthcare Executive - September/October 2013 - 49
Healthcare Executive - September/October 2013 - Satisfying Your Customers
Healthcare Executive - September/October 2013 - 51
Healthcare Executive - September/October 2013 - 52
Healthcare Executive - September/October 2013 - 53
Healthcare Executive - September/October 2013 - Community Health Innovations
Healthcare Executive - September/October 2013 - 55
Healthcare Executive - September/October 2013 - 56
Healthcare Executive - September/October 2013 - 57
Healthcare Executive - September/October 2013 - Public Policy Update
Healthcare Executive - September/October 2013 - 59
Healthcare Executive - September/October 2013 - 60
Healthcare Executive - September/October 2013 - 61
Healthcare Executive - September/October 2013 - Careers
Healthcare Executive - September/October 2013 - 63
Healthcare Executive - September/October 2013 - Governance Insights
Healthcare Executive - September/October 2013 - 65
Healthcare Executive - September/October 2013 - 66
Healthcare Executive - September/October 2013 - 67
Healthcare Executive - September/October 2013 - Improving Patient Care
Healthcare Executive - September/October 2013 - 69
Healthcare Executive - September/October 2013 - 70
Healthcare Executive - September/October 2013 - 71
Healthcare Executive - September/October 2013 - On Physician Relations
Healthcare Executive - September/October 2013 - 73
Healthcare Executive - September/October 2013 - 74
Healthcare Executive - September/October 2013 - 75
Healthcare Executive - September/October 2013 - Executive News
Healthcare Executive - September/October 2013 - 77
Healthcare Executive - September/October 2013 - 78
Healthcare Executive - September/October 2013 - 79
Healthcare Executive - September/October 2013 - CEO Survey
Healthcare Executive - September/October 2013 - 81
Healthcare Executive - September/October 2013 - On the Move
Healthcare Executive - September/October 2013 - 83
Healthcare Executive - September/October 2013 - Member Accolades
Healthcare Executive - September/October 2013 - 85
Healthcare Executive - September/October 2013 - Board Highlights
Healthcare Executive - September/October 2013 - 87
Healthcare Executive - September/October 2013 - Chapter News
Healthcare Executive - September/October 2013 - 89
Healthcare Executive - September/October 2013 - Professional Development Calendar
Healthcare Executive - September/October 2013 - 91
Healthcare Executive - September/October 2013 - Policy Statements
Healthcare Executive - September/October 2013 - 93
Healthcare Executive - September/October 2013 - 94
Healthcare Executive - September/October 2013 - 95
Healthcare Executive - September/October 2013 - 96
Healthcare Executive - September/October 2013 - Cover3
Healthcare Executive - September/October 2013 - Cover4
https://www.nxtbook.com/nxtbooks/ache/he_20181112
https://www.nxtbook.com/nxtbooks/ache/he_20180910
https://www.nxtbook.com/nxtbooks/ache/he_20180708
https://www.nxtbook.com/nxtbooks/ache/he_20180506
https://www.nxtbook.com/nxtbooks/ache/he_20180304
https://www.nxtbook.com/nxtbooks/ache/he_20180102
https://www.nxtbook.com/nxtbooks/ache/he_20171112
https://www.nxtbook.com/nxtbooks/ache/he_20170910
https://www.nxtbook.com/nxtbooks/ache/he_20170708
https://www.nxtbook.com/nxtbooks/ache/he_20170506
https://www.nxtbook.com/nxtbooks/ache/he_20170304
https://www.nxtbook.com/nxtbooks/ache/he_20170102
https://www.nxtbook.com/nxtbooks/ache/he_20161112
https://www.nxtbook.com/nxtbooks/ache/he_20160910
https://www.nxtbook.com/nxtbooks/ache/he_20160708
https://www.nxtbook.com/nxtbooks/ache/he_20160506
https://www.nxtbook.com/nxtbooks/ache/he_20160304
https://www.nxtbook.com/nxtbooks/ache/he_20160102
https://www.nxtbook.com/nxtbooks/ache/he_20151112
https://www.nxtbook.com/nxtbooks/ache/he_20150910
https://www.nxtbook.com/nxtbooks/ache/he_20150708
https://www.nxtbook.com/nxtbooks/ache/he_20150506
https://www.nxtbook.com/nxtbooks/ache/he_20150304
https://www.nxtbook.com/nxtbooks/ache/he_20150102
https://www.nxtbook.com/nxtbooks/ache/he_20141112
https://www.nxtbook.com/nxtbooks/ache/he_20140910
https://www.nxtbook.com/nxtbooks/ache/he_20140708
https://www.nxtbook.com/nxtbooks/ache/he_20140506
https://www.nxtbook.com/nxtbooks/ache/he_20140304
https://www.nxtbook.com/nxtbooks/ache/he_20140102
https://www.nxtbook.com/nxtbooks/ache/he_20131112
https://www.nxtbook.com/nxtbooks/ache/he_20130910
https://www.nxtbook.com/nxtbooks/ache/he_20130708
https://www.nxtbook.com/nxtbooks/ache/he_20130506
https://www.nxtbook.com/nxtbooks/ache/he_20130304
https://www.nxtbook.com/nxtbooks/ache/he_20130102
https://www.nxtbookmedia.com