Healthcare Executive - September/October 2013 - 28

Protecting Patient Medical Data
of security that protects patients and
helps to ensure compliance with federal and state requirements, Diegel
notes. St. Charles Health System had
been using various forms of encryption for many years, but the theft of a
home health laptop from an employee’s vehicle two years ago highlighted
the value of full disc encryption.
Though no one ever gained access to
the information, continuing with the
full disc encryption of laptops and
desktops became an immediate priority. “We’re obligated to protect our
patients and their information, regardless of regulations or requirements,”
Diegel says. “Yes, it added cost. You
have to invest in the technology.”
The system has implemented sophisticated privacy protection software that
audits users and identifies potential
instances of inappropriate access, use
and disclosure of protected health
information. The message, says
Diegel: “Be on notice that if you inappropriately access records with protected health information or move
records in an unauthorized fashion, it
will be picked up.”
An internal auditor also conducts
regular random spot checks. “We’re

detailed, open and transparent,
and we take it seriously,” Diegel
says. And if a security breach does
occur, “our operating practice is to
make credit monitoring services
available to patients if, for example,
inappropriate use or disclosure of a
patient’s demographic information
has been released. We don’t even
talk about cost.”

or visitors to report ethical and legal
concerns regarding potential security
breaches. “We encourage our employees and the public to disclose if they
see something fishy,” says Diegel.
“Many times we find that the concern
isn’t really valid, but sometimes it
leads to other investigations that have
helped us identify a problem or
improve a process.”

It’s also standard operating practice to
go back and identify what went awry
and then address it using rigorous process improvement methods. When
Diegel’s health information was discovered as part of a security breach
investigation, “my question was,
‘What in the process broke down?
Instead of getting mad, we said, ‘Let’s
make sure this doesn’t happen again.’”

Diegel advises providers to “Be diligent about identifying gaps with your
HIPAA risk assessments. If you do
find gaps, you need a plan of correction to bring you back into compliance as soon as possible. Small leaks
always have the potential to become
large. Always assume the worst.

Though privacy and security issues
tend to be process-related, when people are the cause, St. Charles Health
System draws a hard line. Employees
know that inappropriate access, use
and disclosure of patient information
are not tolerated—and may result in
immediate termination.

“We have a moral obligation as well
as a fiduciary and legal responsibility
to act in our patients’ best interest,”
he says. “I don’t see this as burdensome. I see it as standard operating
practice. If the board of directors and
the CEO aren’t advocating for privacy and security, then who is? For
us, it’s just another way of looking at
patient safety.”

The system also uses a national service, Ethics Point, to allow employees

Susan Birk is a freelance writer based in
Wheaton, Ill.

“ ehaveamoralobligationaswellasafiduciaryandlegalresponsibilitytoactinour
W
patients’bestinterest.…IftheboardofdirectorsandtheCEOaren’tadvocatingforprivacy
andsecurity,thenwhois?Forus,it’sjustanotherwayoflookingatpatientsafety.”
James A. Diegel, FACHE
St.CharlesHealthSystem

28

Healthcare Executive
SEPT/OCT 2013



Healthcare Executive - September/October 2013

Table of Contents for the Digital Edition of Healthcare Executive - September/October 2013

Healthcare Executive - September/October 2013
Contents
ACHE Online
Take Note
Perspectives
Health Information Exchange: Achieving Coordinated Care
Protecting Patient Medical Data: The C-Suite’s Role
Global Lessons for U.S. Healthcare Leaders
Professional Pointers
Healthcare Management Ethics
Satisfying Your Customers
Community Health Innovations
Public Policy Update
Careers
Governance Insights
Improving Patient Care
On Physician Relations
Executive News
CEO Survey
On the Move
Member Accolades
Board Highlights
Chapter News
Professional Development Calendar
Policy Statements
Healthcare Executive - September/October 2013 - Healthcare Executive - September/October 2013
Healthcare Executive - September/October 2013 - Cover2
Healthcare Executive - September/October 2013 - Contents
Healthcare Executive - September/October 2013 - 2
Healthcare Executive - September/October 2013 - 3
Healthcare Executive - September/October 2013 - ACHE Online
Healthcare Executive - September/October 2013 - 5
Healthcare Executive - September/October 2013 - Take Note
Healthcare Executive - September/October 2013 - 7
Healthcare Executive - September/October 2013 - Perspectives
Healthcare Executive - September/October 2013 - 9
Healthcare Executive - September/October 2013 - Health Information Exchange: Achieving Coordinated Care
Healthcare Executive - September/October 2013 - 11
Healthcare Executive - September/October 2013 - 12
Healthcare Executive - September/October 2013 - 13
Healthcare Executive - September/October 2013 - 14
Healthcare Executive - September/October 2013 - 15
Healthcare Executive - September/October 2013 - 16
Healthcare Executive - September/October 2013 - 17
Healthcare Executive - September/October 2013 - 18
Healthcare Executive - September/October 2013 - 19
Healthcare Executive - September/October 2013 - Protecting Patient Medical Data: The C-Suite’s Role
Healthcare Executive - September/October 2013 - 21
Healthcare Executive - September/October 2013 - 22
Healthcare Executive - September/October 2013 - 23
Healthcare Executive - September/October 2013 - 24
Healthcare Executive - September/October 2013 - 25
Healthcare Executive - September/October 2013 - 26
Healthcare Executive - September/October 2013 - 27
Healthcare Executive - September/October 2013 - 28
Healthcare Executive - September/October 2013 - 29
Healthcare Executive - September/October 2013 - 30
Healthcare Executive - September/October 2013 - 31
Healthcare Executive - September/October 2013 - Global Lessons for U.S. Healthcare Leaders
Healthcare Executive - September/October 2013 - 33
Healthcare Executive - September/October 2013 - 34
Healthcare Executive - September/October 2013 - 35
Healthcare Executive - September/October 2013 - 36
Healthcare Executive - September/October 2013 - 37
Healthcare Executive - September/October 2013 - 38
Healthcare Executive - September/October 2013 - 39
Healthcare Executive - September/October 2013 - 40
Healthcare Executive - September/October 2013 - 41
Healthcare Executive - September/October 2013 - Professional Pointers
Healthcare Executive - September/October 2013 - 43
Healthcare Executive - September/October 2013 - 44
Healthcare Executive - September/October 2013 - 45
Healthcare Executive - September/October 2013 - 46
Healthcare Executive - September/October 2013 - 47
Healthcare Executive - September/October 2013 - Healthcare Management Ethics
Healthcare Executive - September/October 2013 - 49
Healthcare Executive - September/October 2013 - Satisfying Your Customers
Healthcare Executive - September/October 2013 - 51
Healthcare Executive - September/October 2013 - 52
Healthcare Executive - September/October 2013 - 53
Healthcare Executive - September/October 2013 - Community Health Innovations
Healthcare Executive - September/October 2013 - 55
Healthcare Executive - September/October 2013 - 56
Healthcare Executive - September/October 2013 - 57
Healthcare Executive - September/October 2013 - Public Policy Update
Healthcare Executive - September/October 2013 - 59
Healthcare Executive - September/October 2013 - 60
Healthcare Executive - September/October 2013 - 61
Healthcare Executive - September/October 2013 - Careers
Healthcare Executive - September/October 2013 - 63
Healthcare Executive - September/October 2013 - Governance Insights
Healthcare Executive - September/October 2013 - 65
Healthcare Executive - September/October 2013 - 66
Healthcare Executive - September/October 2013 - 67
Healthcare Executive - September/October 2013 - Improving Patient Care
Healthcare Executive - September/October 2013 - 69
Healthcare Executive - September/October 2013 - 70
Healthcare Executive - September/October 2013 - 71
Healthcare Executive - September/October 2013 - On Physician Relations
Healthcare Executive - September/October 2013 - 73
Healthcare Executive - September/October 2013 - 74
Healthcare Executive - September/October 2013 - 75
Healthcare Executive - September/October 2013 - Executive News
Healthcare Executive - September/October 2013 - 77
Healthcare Executive - September/October 2013 - 78
Healthcare Executive - September/October 2013 - 79
Healthcare Executive - September/October 2013 - CEO Survey
Healthcare Executive - September/October 2013 - 81
Healthcare Executive - September/October 2013 - On the Move
Healthcare Executive - September/October 2013 - 83
Healthcare Executive - September/October 2013 - Member Accolades
Healthcare Executive - September/October 2013 - 85
Healthcare Executive - September/October 2013 - Board Highlights
Healthcare Executive - September/October 2013 - 87
Healthcare Executive - September/October 2013 - Chapter News
Healthcare Executive - September/October 2013 - 89
Healthcare Executive - September/October 2013 - Professional Development Calendar
Healthcare Executive - September/October 2013 - 91
Healthcare Executive - September/October 2013 - Policy Statements
Healthcare Executive - September/October 2013 - 93
Healthcare Executive - September/October 2013 - 94
Healthcare Executive - September/October 2013 - 95
Healthcare Executive - September/October 2013 - 96
Healthcare Executive - September/October 2013 - Cover3
Healthcare Executive - September/October 2013 - Cover4
https://www.nxtbook.com/nxtbooks/ache/he_20181112
https://www.nxtbook.com/nxtbooks/ache/he_20180910
https://www.nxtbook.com/nxtbooks/ache/he_20180708
https://www.nxtbook.com/nxtbooks/ache/he_20180506
https://www.nxtbook.com/nxtbooks/ache/he_20180304
https://www.nxtbook.com/nxtbooks/ache/he_20180102
https://www.nxtbook.com/nxtbooks/ache/he_20171112
https://www.nxtbook.com/nxtbooks/ache/he_20170910
https://www.nxtbook.com/nxtbooks/ache/he_20170708
https://www.nxtbook.com/nxtbooks/ache/he_20170506
https://www.nxtbook.com/nxtbooks/ache/he_20170304
https://www.nxtbook.com/nxtbooks/ache/he_20170102
https://www.nxtbook.com/nxtbooks/ache/he_20161112
https://www.nxtbook.com/nxtbooks/ache/he_20160910
https://www.nxtbook.com/nxtbooks/ache/he_20160708
https://www.nxtbook.com/nxtbooks/ache/he_20160506
https://www.nxtbook.com/nxtbooks/ache/he_20160304
https://www.nxtbook.com/nxtbooks/ache/he_20160102
https://www.nxtbook.com/nxtbooks/ache/he_20151112
https://www.nxtbook.com/nxtbooks/ache/he_20150910
https://www.nxtbook.com/nxtbooks/ache/he_20150708
https://www.nxtbook.com/nxtbooks/ache/he_20150506
https://www.nxtbook.com/nxtbooks/ache/he_20150304
https://www.nxtbook.com/nxtbooks/ache/he_20150102
https://www.nxtbook.com/nxtbooks/ache/he_20141112
https://www.nxtbook.com/nxtbooks/ache/he_20140910
https://www.nxtbook.com/nxtbooks/ache/he_20140708
https://www.nxtbook.com/nxtbooks/ache/he_20140506
https://www.nxtbook.com/nxtbooks/ache/he_20140304
https://www.nxtbook.com/nxtbooks/ache/he_20140102
https://www.nxtbook.com/nxtbooks/ache/he_20131112
https://www.nxtbook.com/nxtbooks/ache/he_20130910
https://www.nxtbook.com/nxtbooks/ache/he_20130708
https://www.nxtbook.com/nxtbooks/ache/he_20130506
https://www.nxtbook.com/nxtbooks/ache/he_20130304
https://www.nxtbook.com/nxtbooks/ache/he_20130102
https://www.nxtbookmedia.com