NAAC Announces HIPAA Compliance Program for Ambulance Privacy Officers
NAAC – The National Academy of Ambulance Compliance – has announced that it will be launching the nation’s first Certified Ambulance Privacy Officer (CAPO) program to help ambulance professionals comply with the Health Insurance Portability and Accessibility Act of 1996 (HIPAA) and its subsequent amendments. “The Certified Ambulance Privacy Officer program is a ground-breaking opportunity for an industry that often struggles with the difficult challenges that HIPAA presents,” according to National EMS attorney, Steve Wirth; one of the developers of the HIPAA compliance program. The healthcare industry has been hit with a number of high profile breaches in recent years and millions of individuals have had their protected health information exposed. The industry faces an increased threat of targeted attacks by cybercriminals looking to steal data to commit identify and medical fraud and the penalties for HIPAA violations as considerable. The OCR has been enforcing HIPAA more aggressively since the introduction of the HITECH Act and substantial financial penalties are being...
Email HIPAA Breach Reported by St. Louis County Health Department
St. Louis County Health Department has reported that a former employee has inadvertently breached the Health Insurance Portability and Accountability Act after she sent an email containing Protected Health Information to her personal email account. The data related to inmates who had previously been held at the Buzz Westfall Justice Center between 2008 and 2014. The data was contained in a document and included Social Security numbers and personal information. It is not clear at this stage why the document was sent to the employees email account and whether this was for the purpose of working from home or to use the data for any other means. St. Louis County Department of Health spokesman, Craig LeFebvre, issued a statement to the media regarding the breach in which he said that the employee was contacted and told to delete the document and she is understood to have complied with the request; although an investigation into the security breach is ongoing. Under the HIPAA Breach Notification Rule, all covered entities are required to notify individuals affected by a data breach...
Obamas Cybersecurity Plan Could Preempt HIPAA
This week President Obama announced a number of new initiatives aimed and improving cybersecurity to better protect consumers. 2014 was a year that saw hackers successfully gain access to the computer systems of retailers, corporations, healthcare providers, educational institutions and even the Pentagons Twitter account was successfully hacked. Cybercriminals were able to steal and expose personal and corporate data, commit identity fraud, obtain Medicare and Medicaid services and make fraudulent insurance claims, and the threats remain for those individuals affected. The volume of electronic personal data now being stored means security breaches can easily affect many millions of individuals. Last year U.S. companies – and many healthcare organizations – were targeted by criminals and highly complex attacks exposed financial and personal consumer data on a grand scale. Home Depot hackers stole the credit card information and personal data of 56 million Americans. Hackers were able to obtain 40 million credit card numbers from Target as well as the personal information of...
Federal Advisers to Propose Legislative Changes Covering Big Data
The Health IT Policy Committee’s Privacy and Security Workgroup has been assessing a number of Big Data issues affecting the privacy and security of patients following on from two public hearings hosted by the group in December last year. The ultimate aim is for the workgroup to make a number of recommendations on policy to the Office of the National Coordinator for Health IT, and ultimately to have these recommendations incorporated into new federal DHHS policies. The public hearings allowed stakeholders to voice their concerns about the use of big data in healthcare, as well as to highlight the benefits it can bring such as improving patient care and treatment outcomes, while reducing operational costs. There is naturally a balance to be struck to ensure the benefits can be gained while privacy risks to individuals are minimized. Having gained valuable information at the hearings, the workgroup now has the task of assessing current policies and determining whether the right framework is in place to gain the all important benefits while protecting patient privacy. A number...
Lack of Mobile Device IT Support in Hospitals Frustrates Physicians
According to a recent report by Spyglass Consulting, the use of Smartphones and tablets by doctors has now risen to an estimated 96%; yet only ten percent of those physicians are willing to use their own devices to communicate or access the electronic health records of their patients. Furthermore, a lack of support from hospital IT departments negates much of the usefulness of these devices in a healthcare environment. One of the major problems comes from a lack of suitable EMR tools provided by the hospital. Many hospitals and clinics are opting for desktop virtualization tools such as those provided by Citrix, and while in theory these tools should work, in practice the system is despised by physicians because of the frequent crashes and user-unfriendly navigation. There is a lack of investment in IT infrastructure according to Spyglass MD, Gregg Malkary. He believes many hospitals that are not part of Meaningful Use are unwilling to make the necessary investments in mobile technology. Spyglass spoke with 100 doctors up to date with current technology as part of its research for...



