HIPAA-Compliant Data Centers
The resources required to set up and maintain an on-premises data center are considerable, so it is no surprise that many healthcare providers are turning to the cloud and are using third-party HIPAA data centers to cut costs. The healthcare industry is under increasing pressure to improve efficiency and patient privacy protections while reducing healthcare costs. The data center is one area where all three can be achieved. By outsourcing the data center, privacy and security protections can be improved, the physical space occupied by the in-house data center can be put to profit-making use, and costs can be significantly reduced. HIPAA-compliant data centers can be set up to provide the same or greater level of performance as in-house data centers, the only difference being where the data is stored. Rather than use in house IT equipment that is expensive to purchase and maintain, healthcare providers just rent the capacity from a cloud service provider. The service provider is responsible for the hardware and infrastructure that supports their data centers, as well as implementing...
HIPAA-Compliant Cloud Hosting
Healthcare organizations have a tremendous amount to gain from moving their applications and infrastructure to the cloud, and an increasing number are turning to HIPAA cloud hosting companies to provide the infrastructure and security to allow patient information to be moved from on-premise applications to the cloud. HIPAA and Cloud Computing There has been a proliferation of cloud computing solutions in recent years, which have been widely adopted across all industry sectors. Healthcare organizations were slow to embrace the cloud at first, but now most healthcare companies are running multiple cloud applications and an increasing number are now using cloud-based infrastructure and cloud-data centers. The cloud has allowed healthcare organizations to improve efficiency, become more agile, and reduce costs. Healthcare providers, health plans, healthcare clearinghouses, and business associates of HIPAA-covered entities are permitted to move their data centers and IT infrastructure to the cloud, but before any electronic protected health information (ePHI) is transferred outside the...
H1, 2024 Healthcare Data Breach Report
Several major healthcare cyberattacks have been reported in the first half of 2024, including a ransomware attack on Ascension that took its electronic medical record system out of action for a month and a ransomware attack on Change Healthcare that caused massive disruption for providers across the country due to the unavailability of Change Healthcare’s platform. The amount of data stolen in the Change Healthcare attack is eye-watering, potentially the protected health information of 1 in 3 Americans – More than 110 million individuals. While these two data breaches could both be massive, at the time of publication, the scale of these data breaches has still not been confirmed. The Ascension data breach was reported to the HHS’ Office for Civil Rights (OCR) in July 2024 and only with a placeholder of 500 individuals due to the ongoing investigation, and while Change Healthcare has started sending notification letters, the breach has yet to be reported to OCR. About Our H1, 2024 Healthcare Data Breach Report The data on which our H1, 2024 Healthcare Data Breach Report is based...
What is PCI Compliance in Healthcare?
PCI compliance in healthcare means securing payment account data in compliance with the Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 when payment account data are maintained separately from Protected Health Information. The failure to comply with PCI DSS can result in the loss of merchant accounts, fines, and civil actions. The PCI DSS (Payment Card Industry Data Security Standard) is an information security standard designed to reduce payment card fraud by increasing security controls around cardholder data and sensitive authentication data. All organizations that process, store, and transmit payment account date are required to comply with PCI DSS unless a federal, state, or industry standard provides greater protection to payment account data than PCI DSS. In the healthcare industry, the HIPAA Administrative Simplification Regulations (“HIPAA”) protect the privacy and security of individually identifiable health information. Any non-health information stored in a designated record set with individually identifiable health information assumes the same protections...
HHS Restructures to Consolidate Technology, Cybersecurity, Data, AI, and HealthIT
The Department of Health and Human Services (HHS) has announced a major restructuring that will allow the department to streamline its operations and more effectively prioritize the use of digital and emerging capabilities such as artificial intelligence. Work related to technology, cybersecurity, and data has historically been distributed across three HHS departments: The Office of the National Coordinator for Health Information Technology (ONC), the Assistant Secretary for Administration (ASA), and the Administration for Strategic Preparedness and Response (ASPR). Opportunities in these areas have grown considerably in recent years, and now is the time to streamline operations and have all tech-centric work handled by a single HHS organization. The ONC will be renamed the Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC), which will be tasked with oversight of technology, data, and artificial intelligence policy and strategy, taking over these oversight roles from the ASA. ASTP/ONC will also be tasked...



