From: GovernmentHealthIT
Anthony Brino, Associate Editor
The Department of Health and Human Services has launched a mobile health privacy and security education campaign, aimed at giving a framework for providers just starting to use mobile devices.
Called “Know the RISKS,” the campaign features a variety of recommendations and materials, including a short YouTube video explaining the intersection of HIPAA and mobile devices.
The agency has a five-point recommendation plan for providers: “Decide, assess, identify, develop and train.”
First, the agency says, providers should “decide whether mobile devices will be used to access, receive, transmit or store patients’ health information, or used as part of your organization’s internal networks or (EHR) systems.”
Next, the agency says, providers need to perform a risk analysis to determine potential data loss or breach threats and scenarios. And in addition to developing organization-wide mobile policies and procedures, training staff is crucial, the agency says.
“Safeguards will not protect health information unless the workforce is aware of its role in following and enforcing those safeguards,” the agency says.
Large health systems may be way ahead of HHS on all of this. But as smaller providers start using mobile devices as part of clinical care and documentation, HHS says, it’s important that they know what they’re getting into.
“The use of mobile health technology holds great promise in improving health and health care,” Joy Pritts, the ONC’s chief privacy officer, said. “But the loss of health information can have a devastating impact on the trust that patients have in their providers. Health care providers, administrators and their staffs must create a culture of privacy and security across their organizations to ensure the privacy and security of their patients’ protected health information.”
While privacy and security risks may still plague healthcare, for mobile devices and IT systems in general, healthcare organizations are starting to embrace prevention tools. Nearly 90 percent of health organizations surveyed in the 2012 HIMSS mobile technology report said they use data encryption for their mobile devices — up from 73 percent in 2011.
Leave a Reply