Mike Miliard
The massive rollout will require a coordinated effort by clinical, business and information technology stakeholders, says Defense Health Agency's William Roberts.
Technology alone won't make successful implementations, a culture change has to follow suit, according to University of South Carolina's Elizabeth Regan.
Single points of failure could open the door for hackers to take out significant portions of a hospital's medical network, expert at HIMSS16 says.
The new software combines analytics, patient outreach, telehealth and administrative tools to help providers adjust to new reimbursement reality with a 'lifecycle' approach to value-based care.
CHIME touts OpenNotes partnership, early success of National Patient ID Challenge; opening keynoter talks challenges and opportunities of patient-generated data.
A new agreement with FHA will allow DirectTrust's federal partners to operate their Direct implementations within its Security and Trust Framework.
The industry veteran also said that visionary CIOs will start to think about limiting EHR exposure to other tasks.
Cybersecurity concerns have become much more than a hypothetical for vulnerable hospitals, most of whom are finally realizing just how vulnerable they are. So it’s no surprise that IT security vendors will surely be among the most visited booths on the HIMSS16 exhibit floor.
Among those: Imprivata will be showcasing the expanded capabilities of its Confirm ID technology, touting new remote access features and two-factor authentication for medical devices.
Initially launched in early 2015 as a comprehensive security tool for e-prescribing of controlled substances, Confirm ID helps providers meet DEA requirements for EPCS while also simplifying eRx workflows in general.
The new platform aims to address, on an enterprise level, other cybersecurity imperatives such as remote employee access, medical device security and in-process authentication for clinical transactions, officials said.
[HIMSS16 survival guide: what you need to know now]
"As healthcare goes digital, critical clinical workflows are using simple usernames and passwords to provide access, making patient information easily vulnerable to hacking," Imprivata CEO Omar Hussain said in a prepared statement.
Imprivata officials said Confirm ID enables fast and secure authentication, protecting workflows against hacking and leaving an auditable "chain of trust" wherever users interact with patient records, financial information or other sensitive data.
"A single, centralized authentication management platform improves security and compliance auditing across the enterprise by enabling better control over how, when, and where users interact with patient records and other sensitive information," added Aaron Miri, chief information officer of Dallas-based Walnut Hill Medical Center.
Miri will discuss Walnut Hill’s use of Imprivata’s identity management and security tools at HIMSS16. Others include Martin Littmann, CTO and CISO at Kelsey-Seybold Clinic, who will present on sstrategies and best practices for achieving EPCS Success, and Rebecca Carter, director of informatics at Bon Secours St. Francis Health System, who will talk about improving patient safety and reducing duplicate records with biometric patient ID.
Plenty of industry partners will also be touting their Imprivata collaborations, with vendors including Allscripts (booth #2612), Cerner (#2032), Citrix (#3412), First Databank (FDB) (#1143), HP (#1332), MEDHOST (#3821), Nuance Communications (#2612), Samsung (#724) and VMware (#2221) displaying the company's tools in their in booths.
Imprivata, meanwhile, can be found at booth #3403.
Twitter: @MikeMiliardHITN
This story is part of our ongoing coverage of the HIMSS16 conference. Follow our live blog for real-time updates, and visit Destination HIMSS16 for a full rundown of our reporting from the show. For a selection of some of the best social media posts of the show, visit our Trending at #HIMSS16 hub.
The Ottawa-based Rich said he’s most interested in learning about the challenges of getting patients engaged via new technologies and the quest to integrate digital health into their lives.
Aiming to help HIPAA covered entities strengthen their cybersecurity preparedness, HHS Office for Civil Rights has published a crosswalk identifying mappings between NIST's Framework for Improving Critical Infrastructure Cybersecurity and the HIPAA Security Rule.
Developed in partnership with NIST and ONC, the crosswalk also includes mappings to other commonly used security frameworks, officials said.
In February 2014, NIST released the framework to help organizations better understand and manage cybersecurity risks. Many organizations in healthcare and other industries voluntarily rely on detailed security guidance and specific standards issued by NIST.
[Also: HIMSS presses NIST to keep cybersecurity framework voluntary]
Entities bound by HIPAA, meanwhile, are required to implement strong data security safeguards to comply with the HIPAA Security Rule and protect the health data they create, receive, maintain or transmit.
"We hear frequently from covered entities and business associates who said they are working hard in an increasingly challenging atmosphere to assure their PHI is adequately protected," OCR officials said. "We also know from our HIPAA enforcement work that far too frequently entities are leaving PHI vulnerable to breach and access by unauthorized persons."
The goal with this new crosswalk is to help health organizations that have aligned their security programs to either the NIST Cybersecurity Framework or the HIPAA Security Rule to identify potential gaps in their programs, they said.
[Also: Cybersecurity Information Sharing Act sails through Senate]
By addressing those gaps, covered entities can improve their compliance with the Security Rule and better protect patient data.
OCR noted that the HIPAA is meant to be flexible, scalable and technology-neutral, enabling it to better integrate with frameworks such as the NIST's.
[Like Healthcare IT News on Facebook]
The Security Rule doesn't mandate use of the NIST Cybersecurity Framework, officials said – and at the same time, use of the framework doesn't guarantee HIPAA compliance. But the crosswalk is meant as a tool to help health organizations manage security risks in a more comprehensive way.
Noting that both the HITECH Act of 2009 and the Cybersecurity Information Sharing Act passed this past October called for guidance on implementation of NIST frameworks, OCR officials said the crosswalk "provides a helpful roadmap for HIPAA covered entities and their business associates to understand the overlap between the NIST Cybersecurity Framework, the HIPAA Security Rule, and other security frameworks that can help entities safeguard health data in a time of increasing risks."
Twitter: @MikeMiliardHITN