Skip to main content

News

By Bill Siwicki | 10:47 am | July 05, 2017
There is a significant gap between threats organizations face and their readiness to address those in a timely or effective manner.
By Tom Sullivan | 10:01 am | July 05, 2017
But almost half the money went toward research, officials said.
By Jessica Davis | 03:43 pm | June 30, 2017
Princeton Community Hospital fell victim to the global NotPetya attack on Tuesday and plans to replace the corrupted network with a newly built system.
By Jessica Davis | 02:54 pm | June 30, 2017
Leveraging the VA’s Tele-ICU equipment, patients in five Air Force facilities will gain electronic access and remote monitoring capabilities to VA doctors and nurses.
By Tom Sullivan | 02:22 pm | June 30, 2017
The hospitals consumers can now read what doctors write about them, message care teams and participate in eVisits.
By Jessica Davis | 02:03 pm | June 30, 2017
While the compromised computer was both locked and encrypted, the forensic investigation team couldn’t determine with certainty if there was unauthorized access to patient data during the April 21 attack.
By Bill Siwicki | 01:10 pm | June 30, 2017
Privacy and security lapses can quickly become professional liability and medical malpractice risks if healthcare organizations aren’t prepared.
By Kaiser Health News | 11:36 am | June 30, 2017
GOP bill could hurt veterans by eliminating Medicaid access yet others argue reform of VA could help eliminate that concern. 
SPONSORED
By Lenovo | Lenovo Health | 10:25 am | June 30, 2017
Currently, the typical patient waits 29 days to see a physician, according to a recently released survey from Merritt Hawkins. And, it could get worse. The country is expected to experience a shortage of about 90,000 physicians by the year 2025, according to the American Academy of Medical Colleges.  As a result, patients are apt to seek primary care for minor ailments such as a cold of flu through emergency departments – or to simply go without any treatment whatsoever.  Delivering care under such conditions could become virtually impossible.  “Access is a huge problem in American healthcare,” said Sylvan Waller, MD, a physician executive. Waller served as one of the catalysts during The Health Innovation Think Tank:  A Collaboration of Global Health Industry Thought Leaders, an event that was co-hosted by Lenovo Health, Justin Barnes Advisors, University of Pittsburgh Medical Center/Critical Care Medicine , Inventiv Health and HIMSS Media. The good news is that virtual care could solve this access dilemma. Indeed, remote monitoring, secure communication and telehealth solutions can connect doctors to patients directly while also addressing healthcare’s triple aim and reducing the need to seek care in inappropriate, high-cost settings. “When all of these virtual technologies are leveraged, a virtual connected health eco-system is created. Consumers can then engage with providers through these virtual systems – and the home becomes the primary care setting.  Technologies such as the Alexa app, with applied health skills, becomes every consumer’s trusted health assistant,” said Tom Foley, director, global health solution strategy at Lenovo Health. The big question: Are healthcare organizations ready to migrate to virtual care delivery? “The technology is there. Consumerism is there. People expect services on demand and they want concierge care,” Waller said. “It is coming. However, [virtual care] is just not quite there yet as barriers to adopting it are much harder than we thought about.”   Steve Aylward, senior vice president of partner enablement at Change Healthcare, agreed.  He explained how he sees both strong demand and challenges on the horizon for virtual health. “Reader’s Digest recently ran an article telling its readers that they have to have three popular telehealth apps. So, when Reader’s Digest starts telling its readers they need something, it is definitely becoming mainstream,” he said. To optimize virtual health’s potential, however, organizations need to overcome a variety of challenges associated with: Regulatory and legal requirements. “In the U.S., prescribing regulations are huge,” Waller said. Many states limit clinicians to providing treatment only to patients who are located in the state where the caregiver is licensed to practice. In addition, clinicians need to establish patient doctor-patient relationships, assess the patient and come up with a treatment plan. Consumers, however, should not be restricted by such constraints, according to Foley.. “This is where we lose patient engagement,” he said. “We should have the choice and the option to work with doctors in other states to get advice. This state barrier should not be an inhibitor. The legislative policies that restrict this need to change.” Trust in virtual health services. “Consumers don’t know the difference between telehealth providers. There is no brand recognition,” Waller said. “When a health system lends their brand, however, those patients have much more trust and adoption is much better.”  Understanding payment rules. According to Jeff Coughlin, senior director of federal and state affairs at HIMSS, Medicare beneficiaries may receive telehealth services in a variety of settings. Current Medicare law (SSA Section 1834(m)), however, restricts telehealth payments by the type of services provided; the geographic location where the services are delivered; the type of institution delivering the services; and the type of health provider. The good news is that payment concerns are becoming less onerous. Indeed, a 2016 Consumer Telehealth Benchmark Survey where just 34 percent of respondents cited reimbursement as an adoption barrier, compared to 72 percent in 2015. Recognizing the sweet spot. Organizations are beginning to realize that virtual care needs to expand to be financially feasible. “Everyone in the 1.0 version of virtual care is realizing that just treating cough, cold, congestion is a losing business model,” Waller said. “So, as they move to the 2.0 version, they are realizing that they need to get into chronic care management.”
By Bill Siwicki | 10:20 am | June 30, 2017
One-third of businesses have suffered an insider-caused breach, with potential losses from each incident surpassing $5 million, according to the State of Cybersecurity Report from cybersecurity firm Forcepoint. No matter how you slice it, the human factor quite often rears its head when there’s a breach. Technology can do its part in protecting against cyberattacks, but user education obviously is key to bolstering the human factor. What is not necessarily so obvious are different ways to look at user education and different ways to train during the educational process, some cybersecurity experts said. Bob Hansmann, director of security technologies at Forcepoint, and Jeff Pollard, a principal analyst who specializes in advanced threats, forensics and incident response at Forrester Research, offer learned takes on the human factor in cybersecurity. [Also: Barracuda unveils AI-driven tech to combat spear-phishing] “Healthcare organizations should look at insiders on a spectrum; essentially, users fall into a category – accidental, compromised or malicious – but can fluidly move along this continuum based on external factors such as job satisfaction, training or fatigue,” Hansmann said. “The key here is that the way that each type of insider interacts with data, like patient records, and their intentions or motivations behind that interaction vary. So, recommended types of education and solutions to prevent the loss of data due to these types of insiders vary as well.” Accidental insiders can be inadvertent actors or convenience seekers – both make unintentional mistakes whether the intent was due to negligence or simply attempting to do their job, but not following the process, Hansmann said. These insiders require a focus on education, awareness and best practices for completing tasks safely and effectively, he added. [Also: In the era of Petya, WannaCry, the good news is users are getting better about passwords] “Compromised insiders can be malware victims or impersonated users,” he said. “In both cases, the malware is attempting to act as the user. After all, the best malware simply impersonates human interaction with data. Since credentials are often stolen through social engineering, these users should be keenly aware of what they are clicking on or information they are providing to unknown sources. Ensuring you have proper web and e-mail solutions in place also can help limit these users’ interactions with potentially malicious content.” Rogue employees or criminal actor employees make up the malicious insider category. Though this is typically the smallest portion of insider threats in a given network, having a strong data loss prevention solution and insider threat program often will lead to the discovery of such users, Hansmann said. It is important to understand their intention and motivation for interacting with certain business-critical data and if it seems anomalous from their day-to-day activities, he added. Organizational culture is a key component often overlooked when it comes to insider threats, Pollard said. “When employees are unhappy, disgruntled or feel taken advantage of, it increases the likelihood that an insider-related incident occurs,” Pollard explained. “So, when organizations look at their risks, especially their risks for insider threat, I recommend working with human resources. Track things like retention rate of employees with access to sensitive data or intellectual property. If you have high turnover in groups with access to sensitive information, your risk for insider threat-related events is increased.” Also, one of the key areas few companies explore is analyzing how employees work, Pollard said. “Understanding exactly what devices they use, how they use them, what applications they access, etc.,” he said. “What you'll find is the way that the organization secures systems might be vastly different from the work style that employees use. Without understanding work style, you can’t properly train or deploy security controls. Then, once you understand work style, train users based on their work habits, the applications they use, and how they use them.” A less obvious method of cybersecurity training is the need for awareness training about the proper tools to accomplish various business tasks, Hansmann said. “This all rests on the idea of looking at the point where healthcare workers interact with sensitive data,” he said. “Many mistakes happen when a user creates a workaround simply because they do not understand the official process available. And on another note, general education about the organization’s ability to monitor for abusive activity can help prevent incidence of opportunity. There are many case studies of this that draw on the use of cameras to help reduce crime because people are afraid they might be caught.” Twitter: @SiwickiHealthIT Email the writer: bill.siwicki@himssmedia.com Like Healthcare IT News on Facebook and LinkedIn