Skip to main content

News

By Mike Miliard | 12:30 pm | May 17, 2016
The draft document takes on topics related to interoperability, data integrity, record retention and more.
By Bernie Monegain | 12:09 pm | May 17, 2016
The center deployed predictive clinical decision support to save diabetic patients’ lives as part of a move to become a data-driven healthcare organization. 
By Ipswitch | 12:02 pm | May 17, 2016
Healthcare organizations are dealing with an epidemic of threats to the security of electronic health records (EHR). From breaches to ransomware to employee data violations, securing healthcare data while meeting data privacy compliance demands is under a heightened threat level. Rise of the healthcare epidemic There’s a perfect storm of events that are causing an increase in cybercrime: national laws and policies have encouraged healthcare organizations to move to EHR (98 percent of hospitals in US); available technology to ease the transition to EHR; and high value for EHR on the black market (FBI Cyber Division Private Industry Notification #140408-009, 8 Apr. 2014, puts the value at $50 for each partial EHR). In addition, there is increased pressure to innovate to stay competitive by delivering differentiated services. Healthcare organizations are now leveraging technology and information systems to reduce costs, improve the quality of care and make it easier for patients to be proactive in their own healthcare. This has revealed new capabilities for healthcare staff to do their jobs more efficiently, but with every technology advancements comes the challenge of ensuring that technology is easy to use, reliable and secure. While cyber criminals are a growing threat as seen by the recent ransomware debacles, it can’t be the only area of focus to protect EHR. In the recent 2016 State of Data Security and Compliance Report published by Ipswitch, Inc, more than 500 IT professionals (91 in healthcare organizations) from around the world were surveyed about their data security policies. Those in healthcare organizations that identified as having experienced a significant data loss noted that only 20 percent was due to malicious activities, while 45 percent was due to human error and 35 percent due to process or network failure. Interestingly, in that same report only 34 percent in healthcare reported their organization as very efficient in identifying risks and 42 percent as very efficient in mitigating risks. No silver bullet to protect EHRs There’s general agreement in the IT community that given the complexity of modern healthcare technology there is no silver bullet for EHR data protection. Employee behavior is a critical risk, including loss of personal devices without adequate access control or EHR data encryption, and their unknowing participation in social-engineering exploits. And while more than 80 percent of hospitals in the U.S. have electronic medical records (EMR) systems (4567 of 5627) that offer protection of EHR, there’s continued need to securely send and receive EHR to externally.  EHR is increasingly vulnerable when in-motion outside of protected healthcare infrastructure. HIPAA/HITECH identifies IT controls to protect data including encryption, network perimeter defense, effective access control and employee training, and yet data loss is a growing trend. A deputy CISO from a large healthcare organization at the recent Secure World Conference in Boston said that his primary focus is no longer on HIPAA compliance. It’s just a given that any new technology they consider must comply. He’s now more interested when talking with technology vendors about their capabilities to help identify and mitigate risks. To learn more, join the upcoming HIMSS Media webinar, Combatting the Epidemic of Healthcare Data Threats with John Houston, VP Information Security & Privacy, UPMC (University of Pennsylvania Medical Center).  During the webinar, you’ll learn: What are the essential IT controls to protect healthcare data-in-motion? What are tips and tricks to cost-effectively pass your next audit? What are practical strategies including automation to cost-effectively reduce data loss?  Which file transfer and sharing technologies help or hurt your data protection?  For additional resources to learn how you can protect your EHR data-in-motion visit https://www.ipswitch.com/resources/case-studies/rochester-general-relies-on-moveit-to-transfer-medical-records-and-meet-hippa-hitech-compliance  
By Jessica Davis | 11:14 am | May 17, 2016
The CERT Division of Carnegie Mellon's Software Engineering Institute has released its list of 10 technologies emerging in the next five years with the greatest vulnerabilities in terms of cybersecurity, finance, personal health and safety.
By Jack McCarthy | 10:24 am | May 17, 2016
The new deal is part of a larger initiative to transform Penn State Health into a hub of telehealth services that cater to patients in Central Pennsylvania. 
By Bernie Monegain | 08:57 am | May 17, 2016
Valita Fredland most recently served as chief privacy officer and counsel at IU Health. In her new post, Fredland will serve as vice president, general counsel and privacy officer.
By Mike Miliard | 08:48 am | May 17, 2016
New species of the malicious code are found in the wild on a regular basis. Here are some of the newest types of ransomware.  
By Bill Siwicki | 08:07 am | May 17, 2016
Cybercriminals have set their sights on healthcare. Ransomware is the new normal. And many providers are approaching security all wrong. CIOs, CISOs, ethical hackers and other experts point the way forward. 
By Mike Miliard | 05:40 pm | May 16, 2016
UC Health – the flagship University of Cincinnati Medical Center, as well as 167 of its affiliated practices – has reached the Stage 7 on the HIMSS Analytics EMR Adoption Model. HIMSS Analytics developed the EMRAM in 2005. Its eight stages (0-7) track a hospital’s implementation and use of health IT applications. In 2011, it launched the ambulatory model, meant to evaluate the progress and impact of EMRs for ambulatory facilities – physician practices, outpatient centers and specialty clinics – owned by hospitals in the HIMSS Analytics Database. Only 4.2 percent of more than 5,400 U.S. hospitals in HIMSS Analytics' database have attained Stage 7; just 7.9 percent of more than 34,000 ambulatory clinics have scored a Stage 7 Ambulatory Award. [Also: Benchmarks: Stage 7 success stories] UC Health, the University of Cincinnati’s affiliated health system is the region’s only academic health system.  It includes University of Cincinnati Medical Center, three additional hospitals, and the University of Cincinnati Physicians, Cincinnati’s largest multi-specialty practice group with more than 700 board-certified clinicians and surgeons. John H. Daniels, global vice president of HIMSS Analytics' healthcare advisory services group, said UC Health "has gone above and beyond the EMRAM Stage 7 criteria. They have already extended the closed-loop medication administration process to their infusion clinic and for interventional radiology cases. Combined with a strong population health program, the UC Health team is making a real difference in their community." "This accomplishment is due to our commitment to improved patient outcomes through the expanded use of information technology," said Jay Brown, UC Health's senior vice president and chief information officer, in a statement. "As the region’s only academic health system, we are surrounded by innovators and visionary leaders who have recognized the importance of leveraging these tools," he added. "The HIMSS Analytics Stage 7 Award highlights our dedication to delivering the highest quality of care and enhancing the experience of our patients."
By Jessica Davis | 12:34 pm | May 16, 2016
Aurora, Colorado-based UCHealth has partnered again with LeanTaaS, a Silicon Valley-based predictive analytics startup. It will implement iQueue for Operating Rooms, which combines lean principles with advanced data tools for operating room utilization improvements. The flagship University of Colorado Hospital is the first of the system's five hospitals to deploy iQueue for Operating Rooms; UCHealth plans to integrate the platform at its other hospitals within the next year. The iQueue platform taps into UCHealth's Epic EHR and analyzes OR usage patterns to determine how to reallocate time to surgeons for improved efficiency. There's also a mobile feature that connects surgeons to the platform with real-time data for OR block management. "Sometimes it's really hard to just look at data and say, what do I do with this? How do I make the data work for the organization?" said University of Colorado Hospital Chief Information Officer Steve Hess. "The data may be there, but we all need to ask ourselves, is the data creating the story that we need? [Also: Analytics works wonders in Colorado] "With its machine learning and tools pushing data to surgeons, these are the changes that LeanTaaS is doing that will make the difference," Hess said. "This is actually retrospective and predictive. Not only will it tell us about OR usage, but it can also tell us what's happening and where it's going." By deploying this platform into the complex OR scheduling challenges facing UCHealth, the organization hopes to tackle capacity issues, improve OR utilization and workflow, according to Hess. Moving the needle just 1 percent, on one OR room can contribute to the bottom line and improve efficiencies, he said. "The combination of analytics, real-time data and block release and assignment exchange platform for smartphones: We see it as a game changer," Hess said. "It's too early to tell what kind of utilization we'll see, but we do expect this to be extremely positive." This is the second time UCHealth has turned to LeanTaas to improve its hospital operations. This past fall, the health system deployed LeanTaaS' iQueue for Infusion Centers across its entire system. Its success drove the decision to bring the technology into its operating room scheduling, Hess said. Twitter: @JessieFDavis Email the writer: jessica.davis@himssmedia.com Like Healthcare IT News on Facebook and LinkedIn