News
The I-STOP legislation, first passed in 2012, aims to combat controlled substance abuse. A provision set to take effect at the end of this month requires doctors to prescribe almost everything electronically.
A recent report from the Department of Health and Human Services Office of the Inspector General claims that HHS could do better when it comes to protecting federal information.
The gaps range from monitoring to security training and contingency planning.
"Exploitation of these weaknesses could result in unauthorized access to, and disclosure of, sensitive information and disruption of critical operations for HHS," according to Ernst & Young, which conducted the independent audit for the OIG. "As a result, we believe the weaknesses could potentially compromise the confidentiality, integrity, and availability of HHS' sensitive information and information systems."
[Also: OIG identifies big HHS security shortfalls.]
Assistant Inspector General for Audit Services Thomas M. Salmon detailed the findings in a March 2016 report by identifying the 10 areas the auditors found lacking. HHS responded to each finding, concurring with some, taking issue with others:
Continuous Monitoring Management. HHS has formalized its Information Security Continuous Monitoring program through development of ISCM policies, procedures, and strategies. However, HHS has not implemented a Department-wide fully-implemented continuous monitoring program which includes continuously monitoring, updating and finalizing policies and procedures indicating how OPDIVs (operational divisions) address, implement strategies and report on DHS metrics. This includes vulnerability management, software assurance, information management, patch management, license management, event management, malware detection, asset management, and network management.
Configuration Management. Some OPDIVs did not consistently review and remediate or address the risk presented by vulnerabilities discovered in configuration baseline compliance and vulnerability scans performed through Security Content Automation Protocol tools.
Identity and Access Management. Some OPDIVs did not consistently implement account management procedures for shared accounts, new personnel, transferred personnel and terminated personnel.
Incident Response and Reporting. Oversight processes had not been implemented by HHS to enforce incident response and reporting procedures at the OPDIVs.
Risk Management. HHS did not implement procedures to oversee that system inventories are complete, accurate and effectively managed, including reconciling to the OPDIV-managed system inventory tools.
Security Training. Some OPDIVs did not monitor the completion of role-based training for significant security responsibilities and other security training for personnel using IT systems.
Plan of Action and Milestones. Plan of Action & Milestones were not consistently documented and tracked by the OPDIVs and HHS.
[Like Healthcare IT News on Facebook]
Remote Access Management. Some OPDIVs had not developed formal and finalized remote access policies and procedures.
Contingency Planning. Some OPDIVs did not complete required contingency planning documentation, including Business Impact Analysis, Continuity of Operation Plans, and Information System Contingency Plans.
Contractor Systems. Some OPDIVs did not have an effective contractor oversight protocols.
Twitter: @HealthITNews
A new report based on customer scores found that the two companies outperformed other EHR-dependent and EHR-independent vendors.
The technology pioneer offered his thoughts on funding new projects and keeping up with change at his HIMSS16 keynote earlier this month. Here are seven takeaways.
New resources focus on available technologies, emerging professional roles and leadership to help health information management professionals more effectively work with both clinicians and patients.
More than 100 member organizations have committed to participating in the effort to empower patients and improve care delivery.
Assistant U.S. Surgeon General Rear Admiral Michelle E. Dunwoody is taking on a temporary senior advisor role to Flint Mayor Karen Weaver as the Michigan city continues to grapple with a water crisis, HHS announced on Friday.
Dunwoody will work with Weaver to establish both short- and long-term goals for the City of Flint Public Health and Medical Recovery and work with city officials to outline the job description for a future full-time Flint-employed Public Health official, while providing insight to building and managing public health and medical infrastructure.
“My priority has always been, and will always be, that Flint’s families have the resources they deserve, as well a voice which allows them a say in how their community’s future is built,” Weaver said in a statement. The partnership is "an opportunity to continue building relationships, while ensuring some of our country’s best experts are working with us to find solutions.”
To that end, Dunwoody will also oversee a Corps-based community engagement team.
"Admiral Dunwoody brings a wealth of expertise to expand the technical capability of the Mayor’s office and ensure Flint develops the local expertise needed to help the community recover in the days, months and years to come," HHS Assistant Secretary for Preparedness and Response Nicole Lurie said in a statement.
Nearly 500,000 residents of Flint have been exposed to water contaminated by lead, and currently much of the city is living off of bottled water rations.
The appointment comes after a Commissioned Corps strike force cleared a backlog of blood lead level screening results in partnership with the Genesee County Health Department.
HHS leaders have made several visits to Flint to assess the crisis, including Secretary Sylvia Burwell, Acting Assistant Secretary for Health Karen DeSalvo and U.S. Surgeon General Vivek H. Murthy.
[Like Healthcare IT News on Facebook]
"Ensuring the men, women and children of Flint have the same opportunity as all Americans to live healthy lives is a team effort, and I have seen first-hand just how dedicated city leaders, city and county health officials, and our Commissioned Corps officers have been to that cause,” said DeSalvo in a statement.
The Commissioned Corps are made of up doctors, nurses, scientists and engineers. Over 30 officers have responded to the Flint water crisis; assisting with behavioral health training, supporting volunteers in community engagement efforts, helping to staff the Genesee County Health Department's information line and providing materials to answer callers' questions.
“The people of Flint need clean water. They need medical care. And, above all, they need trusted voices to communicate the best available public health information in the midst of a crisis,” Murthy, Commissioned Corps commander, said in a statement.
Twitter: @JessiefDavis
Patient access to data will bolster precision medicine, cancer moonshot, US Chief Data Scientist DJ…
The federal government is pursuing a fistful of bold visions to transform healthcare including the Precision Medicine Initiative and the National Cancer Moonshot, and for those to succeed patients are going to need the ability to access and share health data in new ways, according to three federal officials.
“When patients are engaged in research and voluntarily sharing their health data with the research community, the opportunities for new discoveries at the intersection of human biology, behavior, genetics, and data science are unlimited,” wrote U.S. Chief Data Scientist DJ Patil, Senior Advisor Claudia Williams and Precision Medicine Initiative project manager Stephanie Devaney.
[Also: Obama taps Biden to lead cancer cure 'moonshot']
The authors cited President Barack Obama’s Precision Medicine Initiative, an innovative approach that takes into account individual differences in people’s genes, environments, and lifestyles in treatment and research, and the National Cancer Moonshot, which leverages Big Data to find solutions to genetic abnormalities, as examples of data sharing to accelerate research and translate findings into new treatments.
HHS has been taking steps to enable the data sharing that PMI, the Cancer Moonshot, and key research projects will demand.
The agency recently issued guidance to clarify patient rights to access a variety of health information, including personal health records, the information in their health records, clinical laboratory test results, and genetic data. And earlier this month, the Food and Drug Administration held a workshop with patients and providers to understand the best ways to return information that is usable, meaningful, and actionable.
“We’ve worked hand-in-hand with the private sector (to provide patient access to health records) and together, last week, the companies that provide 90 percent of electronic health records to hospitals nationwide pledged to improve the flow of data across healthcare settings, provide people with easy and secure access to their information, and adhere to federally recognized standards that assure that patients can access their own data,” the authors explained.
HHS is also encouraging the development of apps that use open, standardized application programming interfaces to help consumers aggregate their health information in one place that is under their control.
And at the recent Precision Medicine Initiative Summit hosted by President Obama at the White House, six of the major electronic health record vendors announced that they will pilot the use of standard APIs for individuals to access and contribute their data to research.
[Like Healthcare IT News on Facebook]
The authors also pointed to the early traction Blue Button has gotten. Through the public-private effort some 150 million Americans can now access information from providers, medical laboratories, retail pharmacy chains, and state immunization registries. What’s more, three million veterans, service members, and Medicare beneficiaries have now accessed their personal health data more than 43 million times.
“These are exciting steps toward ensuring individuals have access to their data,” Patil, Williams and Devaney wrote. “But we’re far from done.”
Twitter: @HealthITNews
Before joining Cerner, Glaser was the longtime vice president and chief information officer at Partners HealthCare.
Twenty-one companies were awarded spots on the Department of Veterans Affairs' $22.3 billion Transformation Twenty-One Total Technology Next Generation acquisition program, or T4NG, the federal agency announced this week.
The IT modernization project supports the MyVA Initiative -- designed to realign and integrate the VA's disparate organizational boundaries to better serve veterans.
This award is unrelated to the VA's recently reported discussions around its VistA electronic health record system.
[Also: CIO says VA should rethink VistA, consider other off-the-shelf EHRs]
"This T4NG award is one of the many ways the Department is supporting the MyVA breakthrough initiatives by directly providing the technology our Veterans need to support the services they receive from VA," said VA Secretary Robert McDonald, in a statement. "The T4NG will help meet and strengthen VA's long-term technology needs."
T4NG will deliver awardees contractor-provided IT service solutions, such as technical support, program management, strategy planning, systems/software engineering, enterprise network engineering, cybersecurity and other IT and health IT support.
[Like Healthcare IT News on Facebook]
Under T4NG, the firms can bid on any T4NG requirements or service task orders. The base ordering period is five years and a five-year option period.
Among the firms included in the IT contracts were Booz Allen Hamilton, CACI-ISS, HMS Technologies, Kforce Government Solutions, Ellumen and SRA International.
This round of T4NG awardees builds upon the last five-year, $12 billion T4 contract given to 15 vendors in July 2011. Some companies, such as Booz Allen and CACI were included in the 2011 awards.
Twitter: @JessiefDavis