News
Medical image exchange platform vendor lifeIMAGE has inked a 10-year deal with clinical image viewer maker Client Outlook to make Client Outlook’s visualization platform a core component of the lifeIMAGE offering.
Client Outlook’s FDA Class II diagnostic and clinical imaging viewing solution eUnity will become the default viewer across all apps and services on the lifeIMAGE enterprise image exchange platform, which links to providers and patients.
[Poll: What topics will define HIMSS16?]
Client Outlook will be at lifeIMAGE booth 968 at HIMSS16 demonstrating eUnity on lifeIMAGE workstations. The lifeIMAGE technology is a hybrid local network sharing system with a cloud component to share studies outside of a provider network. Client Outlook is a universal viewer for video and still imaging in cardiology, radiology, oncology, pediatrics, emergency medicine, burn care, dermatology and other fields.
“We wanted our customers to have assured availability to viewing technology of today backed by an organization sharing the same commitment we’ve shown to future innovation and interoperability,” said Matthew A. Michela, CEO and president of lifeIMAGE.
Client Outlook and lifeIMAGE will collaborate to ensure the interoperability of image data across their services. Client Outlook will introduce a workflow that enables the fast transmission of studies and clinical information displayed on its viewer through the lifeIMAGE network, and lifeIMAGE is now the only major image exchange provider offering enterprise access to the eUnity universal viewer.
“In partnership with lifeIMAGE we see the clear opportunity to significantly improve image data interoperability while improving physician workflow and clinical outcomes,” said Steve Rankin, president and CEO of Client Outlook.
Twitter: @SiwickiHealthIT
This story is part of our ongoing coverage of the HIMSS16 conference. Follow our live blog for real-time updates, and visit Destination HIMSS16 for a full rundown of our reporting from the show. For a selection of some of the best social media posts of the show, visit our Trending at #HIMSS16 hub.
It seems simple enough: If a piece of medical equipment is storing, receiving, transmitting, or processing electronic protected health information, it falls within the category of devices that are covered under HIPAA.
Yet, “for many practitioners, it just hasn’t occurred to them that medical devices are computers or are interfaced with computers,” said Steve Spearman, vice president of HIPAA Compliance Services of Healthicity, an information security consulting and services firm focused exclusively on healthcare.
In turn, they fail to include the security of medical devices in their risk analysis processes. And that, Spearman warned, can be a dangerous and costly mistake. “In addition to the standard problems with computer vulnerabilities, compromised security in medical devices are particularly prone to issues that can affect patient care, even patient safety,” he said.
[Also: 21 awesome photos from past HIMSS conferences]
As recently as November 2015, Lahey Hospital and Medical Center in Massachusetts agreed to pay $850,000 and implement a corrective action plan after settling with the Department of Health and Human Services Office for Civil Rights over a stolen laptop that was used to operate a portable CT scanner.
The nonprofit teaching hospital was cited for failing to conduct an accurate and thorough risk analysis, failing to implement appropriate physical security measures, failure to assign a unique user name to identify and track users and, lastly, for disclosing the ePHI of 599 individuals whose data was stored on the laptop, Spearman said.
“Medical devices pose risks similar to all other computers,” he said. “Vulnerabilities in medical devices can be exploited to gain inappropriate access to network resources.”
Spearman, along with Mary McGuirl, Director of IT at Oneida Healthcare in New York, will present the session, “Assessing the Risk of Your Medical Devices,” at HIMSS16.
[Like Healthcare IT News on Facebook]
With Spearman as a “nuts-and-bolts kind of guy” and McGuirl providing perspective on practical issues such as resource constraints and organizational challenges related to meeting federal requirements at a small regional hospital, the pair hopes participants come away better equipped to include medical devices in their annual risk assessment.
Left out of risk analyses, medical devices “can be a vector for malware,” Spearman said, noting that many run on software or firmware, and are therefore not easily updated to more secure versions.
He pointed to “inappropriate access controls,” such as weak or non-existent credentials, as a common issue that can be exploited “to undermine the integrity of the medical record.”
“Even worse,” he continued, “sometimes these credentials are hard-coded and they can’t be changed! If there are no ‘unique users’ how can you conduct audits, research complaints, respond appropriately to incidents? You can’t.”
The session “Assessing the Risk of Your Medical Device,” will take place from 11:30 a.m.-12:30 p.m. on Thursday, March 3, in Palazzo L.
Twitter: @HealthITNews
This story is part of our ongoing coverage of the HIMSS16 conference. Follow our live blog for real-time updates, and visit Destination HIMSS16 for a full rundown of our reporting from the show. For a selection of some of the best social media posts of the show, visit our Trending at #HIMSS16 hub.
Aiming to help HIPAA covered entities strengthen their cybersecurity preparedness, HHS Office for Civil Rights has published a crosswalk identifying mappings between NIST's Framework for Improving Critical Infrastructure Cybersecurity and the HIPAA Security Rule.
Developed in partnership with NIST and ONC, the crosswalk also includes mappings to other commonly used security frameworks, officials said.
In February 2014, NIST released the framework to help organizations better understand and manage cybersecurity risks. Many organizations in healthcare and other industries voluntarily rely on detailed security guidance and specific standards issued by NIST.
[Also: HIMSS presses NIST to keep cybersecurity framework voluntary]
Entities bound by HIPAA, meanwhile, are required to implement strong data security safeguards to comply with the HIPAA Security Rule and protect the health data they create, receive, maintain or transmit.
"We hear frequently from covered entities and business associates who said they are working hard in an increasingly challenging atmosphere to assure their PHI is adequately protected," OCR officials said. "We also know from our HIPAA enforcement work that far too frequently entities are leaving PHI vulnerable to breach and access by unauthorized persons."
The goal with this new crosswalk is to help health organizations that have aligned their security programs to either the NIST Cybersecurity Framework or the HIPAA Security Rule to identify potential gaps in their programs, they said.
[Also: Cybersecurity Information Sharing Act sails through Senate]
By addressing those gaps, covered entities can improve their compliance with the Security Rule and better protect patient data.
OCR noted that the HIPAA is meant to be flexible, scalable and technology-neutral, enabling it to better integrate with frameworks such as the NIST's.
[Like Healthcare IT News on Facebook]
The Security Rule doesn't mandate use of the NIST Cybersecurity Framework, officials said – and at the same time, use of the framework doesn't guarantee HIPAA compliance. But the crosswalk is meant as a tool to help health organizations manage security risks in a more comprehensive way.
Noting that both the HITECH Act of 2009 and the Cybersecurity Information Sharing Act passed this past October called for guidance on implementation of NIST frameworks, OCR officials said the crosswalk "provides a helpful roadmap for HIPAA covered entities and their business associates to understand the overlap between the NIST Cybersecurity Framework, the HIPAA Security Rule, and other security frameworks that can help entities safeguard health data in a time of increasing risks."
Twitter: @MikeMiliardHITN
3M Health Information Systems plans to unveil the latest module in its 360 Encompass Health Analytics Suite early next week at HIMSS16 in Las Vegas.
Physician Compare integrates with the company’s Potentially Preventable Readmissions and Potentially Preventable Complications grouping software, according to materials Healthcare IT News obtained ahead of the launch.
Taken together, the risk analysis methodologies enable hospitals to audit doctors to identify avoidable events, notably admissions, emergency room visits, hospital-acquired complications and preventable readmissions.
[Poll: What topics will define HIMSS16?]
Physician compare brings reports for gauging physicians’ efficiency and performance compared to peers, measuring which resources they use and how those impact outcomes – as well as enabling users to identify tactics for improving physician performance.
Another pre-packaged report focuses on what the company called “patient acuity” through avoidable care, admissions and healthcare costs.
Released in the summer of 2015, the 3M Encompass Health Analytics Suite also includes State Compare and Patient Compare modules for benchmarking hospital quality performance and patients’ perspective on costs, performance and length of stay.
The former is why University Health System in San Antonio, Texas reached out to 3M. Well, that and a little philosophy called the Triple Aim, said Camerino Salazar, senior director of health analytics at UHS.
[Also: 21 awesome photos from past HIMSS conferences]
“We initially used 3M software to help with reporting for the 1115 state Medicaid waiver,” Salazar explained. “Now that we’ve been operationalizing the analytics dashboard it’s a way to monitor performance and identify the areas where we need to improve quality.”
Salazar’s colleague Heidy Colon-Lugo, a senior quality data analyst in the UHS health analytics unit, added that UHS has the Physician Compare module and “physicians can use it to track their own progress,” though the hospital has not yet put it into production at an enterprise level.
“We see it as a tool that could be very beneficial on inpatient reporting. It’s on the to-do list – and it’s a gauge for population health management,” Salazar explained because it helps UHS track performance and quality. “If we’re doing a good job of care management and providing timely preventable care, that’s an avenue of keeping people healthy. We’re the downstream so if things are operating well we should see those changes to readmissions, costs, the Triple Aim.”
Twitter: @SullyHIT
This story is part of our ongoing coverage of the HIMSS16 conference. Follow our live blog for real-time updates, and visit Destination HIMSS16 for a full rundown of our reporting from the show. For a selection of some of the best social media posts of the show, visit our Trending at #HIMSS16 hub.
Cerner has announced that Geisnger Health System subsidiary xG Health Solutions will use Cerner’s HealtheIntent population health management platform and, in turn, Cerner will use xG Health’s clinical content.
xG Health’s care management clinical content automates the assessment of a variety of hereditary, socioeconomic, physical, behavioral and environmental risk factors, as well as warning signs and symptoms associated with specific conditions. Cerner clients will be able to use xG Health’s clinical content within HealtheCare, Cerner’s community care management solution that provides algorithms with the ability to identify, stratify and prioritize individuals for assignment to aligned care managers.
[Also: 21 awesome photos from past HIMSS conferences]
The HealtheCare and xG Health clinical content collaboration will provide evidence-based patient assessments for dozens of conditions, be integrated into workflows, and automate the generation of patient-specific action plans to boost personalized care, the vendors said.
The agreement will also see Cerner integrate xG Health’s analytics content into Cerner’s HealtheAnalytics system. The alignment expands Cerner’s population health management suite to provide organizations with analytic discoveries that can help reduce costs and improve healthcare quality and patient outcomes, Cerner said.
“What interested us in xG Health is the commercial arm of Geisinger Health System, which acts as a testbed for technology,” said Brad Carey, vice president and general manager of population health. “We’ve initially partnered with xG Health on things that revolve around care management content and population health, and are looking to xG Health’s business intelligence specially derived from claims data.”
Cerner also announced that the University of Kansas Hospital will deploy the HealtheIntent population health management platform to coordinate and manage care in rural Kansas communities, according to Robert Moser, MD, director of the Kansas Heart and Stroke Collaborative. Moser said the collaborative will also use HealtheCare, Cerner’s community care management system, to engage at-risk patient and ideally provide optimal treatment resources.
Cerner’s population health management platform will be featured in Cerner Booth 2032 at HIMSS16, Feb. 29-March 4 at the Sands Expo Center in Las Vegas.
Twitter: @SiwickiHealthIT
This story is part of our ongoing coverage of the HIMSS16 conference. Follow our live blog for real-time updates, and visit Destination HIMSS16 for a full rundown of our reporting from the show. For a selection of some of the best social media posts of the show, visit our Trending at #HIMSS16 hub.
The vendor plans to show the new SDK for portals and other apps, as well as multiway videoconferencing technologies, at HIMSS16.
SPONSORED
(SPONSORED) Interoperability is a loaded word in the healthcare space. Mention it and people will no doubt stop to hear what is being said--but why?
Deal puts focus on mobile population health, chronic care management.
Too many healthcare organizations are focused on securing the wrong assets, leaving them vulnerable to cyberattacks and putting patients at risk, a new report from Independent Survey Evaluators claims.
When healthcare leaders focus primarily on protecting patient data, they often fail to address actual cybersecurity threats that directly affect patient health, the report said. So if an active medical device or electronic work order were infiltrated by cybercriminals, the patient could be directly affected. On the other hand, an electronic health record is secondary – it requires a provider to alter the data before it could potentially harm a patient.
ISE studied 12 healthcare organizations, two healthcare data facilities, two active medical devices, two Web applications and other devices found on healthcare networks over the course of two years to determine the possibility of remote attacks and the readiness of these institutions to keep data secure.
"We found hospitals were antiquated in their network designs and unsure about the technologies that could effectively help them," the study's authors said.
[Also: Hollywood Presbyterian gives in to hackers]
"In many cases, vendor products purchased for a security purpose were inappropriate for the organization, and those systems that were appropriate were deployed incorrectly, all resulting in heavy waste while not achieving an improvement in security posture," they added.
Researchers separated threat vectors into primary, secondary and tertiary "attack surfaces" that expose patient health, more than their health data.
Many systems that are the focus of prevention efforts "have little value with regard to personally identifiable information or personal health information – the assets hospitals strive to protect
most – yet they have direct consequences with regard to patient health," according to the report.
"These attack surfaces are largely left unprotected by hospitals and are precisely the attack surfaces to be targeted by an adversary seeking to harm a patient."
Among the primary surfaces: clinicians, medicine, active medical devices and surgery. Secondary (EHRs, passive medical devices, test results, work orders) and tertiary surfaces (climate controls, physical storage, barcode scanners, connected power) often get outsized attention.
Actions taken by health leaders often only handled unsophisticated threats, according to study, which left plenty of openings for attackers to get into information systems. Often, protection strategies assumed the attacks weren't aimed toward garnering targeted information, and therefore ignored the specific strategies and motivations of cyberattackers.
All of the hospitals in the study were failing on a range of levels to address modern security issues, largely in part, due to a lack of funding.
[Like Healthcare IT News on Facebook]
"Security vulnerabilities in healthcare are a result of systemic business failures," said Ted Harrington, executive partner at ISE and one of the study's leaders, in a statement. "We found egregious business shortcomings in every hospital, including insufficient funding, insufficient staffing, insufficient training, lack of policy, lack of network awareness and many more."
According to the study, one of the greatest vulnerabilities is that patients and visitors often have physical access to networks and equipment – an issue unique to healthcare. Time, accuracy and the environment also played into sometimes adverse security circumstances.
Along with the study, ISE published a blueprint to aid healthcare organizations in shifting the security focus. It outlines specific threats and the consequences of a breach, in addition to methods for healthcare institutions to better secure its systems.
Twitter: @JessiefDavis
Don’t let the indestructible demeanor of nurses fool you: Like other members of the healthcare team, they too have technological difficulties.
“The public and nurses who are not informaticians may have the impression that the quieter stance from nurses means usability issues don’t exist for them – in fact, user experience issues for nurses are severe,” said Nancy Staggers, a professor at the University of Maryland and an expert on clinical informatics whose experience includes serving as an IT executive on an electronic health records implementation at the U.S. Department of Defense.
[Also: 21 awesome photos from past HIMSS conferences]
Staggers will discuss the top healthcare IT user experience challenges for nurses at HIMSS16 during a roundtable session titled “Conversations on Nursing’s Health IT User Experiences,” at HIMSS16.
Current usability problems include specifics like technology designed to fir nurses’ workflow and cognitive support, as well as broader issues such as needing a vision for health IT and strengthening the voice of nurses within provider organizations.
Because of their role in the care process, nurses have unique IT user experience needs.
“Nurses need a framework for thinking about UX and speaking about their health IT pain points so they can move toward solutions,” Staggers said. “UX is deeper than a simple focus on the computer interface; it is about designing technology to support workflow and the way nurses think and do work.”
[Like Healthcare IT News on Facebook]
How important are the issues nurses have with healthcare IT?
Extremely, considering the sheer number of nurses and the crucial role nurses play in achieving successful health outcomes.
“The U.S. alone has 3.4 million nurses; in fact, nurses are the largest group of health IT users globally, and they act as information hubs for patients in myriad settings beyond acute care, including long-term care, home health, community-based care, and telehealth,” Staggers said. “UX issues span all settings and are critical in the care of consumers, including special groups such as our aging population. Both the volume and the significance of current UX issues make addressing them an imperative to address in supporting nurses as knowledge workers.”
Impractical IT user experiences for nurses can result in errors, patient safety issues, delayed decision making and huge inefficiencies, Staggers added.
“Fixing UX issues is important to patients, nurses and the healthcare profession as a whole to improve safety and outcomes, enhance productivity, support critical thinking, and reduce inefficiencies,” Staggers said.
The session, “Conversations on Nursing’s Health IT User Experiences,” is slated for Tuesday March 1, 2016 from 4-5 p.m. in the Sands Expo Convention Center Galileo 1004.
Twitter: @SiwickiHealthIT
This story is part of our ongoing coverage of the HIMSS16 conference. Follow our live blog for real-time updates, and visit Destination HIMSS16 for a full rundown of our reporting from the show. For a selection of some of the best social media posts of the show, visit our Trending at #HIMSS16 hub.
