Skip to main content

News

By Tom Sullivan | 11:04 am | April 12, 2019
The system worked with a patient design team and turned the metrics of success upside down, for starters.
By Armin Scheuer | 06:07 am | April 12, 2019
The Health Innovation Hub will be the Ministry's bridge to the "digital scene," said health minister Jens Spahn.
By Staff Writer | 01:00 am | April 12, 2019
NSW Health will soon roll out a new radiology information system and picture archiving and communication system (RIS-PACS) across 11 of its organisations. The organisations involved include nine local health districts, the Sydney Children’s Hospitals Network and NSW Health Pathology’s Forensic and Analytical Science Service, and aim to improve the way in which more than 1.8 million medical images are captured, used and archived across these organisations annually. The deployments, the result of a partnership with Swedish-based secure communications company Sectra, are expected to take around three years to roll out and follow a six-month proof-of-concept trial. Specifically, the platform provides more modern and improved services to patients, including SMS reminders for appointments and secure access to their images via an online portal. Benefits to clinicians include: image accessibility to healthcare professionals working in different hospitals and in remote locations; critical results management and radiation-dose tracking; improved security of patient information; integration with other NSW Health systems; and access to prior images to assist with diagnosis and referrals. The system involves a Sectra picture archiving and communication system (PACS), a radiology information system (RIS) provided by Kestral, and a critical result management system provided by Spok. NSW Health said that with more than a million medical images captured by the participating organisations every year, images need to be stored safely and be readily accessible for clinicians. “The new RIS-PACS platform will deliver benefits directly to patients by providing clinicians with improved access to imaging through a centralised image archiving and communication system,” it said. [Read more: NSW’s hospitals enroute to state-wide Electronic Record for Intensive Care (eRIC) implementation | Innovation remains at the centre of eHealth NSW and HealthShare NSW's strategy] eHealth NSW Chief Executive and NSW Health Chief Information Officer Dr Zoran Bolevich said the deployment is a “great example” of the collaboration between NSW Health and industry partners to deliver benefits across the state for both clinical staff and patients. “The project placed key radiologists, ICT specialists and medical imaging users from 11 NSW Health organisations in the driving seat to test critical aspects of the platform prior to proceeding with a full implementation,” he said.
By Bill Siwicki | 01:41 pm | April 11, 2019
Three experts discuss how application programming interfaces help enable system interoperability, and describe what the role of APIs will be in the future.
By Mike Miliard | 01:36 pm | April 11, 2019
Despite some halting progress with cybersecurity readiness, healthcare is still lacking in many key areas, according to a new progress report from the consultancy CynergisTek. In particular, the study took a look at how healthcare organizations are stacking up with the advice and best practices of the NIST Cybersecurity Framework, as well as the HIPAA privacy and security rules. The findings, say CynergisTek researchers, are "sobering." WHY IT MATTERS To start with, the report – based on the results of assessments, audits and reviews performed by CynergisTek at some 600 healthcare organizations and business associates – found that, from the perspective of NIST CSF most of those orgs surveyed were still performing "well below where we would like to see them," said CynergisTek CEO Mac McMillan in the report. It found an average 47 percent conformance with NIST CSF controls and an average 72 percent compliance with the HIPAA Security Rule. While the HIPAA adherence was slightly better and "within normal range," several specific findings underscored a key point that's become a mantra: "compliance does not equate to security," he said. For example, while hospitals and health systems may be meeting the letter of the law when it comes to HIPAA rules, CynergisTek researchers found that one of the key planks of conformance with NIST CSF – breach detection – was not where it should be for many of those organizations it assessed. "Given the threat environment we operate in today where literally some percentage of almost everything computerized is a threat, the inability to effectively discover and respond to events is a real issue," said McMillan. Worse than the numbers themselves is the fact that they represent only a minimal improvement in NIST CST conformance since a similar progress report was done this past year – just a 2 percent increase – and CynergisTek actually saw a 2 percent decrease compliance with the HIPAA Security Rule. Researchers also found that of the five "core functions" of the NIST CSF – identify, detect, protect, respond and recover – there was relative stability, year-to-year, even as "detect" component lagged the other four. But when it came to awareness and training, a key driver of the "protect" plank, there was a slight downtick in conformance, the report shows. That's "likely not significant," researchers conceded, but "it does beg the bigger question around security: If you are not improving, are you actually slipping back?" Among some other notable findings from the study: More than 60 percent of CynergisTek's assessments discovered noticeable gaps in the maintenance of written policies and procedures to guide healthcare workforce around the use and release of PHI. As for third-party vendors, "the most common gaps among included risk assessment, access management, and governance," researchers found. And at healthcare organizations, nearly 75 percent of unauthorized insider access came from employees' household members. THE LARGER TREND Interestingly, at least on the subject of breach detection, the findings of the Cynergistek report diverge somewhat with those of another study this week, from BakerHostetler, which found that while phishing scam artists are still doing their darndest to take advantage of employee error, one of the bright spots had to do with substantial improvements in in-house detection among the organizations it surveyed. Whichever of those stats is more indicative of the true larger picture, however, its inarguable that healthcare still has major work to do when it comes to cybersecurity preparedness – and that goes for all employees across the enterprise, from low-level back office staff to the CEO. Indeed, as we showed this week, too many CEOs – amazingly – still aren't giving infosec the high-level attention and on-the-ground resources it deserves and demands. ON THE RECORD David Finn, executive vice president of strategic innovation at CynergisTek, said the decline in the awareness and training category under the NIST CSF "protect" capability "is very alarming considering how much more sophisticated attackers were with targeted phishing attempts and new attack vectors, such as medical devices." In addition, "the fact that we did not see any improvement in either the respond or recover functions means we may be losing even more ground with the increased number of attacks last year," he noted. "Organizations need to take into account whether their individual security needs are actually being met in order to be truly secure, and not only compliant." Twitter: @MikeMiliardHITN Email the writer: mike.miliard@himssmedia.com Healthcare IT News is a HIMSS Media publication.
By Tom Sullivan | 12:22 pm | April 11, 2019
Infosec is a patient safety issue and it’s critical that customers trust you. But many health systems have been investing too little for years. It’s time for that to change.
By Bill Siwicki | 12:15 pm | April 11, 2019
Three high-profile physician IT leaders offer their takes and advice on the usability of data brought together by interoperability technologies and standards.
By Nathan Eddy | 11:11 am | April 11, 2019
The iPhone app enables patients to access data about medications, immunizations, labs and receive notifications.
By Staff Writer | 01:00 am | April 11, 2019
Cryptographic technology addresses the security problems that blockchain doesn’t, according to Cryptoloc Technology Founder Jamie Wilson. “Everyone is looking at blockchain, but there are a whole lot of flaws with this technology. Even with a private blockchain, you’re enabling a cyberattacker to take control of your entire system. Blockchain also involves the use of an open ledger, which allows an attacker to track back and access your entire medical history,” he told HITNA. “With cryptographic technology, no one else has access to the information except for the user themselves. There’s also a full audit trail where everything is date and time stamped, so you’ll know who has accessed the file and where they have accessed it from.” Wilson said security by design – taking a proactive instead of reactive approach to data security by building security into infrastructures from the ground up – is the best approach. “Cryptographic technology allows just that. By encrypting each and every file uniquely, no two files are the same. And malware and ransomware gets reduced as should a user gets attacked, you can identify that they’re being held to ransom.” Wilson identified that heightened levels of connectivity in Australia’s national healthcare system have also created additional points of exposure for cyberattacks, highlighting the need for new ways to secure these systems “The ideals behind having a national health system to share and control medical records between doctors, specialists and patients is sound and could vastly improve the quality of healthcare in Australia,” he said. “Unfortunately, storing and sharing such a wealth of personal data provides many security vulnerabilities and is a lucrative target for cyber criminals.” With the national healthcare system suffering many compromises – the number of data breaches involving My Health Record has risen from 35 incidents in the last financial year to 42 incidents this year – and more than 2.5 million opting out of using the voluntary system, Wilson said stronger data security technologies are necessary. “Cybercriminals are not looking at just one individual; they’re looking at a wider collection of information to be able to attack them later and abuse their identity,” Wilson said. A recent Office of the Australian Information Commissioner (OAIC) report supported his claim, identifying that malicious and criminal attacks were the second largest source of data breaches from the health sector, at 46 per cent. It also found that cyber incidents were the most common type of attack, accounting for 44 per cent, while theft of paperwork or data storage device was the second most common type of attack (32 per cent). “A centralised health record system is a fantastic idea. However, we need to be able to secure this data and be able to share this information securely on a global stage to ensure that individuals receive the correct medical treatment that they’re entitled to,” he said. [Read more: Connected care: protecting patient privacy and security | Industry calls for more caution over MHR system] Wilson also said Australia is not where it needs to be from a global healthcare security perspective. “Australia is falling with regards to cyber and the securing of information,” he said. “The best way of doing this is reviewing the way that we do security today and bringing the control back to the user. That gives the user the control to be able to share their information with third parties should they wish to do so. This ensures that information is not flowing out to multiple parties outside of the system.” In addition, Wilson addressed the need for more security around external mobile devices, especially with more BYOD (bring-your-own-devices) and Internet of Things devices getting integrated into the healthcare system. “This goes back to what I mentioned around security by design and having security built into every part of the healthcare IT management process,” he added. Wilson will further discuss how the new cryptographic platform of Cryptoloc reinvents data security at the upcoming 2019 HIMSS Health 2.0 eHealth Summit in Singapore.
11:26 pm | April 10, 2019
The Australian Digital Health Agency (ADHA) has opened an online consultation for all Australians to have a say on the development of a more modern, digitally connected health system. The online consultation, part of a nationwide series of discussions used to co-design the National Health Interoperability Roadmap, allows clinicians, healthcare organisations, consumers and the technology sector to converse about standards and priorities required for an interoperable health system. The roadmap is a key priority of the National Digital Health Strategy, which was approved by all states and territories through the Council of Australian Government (COAG) Health Council in 2017. The strategy identifies the importance of connected health services and calls for the definition of standards to support interoperability.  “Industry clinical software supports millions of digital transactions daily through public and private health systems. A collaborative consensus on standards will increase the confidence of all users and make a more interconnected health system possible for patients and their healthcare providers,” Medical Software Industry Association CEO Emma Hossack said.  According to the ADHA, interoperability holds the potential to bring patients’ records together from a range of systems and to provide access to information from disparate sources, give consumers and providers greater visibility and enable research and innovation. “Best use of data and technology is key to sustainable, high quality and person-centred healthcare,” ADHA CEO Tim Kelsey said. “We’ve made progress since the National Digital Health Strategy was launched in 2018 – including creating a My Health Record for nine out of 10 Australians, and developing standards for secure digital messages to replace letters and fax machines in healthcare. “We are now developing the plan to move Australia to the next stage of connected care. Improving the interoperability of health and care services so that the right information is available at the right time for the right person is fundamental to improving the outcomes and experience of healthcare.” In addition to the online consultation, ADHA will be facilitating 50 digital health community conversations nationally in the coming months with members of the healthcare sector, health technology industry and consumer representatives to collaborate on how digital technology can best support the delivery of a person-centred healthcare system. ADHA is also welcoming written submissions by email or mail. This article first appeared on Healthcare IT News Australia. .jumbotron{ background-image: url("https://www.healthcareitnews.com/sites/hitn/files/u2556/InteroperabilityJumbotron.jpg"); background-size: cover; color: white; } .jumbotron h2{ color: white; } Focus on Interoperability During April, we'll talk to experts and thought leaders about what's really happening in interoperability and share insights about what the future holds.