<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avoid Breach Notification - Experior helps PHI Encryption &#187; Add new tag</title>
	<atom:link href="http://www.experiordata.com/blog/tag/add-new-tag/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Security for Meaningful Use: Part 2 &#8211; Electronic Access to Protected Health Information (PHI)</title>
		<link>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/</link>
		<comments>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 17:34:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[Pretty Good Privacy]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=352</guid>
		<description><![CDATA[Standards Set for Providing Secure Access to Patient Records





Image via Wikipedia



According to the Initial Set of Standards for Electronic Health Records patients must be provided with their health information (most certainly protected health information -PHI- under HIPAA) electronically and securely within 96 hours.


&#8220;Consistent with the HIT Policy Committee&#8217;s recommendations, we propose the following additional clarification [...]]]></description>
			<content:encoded><![CDATA[<h2>Standards Set for Providing Secure Access to Patient Records</h2>
<p><br class="spacer_" /></p>
<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:VistA_Img.png"><img title="Sample patient record view from VistA Imaging" src="http://upload.wikimedia.org/wikipedia/en/thumb/8/8f/VistA_Img.png/300px-VistA_Img.png" alt="Sample patient record view from VistA Imaging" width="300" height="225" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:VistA_Img.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>According to the <a title="Initial set of standards for certified electronic health records (EHRs) released by HHS/CMS" href="http://www.experiordata.com/blog/2009/12/31/regulation-bonanza-hhs-releases-two-interim-rules-on-123009/">Initial Set of Standards</a> for <a class="zem_slink" title="Electronic health record" rel="wikipedia" href="http://en.wikipedia.org/wiki/Electronic_health_record">Electronic Health Records</a> patients must be provided with their health information (most certainly <strong>protected</strong> health information -PHI- under <a class="zem_slink" title="Health Insurance Portability and Accountability Act" rel="wikipedia" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a>) electronically <strong>and</strong> securely within 96 hours.</p>
<p><br class="spacer_" /></p>
<address>
<p>&#8220;Consistent with the HIT Policy Committee&#8217;s recommendations, we propose the following additional clarification of this objective. Electronic copies may be provided through a number of secure electronic methods (for example, personal health record (</p>
</address>
<address>
<p>PHR), patient portal, CD, <a class="zem_slink" title="Universal Serial Bus" rel="wikipedia" href="http://en.wikipedia.org/wiki/Universal_Serial_Bus">USB</a> drive).</p>
<p><br class="spacer_" /></p>
<p>Provide patients with timely electronic access to their health information (including lab results, problem list, medication lists, allergies) within 96 hours of the information being available to the EP. Also, consistent with the HIT Policy Committee recommendations, we propose the following additional clarification of this objective. Electronic access may be provided by a number of <span style="font-style: normal;"><strong>s</strong></span><strong>ecure electronic methods (for example, PHR, patient portal, CD, USB drive).</strong> Timely is defined as within 96 hours of the information being available to the EP either through the receipt of final lab results or a patient interaction that updates the EP&#8217;s knowledge of the patient&#8217;s health. We judge 96 hours to be a reasonable amount of time to ensure that certified EHR technology is up to date. We welcome comment on if a shorter or longer time is advantageous.&#8221;</p>
</address>
<address> </address>
<h2><span style="font-style: normal;">How to Secure Health Records</span></h2>
<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:USBVacuumCleaner.jpg"><img title="USB Vacuum Cleaner, a giveaway from an IBM event" src="http://upload.wikimedia.org/wikipedia/commons/thumb/7/77/USBVacuumCleaner.jpg/300px-USBVacuumCleaner.jpg" alt="USB Vacuum Cleaner, a giveaway from an IBM event" width="300" height="225" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:USBVacuumCleaner.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><span style="font-style: normal;">You may be wondering how can patient information be secured. The best way to secure information is by encrypting the </span><span style="font-style: normal;">media. However, note that <strong>patients must be able to decrypt the information</strong> on their own computer equipment. One of the product Experior Data implements is called <a title="PGP Portable allows you to encrypt data on removable media but lets people decrypt it on other computers without requiring special software to be installed" href="http://www.pgp.com/products/portable/index.html" target="_blank">PGP Portable</a>. For example, the patient provides a USB drive for you to copy the PHI onto it. PGP Portable encrypts the entire USB device after the information is copied to it. The patient must provide a passphrase during the <a class="zem_slink" title="Encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/Encryption">encryption</a> process. When the patient goes home he/she inserts the USB drive into their home computer and is prompted for the passphrase. After the passphrase is entered access to the patient information is provided.</span></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://projecthealthdesign.typepad.com/project_health_design/2009/08/hies-are-beginning-to-link-patients-directly-to-their-own-health-data.html">HIEs are Beginning to Link Patients Directly to their Own Health Data</a> (projecthealthdesign.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://chilmarkresearch.com/2009/09/23/pushing-onc-to-act-on-consumers-behalf/">Pushing ONC to Act on Consumer&#8217;s Behalf</a> (chilmarkresearch.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.medicineandtechnology.com/2009/12/medfusion-maintains-leadership-in.html">Medfusion Maintains Leadership in Patient Portal Performance</a> (medicineandtechnology.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blogs.wsj.com/health/2009/12/30/how-to-get-20-billion-for-using-electronic-medical-records/">How to Get $20 Billion for Using Electronic Medical Records</a> (blogs.wsj.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/76960f38-a396-49b1-bf12-c9961f5125fc/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=76960f38-a396-49b1-bf12-c9961f5125fc" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security for Meaningful Use: Part 1 &#8211; Web services</title>
		<link>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-1-web-services/</link>
		<comments>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-1-web-services/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 06:48:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[Service-oriented architecture]]></category>
		<category><![CDATA[SOAP]]></category>
		<category><![CDATA[Web service]]></category>
		<category><![CDATA[XML]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=343</guid>
		<description><![CDATA[



Image via Wikipedia



Web Services At Forefront

If you intend on implementing electronic records and apply for the Electronic Health Record Incentive Program (EHRIP) you must demonstrate &#8220;meaningful use&#8221; of the electronic health record system. One of the provisions in EHRIP is information sharing. The authors of the EHRIP specifically set out to standardize on two protocols [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 285px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:XML.svg"><img title="A graphical depiction of a very simple xml doc..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/6/68/XML.svg/275px-XML.svg.png" alt="A graphical depiction of a very simple xml doc..." width="275" height="313" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:XML.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<h2>Web Services At Forefront</h2>
<p><br class="spacer_" /></p>
<p>If you intend on implementing electronic records and apply for the <a class="zem_slink" title="Electronic health record" rel="wikipedia" href="http://en.wikipedia.org/wiki/Electronic_health_record">Electronic Health Record</a> Incentive Program (EHRIP) you must demonstrate &#8220;meaningful use&#8221; of the electronic health record system. One of the provisions in EHRIP is information sharing. The authors of the EHRIP specifically set out to standardize on two protocols for information sharing:</p>
<ul>
<li><a class="zem_slink" title="SOAP" rel="wikipedia" href="http://en.wikipedia.org/wiki/SOAP">SOAP</a></li>
<li><a class="zem_slink" title="Representational State Transfer" rel="wikipedia" href="http://en.wikipedia.org/wiki/Representational_State_Transfer">REST</a></li>
</ul>
<p>Both of these technologies are know as <a class="zem_slink" title="Web service" rel="wikipedia" href="http://en.wikipedia.org/wiki/Web_service">web services</a>. Essentially, web services provide information sharing capabilities using <a class="zem_slink" title="Data model" rel="wikipedia" href="http://en.wikipedia.org/wiki/Data_model">structured data</a> files called <a class="zem_slink" title="XML" rel="wikipedia" href="http://en.wikipedia.org/wiki/XML">XML</a>. The purpose is to use these <a class="zem_slink" title="Open standard" rel="wikipedia" href="http://en.wikipedia.org/wiki/Open_standard">open standards</a> so that applications developed by different vendors could communicate and share information.</p>
<p><br class="spacer_" /></p>
<h2>Securing Web Services</h2>
<p><br class="spacer_" /></p>
<p>In terms of security it is important to ensure that the transmission between applications using these web services is properly encrypted using SSL <a class="zem_slink" title="Technology" rel="wikinvest" href="http://www.wikinvest.com/industry/Technology">technology</a>. In addition, considerations should be made to implement network and host <a class="zem_slink" title="Intrusion prevention system" rel="wikipedia" href="http://en.wikipedia.org/wiki/Intrusion_prevention_system">intrusion prevention systems</a> to ensure the security and integrity of the systems transmitting the shared information. For example, accepting SOAP requests will require you to set  up a <a class="zem_slink" title="DMZ (computing)" rel="wikipedia" href="http://en.wikipedia.org/wiki/DMZ_%28computing%29">DMZ</a> infrastructure. Servers sitting in the DMZ will need to accept SOAP requests and send them. It is the traffic to and from these servers, and the servers themselves, that need to be protected.</p>
<p><br class="spacer_" /></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.slideshare.net/rnewton/web-services-hacking-and-hardening">Web Services Hacking And Hardening</a> (slideshare.net)</li>
<li class="zemanta-article-ul-li"><a href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/12/11/the-xml-security-relay-race.aspx">The XML Security Relay Race</a> (devcentral.f5.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/11/health-it-buzz-hhs-launches-healthcare.html">Health IT Buzz &#8211; HHS Launches Healthcare Blog to Communicate with Dr. Blumenthal</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://clinicalit.blogspot.com/2009/12/heres-rule-for-meaningful-use.html">Here&#8217;s the rule for meaningful use</a> (clinicalit.blogspot.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/7993140a-f705-4f45-909d-e89dd1de5bd5/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=7993140a-f705-4f45-909d-e89dd1de5bd5" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-1-web-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Oldie but Goodie &#8211; Nurses fired for posting photo of X-Ray</title>
		<link>http://www.experiordata.com/blog/2009/12/29/oldie-but-goodie-nurses-fired-in-for-posting-photo-of-x-ray/</link>
		<comments>http://www.experiordata.com/blog/2009/12/29/oldie-but-goodie-nurses-fired-in-for-posting-photo-of-x-ray/#comments</comments>
		<pubDate>Tue, 29 Dec 2009 04:00:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[breach notification]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[Lake Geneva Wisconsin]]></category>
		<category><![CDATA[oldie but goodie]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=329</guid>
		<description><![CDATA[



Image via CrunchBase



Filed under &#8220;you just can&#8217;t make this stuff up&#8221; from our friends in Lake Geneva, Wisconsin:
&#8216; &#8216;There were two nurses that independently took a picture each of an X-ray of a patient,&#8217; Walworth County Undersheriff Kurt Picknell said.
 The patient was admitted to the emergency room with an object lodged in his rectum. [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 255px;">
<dt class="wp-caption-dt"><a href="http://www.crunchbase.com/company/facebook"><img title="Image representing Facebook as depicted in Cru..." src="http://www.crunchbase.com/assets/images/resized/0000/4561/4561v1-max-250x250.png" alt="Image representing Facebook as depicted in Cru..." width="245" height="100" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://www.crunchbase.com">CrunchBase</a></dd>
</dl>
</div>
</div>
<p><span style="font-size: medium;">Filed under &#8220;you just can&#8217;t make this stuff up&#8221; from our friends in <a title="Nurse fired over posting x-ray of patient on Facebook" href="http://www.wisn.com/cnn-news/18796315/detail.html" target="_blank">Lake Geneva, Wisconsin:</a></span></p>
<p><span style="font-size: x-small;">&#8216; &#8216;There were two nurses that independently took a picture each of an <a class="zem_slink" title="X-ray" rel="wikipedia" href="http://en.wikipedia.org/wiki/X-ray">X-ray</a> of a patient,&#8217; <a class="zem_slink" title="Walworth County, Wisconsin" rel="wikipedia" href="http://en.wikipedia.org/wiki/Walworth_County%2C_Wisconsin">Walworth County</a> Undersheriff Kurt Picknell said.<br />
 The patient was admitted to the emergency room with an object lodged in his rectum. Police said the nurse explained she and a co-worker snapped photos when they learned it was a sex device. Police said discussion about the incident was posted on her <a class="zem_slink" title="Facebook" rel="homepage" href="http://facebook.com">Facebook</a> page, but they haven&#8217;t found anyone who actually saw the pictures.&#8221;</span></p>
<p><span style="font-size: medium;">Well, contrary to common sense one has to wonder at what point do you say to yourself, &#8220;hey, I probably shouldn&#8217;t take a picture of an X-Ray belonging to a patient and post it on Facebook&#8221;.</span> <span style="font-size: medium;">Although its not known if the X-Ray contained protected health information (PHI), we would venture to say that posting the X-Ray is probably not a good idea. I mean they could have encrypted it!</span></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.guardian.co.uk/uk/2009/sep/09/hospital-lying-down-game&amp;a=7536168&amp;rid=3ab074e6-f4ec-4b94-aaa7-00d2d879b785&amp;e=36aafa702ac6ebe5d7613716d047a7f5">Medics suspended over Facebook antics</a> (guardian.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.telegraph.co.uk/news/uknews/6149789/NHS-staff-suspended-for-playing-The-Lying-Down-Game.html&amp;a=7527953&amp;rid=3ab074e6-f4ec-4b94-aaa7-00d2d879b785&amp;e=62745a57d347adc89c45c2c279b009e5">NHS staff suspended for playing The Lying Down Game&#8217;</a> (telegraph.co.uk)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/3ab074e6-f4ec-4b94-aaa7-00d2d879b785/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=3ab074e6-f4ec-4b94-aaa7-00d2d879b785" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
<br />
 </span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/29/oldie-but-goodie-nurses-fired-in-for-posting-photo-of-x-ray/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
