<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avoid Breach Notification - Experior helps PHI Encryption &#187; phr</title>
	<atom:link href="http://www.experiordata.com/blog/tag/phr/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Do your tablet, laptop, and desktop PCs need encryption if you use web-based EMR/EHR/PHR?</title>
		<link>http://www.experiordata.com/blog/2009/11/19/do-your-tablet-laptop-and-desktop-pcs-need-encryption-if-you-use-web-based-emrehrphr/</link>
		<comments>http://www.experiordata.com/blog/2009/11/19/do-your-tablet-laptop-and-desktop-pcs-need-encryption-if-you-use-web-based-emrehrphr/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 15:01:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[emr]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[phr]]></category>
		<category><![CDATA[web app]]></category>
		<category><![CDATA[web-based emr]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=188</guid>
		<description><![CDATA[



Image via Wikipedia



There has been much debate about security of endpoint devices like tablet PCs, desktops, and laptops where web-based EMR packages are used. There is a potential false sense of security by assuming that just because an EMR or PMR app is web-based then data at rest encryption, like whole disk encryption, is not [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Tablet.jpg"><img title="Photo of HP Tablet PC running MS Windows Table..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/4/4f/Tablet.jpg/300px-Tablet.jpg" alt="Photo of HP Tablet PC running MS Windows Table..." width="300" height="314" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Tablet.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>There has been much debate about security of endpoint devices like tablet PCs, desktops, and laptops where web-based EMR packages are used. There is a potential false sense of security by assuming that just because an EMR or PMR app is web-based then data at rest encryption, like whole disk encryption, is not required since no local data is stored. However, consider these possible scenarios:</p>
<p><span style="color: #808080;"><br />
 </span></p>
<p>- <a class="zem_slink" title="Protected health information" rel="wikipedia" href="http://en.wikipedia.org/wiki/Protected_health_information">Protected health information</a> (PHI) is exported from an EMR, practice management, or even an accounting  app and is stored locally in a <a class="zem_slink" title="Text file" rel="wikipedia" href="http://en.wikipedia.org/wiki/Text_file">text file</a> or a Microsoft Office document.</p>
<p><br class="spacer_" /></p>
<p>- If you use mainframes and use terminal emulators a user could do a &#8220;print screen&#8221; to save the image locally.</p>
<p><br class="spacer_" /></p>
<p>- E-mail attachments containing PHI could be saved locally.</p>
<p><br class="spacer_" /></p>
<p>- Web browser temp and cookie files could contain clues about how data is accessed and retrieved.</p>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 133px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Outlook_2007.png"><img title="Microsoft Office Outlook" src="http://upload.wikimedia.org/wikipedia/en/b/b0/Outlook_2007.png" alt="Microsoft Office Outlook" width="123" height="123" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Outlook_2007.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>- E-mail clients that have a local store could be used. The  local store, like a personal folder file (<a class="zem_slink" title="Personal Storage Table" rel="wikipedia" href="http://en.wikipedia.org/wiki/Personal_Storage_Table">.pst</a>) file in Microsoft Outlook, could contain PHI. Also, in a Microsoft Exchange environment the end user could inadvertently enable the AutoArchive feature where older content is stored locally on the computer in a .pst file.</p>
<p><br class="spacer_" /></p>
<p>In a recent <a title="Are You Secured? article in ADVANCE for HIM journal" href="http://health-information.advanceweb.com/editorial/content/editorial.aspx?cc=210501" target="_blank">Advance for HIM article entitled &#8220;Are you Secured&#8221;</a>, Daniela Crivianu-Gaita, chief information officer at The Hospital for Sick Children, Toronto. writes:</p>
<p><br class="spacer_" /></p>
<p>&#8220;Facilities can opt to encrypt parts of their IT system, but full-disk encryption ensures the organization is covered in the event of a breach. &#8220;Temporary files created by various applications, the operating system swap file and hidden partitions may contain sensitive data,&#8221; said Daniela Crivianu-Gaita, chief information officer at The Hospital for Sick Children, Toronto. &#8220;Full-disk encryption is the only approach that assures all the data on the local hard disks is encrypted.&#8221;</p>
<p><br class="spacer_" /></p>
<p>The point is that just because the EMR or other app that is web-based is used in you environment it doesn&#8217;t meant that data at rest protection should be ignored. Installing whole disk encryption to protect data at rest could provide peace of mind and protection against unwanted breach notification should that device be lost or stolen. With the strict enforcement of breach notification rules coming to fruition in February, 2010 it&#8217;s better to be safe then sorry by implementing encryption as specified in the HITECH Act within ARRA.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://docinthemachine.com/2009/11/09/encrypt/">Encrypt EHR &#8211; Else HIPAA Violations Need Be Reported To Government &amp; Media</a> (docinthemachine.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/d8317ec0-b99d-4d68-b2de-7fdfcd765465/"><img class="zemanta-pixie-img" style="border: medium none ; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=d8317ec0-b99d-4d68-b2de-7fdfcd765465" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/11/19/do-your-tablet-laptop-and-desktop-pcs-need-encryption-if-you-use-web-based-emrehrphr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
