chime lead dc 2014 “key attributes for success, challenges and critical success factors” with...

18
A CHIME Leadership Education and Development Forum in collaboration with iHT 2 Creating an Effective Cyber Security Strategy ________ Key Attributes for Success, Challenges and Critical Success Factors ● Angela Duncan Diop, ND, CHCIO, VP of Information Systems Unity Health Care, Inc. ● #LEAD14

Upload: health-it-conference-iht2

Post on 24-Jun-2015

123 views

Category:

Education


0 download

DESCRIPTION

CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc.

TRANSCRIPT

Page 1: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

A CHIME Leadership Education and Development Forum in collaboration with iHT2

Creating an Effective Cyber Security Strategy

________Key Attributes for Success, Challenges and

Critical Success Factors

● Angela Duncan Diop, ND, CHCIO, VP of Information Systems

Unity Health Care, Inc. ●

#LEAD14

Page 2: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

ANATOMY OF A BREACH

A CHIME Leadership Education and Development Forum in collaboration with iHT2

Page 3: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

INTRODUCTION

Page 4: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

Unity Health Care, Inc.Federally

Qualified Health Center

Over 100,000 unique patients

in 2013

30 sites; health centers,

homeless service sites, school based health

centers, correctional sites, and a mobile site Mission

Promoting healthier communities through compassion and comprehensive health and human services, regardless of ability to pay.

4

Page 5: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

5

Unity’s Patients• Patient population is

racially and ethnically diverse and largely minority

• Substantial health disparities and poor health outcomes exist

• Great need for accessible and comprehensive primary care services

Page 6: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

THE INCIDENTData is like water – it always flows through the cracks

Page 7: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

Description• A personal laptop

containing data from a nutrition and exercise program

• Student assisting in the analysis of data saved it to a flash drive.

• Loaded to a personal computer.

• Stolen from a student’s home in a burglary.

FreeDigitalPhotos.net

Page 8: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

Description

• Type of Incident: Theft

• Location of Breach: Laptop computer - unencripted

• Approximate number of individuals affected by the breach: 305

FreeDigitalPhotos.net

Page 9: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

THE CALLTo breach or not to breach – that is the question.

Page 10: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

Type of PHI Involved

• Demographic information – name and DOB

• Clinical Information -diagnosis/conditions

• The data consisted of names, dates of birth, weight, body mass index, and for a limited number of participants, information regarding a history of hypertension or diabetes.

Page 11: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

Risk Assessment

• Consulted our HIPAA auditor• Consulted our attorney• Met/discussed with our Executive

Management team• Decided to treat the incident as a

breach

Page 12: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

THE RESPONSENever let a good crisis go to waste

Page 13: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

Created a Team

• Appointed a breach response team– Privacy Officer– VP of Information

Systems– Legal Counsel– VP of Clinical

Administration– Deputy Chief Medical

Officer– VP of Human Resources

Page 14: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

Gap Analysis &Corrective Action Plan

• Overall responsibility – Privacy Officer or VP of IS

• Identifies the steps that led to incident

• Captures key info surrounding the incident– Description– Issues/Gaps– Lead – Due date

Page 15: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

Incident Response Plan

• Plan that the team creates and follows to address the incident– Investigation– Risk Assessment– Notifications –

Patients, HHS, Staff Exe Man Team, Exe. Board

– Corrective actions

Page 16: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

EPILOGUEMilk the crisis for all it’s worth

Page 17: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

Benefits Gained

• Blue print for responding to a breach

• Breach team• Breach management policy• Breach insurance• Retraining of staff• Heightened awareness by senior

leadership and Board

Page 18: CHIME LEAD DC 2014 “Key Attributes for Success, Challenges and Critical Success Factors” with Angela Diop, ND, CHCIO, VP of Information Systems, Unity Health Care, Inc

Q & AAngela Duncan Diop, ND, CHCIO

[email protected]

A CHIME Leadership Education and Development Forum in collaboration with iHT2

@AngelaDiop@UnityHealthCare