working with hit systems unit 7a protecting privacy, security, and confidentiality in hit systems...

13
Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University, funded by the Department of Health and Human Services, Office of the National Coordinator for Health Information Technology under Award Number IU24OC000013.

Upload: wendy-walton

Post on 18-Jan-2018

220 views

Category:

Documents


0 download

DESCRIPTION

Electronic Health Information Risks and Opportunities Access to electronic vs. paper records Public apprehension around digitization of health information Success of HIT systems depends on ensuring patient privacy Security can facilitate patient-centered care Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring

TRANSCRIPT

Page 1: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

Working with HIT SystemsUnit 7a Protecting Privacy,

Security, and Confidentiality in HIT Systems

This material was developed by Johns Hopkins University, funded by the Department of Health and Human Services, Office of the National Coordinator for Health Information Technology under Award Number IU24OC000013.

Page 2: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

ObjectivesBy the end of this unit the student will be able to:•Explain and illustrate privacy, security, and confidentiality in HIT settings.•Identify common threats encountered when using HIT.•Formulate strategies to minimize threats to privacy, security, and confidentiality in HIT systems.

Component 7/Unit 7 2Health IT Workforce Curriculum Version 2.0/Spring 2011

Page 3: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

Electronic Health Information Risks and Opportunities

• Access to electronic vs. paper records• Public apprehension around digitization of

health information• Success of HIT systems depends on

ensuring patient privacy• Security can facilitate patient-centered

care

Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring 2011 3

Page 4: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

Privacy, Confidentiality, Security Defined

• Privacy: patient is in control• Confidentiality: only authorized individuals

are allowed access• Security: controls/safeguards that ensure

confidentiality

Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring 2011 4

Page 5: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

Security Management System Standards

• ISO 27001• NIST 800-53• HIPAA

Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring 2011 5

Page 6: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

HIPAA and PHI• Health Insurance Portability and

Accountability Act of 1996• Privacy Rule (effective 2003)• Security Rule (effective 2005)• HITECH Act of 2009

Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring 2011 6

Page 7: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

Types of Security Safeguards

• Administrative Safeguards

• Physical Safeguards

• Technical Safeguards

Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring 2011 7

Image: MS Clipart

Page 8: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

Administrative Safeguards• Security Management Process

– Risk Analysis– Risk Management– Sanction Policy– System Activity Review

Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring 2011 8

Image: http://www.hhs.gov

Page 9: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

Administrative Safeguards• Assigned Security Responsibility

– Security officer

Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring 2011 9

Image: MS Clipart

Page 10: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

Administrative Safeguards• Workforce Security, Information Access

Management– Who can and who cannot have access– Who determines who can have access and

how– Employee turnover– Contractors– User roles

Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring 2011 10

Image: MS Clipart

Page 11: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

Administrative Safeguards• Security Awareness and Training

– Training– Security reminders– Log-in monitoring– Password management

Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring 2011 11

Image: MS Clipart

Page 12: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

Administrative Safeguards• Security Incident Procedures• Contingency Plan

– Data backup– Disaster recovery– Emergency operation plan

Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring 2011 12

Image: MS Clipart

Page 13: Working with HIT Systems Unit 7a Protecting Privacy, Security, and Confidentiality in HIT Systems This material was developed by Johns Hopkins University,

Administrative Safeguards• Evaluation• Business Associate Agreements

Component 7/Unit 7 Health IT Workforce Curriculum Version 2.0/Spring 2011 13

Image: http://www.hhs.gov