PhysiciansPractice Members: Login | Register

  • Home
  • About Us
  • Today's Practice
  • Live
  • CME
  • Podcasts
  • Tools
  • Topics
  • Blog
  • Career
  • Coding
  • EHR
  • Finance
  • Malpractice
  • Patient Relations
  • Staff
  • Technology
  • Buyers Guide
  • Publication

Home » Topics

Physicians Practice. Vol. 18 No. 6
Pages: 1  2  3  
Previous Next
 

Technology: Do You Know Where Your Data Is?

Five easy steps to total tech security

By Robert Anthony | April 1, 2008


WAIT! STOP!

Getting a headache? No wonder. A medical practice shouldn’t have to double as an IT support company.

There’s an easier way. It’s called a patient portal, and it lets your practice keep physician-patient communications secure without being too complex or asking patients to download a single thing.

A patient portal is nothing more than a protected Web site that resides on your network server. To access the site, patients have to enter a username and password. Only then can they communicate with the practice or read messages from their physicians. By keeping the Web site on your server, you can make sure your communications remain private.

Family Practice Associates of Lexington uses a portal to communicate with their patients. “We accept requests for appointments, prescription refills, and some basic questions via the Web site in a secure environment,” says Miller.

Luckily, setting up a patient portal isn’t very difficult. In fact, says Dunn, many practice management programs already have some sort of portal component. She recommends using a patient portal over e-mail encryption. Talk to your practice management software vendor to evaluate what option is best for your needs.

3. Grill your vendors
In fact, you should talk to all of your software vendors about their security measures. Most people assume their EMR vendor has adequate security, but that may not be true.

“Don’t be satisfied with hearing, ‘Yes, we adhere to all HIPAA security rules and regulations,’” says Dunn. “Tell me what you mean by that. What ones are you referring to? And how do you adhere to them? Some people don’t even ask, so they don’t really know.”

Also, don’t be surprised if you get an answer you weren’t expecting. Security isn’t the highest priority for many EMR vendors, says Chang. Consequently, only the newest EMR vendors are very tight with security and encrypting user-to-network connections. In fact, Chang estimates that only one or two out of the approximately 300 EMR products on the market today incorporate the very highest level of encryption services.

For many practices, the best solution is to outsource security to people who understand networks and computers better than they do. That’s what Family Practice Associates of Lexington does. With 10 family physicians, two midlevel providers, and a family therapist on staff, the practice can’t afford to hire a full-time IT department for their needs — even if they do have more than 100 workstations!

“There are some of the larger practices with multiple locations that have in-house IT staff, but most of us in the small- to medium-sized group setting . . . tend to contract out the more demanding parts,” says Miller.

If you decide to use an outside company for your networking and security needs, Miller recommends locating a vendor specifically experienced with medical practices. “Not only from the standpoint of the extra security measures that need to go along with patient confidentiality, but also so that they understand the medical environment,” Miller says. “The bottom line is that I can’t be down in the middle of the day for three hours while we’re trying to see patients. It’s just absolutely impossible.”

4. Have a backup plan
Most people don’t think about backing up their data as a security measure, but an important part of HIPAA’s security requirements is data protection and recovery. HIPAA regulations require that your practice have a plan for backing up patient information, storing backups, and retrieving data in the case of an emergency. It’s also a good idea for your practice to have such a plan in place so it can continue operating if something happens to the network.

Family Practice Associates of Lexington has multiple redundancy measures in place when it comes to data protection. “We do have tape backups here on site. We back up on a nightly basis. We keep the tapes here in a fireproof safe, plus we take a copy off-site on a daily basis so that we don’t ever have all of our data in one place,” explains Miller. “More important, our practice management and our EMR are backed up remotely to our software vendor. Our network is backed up to our networking vendor. So we are backed up three or four different ways.”

And make sure that any data that leaves your practice is also protected. “One of the mistakes practices make is they make a backup tape, and they leave it off-site,” says Chang. “What if the tape was lost or stolen? I can grab that tape and stick it in any tape drive and be able to read your information.” Be sure to encrypt or password protect any of your backup tapes or network drives to avoid this scenario.

Pages: 1  2  3  
Previous Next
 

Add your own comment







Topic Index

Best States to Practice
Career

Coding
Classifieds
EHR
Finance
Law & Malpractice

Patient Relations
Patient Dismissal
RVU/Relative Value Units
Staff Management
Staff Salaries
Technology
All Topics

 

-- Advertisement--

FixIt

Decisions, Decisions: Your IT Shopping Checklist
Medical Practice Management Technology Resources
Lab Tracking Tool
Calculate EMR ROI


  • On This Site
  • Most Emailed
  • On This Topic

MostPopular

  • The Best States to Practice: America’s Physician-Friendliest States

    FEB 1 2007 PHYSICIANS PRACTICE READ >>

  • What Should You Pay Staff?

    JUL 14 2010 PHYSICIANS PRACTICE READ >>

  • Solving Your 9 Biggest Billing Blunders

    APR 30 2010 PHYSICIANS PRACTICE READ >>

  • Coding Questions? We’ve Got the Answers

    JUN 1 2010 PHYSICIANS PRACTICE READ >>

  • Coding Questions? We've Got the Answers

    NOV 14 2003 PHYSICIANS PRACTICE READ >>

MostPopular

  • Solving Your 9 Biggest Billing Blunders

    APR 30 2010PHYSICIANS PRACTICE READ >>

  • What Should You Pay Staff?

    JUL 14 2010PHYSICIANS PRACTICE READ >>

  • How to Deal with Grouchy Patients

    AUG 18 2010PHYSICIANS PRACTICE READ >>

  • Preparing for the ICD-10 Transition

    AUG 20 2010PHYSICIANS PRACTICE READ >>

  • Using Social Networking as a Marketing Tool

    AUG 31 2010PHYSICIANS PRACTICE READ >>

MostPopular

  • The Best States to Practice: America’s Physician-Friendliest States

    FEB 1 2007 PHYSICIANS PRACTICE READ >>

  • What Should You Pay Staff?

    JUL 14 2010 PHYSICIANS PRACTICE READ >>

  • Solving Your 9 Biggest Billing Blunders

    APR 30 2010 PHYSICIANS PRACTICE READ >>

  • Coding Questions? We’ve Got the Answers

    JUN 1 2010 PHYSICIANS PRACTICE READ >>

  • Coding Questions? We've Got the Answers

    NOV 14 2003 PHYSICIANS PRACTICE READ >>


SponsoredWhitePapers

EMR Mythbusters
- Nuesoft Technologies

Investing in Patient Education — The Benefits for Your Patients and Your Practice
- Krames

A Beginner’s Guide to Selecting an EHR
- Welch Allyn

EMR Readiness: The R-Factor
- GE Healthcare

View All

 

CancerNetwork | ConsultantLive | Diagnostic Imaging | Psychiatric Times | Physicians Practice | SearchMedica

© 1996 - 2010 UBM Medica LLC, a United Business Media company
Privacy Statement - Terms of Service - Advertising Information - Editorial Policy Statement


 
ADDITIONAL ONLINE RESOURCES FROM UBM MEDICA
Featured Resources > Psychiatry Careers > Practice Management Conference > Today's Practice - Practice Management Resource > RSV Information > EHR Resources
CancerNetwork > Cancer diagnosis, treatment, and prevention > Podcasts for Oncologists > Cancer Patient Resources > Oncology Areas of Confusion > Oncology News > Cancer Management Handbook > Breast Cancer Resource > Bone Metastases > Chronic Myeloid Leukemia
Consultant Live > Diabetes Resources > Pediatric Asthma > Practical Clinical Advice > Medical Photoclinic > Diagnosing and Treating H1N1 flu (swine flu) > Primary Care Conference Reports > Community Acquired MRSA
Diagnostic Imaging > Medical Imaging News and Features > Medical Imaging and Radiology White Papers > Radiology Conference Reports > Radiology Special Reports > Radiology Net Seminars > Imaging Trends and Advances > RSNA 2009 Conference Coverage > Radiology Vendors
Psychiatric Times > Psychiatric News and Special Reports > APA Conference Report > Psychiatric Clinical Scales > Psychiatric Times Blog > Psychiatry Career Opportunities > DSM-5 > Major Depressive Disorder
Physicians Practice > Practice Management > EMR Software > Medical Practice Management Software > Medical Buyers Guide > Medical Coding > Practice Management Blog
SearchMedica > Professional Medical Search Engine > Medical Search Tips Newsletter > Medical Search News > Diabetes Research and Articles
Musculoskeletal Network > Muscle, Bone, Joint Medical Resources > Rheumatoid Arthritis Resource Center
The AIDS Reader > HIV News, Treatment, and Diagnosis for Medical Professionals
CME LLC > Continuing Medical Education > Psychiatry CME > Oncology CME > Practice Management CME > Primary Care CME > Psychiatric Congress > Performance Improvement CME > Treating the Whole Patient (TWP) — The Mind-Body Connection
More Resources > Consumer Healthcare Information > Patient and Caregiver Resource > Search drug information, interactions, images & diagnosis > Infectious Diseases > Respiratory Disease