PhysiciansPractice Members: Login | Register

  • Home
  • About Us
  • Today's Practice
  • Live
  • CME
  • Podcasts
  • Tools
  • Topics
  • Blog
  • Career
  • Coding
  • EHR
  • Finance
  • Malpractice
  • Patient Relations
  • Staff
  • Technology
  • Buyers Guide
  • Publication

Home » Topics

Physicians Practice. Vol. 17 No. 16
Pages: 1  2  3  
Previous Next
 

Technology: Data Security for Non-Techies

You don’t have to hold a degree in computer engineering to keep your data safe. Here are some simple security gaps anyone can plug.

By Pamela Moore | November 1, 2007


The laws are meant to give consumers a chance to protect themselves from identity theft. “So if there is a group that is taking credit card information or using Social Security numbers as identifiers on files” they need to be ready to comply, Adler stresses. “I don’t know many practices that have these policies in place. They need to look at the laws.” He encourages physicians to get away from relying on Social Security numbers, as far as possible, for this reason.

As for taking credit cards for payment, you must comply with privacy stipulations in the contract you have with your merchant as well as with the 2003 Fair and Accurate Credit Transactions Act, or FACTA. This law is the same one that lets you get a free credit report. But it also says credit and debit card receipts should not include more than the last five digits of the card number or the card’s expiration date.

While you are busy protecting your patients’ data, think about destroying some of your own. Businesses are increasingly setting rules regarding the destruction of electronic information and e-mails to avoid undue liability, Alder explains. This idea has merit. Look at how long you need to retain information for legal or business reasons; get rid of what you don’t need, he advises. If you have cleanup rules and follow them as a normal course of business — rather than in response to concerns about a specific case — you’ll be much better protected in the long run. There are now services that erase hard drives for you — which is harder than it sounds — and shred the hard drive itself into little metal nuggets.

Safe travel tips

You might have a firm policy prohibiting physicians from taking home paper charts. But how are staff and physicians using memory sticks — those handy little drives you stick into a USB port? Ross Duncan, vice president of channels for digital security firm Gemalto North America, worries about “the growing popularity of the use of memory sticks. Once [physicians put charts on one] they have probably violated half a dozen regulations.”

Most memory sticks have no protection whatsoever. If someone found the gadget, they could immediately access patients’ medical records. It’s better not to transfer data like that or to use a memory stick that requires a password or some other security.

Same thing goes for laptops and PDAs, which can be vulnerable to hacking. “Every time I put [my laptop] down in an airport, it leaves my sight. Anyone could steal it and break into it. So the information on my computer is encrypted,” says Robert M. Cothren, director for clinical information systems of Northrop Grumman’s health solutions division. What’s on the laptops and PDAs in use at your office? Make sure you regularly clean them and scrupulously protect the data.

What’s the password?

Of course the classic tools in digital security are user identifications and passwords. Effective? Yes, but only if used well.

“Physician practice groups often don’t have unique user IDs and passwords,” warns Adler. “They either share them or have one that everyone uses. If everyone is using the same password, it’s easier for someone to get into the system.”

Another mistake he sees: Practices continuing to use vendor-supplied user IDs and passwords long after they’ve implemented new software into their practice. Since it’s the same user ID and password every other practice initially gets, hackers will test to see if they’ve been reset or not.

If you are going to create new passwords, create good ones. “It can’t be a word,” says Cothren. “It has to have numbers and capital letters. The downside is that most people aren’t very good at remembering those so they tend to write them down.” And if the password expires every 90 days — another best practice — it’s even harder to remember and more tempting to write it down. Passwords on sticky notes pressed onto monitors defeat the purpose. Strive to balance password protection with the realities of adult memory capabilities.

Make sure, too, to have written policies you actually follow for “deprovisioning” passwords — that’s industry-speak for changing passwords when a staff person leaves your office.

In the near future, Cothren says, practices will be able to use two-factor authentication instead of passwords. That’s the technology you use for ATMs; you have a password (one factor) and a bankcard (the second factor). That’s the security gold standard. However, few computers in medical practices are set up with card scanners, and the biometric checks, which might provide an alternative, have so far proven too slow or awkward for medical use. “Finger-print readers can be hard to use if you have a glove on,” Duncan says. “People will crank down the sensitivity of the reader to speed up access, then break security rules.”

However, hospitals are experimenting with substitutes, such as sending physicians who log into a hospital system a second secret key via text message, for example, Cothren says.

Pages: 1  2  3  
Previous Next
 

Add your own comment







Topic Index

Best States to Practice
Career

Coding
Classifieds
EHR
Finance
Law & Malpractice

Patient Relations
Patient Dismissal
RVU/Relative Value Units
Staff Management
Staff Salaries
Technology
All Topics

 

-- Advertisement--

FixIt

Decisions, Decisions: Your IT Shopping Checklist
Medical Practice Management Technology Resources
Lab Tracking Tool
Calculate EMR ROI


  • On This Site
  • Most Emailed
  • On This Topic

MostPopular

  • The Best States to Practice: America’s Physician-Friendliest States

    FEB 1 2007 PHYSICIANS PRACTICE READ >>

  • What Should You Pay Staff?

    JUL 14 2010 PHYSICIANS PRACTICE READ >>

  • Solving Your 9 Biggest Billing Blunders

    APR 30 2010 PHYSICIANS PRACTICE READ >>

  • Coding Questions? We’ve Got the Answers

    JUN 1 2010 PHYSICIANS PRACTICE READ >>

  • Coding Questions? We've Got the Answers

    NOV 14 2003 PHYSICIANS PRACTICE READ >>

MostPopular

  • Solving Your 9 Biggest Billing Blunders

    APR 30 2010PHYSICIANS PRACTICE READ >>

  • What Should You Pay Staff?

    JUL 14 2010PHYSICIANS PRACTICE READ >>

  • How to Deal with Grouchy Patients

    AUG 18 2010PHYSICIANS PRACTICE READ >>

  • Preparing for the ICD-10 Transition

    AUG 20 2010PHYSICIANS PRACTICE READ >>

  • Using Social Networking as a Marketing Tool

    AUG 31 2010PHYSICIANS PRACTICE READ >>

MostPopular

  • The Best States to Practice: America’s Physician-Friendliest States

    FEB 1 2007 PHYSICIANS PRACTICE READ >>

  • What Should You Pay Staff?

    JUL 14 2010 PHYSICIANS PRACTICE READ >>

  • Solving Your 9 Biggest Billing Blunders

    APR 30 2010 PHYSICIANS PRACTICE READ >>

  • Coding Questions? We’ve Got the Answers

    JUN 1 2010 PHYSICIANS PRACTICE READ >>

  • Coding Questions? We've Got the Answers

    NOV 14 2003 PHYSICIANS PRACTICE READ >>


SponsoredWhitePapers

EMR Mythbusters
- Nuesoft Technologies

Investing in Patient Education — The Benefits for Your Patients and Your Practice
- Krames

A Beginner’s Guide to Selecting an EHR
- Welch Allyn

EMR Readiness: The R-Factor
- GE Healthcare

View All

 

CancerNetwork | ConsultantLive | Diagnostic Imaging | Psychiatric Times | Physicians Practice | SearchMedica

© 1996 - 2010 UBM Medica LLC, a United Business Media company
Privacy Statement - Terms of Service - Advertising Information - Editorial Policy Statement


 
ADDITIONAL ONLINE RESOURCES FROM UBM MEDICA
Featured Resources > Psychiatry Careers > Practice Management Conference > Today's Practice - Practice Management Resource > RSV Information > EHR Resources
CancerNetwork > Cancer diagnosis, treatment, and prevention > Podcasts for Oncologists > Cancer Patient Resources > Oncology Areas of Confusion > Oncology News > Cancer Management Handbook > Breast Cancer Resource > Bone Metastases > Chronic Myeloid Leukemia
Consultant Live > Diabetes Resources > Pediatric Asthma > Practical Clinical Advice > Medical Photoclinic > Diagnosing and Treating H1N1 flu (swine flu) > Primary Care Conference Reports > Community Acquired MRSA
Diagnostic Imaging > Medical Imaging News and Features > Medical Imaging and Radiology White Papers > Radiology Conference Reports > Radiology Special Reports > Radiology Net Seminars > Imaging Trends and Advances > RSNA 2009 Conference Coverage > Radiology Vendors
Psychiatric Times > Psychiatric News and Special Reports > APA Conference Report > Psychiatric Clinical Scales > Psychiatric Times Blog > Psychiatry Career Opportunities > DSM-5 > Major Depressive Disorder
Physicians Practice > Practice Management > EMR Software > Medical Practice Management Software > Medical Buyers Guide > Medical Coding > Practice Management Blog
SearchMedica > Professional Medical Search Engine > Medical Search Tips Newsletter > Medical Search News > Diabetes Research and Articles
Musculoskeletal Network > Muscle, Bone, Joint Medical Resources > Rheumatoid Arthritis Resource Center
The AIDS Reader > HIV News, Treatment, and Diagnosis for Medical Professionals
CME LLC > Continuing Medical Education > Psychiatry CME > Oncology CME > Practice Management CME > Primary Care CME > Psychiatric Congress > Performance Improvement CME > Treating the Whole Patient (TWP) — The Mind-Body Connection
More Resources > Consumer Healthcare Information > Patient and Caregiver Resource > Search drug information, interactions, images & diagnosis > Infectious Diseases > Respiratory Disease