PhysiciansPractice Members: Login | Register

  • Home
  • About Us
  • Today's Practice
  • Live
  • CME
  • Podcasts
  • Tools
  • Topics
  • Blog
  • Career
  • Coding
  • EHR
  • Finance
  • Malpractice
  • Patient Relations
  • Staff
  • Technology
  • Buyers Guide
  • Publication

Home » Topics

Physicians Practice. Vol. 17 No. 16
Pages: 1  2  3  
Previous
 

Technology: Data Security for Non-Techies

You don’t have to hold a degree in computer engineering to keep your data safe. Here are some simple security gaps anyone can plug.

By Pamela Moore | November 1, 2007


Let the high-techies do their thing

You — and many physicians along with you — might focus on the safety of new-fangled, Web-based software and encrypted e-mail rather than actual physical protection, such as shredding sensitive papers or locking the chart room door. But be honest. Are you truly the best person for such high-tech concerns? Probably not. So let the experts handle it. You’ll find that an application service provider that lets you run, say, an EMR or practice management software over the Internet “can be more secure than the average paper-based office,” Duncan suggests.

Cothren agrees. Thankfully, this layman-level worry is slowly abating. “More and more people are becoming comfortable with the security level you can put on encrypted information you send over the Internet,” he says. “Most ASP vendors will have more secure systems than most physician offices.”

Just perform your due diligence and create a chain of trust or business associates agreement, Hertzberg suggests.

Running a more secure office takes awareness and endless scrutiny, and it’s not a once-and-done job. Take time to regularly look for holes.


Top Five Recommendations for Securing Patient Data

Take Windows seriously: No one seems to remember that in order to get to sensitive patient information, the system that will be hacked first (if necessary) is the Windows platform it runs on. Without the desire for security on the part of the practice owner, there will be no implementation of security.

“Password” is not an acceptable password: While an outpatient office can be small, it needs to deal with passwords like a major hospital would, requiring separate user accounts with complex passwords (using a combination of mixed-case letters, numbers and special characters) and requiring that passwords change periodically.

Protect against malicious software: Microsoft’s Windows Update can be set to look for patches daily, although Microsoft has a designated “Patch Tuesday” for critical patches and updates to ensure each Windows computer is up to date and able to fend off any known vulnerabilities. Additionally, anti-spyware and anti-virus solutions should be employed to fend off anything that patches don’t cover. While a hacker may not be looking to access your protected health information (PHI), they certainly will take advantage of the situation should they be able to gain administrative control over one of your Windows desktops. Social Security numbers are very appetizing these days.

Automatically lock your PC: When an employee of the office steps away from their PC, after a period of inactivity, Windows can kick in a screensaver that requires a password. This is critical; how many times a day does a physician or nurse step out of a room and leave a PC unattended? 

Where in the network is your PHI? Most practice owners think that their sensitive data only resides in the practice software application. But how about that letter to the insurance company that was written about Mr. Smith’s condition? Or the spreadsheet that contains patient addresses, Social Security numbers, and other information? These files are a necessary evil to keep an office running, but those documents also need to be secured. This means the location in which they are stored (whether local on a single PC or on a common server in the office) needs to be established, potentially sensitive documents need to be placed in that location, and that location needs to be secured to ensure only appropriate access.

Source: Nick Cavalancia, vice president of marketing, ScriptLogic Corporation, Boca Raton, Fla.

Pamela L. Moore, PhD, is senior editor, practice management, for Physicians Practice. She can be reached at pmoore@physicianspractice.com.

This article originally appeared in the November 2007 issue of Physicians Practice.

Pages: 1  2  3  
Previous
 

Add your own comment

It’s important to keep the patient data in your office safe and secure. Here are some basic steps to take:

  • Don’t focus on electronic security at the expense of more mundane issue, such as locking the record room door.

  • Create unique passwords for each staff member. Ideally, passwords should include numbers and letters and should be changed every 90 days, as well as whenever a staff person leaves. But don’t make memorization so hard that staff resort to posting passwords on their monitors.

  • HIPAA is the biggie for medical practices, but also pay attention to compliance rules meant to prevent identity theft. How are you protecting credit card and Social Security numbers?

  • Be ever-vigilant for problems, and take corrective actions immediately.







  • Topic Index

    Best States to Practice
    Career

    Coding
    Classifieds
    EHR
    Finance
    Law & Malpractice

    Patient Relations
    Patient Dismissal
    RVU/Relative Value Units
    Staff Management
    Staff Salaries
    Technology
    All Topics

     

    -- Advertisement--

    FixIt

    Decisions, Decisions: Your IT Shopping Checklist
    Medical Practice Management Technology Resources
    Lab Tracking Tool
    Calculate EMR ROI


    • On This Site
    • Most Emailed
    • On This Topic

    MostPopular

    • The Best States to Practice: America’s Physician-Friendliest States

      FEB 1 2007 PHYSICIANS PRACTICE READ >>

    • What Should You Pay Staff?

      JUL 14 2010 PHYSICIANS PRACTICE READ >>

    • Solving Your 9 Biggest Billing Blunders

      APR 30 2010 PHYSICIANS PRACTICE READ >>

    • Coding Questions? We’ve Got the Answers

      JUN 1 2010 PHYSICIANS PRACTICE READ >>

    • Coding Questions? We've Got the Answers

      NOV 14 2003 PHYSICIANS PRACTICE READ >>

    MostPopular

    • Solving Your 9 Biggest Billing Blunders

      APR 30 2010PHYSICIANS PRACTICE READ >>

    • What Should You Pay Staff?

      JUL 14 2010PHYSICIANS PRACTICE READ >>

    • How to Deal with Grouchy Patients

      AUG 18 2010PHYSICIANS PRACTICE READ >>

    • Preparing for the ICD-10 Transition

      AUG 20 2010PHYSICIANS PRACTICE READ >>

    • Using Social Networking as a Marketing Tool

      AUG 31 2010PHYSICIANS PRACTICE READ >>

    MostPopular

    • The Best States to Practice: America’s Physician-Friendliest States

      FEB 1 2007 PHYSICIANS PRACTICE READ >>

    • What Should You Pay Staff?

      JUL 14 2010 PHYSICIANS PRACTICE READ >>

    • Solving Your 9 Biggest Billing Blunders

      APR 30 2010 PHYSICIANS PRACTICE READ >>

    • Coding Questions? We’ve Got the Answers

      JUN 1 2010 PHYSICIANS PRACTICE READ >>

    • Coding Questions? We've Got the Answers

      NOV 14 2003 PHYSICIANS PRACTICE READ >>


    SponsoredWhitePapers

    EMR Mythbusters
    - Nuesoft Technologies

    Investing in Patient Education — The Benefits for Your Patients and Your Practice
    - Krames

    A Beginner’s Guide to Selecting an EHR
    - Welch Allyn

    EMR Readiness: The R-Factor
    - GE Healthcare

    View All

     

    CancerNetwork | ConsultantLive | Diagnostic Imaging | Psychiatric Times | Physicians Practice | SearchMedica

    © 1996 - 2010 UBM Medica LLC, a United Business Media company
    Privacy Statement - Terms of Service - Advertising Information - Editorial Policy Statement


     
    ADDITIONAL ONLINE RESOURCES FROM UBM MEDICA
    Featured Resources > Psychiatry Careers > Practice Management Conference > Today's Practice - Practice Management Resource > RSV Information > EHR Resources
    CancerNetwork > Cancer diagnosis, treatment, and prevention > Podcasts for Oncologists > Cancer Patient Resources > Oncology Areas of Confusion > Oncology News > Cancer Management Handbook > Breast Cancer Resource > Bone Metastases > Chronic Myeloid Leukemia
    Consultant Live > Diabetes Resources > Pediatric Asthma > Practical Clinical Advice > Medical Photoclinic > Diagnosing and Treating H1N1 flu (swine flu) > Primary Care Conference Reports > Community Acquired MRSA
    Diagnostic Imaging > Medical Imaging News and Features > Medical Imaging and Radiology White Papers > Radiology Conference Reports > Radiology Special Reports > Radiology Net Seminars > Imaging Trends and Advances > RSNA 2009 Conference Coverage > Radiology Vendors
    Psychiatric Times > Psychiatric News and Special Reports > APA Conference Report > Psychiatric Clinical Scales > Psychiatric Times Blog > Psychiatry Career Opportunities > DSM-5 > Major Depressive Disorder
    Physicians Practice > Practice Management > EMR Software > Medical Practice Management Software > Medical Buyers Guide > Medical Coding > Practice Management Blog
    SearchMedica > Professional Medical Search Engine > Medical Search Tips Newsletter > Medical Search News > Diabetes Research and Articles
    Musculoskeletal Network > Muscle, Bone, Joint Medical Resources > Rheumatoid Arthritis Resource Center
    The AIDS Reader > HIV News, Treatment, and Diagnosis for Medical Professionals
    CME LLC > Continuing Medical Education > Psychiatry CME > Oncology CME > Practice Management CME > Primary Care CME > Psychiatric Congress > Performance Improvement CME > Treating the Whole Patient (TWP) — The Mind-Body Connection
    More Resources > Consumer Healthcare Information > Patient and Caregiver Resource > Search drug information, interactions, images & diagnosis > Infectious Diseases > Respiratory Disease