Health IT & The New Information Security Area

No ratings

Presented at BSidesTampa 2019 by

From mainly using IT in supporting processes, IT is now a primary tool in many core clinical processes. This has changed many processes and introduced new type of risks and opportunities related to patient safety and quality of care. The security aspect has been highlighted for many years with HIPAA and HITECH. Now we see a more intense focus on the data integrity, availability, and patient safety aspects of the electronic clinical information and medical records. The Office of the National Coordinator for Health Information Technology (ONC) under the Department of Health and Human Services (HHS) has issued has lead several initiatives for several years. There is a critical need to enhance the risk management related to Health IT. The role of IT and Security is critical to understanding an organization's risk management plans and maturity in this core operational area. Several studies been performed and new guidance is produced on a regular basis, based on the analysis of reported patient safety incidents related to IT. This session will cover the risks and opportunities with Health IT, current regulatory guidance (from HHS, ONC, TJC, FDA, etc.), common best practices and standards (ISO, AHIMA, AAMI, etc.) common issues, critical success factors, and key security risk areas related to Health IT. This important area affects everyone - provider or patient - and has created challenges that require specific skills combining technical and governance areas with clinical operations.