Skip to main content

Risk Assesment and Management of Electronic Health Information

BayBiotech.NET
Health Insurance Portability and Accountability Act of 1996 (HIPAA, Title II) required the Department of Health and Human Services (HHS) to establish national standards for the security of electronic health care information.
Department of Health and Human Services prepared certain guidelines that specify a series of administrative, technical, and physical security procedures for covered entities to use to assure the confidentiality of electronic protected health information (EPHI). This is particularly relevant for organizations that allow remote access to EPHI through portable devices or on external systems or hardware not owned or managed by the covered entity. Guidelines address mainly the privacy of health information issues that may arise by using laptops; home-based personal computers; PDAs and Smart Phones; hotel, library or other public workstations and Wireless Access Points (WAPs); USB Flash Drives and Memory Cards; floppy disks; CDs; DVDs; backup media; Email; Smart cards; and Remote Access Devices (including security hardware).
A significant emphasis and attention is paid on organization’s Risk analysis and risk management strategies; setting up Policies and procedures for safeguarding electronic data as well as Security awareness and training on the policies & procedures for safeguarding the health information if used electronically via remote access.
Main focus has been placed on the risks associated with remote access and offsite use of the EPHI into three areas: access, storage and transmission.

A good risk management planning takes all three areas into account and may vary from one organization to the other depending on the size, usage and infrastructure of the organization.

To read more about the risks assessment and management strategies suggested by HHS, follow the link: http://www.cms.hhs.gov/SecurityStandard/

Comments

Popular posts from this blog

Group C (Treatment IND) Drugs

BayBiotech.NET Since 1976, National Cancer Institute (NCI) in agreement with FDA has established the Group C classification system to allow access to certain drugs for the cancer patients specifically falling under a category that adequate alternative therapy or if the available alternative therapy has significant toxic effects. Each Group C drug protocol specifies patient eligibility and drug use information. Group C drugs are provided only to properly trained physicians who have registered themselves with NCI using a special form to assure that their patient qualifies under guidelines - or protocols - for the drug. Physicians using drugs under Group C have no reporting requirements to the NCI other than the obligation to report adverse drug reactions. Group C drugs are provided free of charge, and the Centers for Medicare and Medicaid Services provides coverage for care associated with Group C therapy. Making Group C drugs available to the critically ill patients not only provi...

FDA Launches Medical Device and Radiation-Emitting Product Transparency Web Site

BayBiotech.NET On April 19th, 2010 FDA launched he Center for Devices and Radiological Health (CDRH) Transparency Web site in support of the agency’s Transparency Initiative. The Web site makes available new information about CDRH’s decision-making processes and displays this information in a more user-friendly format. The site includes new information such as basic information about medical devices and how FDA regulates those products, information about medical devices before and after the products are on the market, in a searchable database, information about the clinical studies and trials conducted to demonstrate the safety and effectiveness of certain medical devices, memos from FDA employees explaining the reasons for the agency's decisions about medical device manufacturer requests to make a significant change in components, materials, design, specification, software, color additive, and labeling of a medical device as well as a step-by-step guide for manufacturers of...

Good Machine Learning Practices

BayBiotech.NET A joint effort by FDA,  United Kingdom’s Medicines and Healthcare products Regulatory Agency (MHRA) and Health Canada have developed guiding principles to help promote utilization of medical devices that are safe and effective and utilize artiificial intelligence and machine learning. To find out more details check out the link here!