Tuesday, January 24, 2006

Sustain You

I love the title of this article: Sustainable Compliance.

Generally, input as to what would be required for the organization to be in compliance came from outside regulators and auditors who probably knew less about IT, and certainly knew less about the business, than the organization itself did. A somewhat natural response was to push back on these requirements, deny that they had validity, and hope that they would go away. By the time many organizations finally got around to doing something, the time was running short. So they did the minimum needed to comply, or more pragmatically, to pass an audit.

Almost every day, I talk to someone who is in this boat. But compliance is not a one-time fix, and so many folks are starting to come apart under the pressure, or have gone the other route and given up, hoping that they will get lucky, and no one will notice. There is a middle ground, though, which involves a more long-view, user-centric approach, that while it certainly is not painless, it can be a lot easier than many make it.

Wednesday, January 18, 2006

Work All Day

Here is a great story from UPI about the efforts of some folks in California to provide healthcare to migrant farm workers. Because many of them have poor english skills and because, legally here or not, they still fear INS trouble, many are unable or unwilling to seek medical help.
One of the unintended side-effects of HIPAA is that the workers do not need to fear the INS when they seek medical attention. And the required technology has made it easy for the folks running the program to connect to the hospital remotely via wireless VPN.
So the workers get healthcare, which goes a ways toward solving the public health issues of having a migrant population, and they can get it with a reasonable expectation of privacy.

Protect and Survive

Data Protection seems to be the word floating around in the air this year. Making certain that your data is secure is the main thrust of the Security Rule, and as the author of this piece in NewsFactor points out, the key is in having your IT ducks in a row.

By asking a few simple questions, an SMB can determine if it is meeting some of the basic compliance elements; identify compliance areas that it needs to address; and establish a starting point for action.
Do you know what will happen to your business operations if parts of your networks or systems fail?
Are your systems and networks protected against viruses and other malware?
Do you have ways to authenticate everyone who accesses your information systems and data?
Can you monitor how your I.T. network is used and by whom?
Do you have the means to track security incidents?
Is your data tamper-proof?
Is your key data backed up off-site?
Have you protected "unstructured" data -- that is, the e-mails, spreadsheets, and other documents on your employees' desktop systems?
Do you have companywide e-mail archiving capability?
How long does your data need to be archived and how quickly must you be able to retrieve it?
Can you show/prove that you are in compliance?

Now, I am an IT guy, and the solutions that come to mind when I am asked about compliance tend to be fairly technological in nature. But I also spend a lot of time speaking to various groups about HIPAA compliance, and most questions I am asked involve more Social Engineering than Computer Science.
As I constantly am nagging about, you must build your systems so that they are as close to transparent to the user as possible. Make a backbone of compliance out of technical solutions, but flesh it out in a pleasing, user friendly fashion.

10 O'clock Postman

From Search Security comes this piece on e-mail encryption. As the writer points out, there is really no longer any excuse:

Given the availability and affordability of encryption technology today, it is difficult for a healthcare organization to justify not using some form of it when transmitting PHI. A number of vendors offer a variety of reasonably priced encryption hardware and software, as well as outsourcing options.

For a smaller practice, there are a number of free or nearly free options, and for larger enterprises, if you don't already have some way to encrypt your e-mail, you better not be sending PHI. Though this is an adressable, I would find it difficult to defend any decision concerning PHI sent over e-mail that doesn't include encryption.

Wednesday, January 11, 2006

Back That Thing Up

Okay, so I am not a big one on cautionary tales, or big time fear-mongering when it comes to HIPAA. Too many front-line healthcare workers have been traumatized by scary HIPAA presentations, and that is a big part of why there is so much push-back. But for IT people there is no excuse. All of us know about back-ups and archiving, and all of us should be aware of what is compliant and what is not. That is why studies like this one are so frustrating to read:

Dowling told Datamation that 42 percent of respondents said there was 'no need' for compliance processes. That comes, according to Bridgehead, despite the fact that Sarbanes-Oxley affects half of U.S. companies and HIPAA regulations affect about a quarter.
''Someone somewhere is going to get sued or charged and the federal government will start to punish folks not in compliance,'' says Dowling. ''And there will be a realization that to be compliant you need to do more than you've been doing.''

If you are simply hoping that your back-up software is going to take the place of having a proper archiving system, there is a very good chance that you will be very unhappy someday. Maybe someday soon.

Tuesday, January 03, 2006

Locked Down

Here is an answer to a question I am often asked about the security of USB devices:

Ecora, Portsmouth, NH, has brought out a new version of its endpoint security system, Ecora DeviceLock V 5.73, which allows administrators to "white list" select USB devices and assign the white listed devices to users and groups while locking out all other devices...
Devices in the white list can now be assigned to users and groups providing more granular control over which users have access to what USB devices on their computers. One user can be allowed to use a certain device, while another user can't use it on the same computer.

You will still have to control what goes on them, and it is still a favorite nightmare that a Geek Stick left in a lab coat will end up at the cleaners where some felon working out his work-release can get his hands on all of the PHI accessed by that doctor over the last six weeks. It is still important to encrypt those handy little doo-dads.

Doctor, Doctor (Give Me the News)

Here is a very interesting collision at the intersection of HIPAA privacy and the Patriot Act:

Robin Moore, practice administrator for the group, said the language in their pamphlet is not unusual, and it complies with HIPAA and the Patriot Act. Sentara Healthcare's policy says the system might release medical information to authorized federal officials for national security activities. By contrast, Bon Secours Hampton Roads Health System, which operates Mary Immaculate Hospital in Denbigh, doesn't mention national security or federal authorities at all in its privacy pamphlets, but it does say information may be released when required by law.

So far, the government has never requested anyone's medical files.

The Department of Justice long has maintained the law is so narrow that a person's medical records would almost never be requested to combat terrorism. John Nowacki, spokesman for the department, said the law only allows the government to search for information pertaining to foreign intelligence that does not concern an American citizen.

"The law specifically provides that it can't be used against a United States person," Nowacki said. It also means that the law cannot be used to investigate "ordinary crimes or domestic terrorism," Nowacki said.


You know, I hadn't even thought of HIPAA in terms of domestic spying, but recent current events are making me think that there may be some conflict between the government's perceived need for information and the provisions set in place to insure privacy. Every spying program in history has been abused. The reassurance by Mr. Nowacki, above that "it can't be used against a United States person" flys in the face of recent disclosures.
I am all for HIPAA, in spite of the nuisances and irritations, the inconsistances and vague interpretations, because I believe in the fundamental right of all of us to keep private those things we ourselves choose to consider private. That some bureaucrat can bypass HIPAA at a whim, without anything more than an administrative warrant (if that, and then signed, not by a judge, but by that bureaucrat's boss) and it is illegal for me to be informed, even when nothing of national security interest is found, makes me very nervous.
There is nothing very interesting in my medical records. No employer is going to hesitate hiring me because of my health--- no insurance company is going to deny me coverage, no enemy or business rival is going to be able to leak my shameful past. But there are many of us whose records are not deadly dull, as mine are.

Wednesday, December 28, 2005

Save Me From Being Alone

This article is a good example of why I subscribe to SearchSecurity.com.


Everyone knows users are the soft spot in security programs. They've even confessed in recent surveys that they take more risks at work -- opening strange email attachments, clicking bizarre IM links and downloading dubious programs -- because they can. Phish scams and spyware, the two major malware trends in 2005, will continue to proliferate with the aid of increased technical proficiency and sophisticated social engineering. Already we've quickly gone from phony financial Web sites to human-resource e-mails to fake jury duty notices and false subscriber notifications. That means security must continue to save us from ourselves. Just be aware some of the biggest offenders are probably sitting in the boardroom.

This is an excellent round-up of the security issues of the last year, including compliance issues, and identity theft, both of which should be of interest to readers here.

Tuesday, December 20, 2005

21 and Invincible

From Benefitnews.com comes an outstanding six step plan for securing PHI:

Certainly this "reasonable safeguards" benchmark is open to interpretation. The good news is this benchmark accounts for the fact that no security system is invincible. The bad news is that if you've failed to review how your benefits office handles PII, identify risks, mitigate those risks, educate your employees, etc., a reasonable individual will find that you did not put in place reasonable safeguards to secure PII. Doing nothing is not an option.

As the writer points out, most information loss comes from humans, not faulty machines, and most of that is non-malicious, just plain old human error.

Tuesday, December 13, 2005

You Can Demand

Here is a on-demand webinar from Citrix about GoToMyPC. It is an extended commercial, of course, but there is a ton of info, and one of the speakers is Ross McKenzie, Director of Information Systems at Johns Hopkins Bloomberg School of Public Health.

As a healthcare industry professional responsible for complying with HIPAA standards regulating patient information, you need to know about Citrix® GoToMyPC® Corporate, a managed remote-access solution that that can help your organization meet HIPAA compliance guidelines while improving patient care, increasing speed of service and reducing IT costs. Join us for a 30-minute interactive Webinar to learn how Johns Hopkins Bloomberg School of Public Health has provided its faculty and staff with secure, easy-to-use remote access. Plus, discover how GoToMyPC Corporate can provide your organization with instant, secure remote access to email, files, applications and network resources in real time. Key benefits of GoToMyPC Corporate:
Highly secure, 128-bit encryption, security time-outs and strong passwords
Supports compliance with HIPAA provisions
No up-front costs or hardware to manage
No training required
Who should watch the on-demand Webinar?
Managers who need the highest level of security and control over remote workers
Budget owners who need to manage costs of implementing IT solutions
Network administrators who need to ensure compatibility with existing architecture
Those responsible for ensuring HIPAA compliance

Some of our regular visitors to this site are from Johns Hopkins, so it is nice to be able to send a referral back that way, however indirect :)

Charles Atlas

Outstanding article from TechWorld on the conflict between IT securtiy and regulatory compliance:

This is the biggest flaw in compliance – that a network that has been audited as meeting its legal obligations is seen as somehow acceptably secure. No network ever will be secure in this sense. Procedures can be laid down in black and white but they will never be followed correctly at all times. Mistakes will be made and unforeseen threats will emerge.

Regulations, by their nature, are static, while IT security is dynamic, reacting to new threats, anticipating future attacks, working to shore up previous weaknesses and new vulnerabilities. HIPAA tried to address this dichotomy by making the regulations non-technology specific, and to some extent it worked. But there is still that dynamic tension between the 97 pound weakling of your IT budget and the bully who is kicking regulatory sand in his face.

Hi Heel Sneakers

3Com wants to hack your sytem, but unlike Sony, they are on your side. Ethical hacking has been around for a long time, and invasive security audits are nothing new--- a very amusing movie was built around the concept a few years ago. "Sneakers" had Robert Redford, Dan Acroyd, and hacking banks--- what could be more fun?
NetworkWorld has this to say about it--- the 3Com thing, not Robert Redford:

In three days or more of onsite testing, the experts would run a variety of tests and assessment tasks, including network mapping, scanning and password cracking. They would attempt to gain access to machines and move up the hierarchy of system privileges on corporate servers - from guest to admin to root access. Emulation of blended attacks on the customer network, penetration testing and evasion techniques are also used.

For a few thousand dollars, you can know for certain if you are Security Rule compliant. Might be worth it.

Friday, December 02, 2005

Take Out the Crime

Now this is really juicy! A HIPAA compliance officer, whose former employers are saying is unreliable, is claiming that HIPAA required her to sit in on interviews of a shooting victim. Her testimony conflicts with everyone else's, including the hospital administrators who seem to be puzzled that she would have been involved.

Chartraw said her job responsibilities included ensuring a patient could submit to an interview and sitting through interviews with law enforcement officers to monitor patients' conditions throughout the interview. All three witnesses said no hospital policy required a HIPAA officer to sit through interviews or monitor patient conditions. The prosecution presented a letter from the hospital's attorney dated prior to Hilde's admittance that reiterated that HIPAA has no such requirement.

HIPAA is so wonderful! It means so many different things to so many different people. In this case, it seems to mean that a compliance officer can insert herself into a real life version of CSI. Or so she would seemingly have us believe.

Driving with the Brakes On

As we move closer to a national health records system, it is important to remember that our consumer is probably going to push back. This recent survey reported in SHRM Online found that 67 percent of Americans are concerned about the privacy of their personal health information and are largely unaware of their rights. And a major concern was that employers would use medical information to discriminate against workers.

Though there is no evidence of massive disregard for the privacy rules, fear of job repercussions is not entirely unfounded.

In 1998, for example, an Atlanta truck driver lost his job when his employer learned from his insurance company that he had sought treatment for a drinking problem, according to one of scores of stories about privacy breeches posted on the Health Privacy Project’s web site.

“The fear of disclosure, the fear of loss of benefits, the fear that people will be adversely affected in their jobs continues,” project director Janlori Goldman told HR News.

The most concerned? Minorities and those with on-going health problems.

Two Dice and a Silent Disguise

Unintentional Truth Department---- from TMCnet:

The scramble to comply with legislated security initiatives such as the Final Rule of the Health Insurance Potability and Accountability Act...

Yes, many of us find parts of HIPAA hard to swallow.

Over all, though shot through with annoying typos, this article provides a pretty good overview of many of the issues of compliance and enforcement of the Security Rule, including many of the reasons many of us are less than fully compliant.
Here is the money quote:

According to Amith Viswanathan, a healthcare industry analyst at Frost and Sullivan, private practices “rely heavily on their venders to be complaint” ... as opposed to actively pursuing compliance themselves.

Relying on your vendors to make you compliant is like driving without insurance, and hoping if you do get in an accident, that the other driver is covered.

Wednesday, November 30, 2005

William Tell Overture

Still struggling with compliance? You are not the Lone Ranger. A HIPAA compliance survey released by HIPAAdvisory.com found that only 30% of payer organizations and 18% of provider organizations were currently compliant with HIPAA security regulations. If you are a provider who falls into that unhappy 82%, it is only a matter of time before someone has a complaint. So far, the HIPAA cops have been pretty easy, preferring that you remediate rather than be penalized. How did we get to this place, even though we have been given years to compy? Security expert Joe Malec thinks there are a number of reasons:

Fearful of lawsuits and hefty civil penalties, some public and private institutions have erred on the side of caution, implementing more stringent HIPAA safeguards than were originally intended. Since the law is intentionally vague on what companies should do to comply, organizations would rather be safe than sorry. Even with the best of intentions, some standards for controls have had to be decided by the courts. One company that learned this the hard way was BJ Wholesalers, which just recently settled with the Federal Trade Commission over charges of failing to adequately safeguard sensitive customer information on their systems.
Then there's the required cultural shift. Beyond the technical safeguards, companies also need to promote security awareness and ethics training as well as education and enforcement of corporate security policies and procedures covering topics such as password standards, encryption and data classification. Such a level of cooperation has been hard to come by. Compliance laws have put more pressure on IT security and on enterprise users who ultimately make or break any approved security program. Political battles and fallout are new to some IT workers.

So what do we do?
For smaller practices, there is probably no way around it. You are just going to have to go to a hired gun. Just yesterday I was chatting with another consultant, and he passed on the story of a 4 doctor practice who decided that they would just roll the dice, not spend the few thousand bucks it would take to make their new systems compliant, and just hope that nobody complains. Because my friend is a pretty ethical guy, he turned down the gig, because he knew that particular shortcut had every possibilty of turning out bad. There are a lot of ways to save a nickle, but failing to take the required steps to protect your patients PHI is a very pound-foolish one.

Monday, November 28, 2005

Baby Got Back

A whole new category of PHI---

Fatter rear ends are causing many drug injections to miss their mark, requiring longer needles to reach buttock muscle, researchers said Monday.
Standard-sized needles failed to reach the buttock muscle in 23 out of 25 women whose rears were examined after what was supposed to be an intramuscular injection of a drug.

Next time someone asks you why they need to keep health information confidential, just remind them of how easy it would be to figure out what the king-size needles are for.

Rocket Man

Most PHI fits nicely into a traditional structured database, but some things, like x-ray images, and other graphical PHI, sometimes do not. XML is a general-purpose markup language for creating special-purpose markup languages, capable of describing many different kinds of data. One of the DB products mentioned below is Windows SQL Server 2005. I will be attending a product launch for this tomorrow--- I'll let you know what Uncle Bill's minions have to say.

"Databases have done a very good job of storing structured data -- but with unstructured data they have not," said Noel Yuhanna, an analyst at Forrester Research Inc., in Cambridge, Mass.
Reaching into that unstructured data to extract information is one pressing integration issue. The other is interoperability -- being able to get information using data from different applications, which may run on different operating systems.
With IBM's DB2 Viper, Microsoft's SQL Server 2005 and Oracle's XML DB feature in 9i and 10g, all three major database vendors are now offering XML capability, which allows a database to query the content of files that are not in relational database form. Bernie Spang, director of databases at IBM, estimated that 35% of business information is already in XML, compared with only 15% in traditional relational databases.

Tuesday, November 22, 2005

Scene Report

Here is a little more of the tension between journalists and privacy. I am a firm supporter of the first amendment--- in fact my first blog was about first amendment issues. I also was a reporter for a couple of years, and I understand the frustration many writers have when trying to gather information or confirmation. No one in the news biz wants to be simply a stenographer. But as recent developments have shown us, the press is not above blame. And even though I agree with three-fourths of this editorial from the College Heights Herald in Bowling Green, Kentucky, I am not willing to hand off privacy decisions to the fourth estate.

HIPAA isn't entirely bad. It makes an attempt to improve health care in this country, but that comes at the expense of press freedom. Some will undoubtedly disagree, but we feel precedence should go to the First Amendment issue. The right to privacy is implied, but not written.Surely there is a way to reconstruct HIPAA in a way that protects the individual with regard to health insurance while allowing journalists to obtain pertinent information for accurate stories.Journalists may not be licensed, but we take our work seriously. We are more than capable of knowing the difference between using information for the public good and abusing it. Have a little faith in our profession.

I would like to, but then I am reminded of Jayson Blair, Jeff Gannon, and others who have shown that some reporters are no more trustworthy than the people they cover, and unlike a hospital administrator or rogue physician, are already protected from the consequences of whatever they report by that very same first amendment.

Friday, November 18, 2005

Man (Opposable Thumb)

Pay attention! If it makes the front page of MSNBC, soon it will be affecting you!

It was just a tiny thumb drive, but now, it's a pretty big problem for a Hawaii hospital. And what happened there could eventually become a problem for you, too.
Last month, Wilcox Memorial Hospital in Kauai had to inform 120,000 past and present patients that their private information had been misplaced. Their names, addresses, Social Security numbers, even medical record numbers had been placed on one of those tiny USB flash drives -- and now, according to a letter sent home, the drive was missing.
The device had been misplaced in early October, and hasn't been heard from since, said hospital spokeswoman Lani Yukimura. While medical information was not on the device, it would be a treasure trove for an ID thief who found it. Once plugged into any computer’s USB port, a finder would have access to about as many identities as ChoicePoint Inc. leaked to criminals last year. So why has the Wilcox incident gotten so little attention?

Oooh! Oooh! Oooh! I know the answer to that one!
Nobody has gotten nailed by a multi-million dollar class-action suit yet.
But they will. Trust me, they will.
Please don't let it be you.