Wednesday, March 25, 2009

HIPAA Security Alert #2

Mobile devices are E-V-I-L.

Several scandals have erupted when cell phone cameras were used inappropriately in health care facilities.

In a couple of cases, improper photos were placed on social networking sites (such as Facebook).

But even with good intent, cell phones, I-phones (and imitators) PDAs and laptops are walking potential HIPAA violations.

First advice:

No devices may contain practice data without prior approval.

No clinical emails may be forwarded unless within established policy.

More advice to follow.....

Monday, March 9, 2009

HIPAA Security Alert #1

How did top secret plans for the Presidential helicopter get to Iran?

An employee of a defense contractor had P2P file sharing software on his computer.

P2P networks, such as BitTorrent or Limewire, are often used by young people to trade songs and videos, and may open your system to access by any hacker in the world.

These file sharing program should never be installed on business computers, let alone computers full of confidential patient data.

Your network should be audited for unauthorized software, and no one (including the physicians) should be allowed to download or install unauthorized software on any practice desktop, laptop or server.

And those cute screensaver programs that pop up on your screen? During a download you are likely to get spyware and adware, or maybe something worse.

Business computers should be all business.

Sunday, March 8, 2009

New Adventure

Our healthcarethinktank blog was going to cover health care reform and health care management, but clearly there is too much material for one blog.

So here we are, with a second blog dedicated to health care management issues, focused on physician practice management, and useful to other types of providers as well.