JUL 26, 2010 3:02pm ET

Related Links

University Settles with Feds After HIPAA Violations
May 22, 2013
Data Entry Error Leads to Data Breach at LSU
May 21, 2013
Quick Turnaround on Breach Notification
May 17, 2013
California Developing Guidance for Patient Consent of HIE
May 17, 2013
Hacker Gets Patient Credit Cards from North Carolina Providers
May 16, 2013
OCR Seminars to Walk through Omnibus HIPAA Rule
May 16, 2013
PHI Breach #3 for Indiana University
May 15, 2013

Web Seminars

Data Protection in the Cloud: What You Need to Know About Security and Compliance—Right Now
Available On Demand
Mobile Security in the Real World
Available On Demand

Data Security is This CIO's Constant Challenge

Print
Reprints
Email

For Chuck Christian, CIO at Good Samaritan Hospital, Vincennes, Ind., end-point security is a constant and ongoing challenge. With a variety of technologies and policies in place to safeguard sensitive information that could make its way to devices, the 232-bed hospital has managed to stay off the HHS data breach Web site so far, in part due to the diligence of Christian and his 25-member I.T. staff. "You have to re-educate people--tell and tell again, no patient data on a laptop," says Christian, summarizing one key policy. "Period."

Earlier this year, Good Samaritan went well beyond its laptop policies, disabling USB ports across the computers connecting to its network. It was a pre-emptive move to preclude inappropriate data transfers to easily lost devices, Christian explains. Nonetheless, the new policy was not well-received. "It caused consternation," Christian says. Christian fielded a call from a purchasing manager at the hospital who wanted to obtain thumb drives in bulk for the stock room. "I said no," Christian recalls. "These things are so convenient, people could store unencrypted personal health information on them. You can put down a thumb drive and they're gone."

Christian's staff gives alternatives to administrators clamoring for additional digital storage space. An engineering supervisor requested eight large-size thumb drives to store building schematics and piping diagrams, asserting that if he lost the drives, little would be at risk. "I told him it could be a big deal because that is not information everyone should have." Christian created a Microsoft-enabled Sharepoint site on his network for the engineering department; it serves as a semi-private location on the network where files can be stored and accessed by authorized members.

The wound care unit also objected to the closure of the USB ports. They had used the ports to download digital photos to the hospital's EHR. "They weren't conscious they were creating a potential security or breach situation because it was so convenient," Christian recalls. His crew then installed card readers for the cameras. "You have to worry about people inadvertently storing data where they shouldn't."

For more information about securing mobile devices, see July’s issue.

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn

As the feds ramp up enforcement of privacy and security rules, providers look to fill protection gaps.

Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Already a subscriber? Log in here
Please note you must now log in with your email address and password.