Security of Computerized Medical Information: Threats from Authorized Users James G. Anderson, Ph.D. Purdue University.

Slides:



Advertisements
Similar presentations
Issue Brief National Association of School Nurses Privacy Standards for Student Health Records.
Advertisements

© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 1 The Goal of HIPAA: Administrative Simplification HIPAA for Allied Health.
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna
Westbrook Technologies from Document Management’s Role in HIPAA.
ITEC 6324 Health Insurance Portability and Accountability (HIPAA) Act of 1996 Instructor: Dr. E. Crowley Name: Victor Wong Date: 2 Sept
SLIDE 1 Westbrook Technologies from Fortis: A Healthcare Solution for Medical Records, Billing and HIPAA.
Today’s Schools face:  Numerous State and Federal Regulations  Reduced Technology Funding  More Stringent Guidelines for Technology Use.
CHAPTER © 2011 The McGraw-Hill Companies, Inc. All rights reserved. 2 The Use of Health Information Technology in Physician Practices.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
© 2011 The McGraw-Hill Companies, Inc. All rights reserved. 2.5 HIPAA Legislation and its Impact on Physician Practices 2-15 The Health Insurance Portability.
Health Insurance Portability and Accountability Act (HIPAA)
Opportunities to Leverage HIT for Medicaid Reform in New York Rachel Block, United Hospital Fund C. William Schroth, NYS Department of Health eHealth Initiative.
Mac McCarthy, FSA, FCA, MAAA Middle Atlantic Actuarial Club September 13, 2013.
POP QUIZ!! What does CMS stand for? What does HIPAA stand for?
2 HIPAA, HITECH, and Medical Records. Learning Outcomes When you finish this chapter, you will be able to: 2.1Discuss the importance of medical records.
Handle with care : Digital marketing and online behavioural advertising Global guidance to help improve consumer trust in practice, techniques and messages.
2 The Use of Health Information Technology in Physician Practices.
MEDICARE: PAST, PRESENT AND FUTURE James G. Anderson, Ph.D. Department of Sociology & Anthropology.
MEDICARE: PAST, PRESENT AND F UTURE James G. Anderson, Ph.D. Department of Sociology & Anthropology.
Privacy and Security Workgroup: Big Data Public Hearing December 8, 2014 Deven McGraw, chair Stan Crosley, co-chair.
Privacy & Personal Information -- Why do we care or do we?
Topic 5 Function, Purpose and Regulations of Financial Institutions.
HEALTH INSURANCE HEALTH INSURANCE --INDIAN EXPERIENCE.
Banks and the Privacy of Medical Information 8 th National HIPAA Summit March 8, 2004 Joy Pritts, JD Health Policy Institute Georgetown University
Lecture 14 Policy, Legal, and Regulatory Issues in HIS (Chapters 18,19,20)
© 2009 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill Career Education Computers in the Medical Office Chapter 2: Information Technology.
The Use of Health Information Technology in Physician Practices
CONFIDENTIALITY The promise of NOT to share personal information inappropriately. Grounded in an individual’s right of privacy.  “DO NO HARM” Slide 2.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
HIPAA & Public Schools New Federalism in a New Century The Challenges of Administering HIPAA in Public Schools ASTHO/NGA Center Joint Audioconference September.
State Alliance for e-Health Conference Meeting January 26, 2007.
Component 1: Introduction to Health Care and Public Health in the U.S. 1.1: Unit 4: Financing Health Care (Part 1) 4.1 a: Overview.
Security of the Distributed Electronic Patient Record: A Case-Based Approach James G. Anderson, Ph.D. Purdue University.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
1 Networked PHR, a framework for personal health applications & services Anne Chapman, Senior Program Manager Personal Health Records, Intel.
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
THE PHARMACY TECHNICIAN CHAPTER 2. SCOPE OF PRACTICE Specific responsibilities and tasks differ by setting –Job descriptions –Policy and procedure manuals.
Robert Guerra Director, CryptoRights Foundation Implementing Privacy Implementing Privacy: Rules of the Game for Developers Mac-Crypto Conference on Macintosh.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
Medical Manager Unit 9 ICBS 170. Medical Manager Electronic Data Interchange (EDI)  Ability to request, receive, transfer and integrate information electronically.
HIPAA LAWS.  Under the privacy rule, the patient must give consent to use his or her Protected Health Information.  Examples in which consent must be.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
Federal Agencies and Laws for Consumer Rights
Welcome….!!! CORPORATE COMPLIANCE PROGRAM Presented by The Office of Corporate Integrity 1.
HIPAA History March 3, HIPAA Ruling Health Insurance Portability Accountability Act Health Insurance Portability Accountability Act Passed by Congress.
Issue: High Spending, Low Results. Goals: Increased Efficiency Improve quality and delivery of health care services provided. Improve the cost effectiveness.
Lee young man. 1) What is the definition of the Financial law ? 2) The definition of insurance fraud 3) Type of insurance fraud 4) Detecting.
Copyright © 2015 by Saunders, an imprint of Elsevier Inc. All rights reserved. Chapter 3 Privacy, Confidentiality, and Security.
The Protection of Personal Information Bill 13 February
E-Commerce and the Consumer. Improving Consumer Protection Consumers in general Vulnerable consumers Information underclass.
Legal, Regulations, Investigations, and Compliance Chapter 9 Part 2 Pages 1006 to 1022.
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
HHS Security and Improvement Recommendations Insert Name CSIA 412 Final Project Final Project.
HIPAA THE PRIVACY RULE Reviewed December HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti-
Health Insurance Portability and Accountability Act (HIPAA) © 2013 Project Lead The Way, Inc.Principles of Biomedical Science.
1 HIPAA’s Impact on Depository Financial Institutions 2 nd National Medical Banking Institute Rick Morrison, CEO Remettra, Inc.
CONFIDENTIALITY AND HIPAA LEGAL AND ETHICAL. HIPPOCRATIC OATH = CONFIDENTIALITY “And whatsoever I shall see or hear in the course of my profession, as.
Health Insurance Portability and Accountability Act
Federal Agencies and Laws for Consumer Rights
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
Health Insurance Portability and Accountability Act
Disability Services Agencies Briefing On HIPAA
Employee Privacy and Privacy of Employee Information
Other Sources of Information
Health Care: Privacy in a Digital Age
Lesson 1: Introduction to HIPAA
FERPA and HIPAA for School Nurses and School Based Health Center Staff
Strategies to Comply with the HPAA Privacy Rule Before the HIPAA Security and Enforcement Rules are Final Presented by: Steven S. Lazarus, PhD, FHIMSS.
Presentation transcript:

Security of Computerized Medical Information: Threats from Authorized Users James G. Anderson, Ph.D. Purdue University

Growth of Health Care Information Technology The health care industry spends $15 billion annually. The industry is expected to grow 20% annually. There are 35 publicly traded companies with market capitalization of $25 billion.

Dilemma How can we provide data required by the health care industry and protect the privacy of patients?

Public Concerns about Privacy 24% of health care providers reported violations of patients’ privacy. 18% of the public felt that it was inappropriate to use patient data without consent. 75% of the public felt that it was inappropriate to use prescription data to detect fraud. 11% of the public reported not filing insurance claims to protect their privacy.

Threats from Authorized Users Errors Curiosity Financial reasons Personal reasons

Secondary Uses of Health Information Employers Insurance companies Sale of information to third parties

Public Policy Issues Existing laws only cover data collected by federal agencies. These laws do not cover secondary users of health information. There is a lack of incentives for institutions to invest in security of health information.

The Health Insurance Portability and Accountability Act of Only covers health information transmitted electronically. Does not cover insurance companies, pharmacies and direct marketers of personal data. Permits use of health information with patient identifiers for health care operations.

The Health Insurance Portability and Accountability Act of May allow sale of patient data for secondary use. Privately funded research is exempt form the regulations. There is concern over the use of a unique patient identifier. There are differences in regulations between the E.U. and the U.S.

The Need for Public Policy EMR systems are critical to support integrated health care delivery systems. EMRs are vulnerable to inappropriate use. A policy framework is needed to direct future development and private investment in IT. Absence of policies creates confusion about privacy rights. Pending legislation contains conflicting proposals that will need to be resolved.