Big Data. Big Decisions
InformationWeek
Special Coverage Series


Patient Privacy Advocate Calls For Better Cloud Security

Letter to Office of Civil Rights calls for stronger data security protections, business associate agreements with cloud computing services.

Health Data Security: Tips And Tools
Health Data Security: Tips And Tools
(click image for larger view and for slideshow)
A leading advocate for the privacy and security of patient health information is urging the government to issue a strong guidance document on how healthcare data should be protected in the cloud.

In a letter to the Office of Civil Rights (OCR) in the Department of Health and Human Services (HHS), Deborah Peel, MD, founder and chair of Patient Privacy Rights, said, "Health providers will benefit from such guidance as they consider moving to cloud services, and patients will benefit by knowing which data privacy and security protections should be in place."

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

Peel's letter cites the HHS' settlement with Phoenix Cardiac Surgery in April 2012 to illustrate the challenges that can arise when providers move to the cloud. In that case, the practice was fined $100,000 for managing appointments using a Web-based calendar that was publicly available.

Today, healthcare providers' use of cloud services goes far beyond that. Electronic health records, billing data, medical images and many other types of healthcare information are now stored on remote servers. According to an Optum Institute report published last March, nearly 60% of responding CIOs from organizations that had an EHR and a health information exchange said they planned to invest in "cloud-based open systems."

[ How can patient engagement help transform medical care? Check out 5 Healthcare Tools To Boost Patient Involvement. ]

Despite the burgeoning use of the cloud to store and manage information, however, Peel could not cite evidence that this shift has led to an increase in security breaches or that cloud storage is inherently less secure than onsite storage of data. "I don't know whether there are any studies of that," she told InformationWeek Healthcare.

What is known, she added, is that "the healthcare industry has the worst security practices of any industry. Eighty percent of hospitals still don't even encrypt data. Hospitals are not putting the money into data protection."

The key issue with cloud storage, she said, is that "there's no way of telling which services are following best practices for state-of-the-art comprehensive security and privacy."

For example, she pointed out, remote servers can be located anywhere. "We don't even know whether they're in the U.S. We have no way of knowing what happens inside the cloud servers, whether the owners of the cloud service snoop in the information or not, and there's no certification or auditing of these systems to verify whether they do what they say they do in a contract."

Even worse, she pointed out, many contracts between cloud service firms and healthcare providers lack even basic security protections. For example, the HIPAA law mandates that cloud services sign business associate agreements requiring them to adhere to the same security and privacy rules that HIPAA-covered entities must comply with. But many providers do not ensure that this provision is in their contracts.

Under the guidance that Peel's group is seeking, the OCR would urge cloud companies to provide:

-- A secure infrastructure, including data encryption and audit controls

-- Security standards consistent with standards required of federal agencies

-- Privacy of protected health information, based on standards for appropriate use, disclosure and safeguarding of individually identifiable information

-- Business associate agreements -- something that OCR has already called for.

Eventually, Peel said, her group wants the government to introduce a certification system for cloud computing, similar to the EHR certification it requires for showing Meaningful Use. Such certification, which could be performed by HHS or by private entities authorized by HHS, would incorporate the guidance elements in Peel's letter. It would also include other requirements set forth in a "trust framework" that her group plans to release within the next few weeks.

Patient Privacy Rights developed and validated the trust framework with the help of Microsoft and PwC and tested it on HealthVault, according to Peel. "We have some tools that could be used to assess every kind of platform, application or system so that some kind of ranking or rating could be created for how well they comply with what the public expects. We have 15 major principles broken down into auditable criteria, such as what nation the servers are in."

Initially, Peel noted, Patient Privacy Rights will release the framework for purposes of discussion, research and self-evaluation by cloud services and healthcare providers. The criteria in the framework, she said, could apply to anybody who stores healthcare information remotely, even on a website.

Clinical, patient engagement, and consumer apps promise to re-energize healthcare. Also in the new, all-digital Mobile Power issue of InformationWeek Healthcare: Comparative effectiveness research taps the IT toolbox to compare treatments to determine which ones are most effective. (Free registration required.)



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.