Commentary

Marianne Kolbasuk McGee
Senior Writer, InformationWeek  

Program Aims To Erase Doubts About Health Data Security

A new certification program could make it easier for healthcare organizations to decide whether their IT security products meet their compliance needs.

A new certification program could make it easier for healthcare organizations to decide whether their IT security products meet their compliance needs.The Health Information Trust Alliance--HITRUST--which was launched in 2007 by an alliance of healthcare professional service and IT vendors, announced today a program to evaluate and certify IT security products used in healthcare settings.

The new HITRUST certification program is aimed at helping healthcare organizations in their vetting process to determine whether IT security products comply with HIPAA criteria, as well as HITRUST's own Common Security Framework, which is free and was released in March. HITRUST's CSF is the first IT security framework developed specifically for healthcare information.


More Healthcare Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

When healthcare organizations are selecting information security products ranging from firewalls to anti-virus software, there's a great deal of uncertainty and confusion whether those products comply to HIPAA and other security requirements important to the protection of personal health data, said Dan Nutkis, CEO of HITRUST in an interview with InformationWeek. The HITRUST certification will help, he said.

"Organizations are struggling to identify products" that meet security requirements for healthcare environments, which aren't as stringent as some classified government agencies, but are more intense than some workplaces and businesses, he said. "The local florist doesn't need the same level of security, except for credit cards," he said.

In a statement, HITRUST said the new program will be coordinated by a steering committee - led by ICSA Labs, McAfee, CA, Cisco, nCircle, NSS Labs, RSA, the security division of EMC, Symantec, Trend Micro and VeriSign - "with guidance by an advisory committee of security professionals from health plans, providers, pharmacies, data exchanges and service providers."

Evaluations for the certification will be done by independent third parties, not HITRUST, said Nutkis, who estimates it will cost vendors between $5,000 and $7,500 for the evaluation. "The goal was not to make it too costly," and inhibitive to smaller vendors seeking certification, he said.

InformationWeek has published an in-depth report on e-health and the federal stimulus package. Download the report here (registration required).


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links