Commentary

Marianne Kolbasuk McGee
Senior Writer, InformationWeek  

Feds Tackling Health IT Privacy, Security Issues

While the federal government is enticing healthcare providers with billions of dollars in stimulus funding to digitize patient health data, the feds also appear serious about the data privacy and security concerns these efforts raise.

While the federal government is enticing healthcare providers with billions of dollars in stimulus funding to digitize patient health data, the feds also appear serious about the data privacy and security concerns these efforts raise.In addition to the much talked-about "meaningful use" incentive programs of the American Recovery and Reinvestment Act's HITECH legislation, the $20 billion-plus stimulus bill also contains several provisions to address privacy and security.

Last week, the U.S. Dept. of Health and Human Services took steps to carry out a couple of those HITECH privacy and security requirements.


More Healthcare Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

For starters, HHS' Office of National Coordinator for Health IT (ONC) appointed its first chief privacy officer, a role mandated by ARRA. Named to fill the new job was Joy Pritts, a lawyer and associate research professor at Georgetown University, who will advise HHS and ONC on electronic health data privacy and security issues related to HITECH programs.

Before her appointment to the new post, Pritts was already a familiar face around health IT circles and within the ONC. As a senior scholar at Georgetown's O'Neill Institute for National and Global Health Law and a research associate at its Health Policy Institute, Pritts worked with ONC on a series of legal surveys of state laws. That research focused on topics including individuals' rights to access their health information; the transmission of prescriptions; and consent requirements for disclosing health information for treatment.

In another cybersecurity related move last week, HHS posted a "pre-solicitation" for a contractor to study the security and privacy risks to health IT.

"The purpose of this contract is to carry out a sequence of related activities with the goal of understanding security risks to Health Information Technology, planning and executing risk mitigation strategies, testing certain risk mitigation strategies, communicating to stakeholders the results, lessons learned, and actions that can be taken to reduce risk in HIT, which will create the foundation for policy development," said HHS in the posting.

Key to the advancement of HITECH programs "is the assurance of safety and security" of health IT, according to the posting. "These include promoting security and accuracy of health information and the protection of privacy through data segmentation and prevention of unauthorized access."

So, as the feds move toward finalizing the "meaningful use" requirements that healthcare providers must meet to receive their financial rewards, it's also pertinent that security and privacy issues are also tackled so that damaging (and embarrassing) breaches don't unfold when the HITECH programs finally come to life.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links