Feature

10 Ways To Lock Down EHRs

John Sankovich

Establish a governance framework that defines roles, responsibilities, policies, procedures, and accountability.

1. Establish a governance framework that defines roles, responsibilities, policies, procedures, and accountability.

2. Use hardened terminals hosted on a trusted network, and continually scan them for viruses and malware.


More Healthcare Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

3. Limit employee access to data needed for their jobs, provide unique access credentials, and use electronic signatures.

4. Locate PCs and other access devices in secure places. Use an inventory system to track mobile devices, encrypt all content, and have a policy for retiring devices.

5. Use data-loss prevention tools, have auditable logs on traffic and downloads, and monitor these.

6. Have business associate agreements with strict rules regarding use and disclosure of personal information.

7. Encrypt all EHR data during transport; filter all communications for sensitive data.

8. Make sure data shared with researchers is anonymized or scrubbed.

9. Have a backup and recovery plan that includes security considerations.

10. Know the rules for retiring data, and make sure it's being completely erased from hard drives and formatted disks.

Related Reading


Informationweek Discussions

Start the Discussion


InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links