Saturday, August 17, 2013

Module 4: Security in Healthcare/ Alanna Schauer


                                                                                 Alanna M. Schauer
                                                                                 Module 4: Security in Healthcare                                                                                                              
                                                                                                  Information and Databases

Liu, C., Chung, Y., Chen, T., & Wang, S. (2012). The Enhancement of Security in Healthcare

            Information Systems. Journal Of Medical Systems, 36(3), 1673-1688.  

            doi:10.1007/s10916-010-9628-3

            http://resources.njstatelib.org/login?url=http://search.ebscohost.com/login.aspx?direct=tr 

            ue&db=aph&AN=74979922&site=ehost-live           

            This article is interesting because it discusses the infrastructure of internet security in the healthcare arena and why it is so important. It is pertinent to the weekly discussion of health information security, data integrity, confidentiality, and access issues. This article provides the foundation of medical information security and the informational security events that can occur. It provides a basic understanding of the internet as it pertains to a hospital and how they go about safeguarding the medical information from hackers, internal and external threats. It is quite detailed, yet simple enough for a greater understanding of the serious issues that healthcare agencies must be prepared to encounter. It outlines the divisions of firewalls, their purpose, and how they protect from a breach of health information.

            It is a descriptive study from a peer reviewed journal which provides information to the readers about arranging information security strategies for medical organizations. These strategies conform to the HIPAA guidelines so there is standardization with the exchange of health information, and security precautions.

            It was informational and educational and addressed the need for detailed instruction on firewalls, classification of hackers, and case studies with actual attacks. It was fascinating to read that most information security threats come from the inside, the employees themselves. It is stated that "threats caused by employees consist of seventy percent of the total three threats to network security," (Liu, Chung, Chen, & Wang, 2012, pg. 1675).

            The solution was to review the weaknesses that may exist with management negligence and propose the application of medical management strategies in the network environment. The solution was the design and implementation of firewall structure like Single-Interfaced Bastion Host, Dual-Interfaced Bastion Host or Screened Subnet Firewall all with packet filtering. The study was to enhance the information security of the present medical network system.

            The implication to healthcare includes avoiding the information security event that occurred in Taiwan in November 2009 from ever happening again. The system crashed and without proper security protection in place health information was leaked. This can happen when there is not the tightest security available protecting patient's health information by system crash or illegal hackers with malcontent.

            I learned about the types of Firewalls available and the basic understanding of how they work to protect our health information. Hospitals are tasked with having electronic health records and health information exchanges but also protecting health information from the hackers and natural events.  This is a huge task for health care organizations but I now have a greater understanding of this situation.

           

2 comments:

  1. Information security is a large barrier to providing resources to patients in managing their own care. The tools must be in place for patients to trust their medical professionals and their information must be constantly secure yet accessible in a moments notice. This is a task that informatics nurses may find difficult but could be a lucrative area of expertise.

    ReplyDelete
  2. Yes Adam, I was unaware of the all the requirements that are needed for health information security. Nursing informaticist's must be educated on the tools to maintain this security.

    ReplyDelete