hipaa summit west september 2011 · what employers need to know • know your employees...

26
Policies to Govern Securing Mobile Technology in Health Care HIPAA Summit West September 2011 Angel Hoffman, RN, MSN

Upload: others

Post on 20-Aug-2020

10 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Policies to Govern Securing Mobile Technology in Health Care

HIPAA Summit WestSeptember 2011

Angel Hoffman, RN, MSN

Page 2: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Session Objectives:

Describe the policies needed to address privacy and security concerns for mobile applications

Identify the issues to consider before adopting mobile applications

Identify how the use of mobile applications can contribute to improving quality of care

2

Page 3: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Wireless Mobile Devices

• Pagers• Cell Phone• PDA• Smartphones

– (Iphone, Blackberry, Android)• Tablet PC’s • Laptops• Ipad-Android based Tablets

3

Page 4: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Social Media and Clinicians• Health care organizations need to establish a road map and complete their

strategy, because Doctors and other clinicians are also implementing mobile devices to monitor:

Vital signs and chronic conditions such as high blood pressure and diabetesUse of mobile technology in health care for diagnostic testing, ordering medications and prescription refills

• Doctors are adopting smartphones at greater than twice the rate of the general population, and there are over 17,000 health care apps available for smartphones

• Overall the adoption of mobile technology’s use in health care is growing faster than anyone could anticipate

• The use of this technology (e.g. in hospitals) is having a direct impact on the mobile choices being made by IT departments today

4

Page 5: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Social Media in Health Care

• Keeping Medical Information Confidential?

• How Does the Industry Protect It?

• What Do We Want As Consumers?

• What If A Patient’s Picture or Medical History Is Posted?

• Compare What Is Posted With the 18 Identifiers?

5

Page 6: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Privacy and Security Issues

• Breaches and Breach Notification Requirement

• Risk of Exposure To Patient

• Risks to Organization

• Education

• Organizational Policies

• Sanctions 6

Page 7: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Legal Implications and Risks

• Confidentiality

• Breach of PHI (e.g. Pictures of Patients Without Authorization)

• Loss of Proprietary Information/Trade Secrets

7

Page 8: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

What Employers Need to Know

• Know Your Employees (Generational Differences)

• Attitudes of Work Force (Social Mores)• Method of Communication (Technology Tool)• Responsibility to the Public• Importance of Social Media and Sanctions

Policies• Consequences for Loosely Distributed

Policies (Financial and Reputational Loss) 8

Page 9: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

ETHICS

• What can we do?

• Can we control it?

• What does ethics have to do with this?

• Knowing right from wrong!

9

Page 10: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

If Ethics isn’t everywhere…

it’s nowhere!

What does your organization say about Ethics?

10

Page 11: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Ethics

• Exercising self restraint• Robert Fulghum – book titled, “All I Really

Need to Know I Learned in Kindergarten”ShareKeep your hands to yourself

Be kind to your neighbor

• Ethics should not be so controversial • Being kind to others should be as easy as

breathing!11

Page 12: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Ethics

• Keep professional and social lives separate

• Offline behavior should follow through with online activity

• Do not make derogatory comments about your employer or coworkers; it could result in job loss

• Do not write or provide information that you would not want to defend in court 12

Page 13: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Ethics

• Need interaction between: Legal, HR, Marketing, Public Relations, Compliance and Ethics and IT

• Keep policy short, but easy to understand

• Set clear expectations for how employees are expected to conduct themselves

• Encourage exercising good judgment13

Page 14: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Social Media Strategies• Culture

• Code of Conduct

• Acceptable and Unacceptable Behavior

• Policies

• Sanctions 14

Page 15: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Education

• We have a responsibility to educate:

• The public

• Students

• Employees

• Patients

15

Page 16: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Social Media and EthicsTechnology is Here To Stay So…

• How Do We Deal With It As A Society?

• What Ethical Issues Have Arisen?

• Social Media + Ethics = A Social Dilemma and Need For Balance.

16

Page 17: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Creating a Policy for Employees

• Write a short and easy to understand policy

• Set clear expectations of how employees should conduct themselves

• Encourage exercising good judgment

• Use of same acceptable behavior whether offline or online

• Keep professional and social relationships separate

• Don’t use social media for personal reasons on work time 17

Page 18: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Creating a Policy (contd.)

• Policy requires input from: Legal, HR, Marketing, Public Relations, Compliance and Ethics and IT

• Can’t totally ban social media, but need to provide guidance through policy & education

• Your policy can hinder the types of messages and information sharing, if they know the consequences for exposing private and secure information 18

Page 19: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Risk & Security Issues• E-prescribing

• Patient Portals, Including Direct

• Communications with Providers

• Provider Portals

• Alerts to Providers

• Alerts to Patients

• Consultation/Referral Services

• Results Delivery (Tests, Imaging) 19

Page 20: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Strategies and Solutions: • Policies

Expectations and Boundaries for WorkforceOperational Guidelines for Social Media Workers and Others

• Patient and Provider Portals• Health Care Consumer Focus• Encryption• Cloud Computing• Software Solutions• Patient Advocacy

20

Page 21: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Social Media/Networking Best Practices Checklist

Is your organization taking ownership of what’s happening with social networking? Is your primary interest how to restrict the use of social media or how to enable it?Does your organization recognize that social networking is about COMMUNICATION, not the individuals who participate?Does your organization view social media as a highlyeffective information gateway?Have you asked your workforce: how can our organization take advantage of the benefits of social media and avoid the pitfalls? 21

Page 22: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Checklist (Cont’d)Does your organization recognize use of social media is a business decision, not a technology decision?

Has your organization developed a business case, supported at the appropriate levels, considering the organization’s Mission/Vision/Values, possible threats, technical capabilities, and potential benefits?

Does IT in organization understand that the goal should notbe to say “No” to social media, but to follow good security guidance,” with effective and appropriate information assurance security and privacy controls?

22

Page 23: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Checklist (Cont’d)

Does your organization have a policy addressing Social Media? Does the policy reflect the needs of various stakeholders (e.g. patient care, research, education constituents)?How does the policy support the Mission/Vision/Values of your organization?How does the policy relationships with business partners and vendors/contractors?How do you conduct training on the appropriate use of Social Media (at work and off work)? Are you including the appropriate use of Social Media in Security and Privacy Awareness Training Program?

23

Page 24: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Checklist (Cont’d)How will you capture the social media traffic, audit, analyze, and use it for security and privacy investigations, as appropriate?

Have you reviewed Regulatory Notice 10-06 from FINRA to determine its applicability to your organization and how you might use the recommendations to strengthen your Social Media program? (Note: FINRA provides guidance on the responsibilities of companies to supervise the use of social networking sites.)

How does your organization plan to use social media to generate new strategies, engage and learn?

Remember that a good policy is just the start. 24

Page 25: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Questions?

25

Page 26: HIPAA Summit West September 2011 · What Employers Need to Know • Know Your Employees (Generational Differences) • Attitudes of Work Force (Social Mores) • Method of Communication

Angel Hoffman, RN, MSN Advanced Partners in Health Care

Compliance, LLC

[email protected]

26