Are electronic medical records worth it?

Yahoo-Microsoft Merger Proxy Fight – May 14, 2008

By G C Network | May 18, 2008

As I alluded to last week, “It’s not over ’till it’s over” Carl Ichan Looking to Start Yahoo Proxy Fight Money – The Microsoft-Yahoo Merger may not be over. Billionaire…

Now in the ring Sun/Amazon! – May 04, 2008

By G C Network | May 18, 2008

The Sun/Amazon cloud may be announced soon. Sun CEO Jonathan Schwartz delivered a short keynote at Startup Camp in San Francisco, an adjunct event to the JavaOne Conference. According to…

Microsoft gives up on Yahoo? – May 04, 2008

By G C Network | May 18, 2008

“Cloud computing is far more than a concept. With Broadband Internet connections now all-but-ubiquitous and microcomputers and locally-run software now so trouble-prone, Cloud Computing’s time has come.” This is a…

IBM, Google and the Blue Business Platform – May 01, 2008

By G C Network | May 18, 2008

Today was good !! This morning. there was a main session built around “CIO 2.0”. The basic premise was that CIOs have now earned a seat at the business management…

The coming cloud – April 30, 2008

By G C Network | May 18, 2008

I attended the IBM Public Sector briefing this morning. The IBM executives were clearly basking in a financial performance glow. After ending 2007 with increases in revenue, profit and earnings…

Google, Cloud Computing, and the US Intelligence Community – April 29, 2008

By G C Network | May 18, 2008

Just arrived in Los Angeles for the IBM Business Partner Leadership Conference. IBM is billing this as a “new” conference, but I have my doubts. I am, however, very interested…

Location Based Services – April 25, 2008

By G C Network | May 18, 2008

INmobile.org is a exclusive community for executives in wireless industry. As a member, I have the opportunity to participate in a number of interesting discussions about mobile and wireless technology.…

IBM Business Partner Leadership Conference – April 23, 2008

By G C Network | May 18, 2008

I just completed registration for the IBM Business Partner Leadership Conference. This is a new invitation-only conference being held this year in Los Angeles from Wednesday, April 30th through Friday,…

Telephone & Web = WOW !! – April 21, 2008

By G C Network | May 18, 2008

The power of the Internet and the web lies in its ability to provide access to information. The mobile web takes this one step further with its ability to provide…

The Power of Family Oral History – April 19, 2008

By G C Network | May 18, 2008

Although I just started this yesterday, I’ve decided to backdate this entry to last Saturday, April 12, 2008. That’s when my family had it’s 3rd Annual Black History Party. The…

The use of Electronic Medical Records (EMR) by medical professionals has increased dramatically. According to HealthIT.gov, 2015 statistics show that 56 percent of all U.S. office-based physicians (MD/DO) have demonstrated meaningful use of electronic health records. The downside of these statistics is that when HIPAA was enacted in 1996, privacy was not a major focus and it actually took HHS eight years to publish the initial HIPAA Privacy Rule. It then took the agency several more years to publish initial security rules which directed “covered entities” (e.g., providers, hospitals, health insurers) to perform a risk assessment, understand where their vulnerabilities were, and to adopt reasonable safeguards to fix them.

Unfortunately this timeline has made healthcare records easy pickings for cybercriminals. Since 2010, incidents of medical identity theft have doubled, according to a survey conducted by the privacy-focused Ponemon Institute. A second report by the Identity Theft Resource Center on breaches in the first four months of 2015 showed that one-third of all data breaches by industry occurred in healthcare: 82 instances in total, exposing over 1.7 million records. Modern Healthcare, in fact, estimated that the medical records of almost one in eight Americans have been compromised. The American Action Forum estimates that all the breaches since 2009 have cost the healthcare system $50.6 billion. Data breaches have been so bad that Blue Cross Blue Shield has announced that they will offer their customers identity protection in 2016.

Figure 1- Number of personal data breach incidents by industry over time (https://www.gemalto.com/brochures-site/download-site/Documents/Gemalto_H1_2015_BLI_Report.pdf)
According to a report by the medical research firm Kalorama Information, the problem will worsen over time because the $25B electronic medical record industry is predicted to grow at a 7-8 percent clip in the coming year. Much of the growth is spurred by the 2009 Health Information Technology for Economic and Clinical Health (HITECH) Act, which offered financial incentives for using electronic records until 2015 and penalties for not using EMR thereafter.

Is EMR worth the cost in privacy and peace of mind?


The value of the technology has been heralded as improved diagnosis and treatment through better information access and sharing. Researches, however, have found that the vast majority of providers don’t share electronic patient data outside their own practice. According to a study by the Agency for Healthcare Research and Quality, just 14 percent of providers were sharing data with other providers in 2013 Psychology Today notes that many medical centers’ outpatient

systems cannot “talk” to their inpatient hospital systems; and actually accused “One of the bigger “providers” of electronic health records” of creating data silos that prevent the sharing of their records with outside organizations unless a high fee is paid. This current state of affairs argues for strong action by the government and even stronger action by healthcare organizations.

On the government side, the Obama administration’s proposed fiscal 2017 budget seeks additional funding for the long overdue HIPAA compliance audit program and a variety of other health data privacy and security efforts. In addition to more funding for HIPAA compliance audits, the HHS budget seeks to boost funding for the Office of the National Coordinator for Health IT to advance secure nationwide health information exchange and interoperable healthcare IT, making sure that, for example, electronic health records can easily exchange data. Ultimately, Congress must approve funding.

Can this problem be fixed?


Although the value of EMR is extremely promising, realization of the promise requires a concerted effort by all concerned. From the healthcare organization side, investments in cyber defense and personnel security training is a critical requirement. This action requires a mix of employee education, smart use of technology and physical security for buildings. Actions should include:
  • Protect the network – Health IT departments need to use a variety of tools to keep attackers out and move faster towards the adoption of technologies that limit the damage when attacks do occur.
  • Educate staff members – Employees are often involved in healthcare data breaches so any IT security program should include a big focus on employee education.
  • Encrypt portable devices – Several data breaches have involved the use of portable computing or storage devices that contained protected health information. Healthcare organizations should always encrypt data on any device that might hold patient data, including laptops, smartphones, tablets and portable USB drives.
  • Secure wireless networks – Wireless networks often introduce security vulnerabilities. To protect against attacks, healthcare providers should ensure that their routers and other components are kept up-to-date, network passwords are secure and changed frequently, and unauthorized devices are blocked from accessing the network.
  • Implement physical security controls – Even as electronic health records become more common, organizations still keep a lot of sensitive data on paper. Providers must therefore make sure doors and file cabinets are locked and that cameras and other physical security controls are used.
  • Create and enforce a mobile device policy – A mobile device policy that governs what data can be stored on those assets is imperative. Mobile device management (MDM) software to enforce those policies should also be deployed.
  • Delete unnecessary data – The more data that’s held by an organization, the larger the risk of loss. Organizations should have policies that mandate the deletion of patient and other information that’s no longer needed.
  • Vet the security of cloud-based services – The biggest IT trend over recent years has been the use of cloud computing. The use of cloud-based services increases the importance for organizations to diligently vet the security of these vendors and other involved third parties.
  • Patch electronic medical devices – Keep the software on all medical devices patched and up-to-date to minimize their vulnerabilities.
  • Have a data breach response plan – Despite the precautions, organizations will never be able to prevent every possible IT security incident. That’s why it’s critical to develop a plan of action for when a breach does occur.
According to Bill Odell, VP of Endpoint Device Management marketing for Dell, one approach for dealing with regulatory issues around Personally Identifiable Information (PII) and the Health Insurance Portability and Accountability Act (HIPAA) is through the use of smart patient monitoring devices. Smart devices can give hospital administrators an ability to inventory, locate and manage all of the hospital’s patient care devices from a single console. Operating within such an environment can also provide enhanced protection to patient data as well.
Organizational attitudes towards security must also be both proactive and preventative. This requires the design and implementation of security programs that:
  • Manage and govern user identity, privilege and access
  • Secure networks with deep protection and control
  • Routinely update and manage application updates
  • Manage and secures all endpoints
  • Data protection policies that encrypt both at rest and in motion.
They should also consider adopting the Security Breaches Maturity Model. Developed by Dell, Intel and other industry leaders, this model can be used to rapidly identify and address gaps in technical safeguards needed to address breach risks. Each of us must also take an active interest in the safeguarding of our individual healthcare information. These changes will not only reduce the impact of data breaches, but they will also improve the return on the investments associated with the deployment of this technological advancement.

This post was written as part of the Dell Insight Partners program, which provides news and analysis about the evolving world of tech. Dell sponsored this article, but the opinions are my own and don’t necessarily represent Dell’s positions or strategies.

Cloud Musings

( Thank you. If you enjoyed this article, get free updates by email or RSS – © Copyright Kevin L. Jackson 2015)

Follow me at https://Twitter.com/Kevin_Jackson
Posted in

G C Network