Physician IT Security - Electronic Health Records (EHR) And Future Threats to Physician IT Security

EHR-- The Future of Healthcare and a Physician ITthat will foster better care, but will also test and
Challengechallenge your ability to ensure the confidentiality,
EHR, or Electronic Health Record is Defined by theintegrity and availability of patient data.
National Alliance For Health Information TechnologyTwo recent examples of large volumes of personal
(NAHIT) as "an electronic record of health relatedhealth information being hacked highlight just how
information on an individual that conforms to actuallydifficult it can be to protect medical records.
recognized interoperability standards and that can beIn October 2008, Express Scripts, one of the nation's
created, managed, and consulted by authorizedlargest processors of pharmacy prescriptions, became
clinicians and staff across more than one healthcarethe target of medical information extortionists. These
organization" will soon be changing the landscape ofhackers threatened to disclose personally identifiable
healthcare forever.medical information for millions of Americans if the
EHR will fundamentally change the health informationcompany did not comply with their demands for
security risks for your practicepayment! At one point Express Scripts was offering a
Perhaps more important to you is that EHR will also$1,000,000 reward for information that would lead to
fundamentally change the way your practice dealsthe arrest and conviction of those responsible.
with Physician IT in the future; especially as it relates toMore recently, in May of 2009 another mass hacking
health information security risks. When taken to itsof health information was reported by the Virginia
logical extension your practice will no longer be aPrescription Monitoring Program (VPMP). The VPMP is
standalone Physician IT entity but rather part of muchused by pharmacists and others to identify potential
larger and more complex interconnected ecosystemprescription drug abuse. It has been reported that the
of information systems through entities known ashackers encrypted over 8 million patient records and
Health Information Organizations (HIOs) and Healthover 35 million prescriptions before posting a note on
Information Exchanges (HIEs).the VPMP website that flaunted the hack-job and
HIOs are defined by the National Alliance for Healthdemanded money before the records would be
Information Technology as organizations that overseereturned.
and govern the exchange of health related informationPhysician IT, Information Security and the Small
among organizations according to nationally recognizedHealthcare Practice
standards. HIEs are defined by the NAHIT asWhile these breaches occurred at much larger
facilitating the electronic movement of health relatedinstitutions they are illustrative of the perils facing small
information among organizations according to nationallyhealthcare providers who may not have the expertise
recognized standards.or capital resources that large healthcare institutions do.
Clearly, the concept of EHR creates an environment