EMRIS

Electronic Medical Records Implementation Services

Protect Electronic Health Information

Objective:

Protect electronic health information created or maintained by the certified EHR technology through the implementation of appropriate technical capabilities.
 
Measure:

Conduct or review a security risk analysis in accordance with the requirements under 45 CFR 164.308(a)(1) and implement security updates as necessary and correct identified security deficiencies as part of its risk management process.

Clinical Importance

Maintaining the confidence of the personal health information of patients is an old and sacred responsibility for clinicians. One concern many practices have with implementing EHRs is the ability to provide the right amount of security for their patients records. Applying safeguards found in The HIPAA Privacy Rule can assist in avoiding common security gaps that lead to cyber attack or data loss which can help protect the people, information, technology, and practices.

Lessons from the Field

A key to identifying outlying privacy and security risks is to utilize existing tools, such as the ONC Security Risk Assessment, in the analysis of a practice. An all-inclusive tool is essential for ensuring all areas of privacy and security are appropriately assessed. Once risks are identified, we recommend the use of sample policies and procedures that can be adjusted to fit the needs of each practice and assist in meeting the meaningful use requirement of protecting electronic health information.

Smaller practices have been very receptive to assistance with risk analysis of privacy and security. By using the ONC Security Risk Assessment, a practice can be guided through the tool to identify risks that exist and develop an action plan with risk mitigation strategies.  After risks are identified, it is important to include a follow-up assessment to adjust and update the tool to reflect any progress or action taken. The use of the risk assessment tool coupled with industry best practices allows providers to identify where improvements are needed during the initial assessment and have a process in place that will allow for continued monitoring of risks.