April 13, 2005
Security Practices
Ever think that application security is just a shortcut that you can take of later. Or that it might add more to the scope.
A nice and frightening statistic is according to Gartner 75% of the breaches of security occur within the patient management and clinical information systems. And you thought that custom access database was nice and tightly secured, especially since you link it to a paradox palm app.
Since the April 20th HIPAA Security deadline is around the corner, health leaders published a full checklist of items for security. Its actually a good list to look at for developing applications and maintaining security.
1. Does the application create, receive, maintain or transmit electronic Protected Health Information (ePHI)? (For all applications that process ePHI in some way, the entity must pursue responses to the next 15 questions.)
2. Is there a procedure for authorizing, establishing and modifying user access?
3. Does the application possess unique user identification capabilities?
4. Have unique user identification capabilities been activated?
5. Are there generic IDs in use?
6. Does an Emergency Access Procedure exist?
7. Does the application facilitate automatic logoff capability?
8. Is automatic logoff capability enabled?
9. Is there an encryption feature for data "at rest" in databases?
10. Is the application capable of performing audit logging?
11. Is the audit logging function enabled?
12. Are audit logs reviewed on a routine basis?
13. Does the application possess person or entity authentication capabilities?
14. Are person or entity authentication capabilities activated?
15. Is there a method to ensure transmission integrity?
16. Is there a capability to encrypt the transmission?
Here is the final security rule.
Finally passed the test
Managing in light of McGregor's Theory X and Theory Y
CMMI
Kicking HIT Leadership Up a Notch
That's just some mumbo jumbo project management BS
Outcomes - The tactic to get to the strategy
Nurse Call, VOIP, and Wi-Fi: Its just cool when things come together!
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
December 2006
November 2006
August 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
November 2005
October 2005
September 2005
August 2005
June 2005
May 2005
April 2005
March 2005
February 2005
January 2005
December 2004
November 2004
October 2004
September 2004
August 2004
July 2004
June 2004
May 2004
April 2004
March 2004
February 2004
January 2004
December 2003
November 2003
October 2003
Joel on Software
David Ross
Edward Prevost
Martin Fowler
The Health Care Blog
The Tales of Hoffman
The Business Word
Medical Rants
Christina's Considerations
Paul Levy
HIS Talk
Appropriate IT
Candid CIO
RSS feed




