Secure Your Communications!
A Presentation for
Healthcare Organizations
9 out of 10 clinicians have a smartphone
and tablet
- Mobile Trends Report 2013
73 percent of clinicians text each other about
work
- Information Week “Text Messaging Between
Clinicians Increasing in Hospitals”
These communications need to be secure.
Secure
Communications
• Generally not HIPAA-Compliant:
– SMS
– E-Mail
– Pagers
• There is secure technology to replace
these
HIPAA and HITECH
Regulations
• The Security Rule of the HIPAA and HITECH regulations require
covered entities to maintain reasonable and appropriate
administrative, technical, and physical safeguards for protecting
electronic Protected Health Information (e-PHI). Protected
Health Information includes any information that can be used to
identify a patient.
• Specifically, covered entities and their business associates must:
– Ensure the confidentiality, integrity, and availability of all
e-PHI they create, receive, maintain or transmit;
– Identify and protect against reasonably anticipated threats
to the security or integrity of the information;
– Protect against reasonably anticipated, impermissible uses
or disclosures; and
– Ensure compliance by their workforce. 45 C.F.R. § 164.306(a).
• Compliance Date: September 23, 2013
• Next round of audits to start in 2015
What is PHI?
HIPAA Privacy Rule
6025.18-R
• Anything that can identify a patient. Examples:
(A) Names;
(B) All geographic subdivisions smaller than a State, including street address, city, county, precinct, zip code, and their equivalent geocodes, except
for the initial three digits of a zip code if, according to the current publicly available data from the Bureau of the Censue:
(1) The geographic unit formed by combining all zip codes with the same three initial digits contains more than 20,000 people; and
(2) The initial three digits of a zip code for all such geographic units containing 20,000 or fewer people is changed to 000.
(C) All elements of dates (except year) for dates directly related to an individual, including birth date, admission date, discharge date, date of death;
and all ages over 89 and all elements of dates (including year) indicative of such age, except that such ages and elements may be aggregated into a
single category of age 90 or older;
(D) Telephone numbers;
(E) Fax numbers;
(F) Electronic mail addresses;
(G) Social security numbers;
(H) Medical record numbers;
(I) Health plan beneficiary numbers;
(J) Account numbers;
(K) Certificate/license numbers;
(L) Vehicle identifiers and serial numbers, including license plate numbers;
(M) Device identifiers and serial numbers;
(N) Web Universal Resource Locators (URLs);
(O) Internet Protocol (IP) address numbers;
(P) Biometric identifiers, including finger and voice prints;
(Q) Full face photographic images and any comparable images; and
(R) Any other unique identifying number, characteristic, or code
Find the PHI
• “Please call 555-555-5555”
• “D.O.B. is 4/4/1944”
• “Jane Smith needs to be seen”
• “I need to see MR# 345678”
• “Fax or e-mail the test results to 333-333-3333 or jsmith@amtelco.com “
HIPAA Breach
Penalties
Civil Monetary Penalties
Tier Penalty
1. Covered entity or
individual did not know (and
by exercising reasonable
diligence would not have
known) the act was a HIPAA
violation.
$100-$50,000 for each
violation, up to a maximum
of $1.5 million for identical
provisions during a calendar
year
2. The HIPAA violation had a
reasonable cause and was
not due to willful neglect.
$1,000-$50,000 for each
violation, up to a maximum
of $1.5 million for identical
provisions during a calendar
year
3. The HIPAA violation was
due to willful neglect but the
violation was corrected
within the required time
period.
$10,000-$50,000 for each
violation, up to a maximum
of $1.5 million for identical
provisions during a calendar
year
4. The HIPAA violation was
due to willful neglect and
was not corrected.
$50,000 or more for each
violation, up to a maximum
of $1.5 million for identical
provisions during a calendar
year
Criminal Penalties
Tier Penalty
Unknowingly or with reasonable
cause
Up to one year
Under false pretenses Up to five years
For personal gain or malicious
reasons
Up to ten years
• Enforcement Process
– OCR enforces the Privacy and Security Rules in several ways:
• by investigating complaints filed with it,
• conducting compliance reviews to determine if covered entities are in
compliance, and
• performing education and outreach to foster compliance with the Rules'
requirements.
http://www.hhs.gov/ocr/privacy/hipaa/enforcement/process/index.html
Audit Program
http://www.hhs.gov/ocr/privacy/hipaa/enforcement/audit/index.html
Who can file a
complaint?
https://ocrportal.hhs.gov/ocr/portal/lobby.jsf
Complaint Process
http://www.hhs.gov/ocr/privacy/hipaa/enforcement/process/index.html
Secure
Communications
• Secure Communications App for clinician-to-clinician, and
staff-to-clinician communications:
– Two-way
– Fast
– Easy to use, native apps
– Connectivity: 3G/4G and WiFi
– Full Audit tracking
– HIPAA compliant
– Trusted company with longevity
Secure
Communications
It’s more important now than ever to ensure
that your organization is communicating
securely.
HIPAA and HITECH
Regulations
Fully complies with HIPAA & HITECH
standards:
Messages are accessed, transmitted, and
stored securely.
Does not use SMS, does not store information
on devices, and uses end-to-end encryption.
If device gets lost, app can be remotely
disabled.
Send encrypted
messages to:
• Android™ (Including Android Wearables)
• Apple® Devices
(Including Apple Watch)
• Web Application
Send
miSecureMessages:
• From your secure Browser-based Directory
• From the OnCall schedule – ensuring you contact the
correct personnel (Optional)
• From Infinity/IS Operator Consoles (Optional)
• Device-to-Device, colleagues communicating
with each other with the miSecureMessages
smartphone app
• From the miSecureMessages Contact Web
application
• To an Individual, or to a Group
• WiFi and 3G/4G
miSecureMessages
Features:
• Send an Unlimited Number of
Messages
• Send an Unlimited Number of
Characters per Message
• No text or SMS plan needed
• A separate Inbox from your text
and e-mail messages
miSecureMessages
Features:
• Persistent alerts – alerting you until you
acknowledge the message
• Priority Messages – ensuring you see the
most important messages first
• Fast Responses – it's easy to quickly send a
secure reply
• Choose from Customizable Default
Responses, or send your own Custom
Reply
miSecureMessages
Features:
• Your app users can change:
– Alert Sounds: we provide various options to
choose from, including “Silent” when appropriate.
– Notification Interval: app users can adjust how
often they’re persistently alerted of a new
message.
• Organize their contact list: Instead of having a
straight A-Z list of contacts, Admins can categorize app
users’ contacts into Circles.
• Group Messaging: App users can send a message to
an individual, multiple people, and to an entire Circle of
contacts.
miSecureMessages
Features:
Real-time updating of messages and
replies, with time-stamps for each
message event.
Message receipts and Full
Reporting with time-stamps for:
•Message Sent
•Message Delivered
•Message Read
•Message Replies
miSecureMessages
Benefits
• Save Time
• Save Money
• Keep Communications Private
• Instantly Communicate
• Easy to Use
• Easy to Access Securely
• Integration
miSecureMessages
Benefits
• Improve Patient Satisfaction
• Quicker response times
• More efficient patient care
• Reduce overhead noise
Web
miSecureMessages
App
miSecureMessages
Contact Web
• Additional Intelligent Series tabs and functionality are available in the MSM
Contact Web: OnCall, Status, and Directory
miSecureMessages (MSM)
Contact Web
OnCall Integration
(optional)
Integrate to our OnCall solution to:
-View real-time OnCall schedules
-Send secure messages to OnCall
staff
-Change your OnCall status
...All from within the
miSecureMessages app!
Intelligent Series Web
OnCall: Roster
Staff can easily contact the OnCall personnel from the web roster.
Intelligent Series Web
Scripting: Group Dispatch
Our customized web scripts simplify individual and
group message dispatching for all types of
situations.
Intelligent Web Scripts pull in real-time
schedule and contact information, including
escalation requirements - ensuring that you are
contacting the right people at the right time!
miSecureMessages (MSM)
Current Release 6.4
The current release of MSM Server 6.4 has the following
improvements over 6.3:
• Attachments (Images, Sound, Video, PDF’s)
• Contact Info (Image/Photo, Phone Number)
• Color Scheme Selection
• Info Button On Thread
• Message Delivery and Read Notification
• Archive/Purge/Retrieve
• Pagination (faster message downloads)
• Email Administrator Upon Events
• Drawer Controller Menu
• Hide Contact options
miSecureMessages (MSM)
MSM 6.4 Enhancements
Users can add Images,
Audio, Video, and PDF’s
to Messages
Add and view PDF’sAdd and view ImagesAdd and view PhotosAdd and play Audio
Or use the Speech to Text Option
miSecureMessages (MSM)
MSM 6.4 Enhancements
Users can add a Phone
Number to their profile
The Phone Number shows
Up to anyone trying to
Reach them
miSecureMessages (MSM)
MSM 6.4 Enhancements
Users can add a Photo or
Image to their profile. Anyone
Trying to reach them will
See the Photo
miSecureMessages (MSM)
MSM 6.4 Enhancements
Users can press the Info
Button or slide over on a
Message to see detailed
Message History
miSecureMessages (MSM)
MSM 6.4 Enhancements
Users can change the
Color Scheme of the App
On their device
miSecureMessages (MSM)
MSM 6.4 Enhancements
All Apps now include a
New Drawer Controller
Menu to replace the
Previous Toolbar
miSecureMessages (MSM)
6.4 Admin Web
New MSM 6.4 Admin Web interface.
New Contact Setup
With Image and
Phone number
New Group Settings
With Password
Complexity New Archive
Screen
miSecureMessages (MSM)
6.4 Admin Web
New MSM 6.4 Admin Web
Notification Settings.
Allows MSM to generate
emails to you when certain
conditions occur.
New Email settings to
Notify you when
Something happens
Such as a new user
registration
New Email alerting me that
A new user has registered.
miSecureMessages (MSM)
6.4 Admin Web
New MSM 6.4
Admin Web
includes
advanced
Diagnostics,
including details
about each
message sent.
New Diagnostic tool to
Show you details about each
Message, including the
Notifications sent out.
As well as when the message
was Delivered and Read
miSecureMessages (MSM)
6.4 Admin Web
New MSM 6.4
Admin Web
allows
specifying
certain users as
Hidden such as
the IS or
Infinity Contact
or someone in
the call center.
Specify a user as Hidden
To they don’t show up in
The Contact List.
Get Started For
Free
• Visit http://miSecureMessages.com and
start your Free Trial today!
• Contact Us:
800.356.9148
info@miSecureMessages.com
Thank you!

HIPAA secure text messaging - miSecureMessages

  • 1.
    Secure Your Communications! APresentation for Healthcare Organizations
  • 2.
    9 out of10 clinicians have a smartphone and tablet - Mobile Trends Report 2013 73 percent of clinicians text each other about work - Information Week “Text Messaging Between Clinicians Increasing in Hospitals” These communications need to be secure.
  • 3.
    Secure Communications • Generally notHIPAA-Compliant: – SMS – E-Mail – Pagers • There is secure technology to replace these
  • 4.
    HIPAA and HITECH Regulations •The Security Rule of the HIPAA and HITECH regulations require covered entities to maintain reasonable and appropriate administrative, technical, and physical safeguards for protecting electronic Protected Health Information (e-PHI). Protected Health Information includes any information that can be used to identify a patient. • Specifically, covered entities and their business associates must: – Ensure the confidentiality, integrity, and availability of all e-PHI they create, receive, maintain or transmit; – Identify and protect against reasonably anticipated threats to the security or integrity of the information; – Protect against reasonably anticipated, impermissible uses or disclosures; and – Ensure compliance by their workforce. 45 C.F.R. § 164.306(a). • Compliance Date: September 23, 2013 • Next round of audits to start in 2015
  • 5.
    What is PHI? HIPAAPrivacy Rule 6025.18-R • Anything that can identify a patient. Examples: (A) Names; (B) All geographic subdivisions smaller than a State, including street address, city, county, precinct, zip code, and their equivalent geocodes, except for the initial three digits of a zip code if, according to the current publicly available data from the Bureau of the Censue: (1) The geographic unit formed by combining all zip codes with the same three initial digits contains more than 20,000 people; and (2) The initial three digits of a zip code for all such geographic units containing 20,000 or fewer people is changed to 000. (C) All elements of dates (except year) for dates directly related to an individual, including birth date, admission date, discharge date, date of death; and all ages over 89 and all elements of dates (including year) indicative of such age, except that such ages and elements may be aggregated into a single category of age 90 or older; (D) Telephone numbers; (E) Fax numbers; (F) Electronic mail addresses; (G) Social security numbers; (H) Medical record numbers; (I) Health plan beneficiary numbers; (J) Account numbers; (K) Certificate/license numbers; (L) Vehicle identifiers and serial numbers, including license plate numbers; (M) Device identifiers and serial numbers; (N) Web Universal Resource Locators (URLs); (O) Internet Protocol (IP) address numbers; (P) Biometric identifiers, including finger and voice prints; (Q) Full face photographic images and any comparable images; and (R) Any other unique identifying number, characteristic, or code
  • 6.
    Find the PHI •“Please call 555-555-5555” • “D.O.B. is 4/4/1944” • “Jane Smith needs to be seen” • “I need to see MR# 345678” • “Fax or e-mail the test results to 333-333-3333 or jsmith@amtelco.com “
  • 7.
    HIPAA Breach Penalties Civil MonetaryPenalties Tier Penalty 1. Covered entity or individual did not know (and by exercising reasonable diligence would not have known) the act was a HIPAA violation. $100-$50,000 for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year 2. The HIPAA violation had a reasonable cause and was not due to willful neglect. $1,000-$50,000 for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year 3. The HIPAA violation was due to willful neglect but the violation was corrected within the required time period. $10,000-$50,000 for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year 4. The HIPAA violation was due to willful neglect and was not corrected. $50,000 or more for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year Criminal Penalties Tier Penalty Unknowingly or with reasonable cause Up to one year Under false pretenses Up to five years For personal gain or malicious reasons Up to ten years
  • 8.
    • Enforcement Process –OCR enforces the Privacy and Security Rules in several ways: • by investigating complaints filed with it, • conducting compliance reviews to determine if covered entities are in compliance, and • performing education and outreach to foster compliance with the Rules' requirements. http://www.hhs.gov/ocr/privacy/hipaa/enforcement/process/index.html
  • 9.
  • 10.
    Who can filea complaint? https://ocrportal.hhs.gov/ocr/portal/lobby.jsf
  • 11.
  • 12.
    Secure Communications • Secure CommunicationsApp for clinician-to-clinician, and staff-to-clinician communications: – Two-way – Fast – Easy to use, native apps – Connectivity: 3G/4G and WiFi – Full Audit tracking – HIPAA compliant – Trusted company with longevity
  • 13.
    Secure Communications It’s more importantnow than ever to ensure that your organization is communicating securely.
  • 14.
    HIPAA and HITECH Regulations Fullycomplies with HIPAA & HITECH standards: Messages are accessed, transmitted, and stored securely. Does not use SMS, does not store information on devices, and uses end-to-end encryption. If device gets lost, app can be remotely disabled.
  • 15.
    Send encrypted messages to: •Android™ (Including Android Wearables) • Apple® Devices (Including Apple Watch) • Web Application
  • 16.
    Send miSecureMessages: • From yoursecure Browser-based Directory • From the OnCall schedule – ensuring you contact the correct personnel (Optional) • From Infinity/IS Operator Consoles (Optional) • Device-to-Device, colleagues communicating with each other with the miSecureMessages smartphone app • From the miSecureMessages Contact Web application • To an Individual, or to a Group • WiFi and 3G/4G
  • 17.
    miSecureMessages Features: • Send anUnlimited Number of Messages • Send an Unlimited Number of Characters per Message • No text or SMS plan needed • A separate Inbox from your text and e-mail messages
  • 18.
    miSecureMessages Features: • Persistent alerts– alerting you until you acknowledge the message • Priority Messages – ensuring you see the most important messages first • Fast Responses – it's easy to quickly send a secure reply • Choose from Customizable Default Responses, or send your own Custom Reply
  • 19.
    miSecureMessages Features: • Your appusers can change: – Alert Sounds: we provide various options to choose from, including “Silent” when appropriate. – Notification Interval: app users can adjust how often they’re persistently alerted of a new message. • Organize their contact list: Instead of having a straight A-Z list of contacts, Admins can categorize app users’ contacts into Circles. • Group Messaging: App users can send a message to an individual, multiple people, and to an entire Circle of contacts.
  • 20.
    miSecureMessages Features: Real-time updating ofmessages and replies, with time-stamps for each message event. Message receipts and Full Reporting with time-stamps for: •Message Sent •Message Delivered •Message Read •Message Replies
  • 21.
    miSecureMessages Benefits • Save Time •Save Money • Keep Communications Private • Instantly Communicate • Easy to Use • Easy to Access Securely • Integration
  • 22.
    miSecureMessages Benefits • Improve PatientSatisfaction • Quicker response times • More efficient patient care • Reduce overhead noise
  • 23.
  • 24.
  • 25.
    • Additional IntelligentSeries tabs and functionality are available in the MSM Contact Web: OnCall, Status, and Directory miSecureMessages (MSM) Contact Web
  • 26.
    OnCall Integration (optional) Integrate toour OnCall solution to: -View real-time OnCall schedules -Send secure messages to OnCall staff -Change your OnCall status ...All from within the miSecureMessages app!
  • 27.
    Intelligent Series Web OnCall:Roster Staff can easily contact the OnCall personnel from the web roster.
  • 28.
    Intelligent Series Web Scripting:Group Dispatch Our customized web scripts simplify individual and group message dispatching for all types of situations. Intelligent Web Scripts pull in real-time schedule and contact information, including escalation requirements - ensuring that you are contacting the right people at the right time!
  • 29.
    miSecureMessages (MSM) Current Release6.4 The current release of MSM Server 6.4 has the following improvements over 6.3: • Attachments (Images, Sound, Video, PDF’s) • Contact Info (Image/Photo, Phone Number) • Color Scheme Selection • Info Button On Thread • Message Delivery and Read Notification • Archive/Purge/Retrieve • Pagination (faster message downloads) • Email Administrator Upon Events • Drawer Controller Menu • Hide Contact options
  • 30.
    miSecureMessages (MSM) MSM 6.4Enhancements Users can add Images, Audio, Video, and PDF’s to Messages Add and view PDF’sAdd and view ImagesAdd and view PhotosAdd and play Audio Or use the Speech to Text Option
  • 31.
    miSecureMessages (MSM) MSM 6.4Enhancements Users can add a Phone Number to their profile The Phone Number shows Up to anyone trying to Reach them
  • 32.
    miSecureMessages (MSM) MSM 6.4Enhancements Users can add a Photo or Image to their profile. Anyone Trying to reach them will See the Photo
  • 33.
    miSecureMessages (MSM) MSM 6.4Enhancements Users can press the Info Button or slide over on a Message to see detailed Message History
  • 34.
    miSecureMessages (MSM) MSM 6.4Enhancements Users can change the Color Scheme of the App On their device
  • 35.
    miSecureMessages (MSM) MSM 6.4Enhancements All Apps now include a New Drawer Controller Menu to replace the Previous Toolbar
  • 36.
    miSecureMessages (MSM) 6.4 AdminWeb New MSM 6.4 Admin Web interface. New Contact Setup With Image and Phone number New Group Settings With Password Complexity New Archive Screen
  • 37.
    miSecureMessages (MSM) 6.4 AdminWeb New MSM 6.4 Admin Web Notification Settings. Allows MSM to generate emails to you when certain conditions occur. New Email settings to Notify you when Something happens Such as a new user registration New Email alerting me that A new user has registered.
  • 38.
    miSecureMessages (MSM) 6.4 AdminWeb New MSM 6.4 Admin Web includes advanced Diagnostics, including details about each message sent. New Diagnostic tool to Show you details about each Message, including the Notifications sent out. As well as when the message was Delivered and Read
  • 39.
    miSecureMessages (MSM) 6.4 AdminWeb New MSM 6.4 Admin Web allows specifying certain users as Hidden such as the IS or Infinity Contact or someone in the call center. Specify a user as Hidden To they don’t show up in The Contact List.
  • 40.
    Get Started For Free •Visit http://miSecureMessages.com and start your Free Trial today! • Contact Us: 800.356.9148 info@miSecureMessages.com
  • 41.