SlideShare a Scribd company logo
1 of 15
Healthcare IT Security
    Shane Molinari, MSc, PMP, CISSP, SSMBB
Don’t Take My Word For It
Ademóla 0., Adesina, A., Agbele, K., Februarie, R., Abidoye, A., & Nyongesa, H. (2011). Ensuring The Security
 And Privacy Of Information In Mobile Health-care Communication Systems. South African Journal Of Science,
 Vol. 107, Doi;10.4102/sajs. Retrieved April 9, 2012

Dimitropoulos, L., Patel, V., Scheffler, S., & Posnack, S. (2011). Public Attitudes Toward Health Information
  Exchange: Perceived Benefits and Concerns. Special Issue: The American Journal Of Managed Care, Vol. 17.
  Retrieved April 12, 2012

Kumar, P. & Lee, H. (2012). Security Issues in Healthcare Applications Using Wireless Medical Sensor Networks:
 A Survey. Sensors, 12, 55-91, doi:10.3390/s120100055. Retrieved April 15, 2012

Kovalchuk, Y., McDonald-Maier, K., and Howells, G. (2011). Overview of ICmetrics Technology – Security
 Infrastructure for Autonomous and Intelligent Healthcare System. International Journal of u- and e- Service,
 Science and Technology, Vol. 4, No. 3. Retrieved April 14, 2012.

Lenert, L. & Sundwall,D. (2012). Opportunity Forged by Crisis: Public Health Surveillance and Meaningful Use
  Regulations–A Crisis of Opportunity. American Journal of Public Health Government, Politics, and Law, Vol
  102, No. 3. Retrieved April 15, 2012.

Sarrico. C. & Hauenstein, J. (2011). Can EHRs and HIEs Get Along With HIPAA security Requirements? Journal
 of Healthcare Financial Management. Retrieved April 15, 2012.


                                                                                                           2
No Paranoia Here!




                    3
Current Situation
                             Laboratory
                             Information
                              System
                Patient
                                           Pharmacy
              Registration




                                                         Insurance
                             Patient
Orthopedics                                              Contracts
                               Info                     Management




                Surgery                    Scheduling
                              Radiology
                             Information
                              System




                                                                     4
Problem Statement




                    5
Problem Statement

 82%                        75%
Consumers                  Consumers

concerned                  concerned
                                        40-64
about EHR
                70%        about HIE

 security                   security   Highest age
               Consumers
                                       group with
               concerned
                                        concerns
               about HIE
                                       over privacy
                privacy
                                       and security




                                                      5
Root Cause




#1 surpassing drug trafficking
$56.6B in costs (not including fines)
80% data loss due to Malware




                                        6
Data Flow
                  C o n t r o l !    A c c e s s


                             Internet!




                                                   C o n t r o l !
A c c e s s

                         Wireless Transfer!


                             Intranet!
C o n t r o l !




                           Local Server!




                                                   A c c e s s
                           Patient Data!




                  A c c e s s    C o n t r o l !




                                                                     7
Systems Approach




                   8
Core Knowledge Required




                          9
Resolution Approach
           STANDARDS & BEST PRACTICES



                                            ENSURE
DOCUMENT        RESOLVE      DEVELOP
                                         SUSTAINABILIT
CURRENT          WEAK       MITIGATION
                                              Y&
 STATE           AREAS      STRATEGIES
                                         COMPLIANCE




                TRAINING & AUDIT




                                                         10
What’s In It For the Client?




Sustainability and Compliance


                                11
Closing




          12
Closing




          12
To Learn More

      BCMPros.com

info@BCMProfessionals.com

     888 - 587 - 4769


                            13

More Related Content

Viewers also liked

Healthcare Security Fundamentals
Healthcare Security FundamentalsHealthcare Security Fundamentals
Healthcare Security FundamentalsEstellesc
 
Using Docker for Testing
Using Docker for TestingUsing Docker for Testing
Using Docker for TestingCarlos Sanchez
 
GitFlow, SourceTree and GitLab
GitFlow, SourceTree and GitLabGitFlow, SourceTree and GitLab
GitFlow, SourceTree and GitLabShinu Suresh
 
DockerCon EU 2015: Continuous Integration with Jenkins, Docker and Compose
DockerCon EU 2015: Continuous Integration with Jenkins, Docker and ComposeDockerCon EU 2015: Continuous Integration with Jenkins, Docker and Compose
DockerCon EU 2015: Continuous Integration with Jenkins, Docker and ComposeDocker, Inc.
 
Presentation skills for managers
Presentation skills for managersPresentation skills for managers
Presentation skills for managersYodhia Antariksa
 
Digital Marketing Trends 2017
Digital Marketing Trends 2017Digital Marketing Trends 2017
Digital Marketing Trends 2017Webrepublic
 
DevOps and Continuous Delivery reference architectures for Docker
DevOps and Continuous Delivery reference architectures for DockerDevOps and Continuous Delivery reference architectures for Docker
DevOps and Continuous Delivery reference architectures for DockerSonatype
 
IT in Healthcare
IT in HealthcareIT in Healthcare
IT in HealthcareNetApp
 

Viewers also liked (14)

Healthcare Security Fundamentals
Healthcare Security FundamentalsHealthcare Security Fundamentals
Healthcare Security Fundamentals
 
Data Security in Healthcare
Data Security in HealthcareData Security in Healthcare
Data Security in Healthcare
 
Using Docker for Testing
Using Docker for TestingUsing Docker for Testing
Using Docker for Testing
 
GitFlow, SourceTree and GitLab
GitFlow, SourceTree and GitLabGitFlow, SourceTree and GitLab
GitFlow, SourceTree and GitLab
 
DockerCon EU 2015: Continuous Integration with Jenkins, Docker and Compose
DockerCon EU 2015: Continuous Integration with Jenkins, Docker and ComposeDockerCon EU 2015: Continuous Integration with Jenkins, Docker and Compose
DockerCon EU 2015: Continuous Integration with Jenkins, Docker and Compose
 
Architecting for Resiliency
Architecting for ResiliencyArchitecting for Resiliency
Architecting for Resiliency
 
Business Track
Business Track Business Track
Business Track
 
Building a Data Lake on AWS
Building a Data Lake on AWSBuilding a Data Lake on AWS
Building a Data Lake on AWS
 
Storage & Content Delivery
Storage & Content DeliveryStorage & Content Delivery
Storage & Content Delivery
 
Presentation skills for managers
Presentation skills for managersPresentation skills for managers
Presentation skills for managers
 
UNIX/Linux training
UNIX/Linux trainingUNIX/Linux training
UNIX/Linux training
 
Digital Marketing Trends 2017
Digital Marketing Trends 2017Digital Marketing Trends 2017
Digital Marketing Trends 2017
 
DevOps and Continuous Delivery reference architectures for Docker
DevOps and Continuous Delivery reference architectures for DockerDevOps and Continuous Delivery reference architectures for Docker
DevOps and Continuous Delivery reference architectures for Docker
 
IT in Healthcare
IT in HealthcareIT in Healthcare
IT in Healthcare
 

Similar to Infinity Success Conference Hit

L2 Using Information Technology
L2 Using Information TechnologyL2 Using Information Technology
L2 Using Information Technologyprimary
 
Insights into the Canadian eHealth Landscape - MaRS Future of Medicine
Insights into the Canadian eHealth Landscape - MaRS Future of MedicineInsights into the Canadian eHealth Landscape - MaRS Future of Medicine
Insights into the Canadian eHealth Landscape - MaRS Future of MedicineMaRS Discovery District
 
VPH in Future Healthcare. Where Will We Be in 10 Years from Now?
VPH in Future Healthcare. Where Will We Be in 10 Years from Now?VPH in Future Healthcare. Where Will We Be in 10 Years from Now?
VPH in Future Healthcare. Where Will We Be in 10 Years from Now?Plan de Calidad para el SNS
 
Linking Nbs To Ehr 130410
Linking Nbs To Ehr 130410Linking Nbs To Ehr 130410
Linking Nbs To Ehr 130410Kari Klossner
 
Next generation sequencing in pharmacogenomics
Next generation sequencing in pharmacogenomicsNext generation sequencing in pharmacogenomics
Next generation sequencing in pharmacogenomicsDr. Gerry Higgins
 
iHT2 Health IT Summit San Francisco 2013 - Christopher Chute, Division of Bio...
iHT2 Health IT Summit San Francisco 2013 - Christopher Chute, Division of Bio...iHT2 Health IT Summit San Francisco 2013 - Christopher Chute, Division of Bio...
iHT2 Health IT Summit San Francisco 2013 - Christopher Chute, Division of Bio...Health IT Conference – iHT2
 
CPHIMS Study Guide 2011
CPHIMS Study Guide 2011CPHIMS Study Guide 2011
CPHIMS Study Guide 2011Robert Levy
 
Rati kiria / Philips
Rati kiria / PhilipsRati kiria / Philips
Rati kiria / PhilipsRati Kiria
 
eHealth Governance in a Local Organisation. The Experience from Pompidou Hosp...
eHealth Governance in a Local Organisation. The Experience from Pompidou Hosp...eHealth Governance in a Local Organisation. The Experience from Pompidou Hosp...
eHealth Governance in a Local Organisation. The Experience from Pompidou Hosp...Plan de Calidad para el SNS
 
HIMSS slides: IT leaders show MU, ICD-10 progress but fear staff shortages
HIMSS slides: IT leaders show MU, ICD-10 progress but fear staff shortagesHIMSS slides: IT leaders show MU, ICD-10 progress but fear staff shortages
HIMSS slides: IT leaders show MU, ICD-10 progress but fear staff shortagesTrimed Media Group
 
2012 02 11 EHRs - healthcare system chicken soup or rotten egg
2012 02  11 EHRs - healthcare system chicken soup or rotten egg2012 02  11 EHRs - healthcare system chicken soup or rotten egg
2012 02 11 EHRs - healthcare system chicken soup or rotten eggdvreeman
 
How AstraZeneca is Applying AI, Imaging & Data Analytics (AI-Driven Drug Deve...
How AstraZeneca is Applying AI, Imaging & Data Analytics (AI-Driven Drug Deve...How AstraZeneca is Applying AI, Imaging & Data Analytics (AI-Driven Drug Deve...
How AstraZeneca is Applying AI, Imaging & Data Analytics (AI-Driven Drug Deve...Nick Brown
 
Utilizing wearable technology in remote patient monitoring with aging populat...
Utilizing wearable technology in remote patient monitoring with aging populat...Utilizing wearable technology in remote patient monitoring with aging populat...
Utilizing wearable technology in remote patient monitoring with aging populat...Valencell, Inc
 
Pentaho Healthcare Solutions
Pentaho Healthcare SolutionsPentaho Healthcare Solutions
Pentaho Healthcare SolutionsPentaho
 
Emerging Trends in Clinical Data Management
Emerging Trends in Clinical Data ManagementEmerging Trends in Clinical Data Management
Emerging Trends in Clinical Data ManagementArshad Mohammed
 
Current ONC Standards Activities
Current ONC Standards ActivitiesCurrent ONC Standards Activities
Current ONC Standards ActivitiesJitin Asnaani
 
Multi-domain and Privacy-aware Role Based Access Control in eHealth
Multi-domain and Privacy-aware Role Based Access Control in eHealthMulti-domain and Privacy-aware Role Based Access Control in eHealth
Multi-domain and Privacy-aware Role Based Access Control in eHealthguest3dc8ca
 
DiabetesManagement mHIseminar.Peeples
DiabetesManagement mHIseminar.PeeplesDiabetesManagement mHIseminar.Peeples
DiabetesManagement mHIseminar.PeeplesmHealth Initiative
 

Similar to Infinity Success Conference Hit (20)

L2 Using Information Technology
L2 Using Information TechnologyL2 Using Information Technology
L2 Using Information Technology
 
Insights into the Canadian eHealth Landscape - MaRS Future of Medicine
Insights into the Canadian eHealth Landscape - MaRS Future of MedicineInsights into the Canadian eHealth Landscape - MaRS Future of Medicine
Insights into the Canadian eHealth Landscape - MaRS Future of Medicine
 
VPH in Future Healthcare. Where Will We Be in 10 Years from Now?
VPH in Future Healthcare. Where Will We Be in 10 Years from Now?VPH in Future Healthcare. Where Will We Be in 10 Years from Now?
VPH in Future Healthcare. Where Will We Be in 10 Years from Now?
 
Linking Nbs To Ehr 130410
Linking Nbs To Ehr 130410Linking Nbs To Ehr 130410
Linking Nbs To Ehr 130410
 
Next generation sequencing in pharmacogenomics
Next generation sequencing in pharmacogenomicsNext generation sequencing in pharmacogenomics
Next generation sequencing in pharmacogenomics
 
iHT2 Health IT Summit San Francisco 2013 - Christopher Chute, Division of Bio...
iHT2 Health IT Summit San Francisco 2013 - Christopher Chute, Division of Bio...iHT2 Health IT Summit San Francisco 2013 - Christopher Chute, Division of Bio...
iHT2 Health IT Summit San Francisco 2013 - Christopher Chute, Division of Bio...
 
CPHIMS Study Guide 2011
CPHIMS Study Guide 2011CPHIMS Study Guide 2011
CPHIMS Study Guide 2011
 
Rati kiria / Philips
Rati kiria / PhilipsRati kiria / Philips
Rati kiria / Philips
 
eHealth Governance in a Local Organisation. The Experience from Pompidou Hosp...
eHealth Governance in a Local Organisation. The Experience from Pompidou Hosp...eHealth Governance in a Local Organisation. The Experience from Pompidou Hosp...
eHealth Governance in a Local Organisation. The Experience from Pompidou Hosp...
 
HIMSS slides: IT leaders show MU, ICD-10 progress but fear staff shortages
HIMSS slides: IT leaders show MU, ICD-10 progress but fear staff shortagesHIMSS slides: IT leaders show MU, ICD-10 progress but fear staff shortages
HIMSS slides: IT leaders show MU, ICD-10 progress but fear staff shortages
 
2012 02 11 EHRs - healthcare system chicken soup or rotten egg
2012 02  11 EHRs - healthcare system chicken soup or rotten egg2012 02  11 EHRs - healthcare system chicken soup or rotten egg
2012 02 11 EHRs - healthcare system chicken soup or rotten egg
 
How AstraZeneca is Applying AI, Imaging & Data Analytics (AI-Driven Drug Deve...
How AstraZeneca is Applying AI, Imaging & Data Analytics (AI-Driven Drug Deve...How AstraZeneca is Applying AI, Imaging & Data Analytics (AI-Driven Drug Deve...
How AstraZeneca is Applying AI, Imaging & Data Analytics (AI-Driven Drug Deve...
 
Utilizing wearable technology in remote patient monitoring with aging populat...
Utilizing wearable technology in remote patient monitoring with aging populat...Utilizing wearable technology in remote patient monitoring with aging populat...
Utilizing wearable technology in remote patient monitoring with aging populat...
 
Pentaho Healthcare Solutions
Pentaho Healthcare SolutionsPentaho Healthcare Solutions
Pentaho Healthcare Solutions
 
CMS III and eHR
CMS III and eHRCMS III and eHR
CMS III and eHR
 
Emerging Trends in Clinical Data Management
Emerging Trends in Clinical Data ManagementEmerging Trends in Clinical Data Management
Emerging Trends in Clinical Data Management
 
Current ONC Standards Activities
Current ONC Standards ActivitiesCurrent ONC Standards Activities
Current ONC Standards Activities
 
Multi-domain and Privacy-aware Role Based Access Control in eHealth
Multi-domain and Privacy-aware Role Based Access Control in eHealthMulti-domain and Privacy-aware Role Based Access Control in eHealth
Multi-domain and Privacy-aware Role Based Access Control in eHealth
 
Mark Dente's Presentation
Mark Dente's PresentationMark Dente's Presentation
Mark Dente's Presentation
 
DiabetesManagement mHIseminar.Peeples
DiabetesManagement mHIseminar.PeeplesDiabetesManagement mHIseminar.Peeples
DiabetesManagement mHIseminar.Peeples
 

Infinity Success Conference Hit

  • 1. Healthcare IT Security Shane Molinari, MSc, PMP, CISSP, SSMBB
  • 2. Don’t Take My Word For It Ademóla 0., Adesina, A., Agbele, K., Februarie, R., Abidoye, A., & Nyongesa, H. (2011). Ensuring The Security And Privacy Of Information In Mobile Health-care Communication Systems. South African Journal Of Science, Vol. 107, Doi;10.4102/sajs. Retrieved April 9, 2012 Dimitropoulos, L., Patel, V., Scheffler, S., & Posnack, S. (2011). Public Attitudes Toward Health Information Exchange: Perceived Benefits and Concerns. Special Issue: The American Journal Of Managed Care, Vol. 17. Retrieved April 12, 2012 Kumar, P. & Lee, H. (2012). Security Issues in Healthcare Applications Using Wireless Medical Sensor Networks: A Survey. Sensors, 12, 55-91, doi:10.3390/s120100055. Retrieved April 15, 2012 Kovalchuk, Y., McDonald-Maier, K., and Howells, G. (2011). Overview of ICmetrics Technology – Security Infrastructure for Autonomous and Intelligent Healthcare System. International Journal of u- and e- Service, Science and Technology, Vol. 4, No. 3. Retrieved April 14, 2012. Lenert, L. & Sundwall,D. (2012). Opportunity Forged by Crisis: Public Health Surveillance and Meaningful Use Regulations–A Crisis of Opportunity. American Journal of Public Health Government, Politics, and Law, Vol 102, No. 3. Retrieved April 15, 2012. Sarrico. C. & Hauenstein, J. (2011). Can EHRs and HIEs Get Along With HIPAA security Requirements? Journal of Healthcare Financial Management. Retrieved April 15, 2012. 2
  • 4. Current Situation Laboratory Information System Patient Pharmacy Registration Insurance Patient Orthopedics Contracts Info Management Surgery Scheduling Radiology Information System 4
  • 6. Problem Statement 82% 75% Consumers Consumers concerned concerned 40-64 about EHR 70% about HIE security security Highest age Consumers group with concerned concerns about HIE over privacy privacy and security 5
  • 7. Root Cause #1 surpassing drug trafficking $56.6B in costs (not including fines) 80% data loss due to Malware 6
  • 8. Data Flow C o n t r o l ! A c c e s s Internet! C o n t r o l ! A c c e s s Wireless Transfer! Intranet! C o n t r o l ! Local Server! A c c e s s Patient Data! A c c e s s C o n t r o l ! 7
  • 11. Resolution Approach STANDARDS & BEST PRACTICES ENSURE DOCUMENT RESOLVE DEVELOP SUSTAINABILIT CURRENT WEAK MITIGATION Y& STATE AREAS STRATEGIES COMPLIANCE TRAINING & AUDIT 10
  • 12. What’s In It For the Client? Sustainability and Compliance 11
  • 13. Closing 12
  • 14. Closing 12
  • 15. To Learn More BCMPros.com info@BCMProfessionals.com 888 - 587 - 4769 13

Editor's Notes

  1. \n
  2. \n
  3. \n
  4. \n
  5. \n
  6. \n
  7. \n
  8. \n
  9. \n
  10. \n
  11. \n
  12. \n
  13. \n
  14. \n
  15. \n
  16. \n