<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>VPN Haus &#187; HIPAA</title>
	<atom:link href="http://vpnhaus.ncp-e.com/category/hipaa/feed/" rel="self" type="application/rss+xml" />
	<link>http://vpnhaus.ncp-e.com</link>
	<description>Rethinking Remote Access</description>
	<lastBuildDate>Wed, 01 Sep 2010 18:50:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='vpnhaus.ncp-e.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/e33cdc29c0f8b9506f2c669079e8e2d9?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>VPN Haus &#187; HIPAA</title>
		<link>http://vpnhaus.ncp-e.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://vpnhaus.ncp-e.com/osd.xml" title="VPN Haus" />
	<atom:link rel='hub' href='http://vpnhaus.ncp-e.com/?pushpress=hub'/>
		<item>
		<title>Healthcare Provisioning: Q&amp;A with Marshall Maglothin</title>
		<link>http://vpnhaus.ncp-e.com/2010/07/22/healthcare-provisioning-qa-with-marshall-maglothin/</link>
		<comments>http://vpnhaus.ncp-e.com/2010/07/22/healthcare-provisioning-qa-with-marshall-maglothin/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 18:39:46 +0000</pubDate>
		<dc:creator>vpnhaus</dc:creator>
				<category><![CDATA[Expert Q&A]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Rethink Remote Access]]></category>
		<category><![CDATA[provisioning]]></category>
		<category><![CDATA[healthcare IT]]></category>

		<guid isPermaLink="false">http://vpnhaus.ncp-e.com/?p=1251</guid>
		<description><![CDATA[VPN Haus recently talked to Marshall Maglothin, a Washington, DC-based consultant specializing in healthcare virtual management. Maglothin gives us his perspective on keeping patient information safe without hindering speedy access to urgent data. VPN Haus: What are the basics for provisioning employees at healthcare organizations? Maglothin: All systems should have all users using unique passwords. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vpnhaus.ncp-e.com&amp;blog=4052628&amp;post=1251&amp;subd=vpnhaus&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>VPN Haus recently talked to <a href="http://www.linkedin.com/profile?viewProfile=&amp;key=16410355&amp;authToken=_NmJ&amp;authType=name&amp;trk=mp_view_prf_t">Marshall Maglothin</a>, a Washington, DC-based consultant specializing in healthcare virtual management. Maglothin gives us his perspective on keeping patient information safe without hindering speedy access to urgent data.</p>
<p><strong>VPN Haus: What are the basics for provisioning employees at healthcare organizations? </strong></p>
<p><strong>Maglothin</strong>:  All systems should have all users using unique passwords. Thus, the system has an electronic audit trail to record which employees accessed which records, with statistical outlier reporting.</p>
<p><strong>VPN Haus: How do you ensure that the records are not so tightly controlled that it delays specialists asked to consult on the case or ICU personnel from urgently accessing the records?</strong></p>
<p><strong>Maglothin</strong>: All stations should have a time-out feature, and work stations in areas such as ICU and CCU are considered more secure/personnel constantly present, so the station&#8217;s time out may be longer. Once a station is logged-on, switching users by password should be real-time.</p>
<p>The greater issue is all the bedside workstations/wireless devices. If it takes more than 15-30 seconds to log-on (some take 90 seconds), then if a physician logs-on to 30 patients a day, that&#8217;s 45 minutes of lost PHYSICIAN productivity &#8211; no patient care and no reimbursement. Doesn&#8217;t sound like much. But calculate 40 hours per week for 250 days per year, this equals 188 hours or more than 4.5 work weeks lost to nothing but logging in!</p>
<p><strong>VPN Haus:  Staggering. So, if the consultant couldn’t access the records, it would be an example of a poor sensitivity error. What other errors should healthcare organizations be mindful of?<br />
</strong></p>
<p><strong>Maglothin</strong>:  There’s the error of excessive credulity.  An example would be a unit clerk on a certain building having a password that would allow her access to, say outpatient records or mental health unit records, for which she would have no reason to have access to.</p>
<p>There’s also the error of excessive skepticism. An example would be, a cardiologist might not be cleared to access mental health records, but one of the patients has just had a cardiac code and the cardiologist is called in for a STAT consult.</p>
<p><em> Marshall Maglothin is owner of Blue Oak Consulting, based in Washington DC. </em></p>
<div class="tweetmeme-button" id="tweetmeme-button-post-1251" style='float: right; margin-left: 10px; margin-bottom: 5px; padding: 4px 0 2px 4px; background: #fff;'>
<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fvpnhaus.ncp-e.com%2F2010%2F07%2F22%2Fhealthcare-provisioning-qa-with-marshall-maglothin%2Ftweetmeme_alias%3Dhttp%3A%2F%2Fwp.me%2Fph0gY-kb%26tweetmeme_source%3D%E2%80%9Dvpnhaus%E2%80%9D"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fvpnhaus.ncp-e.com%2F2010%2F07%2F22%2Fhealthcare-provisioning-qa-with-marshall-maglothin%2F" height="61" width="51" /></a>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vpnhaus.wordpress.com/1251/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vpnhaus.wordpress.com/1251/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vpnhaus.wordpress.com/1251/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vpnhaus.wordpress.com/1251/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vpnhaus.wordpress.com/1251/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vpnhaus.wordpress.com/1251/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vpnhaus.wordpress.com/1251/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vpnhaus.wordpress.com/1251/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vpnhaus.wordpress.com/1251/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vpnhaus.wordpress.com/1251/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vpnhaus.wordpress.com/1251/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vpnhaus.wordpress.com/1251/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vpnhaus.wordpress.com/1251/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vpnhaus.wordpress.com/1251/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vpnhaus.ncp-e.com&amp;blog=4052628&amp;post=1251&amp;subd=vpnhaus&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vpnhaus.ncp-e.com/2010/07/22/healthcare-provisioning-qa-with-marshall-maglothin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d30ae0a99d7b481489730392ec6a2a96?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vpnhaus</media:title>
		</media:content>
	</item>
		<item>
		<title>Network Security with electronic health records</title>
		<link>http://vpnhaus.ncp-e.com/2009/07/28/network-security-with-emrs/</link>
		<comments>http://vpnhaus.ncp-e.com/2009/07/28/network-security-with-emrs/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 21:04:52 +0000</pubDate>
		<dc:creator>vpnhaus</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Posts]]></category>

		<guid isPermaLink="false">http://vpnhaus.wordpress.com/?p=363</guid>
		<description><![CDATA[In last week’s highlights, we included a post from Branden Williams’ Security Convergence Blog on EMRs. We thought this weeks’ post would be a good opportunity to elaborate on Branden’s and our own from earlier in the year, How can businesses ensure HIPAA compliance? The push is on for adoption and if healthcare providers don’t [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vpnhaus.ncp-e.com&amp;blog=4052628&amp;post=363&amp;subd=vpnhaus&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In <a href="http://vpnhaus.wordpress.com/2009/07/23/what-were-reading-week-of-720/">last week’s highlights</a>, we included a post from <a href="http://blogs.verisign.com/securityconvergence/">Branden Williams’ Security Convergence Blog</a> on EMRs.  We thought this weeks’ post would be a good opportunity to elaborate on Branden’s and our own from earlier in the year, <a href="http://vpnhaus.wordpress.com/2009/04/01/how-can-businesses-ensure-hipaa-compliance/">How can businesses ensure HIPAA compliance?</a>    </p>
<p>The push is on for adoption and if healthcare providers don’t adapt, they face some potentially sharp teeth.  We <a href="http://www.tissuepathology.typepad.com/weblog/2009/07/hidden-malpractice-dangers-in-emrs.html">read</a> that, “Failure to implement EMR by 2014 may result in increased malpractice premiums and increased exposure to malpractice claims, as well as a reduction in Medicare reimbursement, beginning in 2015”. Ouch!   </p>
<p>So what’s the tie to VPN’s? We see a significant portion of the EMR communications being wireless. Don’t believe us? Next time you’re in a hospital, take note of all the handheld devices the staff is marching around with.  How about hospice workers who update records via PDA’s? How about in-facility WLAN and WiFi networks? Doctors use laptops from room to room and hotspots are popping up in cafeterias, waiting rooms, etc. all over the country. The list goes on and as it grows so does the threat to information traveling wirelessly. </p>
<p>EMRs are a great benefit to the healthcare industry and have the potential to improve patient care definitively. With solid VPN’s in place, HIPAA can be satisfied as well as protecting the great benefits wireless communications have on worker productivity. The right VPN tech is important too – avoiding vendor lock, ensuring the tech fits facility policy and doesn’t force policy changes, and it must be easy enough to users that they don’t even notice it’s running (otherwise, they’ll find a way around it!). </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vpnhaus.wordpress.com/363/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vpnhaus.wordpress.com/363/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vpnhaus.wordpress.com/363/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vpnhaus.wordpress.com/363/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vpnhaus.wordpress.com/363/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vpnhaus.wordpress.com/363/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vpnhaus.wordpress.com/363/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vpnhaus.wordpress.com/363/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vpnhaus.wordpress.com/363/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vpnhaus.wordpress.com/363/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vpnhaus.wordpress.com/363/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vpnhaus.wordpress.com/363/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vpnhaus.wordpress.com/363/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vpnhaus.wordpress.com/363/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vpnhaus.ncp-e.com&amp;blog=4052628&amp;post=363&amp;subd=vpnhaus&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vpnhaus.ncp-e.com/2009/07/28/network-security-with-emrs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d30ae0a99d7b481489730392ec6a2a96?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vpnhaus</media:title>
		</media:content>
	</item>
		<item>
		<title>How can businesses ensure HIPAA compliance?</title>
		<link>http://vpnhaus.ncp-e.com/2009/04/01/how-can-businesses-ensure-hipaa-compliance/</link>
		<comments>http://vpnhaus.ncp-e.com/2009/04/01/how-can-businesses-ensure-hipaa-compliance/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 20:00:47 +0000</pubDate>
		<dc:creator>vpnhaus</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Posts]]></category>

		<guid isPermaLink="false">http://vpnhaus.wordpress.com/?p=248</guid>
		<description><![CDATA[With recent changes in HIPAA standards announced earlier this week, we wanted to examine how healthcare organizations of all sizes could ensure complicance from a technological perspective. We spoke to NCP Engineering&#8217;s Rene Poot for his thoughts: HIPAA is a collection of standards striving for an effective and efficient method of exchanging information to the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vpnhaus.ncp-e.com&amp;blog=4052628&amp;post=248&amp;subd=vpnhaus&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>With recent changes in HIPAA standards <a href="HIPAA is a collection of standards striving for an effective and efficient method of exchanging information to the right people in a secure manner, thereby creating streamlined workflows in an electronic environment, and so delivering higher quality yet affordable health care. The Privacy Rule protects all &quot;individually identifiable health information&quot; held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information &quot;protected health information (PHI).&quot;">announced earlier this week</a>, we wanted to examine how healthcare organizations of all sizes could ensure complicance from a technological perspective. We spoke to NCP Engineering&#8217;s Rene Poot for his thoughts:</p>
<p style="padding-left:30px;">HIPAA is a collection of standards striving for an effective and efficient method of exchanging information to the right people in a secure manner, thereby creating streamlined workflows in an electronic environment, and so delivering higher quality yet affordable health care. The Privacy Rule protects all &#8220;individually identifiable health information&#8221; held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information &#8220;protected health information (PHI).&#8221;</p>
<p style="padding-left:30px;">The Privacy Rule protects all &#8220;individually identifiable health information&#8221; held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information &#8220;protected health information (PHI).&#8221;</p>
<p style="padding-left:30px;">This ranges from keeping file cabinets/record rooms locked, stricter access controls to computers (password requirements or smart card authentication), to the more complex data storage, digital signatures to ensure non-repudiation, etc.</p>
<p style="padding-left:30px;">Let&#8217;s focus on the PHI that is being transmitted, or in other words, when Electronic Protected Health Information is being transported over open networks: that&#8217;s where secure communication plays a role; this is where NCP steps up to the plate.  These requirements are not by any means limited to HIPAA, as these same requirements are also applicable to the financial institutions, government departments, police departments, and so forth.</p>
<p style="padding-left:30px;">What our customers in these different fields appreciate is NCP&#8217;s understanding of secure communications: the safeguarding of the data in transit; but also verifying the authenticity and authorization of the person receiving and transmitting the information by means of strong authentication (multi-factor authentication).  The HIO in question can select which vendor/provider they want to use for this; be it a PKI environment with smart cards or an OTP setup, NCP is flexible and will allow for this freedom of choice.</p>
<p style="padding-left:30px;">- Strong Authentication: the assurance to one entity that another entity is who he, she, or it claims to be,</p>
<p style="padding-left:30px;">- Integrity: the assurance to an entity that data has not been altered (intentionally or unintentionally) in transit,</p>
<p style="padding-left:30px;">- Confidentiality: the assurance to an entity that no one can read a particular piece of data except the receiver(s) explicitly intended.</p>
<p style="padding-left:30px;">Of course one can impose a lot of restrictions on the user; but besides some user awareness (often overlooked; as not everything can be locked down by technology &#8212; think about discussions about patients and treatments in public areas between personnel or with family members), is user-friendliness.  When a user is confronted with a lot of barriers that keep them from performing their work in an efficient effective manner, they will inevitably find a way to circumvent this.  By making the procedure of establishing a secure connection as easy and as transparent as possible for the user, yet maintaining a high level of security, an administrator can tick this requirement on the list and have the assurance that this base is covered.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vpnhaus.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vpnhaus.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vpnhaus.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vpnhaus.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vpnhaus.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vpnhaus.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vpnhaus.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vpnhaus.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vpnhaus.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vpnhaus.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vpnhaus.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vpnhaus.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vpnhaus.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vpnhaus.wordpress.com/248/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vpnhaus.ncp-e.com&amp;blog=4052628&amp;post=248&amp;subd=vpnhaus&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vpnhaus.ncp-e.com/2009/04/01/how-can-businesses-ensure-hipaa-compliance/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d30ae0a99d7b481489730392ec6a2a96?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vpnhaus</media:title>
		</media:content>
	</item>
	</channel>
</rss>