Most Recent Posts
Archiving Old Data Solution
by JamesNT - 06/28/2025 12:06 AM
Need Advice regarding Data Archiving
by JamesNT - 06/28/2025 12:06 AM
Prescription Drug Monitoring Program
by Bert - 06/26/2025 8:25 AM
AI?
by Bert - 06/25/2025 7:52 AM
PRINTING SCHEDULE
by Raj1 - 06/24/2025 9:54 AM
AC Version 12.3
by beagle - 06/15/2025 8:57 PM
A Tale of Woe: Only Partial Backups
by JamesNT - 06/12/2025 3:00 PM
Member Spotlight
JBS
JBS
Reisterstown
Posts: 2,986
Joined: September 2009
Newest Members
ESMI, It's me, Paradise Family, MedCode, MZ Medical Billi
4,594 Registered Users
Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Dec 2007
Posts: 1,244
Member
OP Offline
Member
Joined: Dec 2007
Posts: 1,244
I'm curious to know what other practices are doing to be compliant with the "Core measure 15: Protect Electronic Health Information."

The State of Maine Regional Extension Center gave all participating offices a toolkit that included numerous self-assessment checklists and flowsheets to address security and protection of protected health information.

Security and protection is looked at by these toolkits as both external security breaches and internal ones. Malicious attacks and inadvertent honest errors. It also accounts for electronic security threats as well as physical threats to on-site storage of protected health information. Backing up data and information sharing to third parties is also part of the assessments. Protection of health information extends not just to the EHR but also your billing program, credit card machine, fax machine, network, and any third parties who may access your network (such as an off-site I.T. administrator/contractor).

Do any of your states offer a similar resource?
Have any of you hired a third party to perform a security/protection assessment?
What have you done to demonstrate proof that you have the proper policies in place to attest to Core measure 15?
What format is your proof recorded so that you can sustain audit from CMS, in the event you are audited? i.e. do you have an Excel spreadsheet or Word documents showing you policies or checklists indicating you've done a self-assessment.
What have you done to address weaknesses in your office so that health information is better protected?

This is the one measure that I found the most difficult to attest to. Everything else was contained directly within A.C. and relatively easy to perform. But this one was a challenge for me.


Adam Lauer, DO (solo FP)
Twin City Family Medicine
Brewer, ME
Joined: Jan 2012
Posts: 22
Member
Offline
Member
Joined: Jan 2012
Posts: 22
Those that attested or even those concerned with the HIPAA security issues - did you get a formal statement from AC regarding the fact that they implement necessary safeguards to protect the confidentiality and integrity of the electronic health information. (I guess to satisfy the "business associate" requirement). I assume that it would only be necessary if you are using the AC back up (since that involves the transfer of info to them).
Donald Phillips MD Cedar Hill Tx

Joined: Mar 2011
Posts: 837
Likes: 10
Member
Offline
Member
Joined: Mar 2011
Posts: 837
Likes: 10
This is pretty much all a work in progress.
I take the position that "strong" passwords and good firewalls create adequate security for a small office.

I refuse to get paranoid about this -- if I have to spend mega$$ on "security", then I'll just go back to paper. Electronic media is inherently insecure.

When we take backup data out of the office, I suppose it should be on an encrypted disk/flash drive. I haven't got there yet, but that would solve the "lost my laptop" data breach problem that even big organizations seem to have.


Tom Duncan
Family Practice
Astoria OR
Joined: Jan 2012
Posts: 22
Member
Offline
Member
Joined: Jan 2012
Posts: 22
I like that answer at least with regards to the electronic part. I am reading too much government edicts regarding security - it gets ridiculous. Once every singly health entity is electronic - I can just imagine how many accidents will happen. Trying to put a policy together - I guess we should also put in our security plan and prevention that we actually have locks on our office doors. As for off site - I will probably just start leaving the external hard drive at work - in a fireproof lock box. However, if we use the I-phone AC app - then that has protected health info on it - maybe I'll just delete it. It is not so much doing common sense protective things - it is the specified "hoops" like a "risk analysis". Geez, I have a 1200 square foot office with my wife and one MA and 3 computers. If somebody wants in at night, they'll get in. I like some of Adam's colorful comments as well - but if I get going too far - I might get visited by a presidential death squad.
Thanks for commenting
Donald Phillips MD Cedar Hill, Texas

Joined: Dec 2007
Posts: 1,244
Member
OP Offline
Member
Joined: Dec 2007
Posts: 1,244
I'd be happy to back you up on colorful comments... but the death squads may come after me too. Imagine a bunch of right winged doctors, holed up with guns, in a fortress compound, refusing to participate in MU. Then ATF comes in with guns blazing while we chant "hell no, we won't M.U., hell no, we won't M.U." oops I hijacked my own thread...

For the government spies reading this thread...JUST JOKING!

Last edited by LauerDO; 01/30/2012 10:29 PM.

Adam Lauer, DO (solo FP)
Twin City Family Medicine
Brewer, ME
Joined: Dec 2007
Posts: 1,244
Member
OP Offline
Member
Joined: Dec 2007
Posts: 1,244
But seriously the REC in Maine has informed us that the criteria for Core 15 is very tough to meet. they feel it's more than just having a password protected system. Have I been led astray?


Adam Lauer, DO (solo FP)
Twin City Family Medicine
Brewer, ME
Joined: Jan 2010
Posts: 1,128
Member
Offline
Member
Joined: Jan 2010
Posts: 1,128
It looks like no one has gotten back to us on this. I too am wondering how to use the encryption feature. Do we encrypt the backup file? Is this just for encrypting other files we export? Adam can you weight in?


Chris
Living the Dream in Alaska
Joined: Jan 2012
Posts: 22
Member
Offline
Member
Joined: Jan 2012
Posts: 22
I don't know if this question pertains to the above but I did have an "encryption" question as well. My AC is on my desktop running Windows 7 Pro (i.e. no server). Are the AC files encrypted already or do I need to encrypt them via the Windows program? If I start downloading the imported items to an external hard drive (have been downloading all to AC back up since I'm new and small amount) - do I at least need to encrypt that file? Thanks,
Donald Phillips MD Cedar Hill, Texas

Joined: Dec 2007
Posts: 1,244
Member
OP Offline
Member
Joined: Dec 2007
Posts: 1,244
Guys, this comes directly from the AC website under offsite backups :

"How It Works
OffSite Backup service allows you to upload your crucial Amazing Charts EHR databases each night to our secure data center for safe keeping. Your databases, patient information, templates, schedules, billing, and other information is encrypted on your own computer then uploaded and stored on our secure servers.
Security

Obviously security is of the utmost importance given that your data contains patient-identifiable health information. The first layer of security occurs on your computer, before the connection to our archiving servers occur. When you run our Amazing Charts OffSite Backup utility your databases and patient records are encrypted using a 128-bit cipher algorithm. It has been calculated that breaking this level of encryption would take a hacker over a million years!

Your encrypted patient and practice data is then uploaded in a HIPAA-compliant manner across a secured 128-bit encrypted SSL internet connection (the type of connections that banks use)."


Adam Lauer, DO (solo FP)
Twin City Family Medicine
Brewer, ME
Joined: Dec 2007
Posts: 1,244
Member
OP Offline
Member
Joined: Dec 2007
Posts: 1,244
so it looks like we do nothing to invoke the encryption?? am I reading this correctly??


Adam Lauer, DO (solo FP)
Twin City Family Medicine
Brewer, ME

Moderated by  DocGene, JBS, Wendell365 

Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Who's Online Now
0 members (), 74 guests, and 19 robots.
Key: Admin, Global Mod, Mod
Top Posters(30 Days)
Bert 10
imcffp 3
beagle 3
ESMI 2
Top Posters
Bert 12,884
JBS 2,986
Wendell365 2,366
Sandeep 2,316
ryanjo 2,084
Leslie 2,002
Wayne 1,889
This board is dedicated to the memory of Michael "Indy" Astleford. February 6, 1961 -- April 16, 2019




SiteLock
Powered by UBB.threads™ PHP Forum Software 7.7.5