Mr. Chung’s three security recommendations:
1. Get your cloud service provider to sign a business associate agreement.
Cloud service providers are not considered business associates — entities that use or disclose patients’ protected health information — under HIPAA, but a business associate agreement can ensure that the provider will assume responsibility for protecting patients’ health information.
2. Always look ahead.
“The need to become more efficient will drive digital transformation and the push to the cloud, but it’s important to think about that before you make that push,” Mr. Chung told VentureBeat.
Set up security policies, think about what applications and data you want on the cloud, and see where cloud migration makes the most sense.
3. Retain visibility of your data.
Ensure that your data is secure by knowing who is supposed to have access to it.
Because physicians can work at multiple locations, they may have access to different data systems. Always check your network to see who no longer needs access to data when they are off duty or at a different facility, the report said.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.