healthcaretechoutlook
| | November 20198UTLOOK Healthcare Tech By Robert Kay, CCO, American Academic Health SystemCOMPLIANCE AND IT SECURITY: PERFECT TOGETHERThe attention of health care compliance and privacy professionals once centered on misdirected faxes or the documents of one patient mistakenly comingled with those of another. Now, on any given day, we deal with phishing attempts, ransomware attacks, lost electronic storage, hacking incidents; the list goes on as to the intrusions into our medical records in particular and our overall privacy in general. Given the technical sophistication involved in this state of affairs, many compliance professionals may be unprepared or under-resourced to address these events. More likely is the fact that technology and compliance function in different silos and, while it may be cliché, we must learn to break down those silos. But how? Given this writers role as a compliance officer, emphasis will be placed on how those in similar roles can initiate some of that destruction.ADD IT SECURITY TO THE COMPLIANCE COMMITTEERegardless of when the Committee meets, IT Security should have a place at the table. This provides another important forum for an audience to hear of potential threats as well as the actions and strategies as to how they might be mitigated. It is not uncommon for many already at the table to be unaware of who IT Security is, what they do, and their importance to the organization. BRING IT SECURITY INTO THE DEVELOPMENT OF THE ANNUAL WORK PLANIf two heads are better than one, that other head should have the knowledge that yours does not. Different perspectives are invaluable, especially when it comes to tech. (Be aware too that you may be teaching IT about your areas of expertise.) This is also an opportune time to cooperate in the enterprise risk management (ERM) if your organization has implemented it. IN MY OPINIONRobert Kay
< Page 7 | Page 9 >