{"id":10435,"date":"2022-10-04T05:00:59","date_gmt":"2022-10-04T09:00:59","guid":{"rendered":"https:\/\/jolt.richmond.edu\/?p=10435"},"modified":"2022-10-04T07:43:05","modified_gmt":"2022-10-04T11:43:05","slug":"electronic-health-records-federal-guidelines-for-managing-cybersecurity-risks","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2022\/10\/04\/electronic-health-records-federal-guidelines-for-managing-cybersecurity-risks\/","title":{"rendered":"Electronic Health Records: Federal Guidelines for Managing Cybersecurity Risks"},"content":{"rendered":"<p>By Jessica Otiono<\/p>\n<p>&nbsp;<\/p>\n<p>Electronic Health Records (EHR) utilize modern technology that allows for electronic entry, storage, and maintenance of digital patient data.<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a> This data includes patient records from doctors such as demographics, test results, medical history, history of present illness, and past and current medications.<a href=\"#_ftn2\" name=\"_ftnref2\">[2]<\/a> In the past two decades, the utilization of information technology in the delivery and management of healthcare, which resulted in the adoption of EHRs, has provided an efficient way of sharing healthcare records between healthcare professionals and patients who enjoy easy access to their records.<a href=\"#_ftn3\" name=\"_ftnref3\">[3]<\/a><\/p>\n<p>However, this ease of access is met with cybersecurity threats and data privacy challenges.<a href=\"#_ftn4\" name=\"_ftnref4\">[4]<\/a>\u00a0 The sensitive and patient-care-centeredness of EHRs make them susceptible to cyber-attacks.<a href=\"#_ftn5\" name=\"_ftnref5\">[5]<\/a>\u00a0 This is because they contain Personal Health Information (PHI), which cyber attackers sell for profit on the dark web.<a href=\"#_ftn6\" name=\"_ftnref6\">[6] <\/a>Cyberattacks on EHRs occur in diverse ways. Some of these cyberattacks include:<\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li>Phishing \u2013 Phishing attacks are the most rampant cybersecurity threats in healthcare. It is the practice of infecting a seemingly harmless email with malicious links.<a href=\"#_ftn7\" name=\"_ftnref7\">[7]<\/a>\u00a0 The usual form of phishing attack is email phishing.<a href=\"#_ftn8\" name=\"_ftnref8\">[8]<\/a><\/li>\n<li>Malware\/Ransomware \u2013 This type of malware disables access to computer systems and files until a ransom has been paid.<a href=\"#_ftn9\" name=\"_ftnref9\">[9]<\/a>\u00a0 Ransomware may infect a computer system through a phishing email containing a malicious link.<a href=\"#_ftn10\" name=\"_ftnref10\">[10]<\/a><\/li>\n<li>Distributed Denial of Service (DDOS) \u2013 DDOS floods a website or computer network with internet traffic to overwhelm it and impair its performance and availability.<a href=\"#_ftn11\" name=\"_ftnref11\">[11]<\/a> Cybercriminals employ bots to submit an excessive number of requests.<a href=\"#_ftn12\" name=\"_ftnref12\">[12] <\/a>DDOs used together with Ransomware are one of the most destructive cybersecurity attack combinations.<a href=\"#_ftn13\" name=\"_ftnref13\">[13]<\/a><\/li>\n<\/ol>\n<\/li>\n<li style=\"list-style-type: none;\"><\/li>\n<\/ol>\n<p>In dealing with cybersecurity threats to EHRs, Federal compliance laws such as the Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health (Act) were enacted to protect the privacy and data security of Personal Health Information (PHI) which are stored electronically.<a href=\"#_ftn14\" name=\"_ftnref14\">[14]<\/a> In addition, the HIPAA privacy rule establishes \u201cnational standards to protect individuals\u2019 medical records and other individually identifiable health information\u2026.\u201d<a href=\"#_ftn15\" name=\"_ftnref15\">[15]<\/a><\/p>\n<p>The HIPAA Security Rule also establishes appropriate safeguards to ensure the confidentiality, integrity, and security of electronically protected health information.<a href=\"#_ftn16\" name=\"_ftnref16\">[16]<\/a> The Security Rule provides administrative, physical, and technical safeguards for managing healthcare data privacy.<a href=\"#_ftn17\" name=\"_ftnref17\">[17]<\/a>\u00a0 Some of these safeguards include: i.) establishing a security management process in which the covered entity must implement policies and procedures to prevent, detect, contain, and correct security violations;<a href=\"#_ftn18\" name=\"_ftnref18\">[18]<\/a> ii.) appointing a designated security official who is responsible for the development and implementation of policies and procedures mandated by the Security Rule;<a href=\"#_ftn19\" name=\"_ftnref19\">[19] <\/a>iii.) implementing policies and procedures to address security incidents when they occur;<a href=\"#_ftn20\" name=\"_ftnref20\">[20]<\/a> iv.) creating policies and procedures for responding to an emergency that damages computer systems containing EHRs;<a href=\"#_ftn21\" name=\"_ftnref21\">[21]<\/a> v.) establishing safeguards for workstation security;<a href=\"#_ftn22\" name=\"_ftnref22\">[22] <\/a>vi.) implementing audit controls for information systems;<a href=\"#_ftn23\" name=\"_ftnref23\">[23]<\/a> and vii.) implementing measures to protect against unauthorized access to electronic personal health information transmitted over an electronic communications network.<a href=\"#_ftn24\" name=\"_ftnref24\">[24] <\/a><\/p>\n<p>In addition, the HITECH Act establishes the Breach Notification Rule. This rule requires Health care providers as well as other covered entities under HIPAA to promptly notify (within 60 calendar days from the day the breach is discovered) individuals of a data breach, as well as the Secretary of the U.S. Department of Health and Human Services (HHS) and the media in cases where the breach affects more than 500 individuals.<a href=\"#_ftn25\" name=\"_ftnref25\">[25]<\/a> Breaches of fewer than 500 individuals must be reported to the Secretary of the HHS on an annual basis, no later than 60 calendar days from the end of the year.<a href=\"#_ftn26\" name=\"_ftnref26\">[26] <\/a>As healthcare delivery technology continues to evolve, cyber-attacks on EHRs continue to happen. It is therefore imperative that healthcare providers and other key players implement policies that align cybersecurity and patient safety initiatives. These measures will protect patient safety and privacy while ensuring continuity in the delivery of high-quality healthcare by mitigating disruptions.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> <em>Electronic Medical Record in Healthcare<\/em>, U.S. Dept. Health Hum. Serv. 1, 3 (2022), https:\/\/www.hhs.gov\/sites\/default\/files\/2022-02-17-1300-emr-in-healthcare-tlpwhite.pdf.<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[3]<\/a> Liu Hua Yeo &amp; James Banfield, <em>Human Factors in Electronic Health Records Cybersecurity Breach: An Explanatory Analysis<\/em>, Perspectives In Health Info. Mgmt. (Mar. 15, 2022), https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC9123525\/.<\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> <em>Id<\/em><em>.<\/em><\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> Greg Kill, <em>Top 5 Cybersecurity Threats to Electronic Health Records and Electronic Medical Records<\/em>, Integracon (Apr. 28, 2018), https:\/\/integracon.com\/top-5-cybersecurity-threats-to-electronic-health-records-and-electronic-medical-records\/.<\/p>\n<p><a href=\"#_ftnref6\" name=\"_ftn6\">[6]<\/a> U.S. Dept. Health Hum. Serv., <em>supra<\/em> note 1, at 6.<\/p>\n<p><a href=\"#_ftnref7\" name=\"_ftn7\">[7]<\/a> Edward Kost, <em>Biggest Cyber Threats in Healthcare<\/em>, Upguard (Aug. 8, 2022), https:\/\/www.upguard.com\/blog\/biggest-cyber-threats-in-healthcare.<\/p>\n<p><a href=\"#_ftnref8\" name=\"_ftn8\">[8]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref9\" name=\"_ftn9\">[9]<\/a> <em>Cyber Attacks: In the Healthcare Sector<\/em>, Ctr. Internet Sec., https:\/\/www.cisecurity.org\/insights\/blog\/cyber-attacks-in-the-healthcare-sector (last visited Sept. 14, 2022).<\/p>\n<p><a href=\"#_ftnref10\" name=\"_ftn10\">[10]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref11\" name=\"_ftn11\">[11]<\/a> Hardik Shah, <em>Top 10 Cybersecurity Challenges in the Healthcare Industry<\/em>, Global Sign (May 5, 2022), https:\/\/www.globalsign.com\/en\/blog\/10-cybersecurity-challenges-healthcare.<\/p>\n<p><a href=\"#_ftnref12\" name=\"_ftn12\">[12]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref13\" name=\"_ftn13\">[13]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref14\" name=\"_ftn14\">[14]<\/a>\u00a0\u00a0 Liu Hua Yeo &amp; Banfield, <em>supra note<\/em> 3.<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[15]<\/a> <em>See The HIPAA Privacy Rule<\/em>, HHS.gov., https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/index.html (last visited Sept. 14, 2022).<\/p>\n<p><a href=\"#_ftnref16\" name=\"_ftn16\">[16]<\/a> <em>The Security Rule<\/em>, HHS.gov., \u00a0https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/index.html (last visited Sept. 14, 2022).<\/p>\n<p><a href=\"#_ftnref17\" name=\"_ftn17\">[17]<\/a> Ryan L. Garner, <em>Evaluating Solutions to Cyber Attack Breaches of Health Data: How Enacting A Private Right of Action For Breach Victims Would Lower Costs<\/em>, 14 Ind. Health L. Rev. 127, 139\u00a0 (2017).<\/p>\n<p><a href=\"#_ftnref18\" name=\"_ftn18\">[18]<\/a> <em>Id.<\/em>; 45 C.F.R. \u00a7 164.308 (a)(3)(i) (2017).<\/p>\n<p><a href=\"#_ftnref19\" name=\"_ftn19\">[19]<\/a> <em>Id<\/em>. \u00a7 164.308(a)(2).<\/p>\n<p><a href=\"#_ftnref20\" name=\"_ftn20\">[20]<\/a> <em>Id.<\/em> \u00a7 164.308(a)(6)(i).<\/p>\n<p><a href=\"#_ftnref21\" name=\"_ftn21\">[21]<\/a> <em>Id.<\/em> \u00a7 164.308(a)(6)(i).<\/p>\n<p><a href=\"#_ftnref22\" name=\"_ftn22\">[22]<\/a> 45 C.F.R. \u00a7 164.308(a)(6)(i) (2017).<\/p>\n<p><a href=\"#_ftnref23\" name=\"_ftn23\">[23]<\/a> <em>Id.<\/em> \u00a7 164.312(b).<\/p>\n<p><a href=\"#_ftnref24\" name=\"_ftn24\">[24]<\/a> <em>Id.<\/em> \u00a7 164.312(e)(1).<\/p>\n<p><a href=\"#_ftnref25\" name=\"_ftn25\">[25]<\/a> 45 C.F.R. \u00a7\u00a7 164. 400-414 (2009).<\/p>\n<p><a href=\"#_ftnref26\" name=\"_ftn26\">[26]<\/a> <em>Id.<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10436 size-full\" src=\"https:\/\/jolt.richmond.edu\/files\/2022\/09\/Screen-Shot-2022-09-26-at-3.34.41-PM.png\" alt=\"\" width=\"800\" height=\"428\" srcset=\"https:\/\/blog.richmond.edu\/jolt\/files\/2022\/09\/Screen-Shot-2022-09-26-at-3.34.41-PM.png 800w, https:\/\/blog.richmond.edu\/jolt\/files\/2022\/09\/Screen-Shot-2022-09-26-at-3.34.41-PM-300x161.png 300w, https:\/\/blog.richmond.edu\/jolt\/files\/2022\/09\/Screen-Shot-2022-09-26-at-3.34.41-PM-768x411.png 768w, https:\/\/blog.richmond.edu\/jolt\/files\/2022\/09\/Screen-Shot-2022-09-26-at-3.34.41-PM-480x257.png 480w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>Image Source:\u00a0https:\/\/www.aranca.com\/knowledge-library\/special-reports\/valuation\/healthtech-decoded<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Jessica Otiono &nbsp; Electronic Health Records (EHR) utilize modern technology that allows for electronic entry, storage, and maintenance of digital patient data.[1] This data includes patient records from doctors such as demographics, test results, medical history, history of present illness, and past and current medications.[2] In the past two decades, the utilization of information [&hellip;]<\/p>\n","protected":false},"author":5472,"featured_media":10436,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366],"tags":[],"class_list":["post-10435","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-post"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/blog.richmond.edu\/jolt\/files\/2022\/09\/Screen-Shot-2022-09-26-at-3.34.41-PM.png","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-2Ij","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/10435","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/5472"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=10435"}],"version-history":[{"count":10,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/10435\/revisions"}],"predecessor-version":[{"id":10453,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/10435\/revisions\/10453"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media\/10436"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=10435"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=10435"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=10435"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}