Health care groups to review telecommuting policies
Computerworld -
To comply with government regulations, health care organizations aren't just overhauling their operations. They're also reviewing their telecommuting policies.
| Under Wraps Health care organizations can protect private information used by telecommuters by: |
The privacy rules of the Health Insurance Portability and Accountability Act, with which health care organizations must comply by April 2003, states that unauthorized persons can't have access to private medical data. That has prompted several health organizations to review their telecommuting policies to prevent off-site privacy breaches.
"At work, you can make sure people don't enter a facility unless they're authorized, but at home, it's different," said Jim Hudack, CEO of UnitedHealth Group Inc.'s technologies division in Minnetonka, Minn.
Although Hudack doesn't think HIPAA will force UnitedHealth to ban telecommuting altogether, he said the company has to "be careful about what we let people work on at home."
For instance, if an employee was telecommuting and his son walked into the room and saw confidential patient information, that would violate the privacy rule.
Health care organizations also need to consider whether telecommuters are downloading patient information from the network and storing it on their home computer hard drives, said James Harvey, an attorney at Alston & Bird LLP in Atlanta who specializes in privacy issues. If so, organizations need to extend security rules to home computers, he said.
"It's much easier to address security issues in a centralized mainframe environment than on a distributed basis," he said.
HIPAA includes measures for both the security and privacy of patient information. Penalties for breaches include severe fines and possible jail time. To avoid these consequences, many health care organizations said they will ramp up security measures to protect applications on home devices, such as using virtual private networks, encryption or public-key infrastructure.
To comply with the final HIPAA security rules, health care managers will have to authenticate who is accessing the data, said Patrick Grotton, CIO at Mercy Hospital in Portland, Maine.
Grotton said he's considering using a biometric device, such as an eye or fingerprint scanner, combined with various layers of password protection to ensure that unauthorized individuals can't access patient information.
But to a large extent, privacy measures will involve educating and training telecommuters and enforcing policies. Some health care IT managers said telecommuters who work in a home office rather than at a computer set up in the living room or bedroom are less likely to invite prying eyes.
Additional Resources


White Papers & Webcasts
Best Practices in Protecting the Technology Systems Revolutionizing Healthcare
With technology infiltrating every aspect of healthcare, traditional approaches to power protection no longer suffice. This paper introduces a new hospital power protection...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....
Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....
Subscribe to Computerworld
