GAO questions HHS efforts to secure electronic health records
It wants the department to devise a comprehensive way to protect data
Computerworld - The U.S. Department of Health and Human Services (HHS) has not come up with a way to tie together the various initiatives it has ongoing to tackle the thorny privacy and security issues related to exchanging health care records electronically.
That concern is in a report released Thursday by the U.S. Government Accountability Office (GAO) that calls on HHS to define and put into place a comprehensive approach for protecting health information. Until it does that -- and identifies milestones for its approach -- the privacy and protection of personal health information exchanged through a nationwide network "will remain unclear," according to the report.
HHS disagreed with the GAO comments, the report said, arguing that it does have in place a "comprehensive and integrated approach for ensuring privacy and security of health information." In addition, HHS disagreed with the report's suggestion that it identify benchmarks for its work, noting that tightly scripted milestones "would impede HHS's processes and preclude stakeholder dialogue on the direction of important policy matters."
In addition to integrating its various privacy and security projects, the GAO recommended that HHS identify an entity who would be responsible for the integration of the privacy and security initiatives. HHS, however, did not comment on this suggestion, nor did it provide any information regarding any effort to assign responsibility for the activities, according to the report.
HHS officials did not respond to a request for comment on the GAO findings.
The report noted that HHS and its National Coordinator for Health IT have taken several steps to protect personal health information, including setting up two health information advisory committees and awarding several contracts that include requirements for addressing the privacy of health information exchanged nationwide.
Read more about IT in Government in Computerworld's IT in Government Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Virtualizing Government Infrastructure
- All server virtualization solutions are not created equal. The more-with-less agenda for government agencies is tailor-made for server virtualization, which is evolving into...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will... All IT in Government White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All IT in Government Webcasts