the use of mobile devises in health care environment; security burden or a blessing? a propose frame...

22
THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Upload: reilly-willoughby

Post on 31-Mar-2015

214 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT;

SECURITY BURDEN OR A BLESSING?A PROPOSE FRAME WORK FOR MOBILE DEVICES

Team 4

Page 2: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

2

Outline• Intro to Mobile devices in healthcare• Mobile devices in healthcare are an emerging technology• Security has always been a concern• Research Question• Security challenges that are associated with mobile devices• Bring your own device (BYOD) environment• Educating Physicians/Medical practitioners• Statistical overview • So what? Fred’s lovely question!!!!!• Survey• Methodology

Page 3: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

3

Intro to Mobile devices in healthcare

According to the Price Water House Coopers report (PwC), entitled "The New Gold Rush," healthcare providers in 2010 spent $88.6 billion worldwide on health IT.

PwC's research indicates that the mobile health market will grow from $1.4 billion in 2008 to $12.7 billion by 2014.

Mobile devices like smart phones and tablets are not just for checking the Facebook wall, Twitter, or playing “angry birds”. The U.S. Department of Health and Human Services (HHS) has been actively involved in a number of mobile health initiatives. The HHS has formed the Text4Health Task force, which provides recommendations to HHS Secretary, and identify both ongoing mobile health initiatives and future projects that would promote mobile health.

HHS.gov website on mhealth. http://www.hhs.gov/open/initiatives/mhealth/http://www.pwc.com/us/en/health-industries/publications/the-new-gold-rush.jhtml

Page 4: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

4

Mobile devices in healthcare are an emerging technology

In every hospital or clinic, examination room, or doctor's office, it is more likely to find a physician or clinician using an iPhone and iPads or any Android devices. These devices are popular because are faster, more portable, and generally more convenient than laptops or desktop computers.

Although mobile technology provides numerous advantages to the healthcare industry, it is not without risks.

Page 5: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

5

Security has always been a concern

Along with these new technologies, come new challenges for IT management.

Patient’s health information is normally stored on database servers. Authorized doctors or health care providers can access this data.

Data is prone to be exposed to a number of mobile attacks while being accessed.

Therefore, security has always been a concern when it comes to healthcare communications given the sensitive nature of the information being communicated.

Page 6: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

6

Research Question

The research question is: What should IT administrators in healthcare institutions do to ensure the protection of sensitive information used on mobile devices?

Many of the messages that are sent to smart phones and tablets throughout hospitals today are being sent via SMS/text messages and email with attachments.

This poses a big problem for organizations in meeting HIPAA and HITECH Act regulations.

http://www.hhs.gov/ocr/privacy/http://www.hhs.gov/ocr/privacy/hipaa/administrative/enforcementrule/hitechenforcementifr.html

•  

Page 7: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

7

Security challenges that are associated with mobile devices

Some of the security challenges that are associated with mobile devices include:

Data Interception: The wireless capability of mobile devices is particularly susceptible to data.

Viruses and Malicious attacks: As mobile devices are directly under the control of the users, they are vulnerable to virus and malicious code attack.

Theft and Loss of the device: The small size and portability of mobile devices make them susceptible to loss and theft. No security provision, any sensitive information on the device can be easily accessed or copied.

Human element: The weakest link in security systems is the human factor. Users do not follow safe computing procedures or perform updates on their devices.

Page 8: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

8

Bring your own device (BYOD) environment

Mobile devices in healthcare are an emerging technology that will dominate the industry in the future.

Four out of five physicians use smart phones devices, tablets, and numerous apps in their medical practice, according to a new report from Jackson & Coker. (The report titled “Apps, Doctors and Digital Devices”.)

The new trend in mobile security strategy is creating software specifically designed for a “bring your own device” (BYOD) environment.

http://www.jacksoncoker.com/physician-careerresources/newsletters/monthlymain/des/Apps.aspxhttp://blogs.healthcareinfosecurity.com/posts.php?postID=1116

Page 9: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

9

Bring your own device (BYOD) environmentIBM introduced a service designed to help companies make sure that the myriad devices employees are now bringing into the office from smart phones to tablets are secure and protected from threats like malware and data theft.

IBM hopes companies will turn to its new Hosted Mobile Device Security Management service.

Rather than issuing them a standard system, under a trend that's been dubbed consumerization of IT or "bring your own device" (BYOD). IBM itself is now letting its workers ditch their BlackBerrys in favor of an iPhone or Android smart phone.

http://www.informationweek.us/news/security/mobile/231902875

Page 10: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

10

Educating Physicians/Medical practitioners

Another important aspect is the security task in a healthcare organization. It isn't hardware, or even software related.

It is educating physicians and other medical providers to ensure that they're implementing all of the security protocols and updates.

A survey by Healthcare Info Security shows that 70 % of hospitals have mobile security policies in place, but physicians or medical providers often are the last to know about or respond to those protocols and updates.

http://blogs.healthcareinfosecurity.com/posts.php?postID=1116

Page 11: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

11

Statistical overview

The mobile computing started with smart phones and tablets in the form of personal digital assistants.

In 2001, 26 % of U.S. physicians used PDAs.

Manhattan Research in the mid 2010 found 72% of U.S. physicians have a smart phone or PDA;

Another statistic in a 2010 Price Water House Coopers survey found 63 % of physicians are already using personal devices for mobile health solutions.

http://mobihealthnews.com/10627/survey-27-%-of-us-doctors-have-tablets/http://www.informationweek.com/news/healthcare/mobile-wireless/229401603http://www.businesswire.com/news/home/20110414005326/en/Physician-Mobile-Grows-45-Apple%C2%AE-Dominates-Android%E2%84%A2http://www.ncbi.nlm.nih.gov/pmc/articles/PMC1480095/?tool=pubmed http://www.ncbi.nlm.nih.gov/pmc/articles/PMC1480095/?tool=pubmed

Page 12: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

12

More to comeThe FDA this past February approved Mobile MIM, a mobile radiology application that allows clinicians to share and make diagnoses based on CT, MRI, and PET scans.

The AirStrip Cardiology app (iPhone, iPad) gets data from GE Healthcare’s Muse Cardiology Information System’s cloud database of current electrocardiograms.

AT&T last month announced similar expansion of its cloud-based Healthcare Community Online to include a mobility interface for smart phones.

Dell, this month released a mobile clinical computing program that allow hospitals using the Meditech health Care Information System to virtualize their system and provide secure access to desktop applications via any number of devices, including tablets.

This year’s iPad 2 processes images nine times faster than the original device in 2010, allowing faster processing of more detailed medical images.

http://www.fda.gov/NewsEvents/Newsroom/PressAnnouncements/ucm242295.htmhttp://www.informationweek.com/news/healthcare/mobile-wireless/227400122http://www.informationweek.com/news/healthcare/mobile-wireless/229401432Choudhri, A. F., & Radvany, M. G. (2010). Initial Experience with a Handheld Device Digital Imaging and Communications in Medicine Viewer: OsiriX Mobile on the iPhone. Journal of Digital Imaging, 24(2), 184-189.

Page 13: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

13

Methodology

Miami Children's Hospital recently found that its count of 3,000 devices accessing its network was only half accurate.

The real number, discovered by specialized mobile device identification software, was 5,600.

The use of mobile devices in health care has advantages. It can give timely access to the latest information, improve data collection, productivity and save money.

http://www.informationweek.com/news/healthcare/mobile-wireless/231903089http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html

Page 14: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

14

Methodology

The objective of this research proposal is to develop a framework model that will address the security challenges that mobile devices pose to healthcare organizations.

This is achieved by:

– investigating existing health governing regulatory requirements to serve as a basis for the security compliance framework model.

– Examine mobile devices, its influence on healthcare and how it affects the privacy and security of health information.

– Explore the threats and vulnerabilities associated with mobile devices.– Investigate existing security and management measures to ensure the privacy and

security of health information.– Design a mobile security compliance framework based on the results.

http://www.informationweek.com/news/healthcare/mobile-wireless/231903089http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html

Page 15: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

15

Methodology

In order to help answer the main question and meet the objectives, the study will produce a survey questionnaire to key physicians and other health care providers that will be used as a case study. Analysis of the survey will result in statistics.

What should IT administrators in healthcare institutions do to ensure the protection of sensitive information used on mobile devices?

http://www.informationweek.com/news/healthcare/mobile-wireless/231903089http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html

Page 16: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

16

Discussion of ExpectationsSo What?

Protecting the confidentiality and integrity of patient medical information is no longer just a best practice for healthcare organizations, but a legal requirement. The framework model will help identify and analyze gaps in an existing security state compared to requirements for security best practices and legal requirements.

Furthermore, it designs and implements solutions to close those gaps, as well as ensure ongoing consistency and compliance.

Page 17: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

17

So What?

The ability to share information with patients is key.

Mobile applications provide another opportunity to reduce the separation between health care provider and patient.

As the baby boomers become senior citizens and increasingly need health care services, the mobile devices may be the answer to this challenge.

Maki, A. (2011, April 14). Medical Breakthrough: Health Care Providers Hope iPad Can Enhance Their Services. Memphis Daily News. Retrieved from http://www.memphisdailynews.com/editorial/Article.aspx?id=57807Davis, M. (2011, April 4). For some doctors, the iPad is claiming a key spot next to the stethoscope. Boston Globe. Retrieved from http://articles.boston.com/2011-04-04/business/29380774_1_ipad-tablet-computers-ulcer

 

Page 18: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

18

Who uses smartphones and/or tablets in your hospital for work-related communications?

Which of the following devices do personnel currently use to receive job-related alerts (pages, codes, other critical messages) at your facility?

Which devices do you expect to be used two years from now?

www.amcomsoftware.com

 

Survey

Page 19: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

19

Of the personnel who use smartphones or cell/feature phones for work-related communications, which types of devices are currently used? Which types of devices do you expect to be used two years from now?

www.amcomsoftware.com

 

Survey

Page 20: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

20

Survey

Of the personnel who use tablets within your organization, which types of devices are currently used? Which types of devices do you expect to be used two years from now?

www.amcomsoftware.com

 

Page 21: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

21

References:Mhealth: New Horizons for Health Through Mobile Technologies. World Health Organization. 2011HHS.gov website on mhealth. http://www.hhs.gov/open/initiatives/mhealth/http://www.pwc.com/us/en/health-industries/publications/the-new-gold-rush.jhtmlhttp://www.hhs.gov/ocr/privacy/ http://www.hhs.gov/ocr/privacy/hipaa/administrative/enforcementrule/hitechenforcementifr.htmlhttp://www.jacksoncoker.com/physician-career-resources/newsletters/monthlymain/des/Apps.aspxhttp://www.informationweek.us/news/security/mobile/231902875http://www.fiercemobilehealthcare.com/story/mobile-technology-implementation-now-top-mind-most-docs/2011-11-17http://blogs.healthcareinfosecurity.com/posts.php?postID=1116u, Y. C., Lee, J. J. K., Xiao, Y., Sears, A., Jacko, J. A., & Charters, K. (2003). Why Don’t Physicians Use Their Personal Digital Assistants? AMIA Annual Symposium Proceedings (Vol. 2003, p. 405). http://www.ncbi.nlm.nih.gov/pmc/articles/PMC1480095/?tool=pubmedBottles, K. (2011). Physician Executives Should Not Ignore How Smartphones Will Transform Healthcare. The Health Care Blog. Retrieved April 22, 2011, from http://thehealthcareblog.com/blog/2011/01/31/physician-executives-should-not-ignore-how-smartphones-will-transform-healthcare/Dolan, B. (2011, March 31). Survey: 27 % of US doctors have tablets. mobihealthnews. Retrieved April 21, 2011, from http://mobihealthnews.com/10627/survey-27-%-of-us-doctors-have-tablets/Lewis, N. (2010b, September 10). Mobile Devices To Transform Healthcare. InformationWeek: Healthcare. Retrieved April 21, 2011, from http://www.informationweek.com/news/healthcare/mobile-wireless/227400122Choudhri, A. F., & Radvany, M. G. (2010). Initial Experience with a Handheld Device Digital Imaging and Communications in Medicine Viewer: OsiriX Mobile on the iPhone. Journal of Digital Imaging, 24(2), 184-189. http://www.informationweek.com/news/healthcare/mobile-wireless/231903089http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.htmlMaki, A. (2011, April 14). Medical Breakthrough: Health Care Providers Hope iPad Can Enhance Their Services. Memphis Daily News. Retrieved from http://www.memphisdailynews.com/editorial/Article.aspx?id=57807www.amcomsoftware.comDavis, M. (2011, April 4). For some doctors, the iPad is claiming a key spot next to the stethoscope. Boston Globe. Retrieved from http://articles.boston.com/2011-04-04/business/29380774_1_ipad-tablet-computers-ulcer

 

Page 22: THE USE OF MOBILE DEVISES IN HEALTH CARE ENVIRONMENT; SECURITY BURDEN OR A BLESSING? A PROPOSE FRAME WORK FOR MOBILE DEVICES Team 4

Team 4-Mobile devices in Health care

22

Any Questions?

Team 4