voice over the internet protocol (voip) technologies… how to select a videoconferencing system for...

34
Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima, R., Moeini, S. & Firouzani, P. (2010).‘VOIP for telerehabilitation: A risk analysis for privacy, security, and HIPAA compliance’ . International Journal of Telerehabilitation: 3-14

Upload: kent-musgrave

Post on 14-Dec-2015

215 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Voice over the Internet Protocol (VoIP) Technologies…

How to Select a Videoconferencing System for Your Agency

Based on the Work ofWatzlaf, V.M., Fahima, R., Moeini, S. & Firouzani, P.

(2010).‘VOIP for telerehabilitation: A risk analysis for privacy, security, and HIPAA compliance’ . International

Journal of Telerehabilitation: 3-14

Page 2: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Selecting a Platform

Page 3: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Most VoIP technology systems provide a very reliable, high quality, and competent teleconferencing session with their

patients……… However, to determine if the VoIP

videoconferencing technologies are private, secure, and compliant with HIPAA, a risk

analysis should be performed.

Watzlaf, et al., 2010

Page 4: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Skype, VSee or Other Vendors

• Questions regarding 3 HIPAA requirements– Audit trails– Chat box information stored on company’s computers– VSee can track which accounts connect but does not

know the time or the content

• For a review of vendors visit:– http://www.telementalhealthcomparisons.com/You will have to provide your email address to review these comparisons

Page 5: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Let’s Take Specific Vendors OUT of the Discussion

Page 6: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

2 Choices

Page 7: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

1st CHOICE

Use the HIPAA compliance checklist (prepared by Watzlaf & colleagues) and

compare it to the VoIP technology software privacy and security policies

provided by the software vendor and ask if they are willing to enter into a BAA

(Business Associate Agreement)

Page 8: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

2nd CHOICE

Purchase HIPAA compliant software specific to VoIP with vendors that will walk

you through each piece of the HIPAA legislation to make certain the software is private and secure and be willing to enter

into a BAA (Business Associate Agreement)

Page 9: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

HIPAA Compliance Checklist for VoIPChecklist on NFAR website

Page 10: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Example of Items on Checklist• Personal Information- Will employees and other

users of VoIP software be able to listen in to video-therapy calls between patient and therapist?

• Retention of Personal Information- Are video conferencing sessions for therapy services recorded?

• Requests for Information from Legal Authorities etc.- Will personal information, communications content, and/or traffic data when requested by legal authorities be provided by the VoIP software company?

Page 11: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Every potential user (therapist or healthcare facility) should review the

privacy and security policies that are found on the VoIP software system’s website to determine if they answer the questions

listed in this checklist….If the question is not addressed in the

policy, then the user may want to contact the software company and ask them how

the company will address a particular question(s).

Page 12: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Next Steps……

Page 13: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

1. Form a team that will examine VoIP software systems to determine if it meets federal (HIPAA), state, local, and facility-

wide privacy and security regulations

Page 14: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

The team may consist of the provider attorney, risk

management personnel, health information administrator/

privacy officer, security officer (IT), clinical directors/

supervisors and counselors

Page 15: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

2. Designate someone on the team to stay on top of all the changes

videoconferencing software systems

(federal state and local)

Page 16: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

3. Educate all staff (not just counselors) on how to use software system for

videoconferencing

Page 17: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Training should include:

• Privacy and Security related to HIPAA• Issues Related to PHI (Private Health Information)

Exchange• Encryption • Spyware• Password Security• Use of Equipment by Counselor/Client• ATA Guidelines

Page 18: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

4. Develop Patient Informed Consent Form

• What therapy will be provided using the VoIP technology

• How the technology will be used• Benefits associated with videoconferencing • Risks associated with videoconferencing (privacy

and security)• Informed Consent Form reviewed by team attorney

Page 19: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

5. Incident response is necessary and should include….

• documentation regarding the incident• the response to the incident, any effects of the

incident as well as whether policies and procedures that were followed in response to the incident

• if policies and procedures are not in place for incident response, then these should be developed with the security and privacy officers

Page 20: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Suggested General Rules for VoIP

Kuhn, Walsh, & Fries, 2005National Institute of Standards and Technology

Page 21: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Do not use the username and password for anything else but videoconferencing, change it frequently and do not make it

easy to identify

Page 22: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Avoid having computer viruses on the computer used for video

conferencing

Page 23: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Never use it for emergency services

Page 24: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Consistently authenticate who you are communicating with

especially when used for tele-therapy video sessions

Page 25: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Focus on the transmission of data through video conferencing…..

How that data is made private and secure during the telecommunication….

How private and secure it is stored and released to internal and outside entities.

Page 26: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Provide audit controls for using software applications so that they are secure and private

Page 27: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

There are three types of

information security risks: Confidentiality, Integrity, and Availability

Page 28: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Confidentiality refers to the need to keep information secure and

private.

Page 29: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Integrity refers to information remaining unaltered by unauthorized

users.

Page 30: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Availability includes making information and services available for use

when necessary.

Page 31: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

VoIP Risks and Recommendationsrelated to

Confidentiality, Integrity, and AvailabilityList on NFAR Website

Page 32: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

Information Security Risk & Recommendation Example

Risk, Vulnerability or Threat

Specific Area Risk Level Recommendation

Confidentiality & Privacy

Retention of personal data & information as well as eavesdropping on conversations

High

(increases in VoIP because of the many nodes in a packet network)

Change default passwords

disable remote access to graphical user interface use authentication mechanisms

See VoIP Risks and Recommendations Checklist

Page 33: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

All credit for this presentation goes toDr. Watzlaf and colleagues for allowing the

use of their article as the basis for this presentation and allowing us to post the HIPAA Compliance Checklist and the Risk

and Recommendations List on our Website

Page 34: Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,

www.nfarattc.org