Showing posts with label mobile healthcare technology. Show all posts
Showing posts with label mobile healthcare technology. Show all posts

Wednesday, October 25, 2017

top 5 findings from 2017 Healthcare Data Breach Report


Beazley, a provider of data breach insurance and response services, has published a special report on healthcare data breaches covering the first nine months of 2017.

While hacking and malware attacks are common, by far the biggest cause of healthcare data breaches in 2017 was unintended disclosures. Hacking and malware accounted for 19% of breaches, while unintended disclosures accounted for 41% of incidents. The figures show healthcare organizations are still struggling to prevent human error from resulting in the exposure of health data.

As Beazley explains in its report, it is easier to control and mitigate internal breaches than it is to block cyberattacks by outsiders, yet many healthcare organizations are failing to address the problem effectively. “We urge organizations not to ignore this significant risk and to invest time and resources towards employee training.”

Beazley notes that the number of cases of employee snooping on records and other insider incidents is getting worse. This time last year, 12% of healthcare data breaches were insider incidents, but in 2017 the percentage has increased to 15%.

While it is not possible to eliminate the risk of healthcare employees improperly accessing patient records, it is straightforward to ensure that when incidents occur they are detected quickly. As the Protenus Breach Barometer reports clearly show, many healthcare employees have been discovered to have been improperly accessing patient health data for months or even years before the unauthorized access is detected. As Beazley points out in the report, the failure to detect insider incidents promptly and take action increases the risk of regulatory action.

Phishing and social engineering attacks also increased significantly in 2017. There has been a 9-fold increase in social engineering scams in 2017. Beazley reports that two types of social engineering attacks in particular have increased in 2017 – Fraudulent instruction incidents and W-2 Form phishing scams.

Fraudulent instruction incidents are a type of Business Email Compromise (BEC) scam where the attacker pretends to be a company executive and sends a request to make a bank transfer. W-2 Form phishing scams similarly involve the spoofing of a company email address. In this case a request is made to send the W-2 forms of all employees that have worked in the previous fiscal year. The information is then used to submit fraudulent tax returns. Healthcare organizations can reduce risk by teaching employees how to recognize these types of email scams.

Along with an increase in data breaches, there has also been an increase in HIPAA enforcement actions by the Department of Health and Human Services’ Office for Civil Rights (OCR). The report notes that there have been nine settlements announced so far in 2017 on top of 13 HIPAA settlements in 2016. In 2014 and 2015 there were 13 settlements.

There has also been a notable increase in settlement amounts. In 2014/2015, the average settlement amount was around $1,000,000. In 2016/2017, the average settlement was $1.8 million.

As Beazley explained in the report, experiencing a breach opens the door to OCR investigators. Part of the OCR breach investigation involves a review of basic HIPAA compliance. When noncompliance is discovered, financial penalties may be deemed appropriate.

Beazley explains there are two main reasons for the increase in settlements for noncompliance with HIPAA Rules: OCR’s growing frustration with covered entities that are still failing to comply with the HIPAA Privacy and Security Rules, and more available resources to devote to pursuing settlements.

Source

Thursday, September 14, 2017

how secure electronic messaging helps to communicate with patients


"Deliver better healthcare through effective use of secure mobile messaging"

Deliver better healthcare through effective use of secure mobile messaging

Secure electronic messaging can help patients be better informed about their healthcare and improve access to healthcare providers, but the authors of a new study say more education is needed to improve the quality and efficiency of secure communication.

Researchers analyzed 1,000 threads – defined as strings of related messages – from two Department of Veterans Affairs (VA) facilities. Patients initiated an overwhelming majority of threads (90.4%), while caregivers began 4.1% of threads on behalf of a patient. Primary care team members initiated 5.5% of threads.

Patients and clinicians also used secure electronic messaging for different purposes.

Patients most often initiated messages to ask for a medication renewal or refill (47.2%). Patients also used secure messaging for scheduling requests (17.6%), medication issues (12.9%) and health issues (12.7%).

The majority of clinician-initiated threads (32.7%) were sent to report test results, followed by medication issues (21.8%), scheduling issues (18.2%) and medication renewals (16.4%).

Although some providers have expressed concern that patients would use secure electronic messaging for urgent medical issues, the researchers found that only 0.7% of patient-initiated messages contained content deemed clinically urgent.

Overall, patients viewed the use of secure messaging as an alternative to unnecessary in-person visits. It was also convenient and enabled easy, round-the-clock access to clinicians. Secure messaging also enabled patients to discuss potentially embarrassing topics.

The authors of the study, which was published in the Journal of the American Medical Informatics Association, concluded that both patients and clinicians could benefit from further education and training on the uses of secure electronics messaging. Most current guidelines for secure messaging focus on the technical and administrative areas, and not the potential use cases.

Source

Monday, August 28, 2017

how do you get patients to actually use your patient portal secure messaging


Secure messaging over the patient portal increased in-office visits by six percent. 



Patient portals have long been championed as the new and innovative strategy for improving patient engagement and access to quality healthcare. Patients can communicate with their providers about health concerns using secure messaging and become activated in their own health.

However, new research indicates that there could be some adverse effects of patient portal secure messaging, primarily in driving up in-office patient visits.

“While there are a number of plausible arguments for the benefits of e-visits, it is also possible that the adoption of e-visits may increase the consumption of healthcare services since easier access to healthcare providers may generate additional reasons for an office visit without any attendant health benefit,” said the researchers, who hail from the Wharton School at the University of Pennsylvania and the Wisconsin School of Business at University of Wisconsin-Madison.

“Thus, the impact of e-visits on physician utilization and health outcomes is an empirical question, the answer to which is important for understanding whether and how to promote this technology.”

Frequent clinic visits can have a direct impact on clinician caseload and number of clinicians employed, the researchers argued. These factors also have an effect on patient access to healthcare, especially for patients who did not adopt the patient portal or who are new patients at the primary care clinic.

The researchers looked at secure messaging rates and office visit patterns for over 14,000 patients at a large primary care clinic system. The team also looked at how these clinic visits affected patient health and access to care for patients who did not have the clinic’s patient portal.

Overall, secure messaging resulted in six percent more in-office visits and seven percent more phone call visits, the researchers found. There was also a positive correlation between the number of office visits and health outcomes (measured using LDL cholesterol and hbA1c levels). When adjusting for external factors, that correlation became negligible.

Secure messaging removes a clinic “gatekeeper” from patient care access, the researchers pointed out. Patients who secure message with their providers about a concern do not have to go through front-office staff or nurses before accessing their clinician or scheduling an appointment, potentially resulting in an influx of visits, the researchers posited. 


"Deliver better healthcare through effective use of secure mobile messaging"

Deliver better healthcare through effective use of secure mobile messaging


The research team also found that visits arising from secure messaging are coming at the cost of patients who are portal non-adopters. Patients who do not have the patient portal have fewer telephone visits monthly, although there was no difference in the number of in-office visits for these patients.

Healthcare professionals should continue to encourage patient portal adoption and use with these patients. Physicians have a regulatory obligation to drive patient portal adoption and they want to ensure all of their patients can equally reap the benefits of the technology.

New patients who had not yet visited the practice also bore the brunt of increased office visits, the researchers said.

“Interestingly, we find that the additional visits appear to come at the sacrifice of new patients: after adopting e-visits, providers see 15 percent fewer new patients each month,” the team found. This means that physicians saw 1.59 fewer new patients each month.

Some clinics may be better suited for accommodating appointment influxes than others, the researchers said.

“The overall impact of e-visits on a health system will depend on the extent to which a system is (a) at capacity, and (b) compensated on a fee-for-service basis,” the team explained. “In particular, the bottom line will improve for health systems which are not at capacity and in which physician compensation is primarily on a fee-for-service basis since e-visits can increase physician utilization.”

However, these results may be bad news for providers working with a value-based or capitated reimbursement model. Clinicians are not reimbursed for the time they spend communicating with patients via the patient portal, nor are they paid a la cart for resultant in-office visits.

Additionally, these results challenge popular sentiment in the healthcare industry. Experts have long praised patient portals for being effective in streamlining patient-provider communication and potentially reducing the number of in-office visits providers must conduct. That may not be the case, the researchers concluded.

“We also show that provider e-visit adoption is linked to about a 15% reduction in the number of new patients each month, challenging notions that e-visits may increase provider capacity by offloading some care to an online channel,” the team said. “Together, our findings highlight the importance of considering patient and physician responses when introducing new models of service delivery in healthcare.”

Clinicians have long feared that patient portals would create more work for them. Responding to surveys about patient access to clinician notes and portal functionality, physicians expressed concern that patients could communicate in any given moment. Some even feared that patients would over-utilize the tools in an effort to receive “free” healthcare.

Going forward, providers will need to exercise good judgment when answering patient queries to determine the best path forward. It may not be wise for primary care clinics to allow in-office visits to become out of hand, but it is also important for providers to take secure messaging requests seriously.

Using both medical expertise and strong communication skills, providers should work to mitigate problems via secure message when possible and appropriately address larger problems as they escalate.

Source

Sunday, August 27, 2017

4 key concerns in healthcare mobile security options to permit hipaa compliance

Accounting for healthcare mobile security within the IT budget and maintaining HIPAA compliance are essential considerations in the current environment. 



It can be daunting to choose the right mobile tools to help a healthcare organization stay innovative. It can be even more daunting though to ensure that mobile security remains a top priority and that PHI stays secure.

Healthcare IT leaders might see the value in implementing mobile options, but studies show that security is often a top concern.

How can entities properly budget for mobile options? What are the potential consequences if a HIPAA violation occurs? Why is employee training so critical for strong mobile security?

Four key considerations with mobile security. Organizations of all sizes must budget for cybersecurity, choose the right mobile tools, conduct regular employee training, and maintain HIPAA compliance with all devices.

"HIPAA compliant HL7 Messaging"

Enable secure text messaging from any healthcare interface


Choosing the right mobile healthcare tool


Different mobile solutions will be beneficial at different healthcare organizations. Secure messaging might be necessary for larger hospital systems with specialty clinicians who need to communicate with patients. Smaller providers might not require the same mobile strategies.

Regardless, mobile security must be a key consideration throughout the entire decision-making process.

Direct secure messaging is becoming more popular, for example. DirectTrust is a non-profit trade alliance that facilitates secure HIE through the Direct Protocol. July 2017 numbers showed a 15 percent increase in the number of trusted Direct addresses able to share PHI.

There was also a reported 68 percent increase in the number of healthcare organizations served by DirectTrust health information service providers (HISPs) and engaged in Direct exchange.

The American Hospital Association’s Hospital & Health Networks (H&HN) Most Wired rankings showed that nearly three-quarters of the Most Wired hospitals offer secure messaging with clinicians on mobile devices.

Seventy-four percent said they use secure emails for patients and families to maintain contact with the care team when patients require ongoing monitoring at home. Sixty-two percent of respondents also said they can simplify the prescription renewal process by letting patients make the requests on mobile devices.

“The Most Wired hospitals are using every available technology option to create more ways to reach their patients in order to provide access to care,” AHA President and CEO Rick Pollack said in a statement. “They are transforming care delivery, investing in new delivery models in order to improve quality, provide access and control costs.”

Pagers are however still a popular tool for many healthcare organizations, according to a study published in the Journal of Hospital Medicine. Nearly 79 percent of respondents said they are provided pagers for communications, while 49 percent said they receive patient care–related (PCR) communication through pagers.

Fifty-three percent of 567 clinicians also said they received standard text messages once or more per day.

For secure messaging, 26 percent of 549 of those surveyed said that their organization had implemented a secure messaging option that was being utilized by some clinicians.

Overall, healthcare providers need to opt for mobile options that will aid staff members in daily operations without compromising data security.

Budgeting for necessary mobile security tools


Cybersecurity budget and resource constraints are often cited by providers as hindrances to data security. Healthcare organizations cannot expect to properly keep data secure if they do not have the necessary funds to purchase, implement, and utilize the right security tools.

With mobile security, this could include budgeting for mobile device management (MDM) solutions if BYOD is being used in a hospital. Or, a provider might need to ensure that it can afford to hire a CISO to help lead the security team.

A recent Spok survey that was administered by CHIME found that 56 percent of healthcare CIOs say that budget and resource constraints are the largest threat to patient data security. Ninety-five percent of respondents also said they were concerned about data becoming compromised, while approximately one-quarter stated they are unsure how much PHI is being shared unsecurely.

“Mobility and clinical process improvements are important to hospital leaders, and CIOs plan to make impactful changes,” the survey authors explained. “However, the execution remains a work in progress.”

Sixty-nine percent of those surveyed said mobile strategies were a key initiative to improving clinical and operational outcomes. The survey also found that 40 percent of CIOs are considering or planning to hire consultants in the next 12 months to aid in the mobile communications process.

However, a ZingBox survey from July 2017 revealed that some healthcare IT decision makers find traditional security solutions used for securing laptops and servers were also enough for IoT connected medical device security. This could indicate inconsistent approaches when it comes to choosing which investments are necessary for healthcare security.

Seventy percent of respondents said their traditional security solutions were enough, while nearly 75 percent added that they are confident or very confident that all devices connected to their network are protected.

Organizations need to have communication between the C-suite and IT teams, ensuring that everyone understands the areas in which stronger data security measures are required. Mobile security solutions can differ from traditional legacy options, and applicable privacy and security tools need to be budgeted for and implemented properly.

Implementing regular employee training



Once a mobile option has been chosen and then budgeted for, employees at all levels must be trained and educated on how to use it. Employees are often cited as a top security threat to an organization, as it only takes one individual to download a malicious link, have a smartphone stolen, or send PHI to the wrong email.
OCR’s July Cybersecurity Newsletter underlined the importance of data security training, especially as the threat landscape continues to evolve.

Understanding HIPAA compliance for mobile options


The HIPAA Security Rule does not require specific technology solutions when it comes to mobile device technical safeguards. HHS does require that entities implement reasonable and appropriate security measures for standard operating procedures.

For mobile security, this means for example that a hospital utilizing smart phones will need to implement applicable security measures for those devices. This could include having remote wipe capability. That way if a phone is lost or stolen, the hospital can delete any potentially sensitive information on the device before it can fall into the wrong hands.

“HHS recognizes that covered entities range from the smallest provider to the largest, multi-state health plan,” HHS explains on its site. “Therefore the Security Rule is flexible and scalable to allow covered entities to analyze their own needs and implement solutions appropriate for their specific environments. What is appropriate for a particular covered entity will depend on the nature of the covered entity’s business, as well as the covered entity’s size and resources.”

Failing to adhere to HIPAA regulations with mobile devices could lead to heavy fines. OCR reached a $2.5 million settlement with Pennsylvania-based CardioNet in April 2017 for lacking mobile security safeguards.

“Mobile devices in the health care sector remain particularly vulnerable to theft and loss,” OCR Director Roger Severino said in a statement. “Failure to implement mobile device security by Covered Entities and Business Associates puts individuals’ sensitive health information at risk. This disregard for security can result in a serious breach, which affects each individual whose information is left unprotected.”

Mobile devices can assist healthcare organizations, but security cannot be an afterthought. Choosing the right tools, training employees, and focusing on HIPAA compliance will help covered entities find the right balance between innovation and security.

Source

Thursday, August 24, 2017

how diabetes can be effectively managed in most patients thorugh online text messaging




"Deliver better healthcare through effective use of secure mobile messaging"

Deliver better healthcare through effective use of secure mobile messaging



A US study reports people can improve their diabetes management following secure online messaging with their healthcare team.

A cohort of people with type 2 diabetes who had enrolled in an online portal of an outpatient healthcare organisation from 2011-14 were evaluated. This communication was an accompaniment to routine visits to healthcare providers.

Scientists from the Palo Alto Medical Foundation Research Institute in California wanted to see if messaging increased quality measures among the cohort. Around 72 per cent of the cohort used the messaging service, and those who frequently visited their health provider were more likely to message.

Those who used the messaging service were more likely to meet their HbA1c targets. This association grew in accordance with frequency of messaging, and regardless of whether the messages were initiated by doctors or patients. This relationship was strongest amongst those not treated with insulin.

In comparison, those who didn't use the messaging service were less likely to meet their HbA1c target.

The researchers also discovered that increased messaging frequency was also positively associated, but less significantly, with process measures such as eye examination.

"Internet-based secure messaging between patients and providers through a patient portal is now common in the practice of modern medicine".

"Patients with diabetes frequently used secure messaging for medical advice in addition to routine visits to care providers. Messaging was positively associated with better diabetes management in a large community outpatient practice."

Source

Thursday, August 3, 2017

how the health industry is using SMS to improve patient care



The growth of text messaging (SMS) has matured over the last several years, and the potential for businesses across all industries to incorporate texting into business operations and customer communication is vast. Companies in the restaurant delivery, banking, transportation, and ride-sharing industries have been successful in using SMS as a communication channel because it provides their employees and customers with an efficient, private and convenient way to interact.

Text messaging has also emerged as a popular and effective way for many organizations to improve customer experience. According to a national survey, alongside email and phone calls, SMS ranks in the top three communication methods consumers prefer when interacting with businesses. In fact, over half of survey respondents indicated they would view a business more positively if it offered SMS capabilities.

"Deliver better healthcare through effective use of secure mobile messaging"

Deliver better healthcare through effective use of secure mobile messaging


The healthcare industry in particular is outpacing others in its use of SMS. Physician's offices are leveraging texting as a strategic tool to improve the patient experience and their own internal processes. Common use cases for SMS include notifications around appointment reminders, prescription refills and test results, as well as managing wait times.

Independent and hospital-owned practices that employ SMS for the processes listed above, can realize a number of benefits pertaining to internal and external procedures.
 

The following are three examples of how healthcare providers are using SMS as a communication channel to their benefit:


 
Optimized appointment schedules.The ability to manage appointment schedules by sending reminders, cancellations, and reschedule-requests via text is not only convenient for patients, it also has direct implications on the physician office's bottom line.

For example, if the office has a waitlist and the ability to text patients when there is an appointment opening - especially a last minute opening - they are able to fill the appointment slot and utilize the staff present where there would have been a no-show appointment (a major expense costing the U.S. healthcare system more than $150 billion each year).

Being able to mitigate no-shows via text alerts is a definitive way to optimize the appointment schedule and minimize operational costs such as overstaffing, improper booking of machinery/lab equipment, etc. A more organized schedule with accurate wait times results in a more relaxed environment and happier patients.

Increased flexibility for customers. SMS also gives patients the freedom to communicate with their healthcare providers in a way that is intuitive and easy for them. By giving patients the choice of how to interact with their healthcare providers, SMS has the potential to enhance the patient-provider relationship and strengthen patient loyalty, increasing the likelihood that the patient will reach out for preventative care, as well as ongoing treatment for chronic issues. In addition, offering the flexibility to communicate via text reduces much of the hassle associated with listening to voicemails or making phone calls about test results at an inconvenient time or place.

Improved treatment and patient care. Physicians' offices have also begun to use SMS in innovative ways such as reminding patients to take their medication, checking insulin levels, and sending motivational text messages that encourage positive behaviors (i.e. eating healthy and increasing activity) and reduce negative behaviors (i.e. smoking). These alerts demonstrate a level of care and involvement from the healthcare provider, while also improving the patients' health and quality of treatment.

In fact, a recent study from the American Heart Association hypothesized that using automated mobile health notifications with tracking and texting components may increase physical activity. The results showed that patients who received these motivational and informative text messages walked an additional 2,500 steps each day, compared to individuals who did not receive the messages. This strategy, although not yet widespread, has great potential to become a common and successful practice among healthcare providers due to the huge popularity of wearable activity trackers on the market today.

Together, these strategies have the potential to make a significant difference in enhancing the patient experience with a provider, as well as their engagement with a treatment plan. Healthcare providers looking to incorporate SMS as a communication channel not only have the potential to further benefit a patient's well-being, but also establish themselves as a trusted partner with a deep level of emotional investment in their patients long-term health plan.

Source

Wednesday, August 2, 2017

how digitization is transforming care in patient engagement programs


"Deliver better healthcare through effective use of secure mobile messaging"

Deliver better healthcare through effective use of secure mobile messaging


American healthcare is one of the last industry holdouts when it comes to fully embracing digitization. McKinsey Global Institute has ranked healthcare 19th out of 22 sectors in its oft-cited Industry Digitization Index.

Even as health systems implement digital health tools and practices, many of these technologies remain separate, leading to a disconnected patient experience.

But there is hope for the digitization of healthcare. Many digital health tools are designed to automatically link information from different digital sources, creating efficiencies that result in a better experience for patients and better workflows for staff.

Consider the typical digital hospital-patient relationship: One hospital department asks a patient to log into a portal to check lab results. Another uses an app for appointment reminders, and yet another sends digital health information to help manage patients’ care.

This disparate sea of digital tools can be overwhelming and burdensome for both patients and providers, causing confusion and poor use of the resources the hospital provides.

Here are some ways you can improve care coordination by taking advantage of digitization without a lot of extra work on your part.

Connect your digital systems

Different digital health tools have different purposes, and hospitals need multiple tools to accomplish their goals of improving health outcomes. But from the patient’s perspective, it’s all one connected topic: their health.

Through links, application programming interfaces (APIs) and other simple solutions, you can connect your digital tools to make it easy for patients to navigate between these resources to create a seamless patient experience.

Add a “push strategy” to your patient engagement

Many health IT systems deal with protected health information (PHI) that must be locked behind passwords—information such as treatment plans, lab results and appointment history. Those systems use a “pull strategy,” one that depends on patients choosing to visit a website and logging in.

A push strategy, on the other hand, proactively sends information directly to patients. These messages contain population-based information and do not discuss an individual’s specific health details. With push strategies, the information is put right in front of patients—on mobile devices, for example. There is no need to remember website URLs or passwords, and this increases access and use.

You can take your digitization to the next level by combining push and pull strategies. In other words, use your push messages to educate and engage patients, while also prompting them to visit the sites that contain their password-protected personal health information.

Use the data available to you

Being digital, these tools inherently collect data that may provide insights into how your patients are doing, who is more at risk and who needs additional attention. This data may come from survey responses, secure messages, patient-reported feedback and other statistics and information.

The data enables significant improvements in care quality and customer service that, in turn, can improve patient satisfaction, drive meaningful patient relationships and discourage patients from searching online for potentially inaccurate health information.

Use your data to gain a better understanding of your patient population and to make your patient navigators’ work more efficient.

Act on that data by providing further resources to patients who need it, thereby encouraging them to become better partners in their care. Patient activation is proven to impact outcomes and cost of care.

Digitization is where healthcare is heading, even if at a slower pace than other industries. Going digital creates efficiencies for your team and your patients, and it ensures that you’re providing the right care resources in the most efficient way.

Source

Thursday, July 13, 2017

making healthcare marketing hipaa compliant



Searching for health-related information on the Internet is perhaps one of the most popular activities today. Statistics reported by Pew research data indicates that about 72% of internet users have been found looking for healthcare information online. And in an attempt to keep pace with the changing trends, marketers are inclining more towards digital marketing tactics, making it necessary for their digital campaigns to be crafted in adherence to Health Insurance Portability and Accountability Act (HIPAA) regulations.

If marketers are not HIPAA-ready yet or are not knowledgable about compliance measures, then it’s high time that they check out these valuable tips to stay on a safer side.




"HIPAA compliant HL7 Messaging"

HIPAA compliant HL7 Messaging


Sharing Patient Information is a Big No


With the digital intervention, the health care industry has become vulnerable to data breaches, leaks, and unwanted disclosures leading to misuse of patient data and other medical information. In the light of such an alarming situation, HIPAA rules and regulations came into force for protecting patient confidentiality and satisfying the Privacy Rule from getting into wrong hands via digital channels and marketing campaigns. And so to be HIPAA compliant, marketers need to avoid the use of protected health information (PHI) for marketing purpose in a way that can reveal patient’s identity online.

The best way to deal with the ordeal is to either seek for written authorization for the use of data from the patient itself or segment such information by eliminating identifiers such as names, administrative details, geographic and biometric identifiers, etc.

Don’t Use Real Life Patients Images


Being too desperate to win the digital war can land healthcare organizations into trouble. Making their digital presence HIPAA compliant is mandatory on a marketer’s part to avoid being heavily fined. While trying to decorate the healthcare marketing brochure, the landing pages of the website or their brand’s social media profile, marketers should hire actors or use stock photos to portray patients receiving care or being diagnosed rather than referring to real-life patient photos. Being Ignorant of Minute Details May be Dangerous

Using treatment success stories as examples for marketing purposes is fine only if it does not violate HIPAA rules and places patient data at risk. While narrating the case study or client testimonial as part of marketing, marketers should be careful of what information they are sharing. Even sharing of patient case history and other details via direct messages are considered to be a violation of HIPAA.

Train Your Marketing Team with HIPAA Regulations


What equally matters in the field is how knowledgeable and well informed the marketing team of a medical organization is about HIPAA rules, regulations and punishment details. The people who are the behind the development of any healthcare email marketing campaign, social media blogs, and content marketing campaigns must be competent enough to pass the compliance challenge for their brand. Also, if the marketing campaign involves third-party vendors, then marketers must ensure that they are HIPAA certified to avoid violation of rules.

On a Healthy Note

Though HIPAA has restricted the marketing efforts of the healthcare industry up to certain limits, still it’s not impossible to develop and deliver effective marketing messages to a targeted audience while being compliant. For example, healthcare organizations can market content on general topics such as healthcare tips, educational documents excluding patient-specific data and much more to make sure that their marketing strategies don’t pose security threats to the electronically stored medical information.

Remember, penalties for noncompliance may incur heavy losses for your healthcare business which may range from a potential fine of $100 to $50,000 per violation depending on the level of negligence.

Source

Tuesday, July 11, 2017

how digital health technologies help long-term health issues


"Deliver better healthcare through effective use of secure mobile messaging"

Deliver better healthcare through effective use of secure mobile messaging


Digital technologies have had a game-changing impact on most aspects of our day-to-day lives. But one area that hasn’t yet felt the full benefit of digital is healthcare, in particular preventative health. The main reason being that technology can only get you so far, it then takes a more ‘human effort’ to encourage people to ultimately change their behaviour. To use the old adage: you can bring a horse to water, but you can’t make it drink.

As we’ve developed as a society, our perspective on healthcare is that it is something we should all be freely provided with. This is the problem with healthcare as it is today: with treatment so readily available and accessible, people have gained a sense of entitlement to care from professionals, rather than taking responsibility for their own health and preventing issues before they require treatment, ultimately placing unnecessary pressure on health services.

This is clearly unsustainable. It is therefore becoming our responsibility as individuals to be more accountable for our own health in order to truly facilitate a sustainable future for healthcare. The obvious place to start is finding preventative approaches to health - in other words, the ‘health’ side of ‘health(care)’.

Helpfully, today we have a new generation of digital health technologies that not only offer consumer friendly features, but more importantly, have been designed with a deep understanding of the human condition, to make it easy for people to adopt healthy behaviours - empowering anybody with a smartphone to manage their own health, without the need to visit a healthcare professional.

There are now a huge number of health monitoring apps and platforms available to individuals, enabling them to improve their health through analysis of data from their daily activities and lifestyle habits. Historically, we have relied on healthcare with the approach of treating issues but, with access to insights on our health now available, this approach is outdated. For many, simply knowing you need to sleep more or consume less alcohol isn’t enough to make a positive change but, as health tech is adopted, it seems having a platform which directly informs you of issues, with evidence gathered from monitoring of your everyday activity, is.

Many long-term health issues stem from everyday lifestyle behaviours which can be prevented should individuals be aware of the causes and immediate action they can take. As technology advances and more individuals adopt a preventative and self-managed approach to their health, we will be able to significantly reduce the prevalence of preventative diseases such as type 2 diabetes and alleviate pressure on health services worldwide.

By implementing technology which encourages self health management, healthcare providers can help prevent diseases by supplying suitable products to vulnerable individuals and providing tailored care plans based on personal data.

At present, the health tech space is nurturing a growing number of individuals to adopt the use of wearables and using niche health apps targeted to monitor one specific area of their lifestyle. However, evidence shows many people discontinue use of devices such as smartwatches or fitness trackers because they don’t find them useful or are unable to draw conclusions from the data they gather. The next step in health tech is not just gathering data, it’s making sense of it and providing recommendations from self improvement.

There are now platforms available which bring together all health and lifestyle data tracked from the multiple devices people use and combine results to provide recommendations for prevention or pre-treatment of issues. This is the future of healthcare and where we will begin to see real change, but the key behind this is to engage people with their own health and empowering them to take control and become self-accountable, rather than rely on health care systems, something we have been guilty of for far too long.

Source

Thursday, June 29, 2017

strategy of communication between a healthcare businesses and a patient groups


"Deliver better healthcare through effective use of secure mobile messaging"

Deliver better healthcare through effective use of secure mobile messaging


As promotional specialists, healthcare marketers are tasked with the mission of conveying the value of specific treatments and products to the public while also influencing patients to see a compelling need to use them. Understanding this communication between a healthcare businesses and a patient group is an essential element in developing a successful marketing strategy.

To build this strategy, marketers identify a patient group, understand their needs and interests, and then decide which channels will be most effective to reach those patients and how to leverage each channel. Potential channels of communication include professional referrals, internal marketing, external marketing, branding, Internet marketing, and public relations.

While understanding how to leverage these channels is an essential piece of success, creating the right message that resonates with the target patient audience will have a profound impact on elevating the success of marketing efforts. For this reason, it is vital that marketers specifically tailor the details of each message using predictions of patient behavior. By doing so, marketers ensure that a product or treatment is framed under the proper context and increase the probability that a patient will see their call to action as a successful course of treatment.

So is this really how medical marketers should elevate their messaging? Here are three reasons why utilizing patient behavior predictions can healthcare marketers develop authentic break-through messaging that effectively communicates to their patients the benefits of a product.

1) Understanding patient behavior is extra insurance for developing an empathetic tone within messaging

By taking time to understanding the pains, worries, fears, and expectations of patients, marketers gain valuable insights into the psychographics of their target group. Asking questions to understand what perceptions and biases the clientele already hold will also give key insights into the decision-making process that a strategy attempts to leverage.

As they gather this information, marketers create an empathetic foundation upon which messaging can be developed. By seeking first to understand the thoughts and feelings of the patients, marketers also create an early detection system that will quickly weed out any message that could be interpreted as insensitive, purely profit-driven or callous.

2) Use patient predictive behavior to expand a patient’s perspective

While marketers should definitely use messaging to demonstrate to patients that they understand the patient’s situation, they miss out on a key opportunity if the messaging does not extend beyond basic empathy. After a patient’s situation has been treated with the appropriate sensitivity, messaging should move to strengthen the confidence a patient has in the entire treatment process, providing information that surpasses the individual’s limited perspective.

In this sense, marketers can convey valuable medical information in common language that will help the patient understand all of the care and effort being take towards their treatment. For example, by explaining the training that a medical staff goes through, such as diagraming the testing process that occurs with each new drug, marketers help patients understand the bigger picture of health intervention.

3) By creating a journey map for each specific patient, marketers understand the big picture of each patient’s illness

One specific tactic of predicting patient behavior is to map out the patient’s entire medical journey. By beginning with the initial steps of symptom detection, awareness and diagnosis, and eventually reaching successful treatment and health restoration, marketers identify the specific scenarios a patient will pass through and gain a better understanding of what the patient has already experienced in addition to future challenges.

Taking a deeper look at these scenarios will also help marketers to evaluate and determine which points of the journey are most difficult for the patient and where key decisions are made. Without a journey mapping technique, marketers run the risk of promoting a product too late in the patient’s treatment cycle or too soon. Finding the right timing can strengthen the marketing pitch by positioning the message as organically as possible within the course of treatment. With big data becoming a bigger player across the medical industry, developing data-driven journey maps can help marketers produce sharper insights like never before.

With these clear benefits and many others, understanding and predicting patient behavior helps marketers develop accurate, effective messaging that clearly communicates the value and purpose of a product.


Source

Monday, June 19, 2017

Importance of 2-way text communication between physicians and patients





There are no government regulations specific to text communication between patient and provider. As such, the same general rules for privacy and security that apply for any other phone texting exchange hold for texting about a patient or directly with a patient. To address the implications of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the privacy rule restricts who has access to protected health information (PHI), while the security rules loosely define parameters for preventing breach of PHI.

In any communication between patient and provider, both parties should presumably have access to any PHI—satisfying the privacy rule. However, an important consideration is ensuring that the 2-way communication by text message is actually between the intended parties. In other words, be certain that your messages are reaching only the desired recipient.

"HIPAA compliant HL7 Messaging"

HIPAA compliant HL7 Messaging



Establish PHI Privacy Safeguard


In general, it is advisable to ensure that privacy is maintained by confirming the patient’s identity and desire to communicate by text message prior to engaging in an initial text communication. You might have your first message exchange with the patient in clinic, for example. At that time, you can ask if others have access to the patient’s mobile device and gain assurance that the patient is comfortable with the level of security afforded by text messaging.

If communication is ever initiated by an unknown contact, you should not share PHI until you have confirmed the identity of the person face to face or by phone call to be certain that the unknown contact is, in fact, the patient or someone the patient has indicated may communicate directly with you and that patient wishes to communicate by text message.

Under these circumstances, it is of utmost importance that the patient has an expressed desire to use phone texting to communicate about ongoing medical care, and is comfortable receiving and sending texts rather than more traditional forms of communication. However, this does not necessarily mean that security standards under HIPAA will have been met.

Employ Safe Harbor De-identification


As defined by HIPAA, covered entities (ie, providers, institutions, etc) are expected to use “appropriate administrative, physical and technical safeguards” to ensure privacy of PHI.1 This description is vague and implies technological neutrality. In other words, HIPAA does not require, and the US Department of Health and Human Services does not endorse, any specific technology or security standards for the protection of PHI.

Therefore, providers may use any level of encryption, along with other technological (eg, operating system passwords) and physical (eg, screen shields) methods to enhance protection against an information breach.2 While the vague description may seem cumbersome, there is an easier method to maintain HIPAA security rule compliance: de-identification.

If you remove all personal identifiers (Table) from the information you are transmitting, than you are providing sufficient and appropriate privacy and security measures under the Safe Harbor method.4 Under HIPAA, the Safe Harbor rule lists 18 personal identification markers that should be eliminated from any communication to prohibit the possibility of a person’s identity being linked to original data.4 When information contains no specific identifying information (ie, de-identified), it is no longer “protected” health information under HIPAA. De-identification of any transmitted information is surely the safest, least expensive, and most effective means for maintaining compliance, particularly if a patient has initiated the communication and identified text messaging as a preferred means of communication.

Take All Necessary Safety Precautions


Since patients may not be aware of HIPAA rules, it is reasonable for you to inform your patients of potential concerns (eg, that you are not using advanced security features in the communication) when they initiate or transmit their own PHI. However, you are responsible for the information that you transmit or disclose. In effect, any PHI on your device is your responsibility, and therefore, you should optimize features and practices such as operating system passwords, remote phone deactivation, deleting of old messages from the device (and storage/backup systems), and disabling message previewing.

For the most part, text messaging should be considered safe and effective. There are many ways that texting can improve communication between physicians and providers, and improve patients’ access to healthcare at little or no cost to them. In general, providers can maintain Security Rule compliance by avoiding the use of PHI in messages. However, this should not preclude much of the dialogue that is “text appropriate.”

A message like “are you feeling any better?” has minimal risk to patient or provider. Conversely, it is quite obvious that you should not be transmitting messages like “Your viral count is down.” Clearly, if benign communication becomes sensitive or worrisome during a text exchange, then this should prompt a switch to a telephone call or, if necessary, schedule an office visit.

Ultimately, all levels of security can be breached—consider that both the US Department of Defense and Central Intelligence Agency have been hacked within the last 2 years. If hackers want to break into a secure messaging system, they will. Therefore, clinicians would be best served to remove all identifiers from all messages, all the time, and limit use of text messaging for routine, benign communication with patients.

Source

Thursday, June 15, 2017

what the latest update on hipaa privacy rules mean for healthcare providers



The Department of Health and Human Services’ Office for Civil Rights has updated its HIPAA Privacy Rule guidance for healthcare professionals to help clear up confusion about allowable disclosures of protected health information to spouses, relatives, and patients’ loved ones.

The majority of healthcare professionals are aware that the HIPAA Privacy Rule permits them to share the protected health information of a patient with a relative or loved one. However, the 2016 Orlando nightclub shooting incident revealed that many healthcare professionals are unsure about how the HIPAA Privacy Rule


"SEAMLESS INTEGRATION OF HEALTHCARE MESSAGING"

HIPAA compliant HL7 Messaging



OCR has confirmed that the Privacy Rule permits a covered entity to “share [PHI] with an individual’s family member, other relative, close personal friend, or any other person identified by the individual, the information directly relevant to the involvement of that person in the patient’s care or payment for health care.” OCR has also confirmed that covered entities are allowed to disclose relevant information “to notify, or assist in the notification of (including by helping to identify or locate), such a person of the patient’s location, general condition, or death.”

The recipient can be a “patient’s family member, relative, guardian, caregiver, friend, spouse, or partner,” but also any other individual that is a nominated personal representative of the patient. A personal representative of a patient must, as far as the Privacy Rule is concerned, be treated as the individual for purposes such as exercising the patient’s Privacy Rule rights, including providing access to their health information. There are limited exceptions, which are detailed in 45 CFR 164.502(g).

OCR has confirmed that covered entities are permitted to share a patient’s PHI with same-sex partners, and explains that the list of potential recipients of PHI is in no way affected by an individual patient’s sex or gender identity, and neither by the sex or gender of the potential recipient.

OCR also sought to confirm who can be classed as a personal representative of the patient, saying “the Privacy Rule generally looks to state laws governing which persons have authority to act on behalf of an individual in making decisions related to health care.”

For example, if a state grants legally married spouses health care decision making authority for each other, a covered entity would be in violation of the Privacy Rule if access to the patient’s information was not granted if requested by a spouse, regardless of the sex of that individual.

While the covered entity should seek permission from the patient concerned prior to sharing information, in cases when the patient is incapacitated or not available, covered entities should use their professional judgement if the sharing of information is in the patient’s best interest. Should a patient be deceased, information can be shared with a person who has been involved in the patient’s care or who has made payment for medical services prior to the patient’s death.

Source

Monday, June 12, 2017

encryption techniques for patient records in the healthcare industry



The days of using primarily paper patient files are on the decline. Electronic patient record use is now widespread. While the electronic medical records make it easy to store, update and enter information, unauthorized individuals may also make use of the records. Consider these encryption techniques used in the health care industry for patient data.

Hashing Encryption

Hashing encryption is a common way of encrypting data that is included in a data set. Health care involves the collection of a lot of information, so this is an ideal method for keeping patient data secure. In the hashing method of encryption, a unique signature of a fixed length is attached to the data. The hashes are created with an algorithm or a hash function that is encoded into the software. This method of encryption is highly resistant to attempts at unauthorized access.

Learn More about Medical Data

In this day and age, the protection of sensitive patient data is paramount. Earning a degree in nursing informatics will prepare you for the data-intensive aspects of the medical and healthcare industries. Nurses must be able to accurately record patient data, such as vital signs, doses and timing of administration of medication and patient complaints. This type of a degree will allow you to combine your nursing skills with the accurate entry and analysis of patient data.

Symmetric Encryption

The use of symmetric encryption for patient data requires the implementation of a private key. The sender uses the encryption key to transmit a secured message. This can be useful if one physician needs to transmit information about a patient to another physician. It is helpful for sharing lab results among members of a care network or team. The receiver must have the encryption key in order to decode the message.

Asymmetric Encryption

In asymmetric encryption techniques for patient data, programmers or transmitters set up a public key to encrypt the information. A private key is required in order to decode the data. This avoids the problem of having to share the private key between the sender and receiver. Each user or receiver of the data has his or her own private key. Each access attempt can be tracked by key usage.

The Healthcare Information Privacy and Accountability Act (HIPAA) requires that patient data be protected. Encryption techniques are one of the leading defenses against preventing unauthorized access of a person's confidential information. Hacking methods change frequently, and so should your encryption. Earning a degree in nursing informatics will help to keep you up-to-date on these techniques.

Source

Monday, June 5, 2017

how messaging can help physicians decrease workload and improve performance


In the last few years, health care industry developments have increased record-keeping responsibility on physicians, making their job more difficult. A national survey commissioned by The Physicians Foundation revealed that 80 percent of physicians say they are overextended and spend 21 percent of their time on non-clinical paperwork.

The adoption of “meaningful use” of electronic health records (EHRs) has led to a expansion of new responsibilities for doctors. Many have found it challenging to provide their usual high standard of patient care while simultaneously managing new methods to track and record patient health information.

In order to help doctors ease the burden of tedious administrative work and improve performance, let’s look at ways hospitals and health systems can take the load off clinicians and give them added time and freedom to do more of what they love, caring for patients.

1. Optimize EHRs

Frustration with EHRs is a leading cause of doctor dissatisfaction as 60 percent of respondents to The Physicians Foundation survey said EHRs detract from patient interaction. The move to digital records was meant to optimize the medical information collection process, but the technology and how doctors work sometimes do not match up.

Often, doctors are forced to pay attention to their computer screen instead of being solely focused on patients. Also, the programs are not always user friendly and slow down clinicians who are expected to enter all their interactions in excruciating detail. Doctors simply don’t have enough time to spar with computers before a new patient needs to be seen, starting the cycle again.

The main purpose of EHRs was capturing reimbursement, and the doctors’ preferences and tendencies were not factored in during development. Counterintuitive technology is a barrier to treating patients, and to break this barrier, doctors need new tools that work more seamlessly with their processes.

Integrating mobility tools and computer-assisted physician documentation into doctors’ workstations and processes will ease physician frustrations. They will also allow clinicians to spend more time interacting with their patients and less time fighting with their mouse and keyboard.

2. Integrate Artificial Intelligence

Healthcare applications derived from artificial intelligence (AI) are expected to solve macro-scale problems. Many healthcare professionals and researchers look forward to utilizing the value generated from incorporating AI to assist with massive volume of population health, outcome analysis and clinical trial data.

AI doesn’t always solve problems from a 30,000 foot view, though, and some AI-driven technologies are being applied in individual doctors’ offices to help physicians improve care. Near-perfect speech recognition technology is the product of advances in AI. Integrating speech technology with EHRs relieves the burden of manually entering information. A recent EHR survey conducted by HIMSS Analytics, and commissioned by Nuance, found 67.5 percent of respondents’ organizations were adopting new technology and tools to improve clinician satisfaction with EHRs. It also found 24.7 percent of respondents’ organizations were planning to add speech recognition at point-of-care in the coming year.

The capabilities of AI are only starting to be realized, and in the future AI will deliver facts and evidence to doctors in real time. For now it plays a valuable role in helping doctors dictate their sessions, easily and instantly capturing all relevant information.

3. Improve Digital Security

Clinical info tech systems are expanding rapidly as healthcare organizations move deeper into the digital realm. Securing these applications is essential as patient data becomes increasingly vulnerable to threats that info tech departments have not previously experienced.

The nature of patient data poses document security issues unique to healthcare, which are made more difficult by the wide range of users accessing that information and the critical impact of federal privacy regulations.

Investing resources in document technologies, like print management and document capture software, add another layer of security to clinical info tech systems. They provide a secure method for tracking and printing documentation at the point of care. These technologies give doctors peace of mind by reducing the risk of healthcare information compliance breaches while also protecting documents from being accessed by those not authorized to view the information.

Incorporating technologies to optimize EHRs and tighten digital security, while also proactively integrating advancements like artificial intelligence into hospitals and health systems will allow physicians to feel what it’s like to have technology work with them for a change.

Source

Thursday, June 1, 2017

4 key factors of encrypted text healthcare messaging


http://www.vectramind.com/hipaa-compliant-messaging.html

Enable secure text messaging from any healthcare interface


Ask any teenager why they prefer text messaging, or SMS, over email and the answer they'll give is likely to reflect the needs of the healthcare industry and hospital/physician communication, too. Here are a few reasons why:

  • Email isn't fast enough. Email travels over the Internet and can be delivered with the speed of lightning or of a snail. Delivery is less predictable than text messages and just doesn't always happen right away. Text messages, by comparison, are typically received within a few seconds of being sent.

  • Text messages get delivered (and delivery can be verified). SMS isn't subject to spam filters and blockers that occasionally prevent important email messages from getting through. Text messages sent by enterprises to their constituents (such as a hospital or practice office to a physician) do not require the standard opt-in process granting permission by the intended recipient to the sender for them to receive text messages, but more importantly these messages don't get trapped in over-zealous spam filters or simply get ignored. Plus, email can't be tracked whereas the status of a text message (e.g., "sent," "delivered" and in some cases "read") is available through the national SMS network.

  • Text messages stand out. Dozens, sometimes hundreds, of emails clog people's smartphone inboxes, so it might take a long time to read one that's urgent. Text messages are perceived as more important and statistics show that 90 percent or more are opened within a few minutes.

So if even a teenager could tell us that text messaging is an ideal solution for healthcare, why isn't it used more extensively than it is in the one area that demands rapid response, accuracy and trackable delivery? In short, text messaging — in its basic, off-the-shelf incarnation — is not secure. And given the litigious world we live in, particularly when any aspect of healthcare is involved, privacy, security (and, almost by definition, HIPAA compliance) is a prerequisite.

There are several companies that offer some form of secure or encrypted text messaging. Almost all take a different approach from one another in their methodology. Presuming that all of these various methods are sufficiently secure (and if they are not you shouldn't consider them as a viable option for your facility in the first place), it's important that IT professionals and office managers consider the following key factors when making a selection:

1. Ease of use. If the system isn't as simple to use as typing a message, selecting the intended recipient and clicking "send" the chances of your office staff using it to its full effect diminishes. If a vendor's approach doesn't include an easy-to-use web-based application you should probably consider other solutions. The web-based application a vendor offers should include things like an address book so that individuals and groups can be easily selected. The system should also offer the option for those receiving the encrypted messages to select their own password with which to open it.

2. Ease of hospital/practice installation.
A web-based application is, by definition, cloud-based so no software or hardware installation is required — just open a browser, log into a fully secured web page and send your message. Users won't have to deal with upgrades, software versions, syncing, etc., because they will be able to access the sending process from any Internet-connected computer. In addition, it is likely that you will want to have multiple senders, perhaps in different departments, with the ability to quickly dispatch an encrypted text message. Having a cloud-based application makes it easy to track usage for internal billing purposes if needed and much more just by having different IDs and passwords assigned to those departments. Some solutions require hardware/software combinations that must be installed at your facility to facilitate their operation. This may require an IT expert or consultant, considerations for space, security, power and backup, and maintenance of the box or desktop application. Ideally the solution will be cloud-based and require only a web-based, secure login page to send encrypted messages to recipients.

3. Ease of recipient implementation. Some solutions require each potential recipient to download an app to their phone, keep it updated and know how to use it. This may be perfectly acceptable to your organization, but you should solicit the likely recipients' opinions in advance. You may want to select a vendor whose solution allows the recipient of the encrypted message to use the apps that are native to their device without having to download any additional apps. It reduces confusion, training requirements, the need to download apps for new or replacement devices and much more. SMS capability is, for example, embedded on every phone device manufactured today. Make it easy for the recipient, and they'll use the system more. Without their cooperation, you'll have little uptake and it might waste your time and investment.

4. Cost. A costly implementation due to complexities in implementation or the need for special equipment can — and should be — a barrier when selecting a solution. Furthermore, there should not be any additional charges on a per message basis for those messages to be encrypted. Any vendor proposing a service to you should offer a low monthly fee and a small cost per message. Vendors that charge for additional "keywords" or phone support may be less desirable than those that don't. A good vendor will keep all the complexities "under the hood" and make it simple and inexpensive for you to deploy their solution.

Presuming that you have found a satisfactory vendor for the encrypted messaging services, you will need to establish procedures in the practice or hospital for sending messages. It will become increasingly important, for example, for each department or sender to have unique IDs and passwords so that you can track the usage appropriately. Some upfront coaching or training for those who will be sending messages is understandable; a good vendor will provide you with the instructional materials or even customized screencasts for your organization.

Text messaging is and will remain the fastest and most direct route to deliver information to someone's pocket. Utilizing an encrypted messaging system via SMS ensures that communication between physicians and their practices or affiliated hospitals remains secure and confidential.