Operational Considerations and Organizational Approaches for Managing Health Information Technology
Health care data is extremely sensitive in nature, and ensuring that patient information is kept secure and private should be a high priority for every health care organization. There are numerous technological tools available to provide the necessary system safeguards for electronic data. However, it is up to the individual organization to develop a security program that protects the privacy of the patient information that is collected, transmitted, and stored in its information systems, and that enables the organization to identify potential risks and to respond to system breaches as quickly and effectively as possible.
To prepare for this Discussion, read Case Study 17, “Breaching the Security of an Internet Patient Portal” on page 507 in your course text, Health Care Information Systems: A Practical Approach for Health Care Management.
By Day 4, post a comprehensive response to the following:
As a member of the crisis team put in place to respond to this security breach, what are two administrative, physical, and/or technical security safeguards that you would recommend be put in place? Why and how would you go about doing so?
What approach to information technology governance do you think would work best in addressing this situation? Why do you think that that approach would work better than other approaches? Explain your reasoning.
Note: For your Week 7 Discussion, answer only the course-specific questions listed above. DO NOT refer to or answer any of the discussion questions that are included in your course text as part of a numbered list at the end of the case study, as they are not applicable to the course-specific Discussion Assignment.
Read a selection of your colleagues’ postings.
By Day 6, respond to at least one of your colleagues’ postings in one or more of the following ways:
Ask a probing question.
Expand on the colleague’s posting with additional insight and resources.
Offer polite disagreement or critique, supported with evidence.
In addition, you may respond as follows:
Offer and support an opinion.
Validate an idea with your own experience..
Make a suggestion or comment that guides or facilitates the discussion.
Return to this Discussion in a few days to read the responses to your initial posting. Note what you have learned and/or any insights you have gained as a result of your colleagues’ comments. You are not required to post these final insights.
253642
5 minutes ago
Readings
Course Text: Wager, K. A., Lee, F. W., & Glaser, J. P. (2017). Health care information systems: A practical approach for health care management (4th ed.). San Francisco: Jossey-Bass.
Chapter 10, “Performance Standards and Measures”
This chapter provides an overview of the laws, regulations, and standards that influence the manner in which information is collected and maintained by health care organizations.
Chapter 9, “Privacy and Security”
This chapter reviews potential threats to the security of health information systems and the administrative safeguards that can be employed to protect against these threats.
Chapter 13, “IT Governance and Management”
This chapter explores key organizational concerns for the management of health care information technology, including the structural approaches to governance, measurements of effectiveness, allocation of funding, and budget management.
Case Study 17, “Breaching the Security of an Internet Patient Portal”
This case study presents a scenario involving considerations for information systems security and approaches to information technology governance within health care organizations.
Course Text: Tan, J. K. (2021). Adaptive health management information systems: Concepts, cases, and practical applications (4th ed.). Jones and Bartlett.
Policy Review III, “Health IT Standards Adoption in Health Systems” (pp. 310- 317)
MacMahon, S. T., Cooper, T., &McCaffery, F. (2018). Revising IEC 80001-1: Risk management of health information technology systems.Computer Standards & Interfaces,60, 67–72.https://doi-org.ezp.waldenulibrary.org/10.1016/j.csi.2018.04.013
Fahy, K., & Hermann, M. (2017). Case Study #6: Enterprise Information Management at Children’s Health System of Texas: Updating Organizational Policies and Procedures for Information Governance.Journal of AHIMA,88(6), 46–47.
Fatima, A., & Colomo-Palacios, R. (2018). Security aspects in healthcare information systems: A systematic mapping. Procedia Computer Science, 138, 12–19. https://doi.org/10.1016/j.procs.2018.10.003
Helmers, R. A., Gabrielson, S. R., & Harper, M. M. (2016). Developing a new governance structure: The Mayo Clinic experience. Physician Leadership Journal, 3(3), 40–45.
Gomillion, D. L. (2017). Comprehensive care and the stalled adoption of an electronic health records system: IT governance and employee succession. Journal of Information Systems Education, 28(2), 93–100.
Websites
AHIMA: Privacy & Security
http://ahima.org/advocacy/privacysecurity.aspx
This site reviews industry standards for privacy and security and provides links to the policies of a number of major governmental agencies and industry groups.