Distinguish between information and data governance _________/10
List Five benefits of information governance in healthcare _________/15
Discuss the importance of data accuracy and integrity in healthcare _________/15
Apply the use of policies, procedures, and various strategies to
ensure data accuracy and integrity by healthcare facilities and
providers _________/20
Identify the impact of information governance on patient care
Information Governance
Information Governance is the center of the healthcare industry. All healthcare organizations utilize information whether it’s in written or oral form. Safe and accurate information are some of the keys to quality care. With the health industry constantly changing and the several ways of accessing processed data, safeguarding patient information is top priority. Information governance (IG) seeks to improve how information is handled (Hutchinson & Sharples, 2006). IG includes the protection of data, personal health records (PHR), electronic health records (EHR), and medical information exchanged via telemedicine. Breaches of personal information have been occurring more often and the time for information governance is indeed now. This paper will explain what information governance is, give examples of data breaches and how the particular organization was affected, and explain the importance of implementing information governance.
Information Governance
One of the most common issues in healthcare is the proper exchange, use, storage and disposal of information. Information exchange is what drives healthcare organizations. Whether in written or oral form, it is a way for organizations to communicate internally as well as externally. With technology constantly on the rise, information can easily be accessed in several different forms such as smartphones, tablets and social media. Healthcare organizations have also been implementing the use of electronic health records (EHR) which opens the door to a variety of data. Now more than ever, organizations are paying closer attention to the security of such personal information by implementing information governance (IG). In this paper, readers will find out what IG is and the many systems it encompasses, breaches that have taken place due to the lack of IG, and the importance of ensuring the protection of such personal information.
What is Information Governance
Information governance (IG) is defined as an organization-wide framework for managing information throughout its lifecycle and supporting the organization’s strategy, operations, regulatory, legal, risk, and environmental requirements (AHIMA, 2015). So, what exactly does this mean? The role of IG is to ensure the quality of care for individuals, to make sure information can be trusted, and to lower the costs of healthcare per capita (AHIMA, 2015). Information governance is about properly managing information. IG is a framework of rights and accountability… (Kloss, 2013). It is important to have an accountability framework to state who is responsible for what and who can make business decisions about an information asset (Gordon, 2014). IG is about properly managing both internal and external information. Good information governance is important whether receiving or providing services (Nwolie, 2011). It is necessary for healthcare information to be valued, controlled, and trusted. IG encompasses the protection of information included in several healthcare and clinical information systems. Each being unique in its own way.
Internal Information
Healthcare organizations communicate both internally and externally. Internal information deals with activities surrounding the patient encounter (Wager, Lee, & Glaser, 2013). Included in the patient encounter is patient-specific or identifiable health care information, defined by the Health Insurance Portability and Accountability Act (HIPAA) as protected health information (PHI) (Wager, Lee, & Glaser, 2013). Patient-specific information includes health records such as the electronic health record (EHR), electronic medical record (EMR), and the personal health record (PHR).
EHR
Electronic health records (EHRs) are being implemented in healthcare organizations all over the world. An EHR is health-related information on an individual that is electronically created, gathered, managed, and consulted by authorized clinicians and staff within one health care organization (Wager, Lee, & Glaser, 2013). More and more health care organizations are doing away with paper medical records and adopting EHR practices. Electronic health records may not be as secure as paper records but they are more efficient. It is important to also understand that any information that can be accessed electronically is at risk for a security breach. To ensure that technology will fulfill its promise of guiding better, more efficient patient care, EHR needs to be standardized by a more improved and unified Health Information Governance (AHIMA, 2012). Along with EHRs, telemedicine has its pros and cons to ensuring the protection of personal information.
Telemedicine
Telemedicine is the use of telecommunications for the clinical care of patients and may involve various types of electronic delivery mechanisms (Wager, Lee, & Glaser, 2013). Over the past few decades, telemedicine has evolved, becoming more prevalent. Providers are able to deliver services to patients in distant locations. With the inclusion of several forms of telecommunication technologies such as e-mail, smart phones and wireless tools, the main concern is to ensure that the personal health information of patients is protected. With an increase in consumers turning to personal health records (PHR), the possibility of an information breach is huge.
PHR
A personal health record (PHR) is a record that is customizable and personalized, pertaining to any information on an individual’s healthcare (Kupchunas, 2007). The personal health record has its pros such as patient empowerment, improved patient-provider relationships, enhanced patient safety, and health information privacy (Kupchunas, 2007). Two huge concerns with the PHR are the health literacy and technological literacy of the patients. It is important for a patient to understand their personal health information and be technologically savvy enough to input and edit electronic records (Kupchunas, 2007). The more easily accessible computer-based patient information becomes, the demand for such data is expected to increase (Smith, 2000). The access to such information can potentially increase the risk of the unauthorized disclosures of patient identifiable information (Smith, 2000).
Information and Data Breaches
With the increase in technology use comes the increased probability of a data breach. The media has reported several incidents regarding security breaches of confidential data stored by the Government (Baskaran & Wickramasinghe, 2013) Within the past few years, there has been a number of well-publicized breaches to occur (Myers, 2008). There was an accidental attachment to an email that included the names and addresses of 6500 HIV/AIDS patients in a county health department (Myers, 2008). In 2015 alone, there were a total of 253 healthcare breaches affecting 500 or more individuals and having a combined loss of over 112 million records (Munro, 2015). The largest of those breaches was Anthem. They represented over 70% of the breaches that occurred (Munro, 2015). The cause of Anthem’s breach was traced back to phishing attacks (Munro, 2015). This is just proof that organizations need to spend more time training their staff on how to protect data. There have been major concerns from individuals, public bodies, social groups and professional organizations expressing the safety, security and privacy of electronic patient records (Baskaran & Wickramasinghe, 2013). Since 2009, about 21 million individuals have been affected due to large healthcare data breaches (Reeves & Bowen, 2013). Majority of the breaches involved data from laptops that were lost or stolen, removable disk drives, or other media that could be transported (Reeves & Bowen, 2013). These types of breaches can lead to the community’s loss of trust and also potential market share (Reeves & Bowen, 2013). There is also the concern of the several threats to medical record privacy. Some of these threats include administrative actions such as released errors, user misuse, and the uncontrolled access to medical records (Smith, 2000). Medical record privacy is also threatened by computerization, which enables the storage of large amounts of data in small places (Smith, 2000). Healthcare organizations often network with each other. This information can be accessed from anywhere and at any time (Smith, 2000). Because information is so easily gathered, exchanged and transmitted, its potential for circulation is endless (Smith, 2000). The availability of healthcare information in electronic format creates several opportunities for confidentiality and integrity breaches (Baskaran & Wickramasinghe, 2013).
Recommendations
The protection of information in this day and age is extremely important. With the increase of healthcare organizations implementing EHRs and more patients turning to PHRs, any slight incident can lead to a major breach. There are some ways that organizations can try to reduce the possibility of a security breach. First, I feel organizations should increase training for their employees and establish privacy and security policies. Anyone who handles confidential patient information should have proper training. If privacy and security policies are learned, it would definitely help reduce the probability of a breach. Secondly, healthcare organizations should perform protected health information (PHI) risk assessment. Organizations should know where their information resides. Information should also be prioritized by their terms of sensitivity as to determine their level of protection. Privacy measures should be implemented to protect sensitive data. Not only must files be password protected, but they should be encrypted as well. Organizations should definitely have an incident response plan that clearly defines the guidelines and responsibilities to manage loss or theft of PHI. This could help shorten the time frame of recovery in case of a data breach. Lastly, organizations should make sure that security and privacy of information is included in their budget plans. The lack of budget and risk assessments are one of the greatest weaknesses for organizations.
Last Completed Projects
| topic title | academic level | Writer | delivered |
|---|
