Most Popular Stories
- AMA wants two-year delay of ICD-10
- Debate: Can mobile apps achieve what pills can't?
- Kinect works toward degree in early autism diagnosis
- Hybrid heart surgery helps patients bounce back
- Docs should be wary of anti-kickback laws when implementing HIT
- New research disputes claims EHRs improve diabetes care
Hottest Products
Compare Top Solutions in:
Events
- Digital Marketing: Everyone's Saying "Do It," Few Tell You What Works
- Webcast: Engaging Patients as Consumers
Tuesday May 22nd 4:00 pm ET - Northwestern Online Master of Science in Medical Informatics Program
- 2nd Annual Medical Devices Summit West
June 7-8, 2012 — DoubleTree by Hilton Hotel San Diego - Mission Valley San Diego, CA
Paid Research Reports
- Electronic health records: getting it right first time
- Cloud Computing Adoption In The APAC Life Sciences Industry
- Stakeholder Opinions: Ophthalmology - Leading brands under threat
- Genomics, Proteomics and Metabolomics in Diagnostics: Market landscape, innovative technologies and future outlook
- Healthcare Regulatory Update: The United Arab Emirates
- Point of Care Testing: Evaluating the return to evidence based medicine, novel technologies and the competitive landscape
Free Newsletter
Free Newsletter
FierceHealthFinance is a weekly healthcare finance update for health executives and financial managers. Join 23,000+ industry insiders who get FierceHealthFinance via email for their must-know healthcare finance news. Sign up today!
About | View Sample | Privacy
Latest News
Top Tags
Whitepapers
- The Hidden Benefits (and Costs) of Electronic Provider Payment - More Than Saving a Stamp?
- Home Healthcare Equipment: An Overview
- What you need to know in planning and budgeting for digital signage in healthcare
- Advancing Emergency Department Discharge Instructions
- Selecting the right bar code scanner for mission critical healthcare applications
- BREAKING THE LANGUAGE BARRIER: Health Care Quality, Efficiency and Savings through Professional Medical Interpretation
Action steps CFOs can take to boost data security
![]()

Following up on my April 21 column detailing why hospital chief financial officers need to take an interest in the privacy and security of patient data, I spoke with Dr. Barry Chaiken, MPH, chair of the Healthcare Information and Management Systems Society (HIMSS), who shared some additional insights. So, quick: How do you filter viruses out of emails?
If you don't know the answer, that's OK. You can leave those types of tactical issues to the information technology (IT) professionals, advises Chaiken. However, "CFOs are responsible for the financial integrity of the institution. They are therefore responsible for security and privacy, whether they like it or not," he points out.
CFOs should consider privacy and security "a strategic issue," says Chaiken. "CFOs have to formulate the strategic solution--what parameters they want to set to prevent breaches of security and privacy--and then allow the vice president for management systems or the CIO [chief information officer] to figure out how to deliver that strategic vision. The CIO is not necessarily going to understand the ramifications of a breach the way a CFO might."
Chaiken explains three critical steps that CFOs can--and should--take:
No. 1: Audit work flows.
CFOs should review financial processes to look for places where damage can occur, says Chaiken. "Everything is about work flow in healthcare. You have to examine those processes to see where you think there are weak points." One obvious example of what a CFO might review: a lobby kiosk where an employee is entering personal data. "That is clearly where a work flow could be broken," he explains. "So you have to examine those processes."
No. 2: Institute surveillance.
Surveillance is a common tool for dealing with public health emergencies, but Chaiken believes in surveillance "all across the board." Hospital CFOs should create a surveillance process to monitor processes "to, in an early way, identify potential breaches that could become huge problems," he advises. Often, data breaches start out small, but they aren't caught until the drip becomes a flood. For example, CFOs need to have a surveillance tool to check whether anyone is accessing records that they shouldn't. "You would want to know that early on vs. finding out later that large numbers of people are accessing records without authorization or inappropriately."
It's important to note that surveillance "is not about identifying a problem," stresses Chaiken. "It is about identifying a potential problem."
No. 3: Drop the "silo" mentality.
The interoperability of financial systems and clinical systems in hospitals means "access to one often gives you at least some partial access to the other," says Chaiken. Consequently, CFOs should work collaboratively with the clinical IT leadership to address privacy and security. If the chief medical information officer (CMIO) has a weak process, "that could potentially expose the CFO," he points out. Likewise, a weak security process on the financial side could potentially cause a breach of the clinical data.
"We can no longer in healthcare work in silos," says Chaiken. "Everybody is interconnected, so clinical and nonclinical people have an obligation to work closely together to address all the issues in healthcare, particularly privacy and security."
CFOs need to get started developing a strategic plan for data privacy and security "yesterday," says Chaiken. "The planning must begin now. This is a stepwise process. You don't say, 'I'm going to put together an ironclad system, and it is going to take me three years.' You develop a good plan, and you start to gradually ramp up your ability to establish security and privacy." - Caralyn
P.S., we've just published a new e-book examining the ins and outs of revenue cycle dashboards. You can download it for free here. Enjoy!
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site Map
| Editors | List in Marketplace | Supplier in MarketplaceTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceCRO | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2012 FierceMarkets. All rights reserved. |
![]() |
