Welcome!

Containers Expo Blog Authors: Yeshim Deniz, Pat Romanski, Liz McMillan, Elizabeth White, Ravi Rajamiyer

Blog Feed Post

HIPAA and Encryption Lower the Cost of Healthcare

how to be HIPAA compliant HIPAA Compliance HIPAA Cloud HIPAA Cloud Encryption  electronic health reporter HIPAA and Encryption Lower the Cost of HealthcareAdd to the list of known certainties: death, taxes, and the need to lower the cost of healthcare.

Neither HIPAA standards nor encryption were created with the purpose of lowering the cost of healthcare, but neither was penicillin originally purposed as an antibiotic. Both welcome side effects in the world of medicine.

Cloud Computing and Healthcare

Healthcare and medical companies are migrating to cloud computing in record numbers. The cloud offers flexibility and scalability to manage ever-growing databases of patient records. At the same time, it offers mobility to enable care providers to access patient information remotely and shareability to share data with colleagues, specialists, and labs. The cloud, perhaps most importantly, enables cost reduction on several levels.

  • It eliminates the need healthcare organization have to purchase, maintain, upgrade, and replace costly computing equipment and staff.
  • It saves costs of multiple providers running multiple tests by enabling them to share and track the results.
  • It saves time and money by enabling paperless transmission of prescriptions and insurance claims. It also increases the accuracy of reimbursement coding.

Now, HIPAA omnibus and the American Recovery and Reinvestment Act (ARRA) requirements stipulate everyone in the healthcare industry begin migrating patient records and other data to cloud computing. Essentially, by 2015, all medical professionals with access to patient records must utilize electronic medical and health records (EMR and EHR), or face penalties.

 

The North American healthcare cloud computing market is expected to grow to nearly $6.5 billion by 2018.[1] [2] Healthcare Financial Management recently reported that savings benefits of EMRs/EHRs can amount to upwards of $37 million over a five-year period.

These are big numbers and big savings for healthcare.

HIPAA Standards and Encryption

HIPAA advises us to encrypt our e-PHI, whether at rest or in motion, whenever it is “reasonable and appropriate” to do so. And, especially in the cloud, it is fair to say that it is always “reasonable and appropriate” to encrypt Personal Health Information.[3]

What encryption of ePHI aims to resolve, essentially, is breaches of patient data.

And, it is succeeding!

A  Ponemon Institute study recently found that healthcare data breaches declined in both number and size in 2013, which is great news because data breaches cost healthcare organizations $5.6 billion annually.

To enable organizations to both protect e-PHI and lower the overall cost of healthcare, the Secretary of Health and Human Services published guidance on “technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals.” The guidance emphasizes that data encryption is not only a best practice for protecting privacy and security – it also provides a safe harbor to the organization in case of data loss.

By using accepted HIPAA encryption techniques, companies can mitigate risks and reduce their exposure to costly data breaches, thereby reducing the cost of healthcare.

Encryption Key Management for HIPAA Compliance

In the cloud, security and privacy concerns amass. Experts agree that while encryption is a critical component of a cloud security policy, it is not sufficient. To fully protect e-PHI in cloud computing scenarios, encryption keys must be managed in a way that is secure, automated, and constantly remains at the sole ownership and discretion of the covered entity or their business associate.

That is, encryption keys absolutely cannot be stored alongside encrypted data or visible to (much less, managed by) a cloud provider or other third party. An accepted best practice for encryption key management and HIPAA compliance is split key encryption with homomorphic key management.

Cloud Encryption and Cloud Key Management Lower Costs

By enabling healthcare organizations to securely enjoy the benefits of cloud computing, innovations like these reduce risk and mitigate costs associated with expensive data breaches. By enabling the covered entities to claim “safe harbor,” they also negate the possibility of additional fines, penalties, and expensive bureaucracy that can accompany a breach in the cloud.

The post HIPAA and Encryption Lower the Cost of Healthcare appeared first on Porticor Cloud Security.

Read the original blog entry...

More Stories By Gilad Parann-Nissany

Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.

IoT & Smart Cities Stories
Digital Transformation: Preparing Cloud & IoT Security for the Age of Artificial Intelligence. As automation and artificial intelligence (AI) power solution development and delivery, many businesses need to build backend cloud capabilities. Well-poised organizations, marketing smart devices with AI and BlockChain capabilities prepare to refine compliance and regulatory capabilities in 2018. Volumes of health, financial, technical and privacy data, along with tightening compliance requirements by...
We are seeing a major migration of enterprises applications to the cloud. As cloud and business use of real time applications accelerate, legacy networks are no longer able to architecturally support cloud adoption and deliver the performance and security required by highly distributed enterprises. These outdated solutions have become more costly and complicated to implement, install, manage, and maintain.SD-WAN offers unlimited capabilities for accessing the benefits of the cloud and Internet. ...
Discussions of cloud computing have evolved in recent years from a focus on specific types of cloud, to a world of hybrid cloud, and to a world dominated by the APIs that make today's multi-cloud environments and hybrid clouds possible. In this Power Panel at 17th Cloud Expo, moderated by Conference Chair Roger Strukhoff, panelists addressed the importance of customers being able to use the specific technologies they need, through environments and ecosystems that expose their APIs to make true ...
Business professionals no longer wonder if they'll migrate to the cloud; it's now a matter of when. The cloud environment has proved to be a major force in transitioning to an agile business model that enables quick decisions and fast implementation that solidify customer relationships. And when the cloud is combined with the power of cognitive computing, it drives innovation and transformation that achieves astounding competitive advantage.
DXWorldEXPO LLC announced today that "IoT Now" was named media sponsor of CloudEXPO | DXWorldEXPO 2018 New York, which will take place on November 11-13, 2018 in New York City, NY. IoT Now explores the evolving opportunities and challenges facing CSPs, and it passes on some lessons learned from those who have taken the first steps in next-gen IoT services.
"Space Monkey by Vivent Smart Home is a product that is a distributed cloud-based edge storage network. Vivent Smart Home, our parent company, is a smart home provider that places a lot of hard drives across homes in North America," explained JT Olds, Director of Engineering, and Brandon Crowfeather, Product Manager, at Vivint Smart Home, in this SYS-CON.tv interview at @ThingsExpo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
In an era of historic innovation fueled by unprecedented access to data and technology, the low cost and risk of entering new markets has leveled the playing field for business. Today, any ambitious innovator can easily introduce a new application or product that can reinvent business models and transform the client experience. In their Day 2 Keynote at 19th Cloud Expo, Mercer Rowe, IBM Vice President of Strategic Alliances, and Raejeanne Skillern, Intel Vice President of Data Center Group and G...
The current age of digital transformation means that IT organizations must adapt their toolset to cover all digital experiences, beyond just the end users’. Today’s businesses can no longer focus solely on the digital interactions they manage with employees or customers; they must now contend with non-traditional factors. Whether it's the power of brand to make or break a company, the need to monitor across all locations 24/7, or the ability to proactively resolve issues, companies must adapt to...
DXWorldEXPO LLC announced today that ICC-USA, a computer systems integrator and server manufacturing company focused on developing products and product appliances, will exhibit at the 22nd International CloudEXPO | DXWorldEXPO. DXWordEXPO New York 2018, colocated with CloudEXPO New York 2018 will be held November 11-13, 2018, in New York City. ICC is a computer systems integrator and server manufacturing company focused on developing products and product appliances to meet a wide range of ...
René Bostic is the Technical VP of the IBM Cloud Unit in North America. Enjoying her career with IBM during the modern millennial technological era, she is an expert in cloud computing, DevOps and emerging cloud technologies such as Blockchain. Her strengths and core competencies include a proven record of accomplishments in consensus building at all levels to assess, plan, and implement enterprise and cloud computing solutions. René is a member of the Society of Women Engineers (SWE) and a m...