RUNNING HEAD
1-2 Journal: Security Measures
Erica Cleveland
Southern New Hampshire University
SECURITY MEASURES
1-2 Journal: Security Measures
In the fast-paced environment of today's healthcare system, measures must be
implemented to ensure that patient data and healthcare records are secure from those that may
wish to utilize it for personal gain or inappropriately. Data such as personal health information
(PHI), billing information and medical histories are vital parts of the overall patient-driven
healthcare experience. When patients interact with the organization, they do so with a sense of
protection and with the expectation of privacy. It is the responsibility of the organization to put
into place security protocols which will reduce the incidents of medical fraud, stolen identity, or
breaches in private medical records. There are many ways to protect the patient. Some
suggestions are the implementation of administrative safeguards such as security management,
information access management, security awareness and training, and enforcing workforce
security.
Security Measure Choices
Security management consists of methods of strategy which attempt to identify possible
security breaches before they occur. It consists of the areas of risk analysis, risk management,
sanction policy, and information system activity reviews. Once risk analysis identifies specific
potential breaches, they are then classified as high risk or low risk offenses. Risk management
steps in and categorized a protocol to correct the breach based on its level of importance and
prioritizes the high risk as the most immediate threat to be resolved. The information system
activity is utilized to locate the breach and find the culpable individual. Once resolved, sanction
policy is implemented which decrees what the penalty will be for the individual responsible for
the data breach.
SECURITY MEASURES
Information access management is responsible to for setting the parameters within a data
system and establishing credentials for those individuals who will have authorization to utilize
the program. Within this system, a chief security officer is assigned to govern and establish the
set security protocols and procedures. They are to establish and dictate how breaches in security
will be handled and oversee that the logs, incident reports, and both internal and external
information are protected as required by law.
Security awareness and training allows employees and upper management the ability to
stay current to privacy protection policies which help maintain patient confidentiality. It provides
the tools needed to facilitate the steps needed to prevent a data breach as well as the knowledge
to correct the problem if one occurs. It provides unwavering protocol to ensure that resolutions
are quick and precise.
The enforcement of workforce security provides access to those individuals who are
necessary for a particular process to be performed and limits access to those that are not
fundamental to the process. It implements procedures to ensure that the individual who is
accessing the item has a need for this information as part of their job function. To ensure this
process, certain security measures are put into place such as passwords, key cards, two-factor
authorization, and biometric security. Each of thes