Saturday, 17 March 2018

Aadli Abdul-Kareem: True Interoperability is finally being addressed

Aadli Abdul-Kareem: True Interoperability is finally being addressed - Paubox

The mother of all healthcare conferences, HIMSS Annual, went down last week at the Venetian in Las Vegas. At least 40,000 people descended upon the Sands Expo Center to network, learn and probably do a bit of gambling.

Aadli Abdul-Kareem, Electronic Health Network Co-Founder

We setup an impromptu interview center outside Palazzo Ballroom L.

Aadli Abdul-Kareem, Managing Partner and Co-Founder of Electronic Health Network, stopped by to share his biggest takeaway from HIMSS18.

Here’s the transcript from Aadli’s takeaway:

Aadli Abdul-Kareem: My biggest takeaway is actually going down to the Interoperability Showcase and seeing how much they’re promoting system integration and interoperability across applications.

It looks like now everything from having a data center infrastructure that’s HIPAA-secured and ensuring that within that data center infrastructure, there’s tools that developers can leverage to integrate with EHR systems, more easily consume laboratory and share laboratory information, even down to consent. Like having behavioral health be a very huge topic in tackling “how do I drive consent-driven transactions in compliance with behavioral health?” It’s been pretty amazing.

So that’s my biggest takeaway: True interoperability is finally being addressed the way it needs to be.

SEE ALSO: Chris Cruttenden: HIMSS18 Interview with Safety Net Connect

HIMSS18

The HIMSS Annual Conference & Exhibition brings together 40,000+ health IT professionals, clinicians, executives and vendors from around the world. Exceptional education, world-class speakers, cutting-edge health IT products and powerful networking are hallmarks of this industry-leading conference.

The post Aadli Abdul-Kareem: True Interoperability is finally being addressed appeared first on Paubox.

Friday, 16 March 2018

Memorial Hospital at Gulfport Suffers HIPAA Email Breach

Paubox HIPAA Email Breach

On February 28, 2018, Memorial Hospital at Gulfport submitted a HIPAA Email Breach to the U.S. Department of Health and Human Services (HHS).

Located in Mississippi, the Memorial Hospital at Gulfport email breach affected 1512 individuals’ protected health information.

Memorial Hospital at Gulfport is classified as a Healthcare Provider.

HHS Wall of Shame

The HHS Wall of Shame is a website under the jurisdiction of HHS that lists all HIPAA breaches reported within the last 24 months. The Wall of Shame displays breaches that are currently under investigation by the Office for Civil Rights.

As part of section 13402(e)(4) of the HITECH Act, the HHS Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.

HIPAA Breach Report

The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame.

The post Memorial Hospital at Gulfport Suffers HIPAA Email Breach appeared first on Paubox.

Lance Spitzner: Making Security Simple – FISSEA NIST Conference

Lance Spitzner: Making Security Simple - FISSEA NIST Conference - Paubox
Lance Spitzner: “We’re nothing more than another operating system. The HumanOS.”

Day two of the 31st Annual FISSEA conference at NIST kicked off with a Keynote presentation from Lance Spitzner, Director of Security Awareness at SANS.

His Keynote was titled: Making Security Simple – It’s Really, Really Hard.

Lance was fired up on stage, which in turn got me fired up.

I was especially encouraged to hear that when it comes to enhancing security, Lance strongly recommends a focus on making the new behavior as simple as possible. In the case of Paubox and our approach to seamless encryption and HIPAA compliant email, there is no new behavior for senders to learn.

Here are my takeaways and pics from his energetic presentation:

  • Lance outlined his 3 step process for making Cybersecurity Simple.
  • Changing human behavior is key to managing risk.
  • Lance Spitzner created the honeypot in 1999.
  • The best security awareness officers often do not have technical backgrounds.
  • “Once people interact with technology, then the game radically shifts.”
  • In general, people are smart.
  • Defense organizations tend to have the strongest security programs. At the other end of the spectrum, manufacturing firms.


Lance Spitzner’s Three Steps to Making Cybersecurity Simple:

  1. Teach as little as possible (be wary of cognitive overload).
  2. Make the new behavior as simple as possible.
  3. It has to be “Sue” proof (Can a non-technical person understand it?).

20 years ago, it was easy to hack default Windows OS installs.
Lance Spitzner: Making Security Simple - FISSEA NIST Conference
The BJ Fogg Behavior Model – Curse of Knowledge: The more of an expert you are at something, the worse you are at communicating it
Lance Spitzner: Making Security Simple - FISSEA NIST Conference
“Every behavior has a cost.” Used disabling of auto-complete within Outlook at the world’s largest bank as an example
Lance Spitzner: Making Security Simple - FISSEA NIST Conference
Lance spent a good chunk of time (rightly so) on NIST Special Publication 800-63B
Lance Spitzner: Making Security Simple - FISSEA NIST Conference
Lance reported only 10% of G Suite users are using 2FA (Two-Factor Authentication)
Lance Spitzner: Making Security Simple - FISSEA NIST Conference
Infographics are great for communicating information
Lance Spitzner: Making Security Simple - FISSEA NIST Conference
Lance’s 3 Takeaways for Making Security Simple (Hint: It’s Really, Really Hard)
Lance Spitzner: Making Security Simple - FISSEA NIST Conference

Also, thanks for fielding my question Lance!

The post Lance Spitzner: Making Security Simple – FISSEA NIST Conference appeared first on Paubox.

Thursday, 15 March 2018

How Can My Patients Send Me A Secure HIPAA Compliant Email First?

When a patient has a medical concern and wants to reach out to their healthcare provider, office phones can be tied up and they are left with no answers. Additionally, some medical concerns are better explained visually than verbally.

Considering some medical practices have perpetual busy tones, how else can your patients reach you? Thanks to technology, there is a popular alternative: email.

However, most medical concerns involve mentioning protected health information (PHI) of some kind. In order to ensure your organization is HIPAA compliant, any communication with your patients needs to be secure and encrypted.

With Paubox, there are ways for your patients to engage securely with your organization without you having to send an email to them first. Here’s how it works.

Use a secure URL to receive secure messages from patients

There is no way a patient can send you a secure email first without having email encryption in place themselves. However, a Paubox encrypted contact form is a seamless workaround for patients to send secure messages to their healthcare providers.

Our Paubox encrypted contact form features basic fields for patients to fill in, such as their name, email address, phone number, and a brief message. We’ll also include a space where patients can upload up to 50 megabytes of attachments (such as photos or documents).

Patients can access the encrypted contact form through a secure, custom URL that can be placed anywhere on your website. This allows the patient to send a secure message to your organization first, and the information will be delivered in a HIPAA compliant email straight to your inbox, avoiding the hassle of hard copies, scanning and manual entry.

Every Paubox account comes with one encrypted email address and one encrypted contact form.

READ MORE: How Does a Paubox Encrypted Contact Form Work? (With Pictures)

You can attach encrypted contact forms to your website or send it through an email.

The contact form link will be hosted on our secure Paubox server, so you don’t need to worry about having a HIPAA compliant website and server.

READ MORE: How to Make Sure You Have a HIPAA Compliant Website

How Paubox’s contact form encryption works

If your patient is not a Paubox subscriber, Paubox can still encrypt their incoming contact form email.

The Paubox encrypted contact form links with any G Suite, Office 365 or Microsoft Exchange email account. The selected email account will receive the contact form via email after the patient fills it out.

If your business email provider includes a BAA with its service, then the BAA will cover any emails at rest in your inbox for HIPAA compliance.

For emails in transit, Paubox utilizes TLS encryption to secure the email as it is delivered to the selected inbox.

If you use Paubox’s email encryption service, you can take the Paubox encrypted contact form one step further by directly replying to the contact form email in a secure, HIPAA compliant manner.

You can see a visual confirmation of this process at the footer of every Paubox email. The footer reads, “This incoming email was seamlessly encrypted by Paubox,” as seen below:

Paubox encrypted email takes care of in-transit encryption at no extra cost. And just like our encrypted contact form, it’s very easy to use.

A Paubox encrypted contact form on your website will show your patients that you are taking their privacy and security seriously by allowing them to contact your organization in a secure, HIPAA compliant manner.

The post How Can My Patients Send Me A Secure HIPAA Compliant Email First? appeared first on Paubox.

Sunday, 11 March 2018

Uber Health: Is it HIPAA Compliant?

Uber Health: Is it HIPAA Compliant? - Paubox

We were recently asked on Twitter whether Uber’s new service, Uber Health, was HIPAA compliant or not.

We know the HIPAA industry is vast so we can empathize with just how many people need to use cloud services in this sector.

In previous posts, we’ve covered the following cloud solutions and their capabilities for HIPAA compliance:

Today, we will determine if Uber Health offers HIPAA compliant service or not.

SEE ALSO: HIPAA Breaches and Cloud Providers

Uber Health

This month Uber launched a new business line called Uber Health. The service provides a ride-hailing platform available specifically to healthcare providers.

Uber Health allows covered entities like clinics, hospitals, and rehab centers assign rides for their patients and clients from a centralized dashboard. The rider is not required to have the Uber app, or even a smartphone.

Uber Health and the Business Associate Agreement

We’ve previously talked about how a Business Associate Agreement is a written contract between a Covered Entity and a Business Associate. It is required by law for HIPAA compliance.

We checked Uber Health’s site and on their homepage, they state:

Uber Health engaged HIPAA experts to design a program customized for the healthcare environment with numerous safeguards in place to protect PHI — including Business Associate Agreements with partners, technical controls and administrative processes.

In the Uber Newsroom, we also found this:

HIPAA Compliance. To ensure Uber Health meets HIPAA standards, we have been working hard to develop, implement, and customize numerous safeguards. We also worked with Clearwater Compliance, a leading HIPAA compliance company, to conduct comprehensive risk and compliance assessments. We are thus pleased to sign Business Associate Agreements (BAAs) with our healthcare partners.

Does Uber Health Offer HIPAA Compliant Service?

The Business Associate Agreement is a key component to HIPAA compliance between a covered entity and a business associate.

We were able to quickly determine that Uber Health is willing to sign Business Associate Agreements with the healthcare organizations they serve.

Conclusion: Uber Health is HIPAA compliant.

The post Uber Health: Is it HIPAA Compliant? appeared first on Paubox.

Friday, 9 March 2018

Flexible Benefit Service Corporation Suffers HIPAA Email Breach

Paubox HIPAA Email Breach

On February 16, 2018, Flexible Benefit Service Corporation submitted a HIPAA Email Breach to the U.S. Department of Health and Human Services (HHS).

Located in Illinois, the Flexible Benefit Service Corporation email breach affected 5123 individuals’ protected health information.

Flexible Benefit Service Corporation is classified as a Business Associate.

HHS Wall of Shame

The HHS Wall of Shame is a website under the jurisdiction of HHS that lists all HIPAA breaches reported within the last 24 months. The Wall of Shame displays breaches that are currently under investigation by the Office for Civil Rights.

As part of section 13402(e)(4) of the HITECH Act, the HHS Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.

HIPAA Breach Report

The Paubox HIPAA Breach Report analyzes breaches that affected 500 or more individuals as reported in the HHS Wall of Shame.

The post Flexible Benefit Service Corporation Suffers HIPAA Email Breach appeared first on Paubox.

Chris Cruttenden: HIMSS18 Interview with Safety Net Connect

Chris Cruttenden: HIMSS18 Interview with Safety Net Connect President - Paubox HIPAA Center

  • We learned more about eConsult and Care Coordination Connect System.
  • Chris shared his biggest takeaway from HIMSS18.
  • Chris participated in our signature Paubox Lightening Round.

The mother of all healthcare conferences, HIMSS Annual, went down this week at the Venetian in Las Vegas. At least 40,000 people descended upon the Sands Expo Center to network, learn and probably do a bit of gambling.

Chris Cruttenden, Safety Net Connect President

We setup an impromptu interview center outside Palazzo Ballroom L.

My friend Chris Cruttenden, President of Safety Net Connect, stopped by to catch up.

Here’s the transcript from our conversation:

Hoala Greevy: Howzit! This is Hoala Greevy, Founder CEO of Paubox. We’re here at HIMSS18, in Las Vegas and I’m here with my friend Chris Cruttenden, President of Safety Net Connect. Without further ado, let’s get started.

Chris, can you tell me more about what your company does and what problems you guys solve?

Chris Cruttenden: We solve two problems in healthcare. One is the communication problem between primary care physicians and specialists. We’ve created a system we refer to as eConsult and it helps coordinate the care and do away with the need for inappropriate referrals.

The second system that we provide is what we call Care Coordination Connect System, where we help deal with patients that when they’re discharged from a hospital, [we] get them the appropriate care and transitions of care through our systems.

Hoala Greevy: What would be an example of an inappropriate referral?

Chris Cruttenden: Typically in some of the systems, the physician is fairly busy, they still use some archaic systems like a fax. Somebody would come in and be complaining about a rash on their arm and he’s like, “Oh I don’t know, you need to see the dermatologist.” He’d give it to the nurse, the nurse would fax it over, get an auth, they would go have to see the dermatologist.

In our system, they would take a picture, ask a question, “Can I resolve this here or do I need to send them to the dermatologist?” We ask them questions like, “Have they changed the soap, have they been hiking in a place where maybe they got poison oak?” Through the process of education elimination, probably that patient would get help and not need to do an extra visit at the dermatologist.

Hoala Greevy: For the second set of services you folks provide, can you tell us more about this safety net concept, because I was very unfamiliar with it.

Chris Cruttenden: When we first got into the business, we found there was so much low-hanging fruit and county health systems where we could do a lot of good. We’ve basically focused on just the safety net population, which is in California, Medi-Cal or indigent programs which is basically county-run programs that deal with people that are uninsured, homeless people, and whatnot.

We created basically everything that high-tier people get with private insurance, we created an electronic system that allows them to have appropriate care coordination, services, efficient referrals, and when they show up at the myriad of different places, their information follows them. Which is really nice.

Hoala Greevy: That’s cool man. So what does your ideal customer look like, is it a county?

Chris Cruttenden: Yes, we we love county health programs, public health programs, we like working with those systems.

Typically, we love to go into a system where they have a backlog of referrals. We can bring in eConsult and change the workflow. We reduce inappropriate referrals by around 50% on some of the specialties. We reduce the backlog sometimes for a GI visit, it’s it’s you know, 180 days. We get access to the specialist down to two days and then we actually turn it into a system where they actually schedule the appointment within the appropriate time, whether it’s 30 days or 45 days. We’ve eliminated basically backlogs for specialty visits.

Hoala Greevy: How big is your team and where you guys located?

Chris Cruttenden: We’re 20 plus people, we’re located in Newport Beach. We also have an office in Texas and then we have some affiliate offices. [We have] partners, one in Chicago and one in Connecticut.

Hoala Greevy: Wow. All over. That’s cool. So what’s your what’s your biggest takeaway from HIMSS18 so far?

Chris Cruttenden: It seems to be a lot of hype about AI and blockchain. The takeaway on blockchain is it is not ready for primetime, at least in healthcare. It is far, far, far from ready.

The AI stuff was extremely interesting and I think it’s going to create some efficiencies, especially in specialty care- radiology, dermatology, anything in a visual aspect where you can, retinopathy, where you can basically look at the images and have it learn which is a bad image versus a good image.

Hoala Greevy: Chris, where do you see the industry going in the future?

Chris Cruttenden: I don’t want to give away too many secrets! I’m just kidding. But basically there’s gonna be some consolidation as far as what we’re seeing with the EMRs, smaller healthcare software plays. Seems like care coordination is evolving and I think analytics supporting the real-time care coordination is really going to change how people get health care and interact with it. All these mobile devices are really doing big change too. Patients are more hooked in than they’ve ever been before.

Hoala Greevy: Yeah. Optimistic for the future?

Chris Cruttenden: Oh yeah! I do think technology is gonna solve some of the issues that are facing us that politicians cannot solve. But we can solve it.

Hoala Greevy: Okay we’re gonna do the lightning round with Chris Cruttenden. Ready?

Chris Cruttenden: Yeah.

Hoala Greevy: Favorite Hawaiian food?

Chris Cruttenden: Poke.

Hoala Greevy: Yeah! Right on. How many times have you seen the movie, The Big Lebowski?

Chris Cruttenden: Two times.

Hoala Greevy: Two times!? I thought you gonna say too many. You ever been kayak fishing?

Chris Cruttenden:I have not been kayak fishing, no.

Hoala Greevy: Okay we gotta get that going. What book or books are you reading now?

Chris Cruttenden: One of my favorite books is the Art of the Start by Guy Kawasaki. He has an updated version and I always print out some of the pages and tape them on my desk.

Hoala Greevy: No kidding!

Chris Cruttenden: Love it. Because I do a lot of presentations. Love it.

Hoala Greevy: I know someone who knows him. I will make sure he hears about that.

Chris Cruttenden: OK.

Hoala Greevy: That’s cool. I don’t know I’m directly though, but I can get to him.

When’s the last time you sent a fax?

Chris Cruttenden: Believe it or not, I had to send one a couple weeks ago for, like a soccer thing. Nothing to do with health care.

Hoala Greevy: favorite karaoke jam, go-to song?

Chris Cruttenden: Stone Temple Pilots, Vaseline.

Hoala Greevy: Oh that’s a good one. Okay last question, who would win in the Octagon- a silverback gorilla or a polar bear?

Chris Cruttenden: I’m gonna go with polar bear.

Hoala Greevy:Team Polar Bear all the way! I mean c’mon, it’s not even a question. Right on Chris, thanks a lot man!

HIMSS18

The HIMSS Annual Conference & Exhibition brings together 40,000+ health IT professionals, clinicians, executives and vendors from around the world. Exceptional education, world-class speakers, cutting-edge health IT products and powerful networking are hallmarks of this industry-leading conference.

The post Chris Cruttenden: HIMSS18 Interview with Safety Net Connect appeared first on Paubox.