Reducing Shadow IT in healthcare by embracing “good enough for HIPAA” business-friendly SaaS tools
I was invited by the Box.com healthcare team to discuss Shadow IT in Healthcare for their "Secure Cloud Collaboration in Healthcare" webinar. The recorded webinar is available at https://www.brighttalk.com/webcast/8843/67115
software engineering and multi- site healthcare system deployment experience • 12+ years of healthcare IT and medical devices experience (blog at http://healthcareguy.com) • 15+ years of technology management experience (government, non-profit, commercial) • 10+ years as architect, engineer, and implementation manager on various EMR and EHR initiatives (commercial and non- profit) Author of Chapter 13, “You’re the CIO of your Own Office”
When they only had access to MS Office, “Shadow EHRs” were created using Word, Excel, and Access. • In the cloud era, they pick consumer-grade and least-secure options when you don’t give them reasonably secure options instead.
– http://www.hhs.gov/ocr/privacy/hipaa/administrative /omnibus/ Read the rules, don’t take anyone else’s informal legal opinion (these are federal regulations).
Covered Entities [CE] (plans, providers, clearinghouses) • Business Associates [BA] (needs data to help a CE) Safeguards (Guidance) • Administrative • Physical • Technical get a business associate agreement (BAA)
• Consumer-grade ease of use • Auditable with easy to use notifications (reduce permissions requirement) • Workflow-independent • Platform-independent • Device-independent
neither technically challenged nor simple techno-phobes (they’re busy saving lives) • Most technology product decisions are no longer made by the CIOs • Complex, full-featured, products are not better than stand alone tools that have the capability of interoperating with other solutions • Hospitals will not buy unless one proves value.