Raths David
Healthc Inform. 2010 Feb;27(2):20, 22-3.
THE LANDSCAPE: Because HIPAA enforcement previously lacked teeth, many healthcare organizations haven't developed the policies and procedures required to prevent data breaches. The ARRA-HITECH Act is about to change all of that.
HITECH's security provisions and heightened enforcement may force hospitals and their business associates to spend more on training and security features such as encryption and audit trail systems, and to hire consultants to conduct audits.
现状:由于此前《健康保险流通与责任法案》(HIPAA)的执法力度不足,许多医疗保健机构尚未制定预防数据泄露所需的政策和程序。《美国复苏与再投资法案》(ARRA)中的《健康信息技术经济和临床健康法案》(HITECH)即将改变这一切。
HITECH的安全条款以及加强的执法力度可能会迫使医院及其业务合作伙伴在培训以及加密和审计跟踪系统等安全功能方面投入更多资金,并聘请顾问进行审计。