
Weak password and security guidelines put patient health records at risk
Strong passwords are the first line of defense against computer hackers. But a government report warns that patients are at risk because the certification process for electronic health records doesn’t require the use of a strong password.
Strong passwords are the first line of defense against computer hackers. But a government report warns that patients are at risk because the certification process for
An audit by the U.S. Department of Health and Human Services'
"Our audit revealed vulnerabilities with the Temporary EHR certification program,” said
noted that the acceptance of a single character password for certification was inadequate and pointed to the need for more complex passwords.
The ONC currently deputizes private bodies, known as Authorized Testing and Certified Bodies (ATCBs), to certify that records meet defined minimum technology standards in seven information technology areas: access control, emergency access, automatic log-off, audit log, integrity, authentication, and general encryption. The agency also defines the criteria for the certification process.
The ONC responded that the temporary process was no longer active and that its 2014 certification criteria had “strengthened test procedures for common security and privacy features for inclusion in EHRs,” but the OIG says that the 2014 criteria still did not address common security issues, such as password complexity and/or logging emergency access or user privilege changes.
Since 2009, 32 million Americans have had their medical records compromised, according to an
Next: Large-scale cyber breaches becoming more common
Large-scale cyber breaches of personal records, such as the
The Affordable Care Act requires that all public and private healthcare providers and other eligible professionals (EPs) adopt and demonstrate meaningful use of electronic health records beginning January 1, 2014 to maintain their existing Medicaid and Medicare reimbursement levels.
A key factor is that providers can't use noncertified EHR software to attest to meaningful use.
There are financial incentives for healthcare providers who prove meaningful use of EHRs, and penalties for non-compliance. EPs who haven’t implemented EHR systems and demonstrated their meaningful use by 2015 will experience a 1% reduction in Medicare reimbursements, with rates of reduction likely to rise annually thereafter.
In addition to incentives and penalties for EHR adoption, EPs also might have difficulty using the
As a result, EHR adoption is at a
But adopters are looking to the government for assistance in making sure records are safe, a fact noted in the OIG report.
"The process of certifying EHRs is designed, in part, to give providers the confidence to know that patient health information is secure and protected," OIG stated. Government guidance is especially crucial because many healthcare organizations and EPs have little awareness of the risks associated with health information technology,
“Health IT safety often competes with other pressing priorities for limited resources within healthcare organizations,” the ONC wrote in a blog post. “It also tells us that users of electronic health records (EHRs) see EHRs as a solution to patient safety problems, and may not understand new risks that may be introduced by EHRs.”
The large-scale rollout of EHRs comes as hackers are increasingly exploiting vulnerabilities like weak passwords to gain access to personal information. In 2012,
“ONC’s baseline does not address certain specific security concerns and industry best practices,” the OIG audit noted. “Therefore, we continue to recommend that ONC strengthen EHR Test Procedure requirements to address such issues to ensure providers have EHR systems that have adequate security and privacy features.”
Related Articles:
Newsletter
Stay informed and empowered with Medical Economics enewsletter, delivering expert insights, financial strategies, practice management tips and technology trends — tailored for today’s physicians.




















